Gartner: Unattended PCs a menace
It's 10 a.m. and you're on break; so who's using your computer?
September 29, 2005 12:00 PM ETTechWorld.com -
Many organizations turn a blind eye to the risks posed by PCs that are logged into corporate networks but left unattended, according to a new analysis from research firm Gartner Inc.
The main risk is that confidential information could be accessed and changed in an effort to carry out fraud, Gartner said, although the tendency of employees to send bogus or prank e-mails is also a concern. The latter can have potentially serious legal consequences.
Another potentially damaging issue is that lax PC security could allow employees who gain illegal access to data a way to plausibly deny any wrongdoing -- something Gartner termed the "someone else used my PC" defense. If companies can't prove that malicious activity was done by the person using the PC, disciplining them would be difficult.
"There is little point in implementing some sort of sophisticated identity and access management system unless you can ensure that when people are logged into systems, they stay at their PCs," said Jay Heiser, co-author of the report.
According to Gartner, there is no easy solution to the problem. Some companies should consider using timeouts, which force users to log back into servers after predetermined periods. But that idea tends to be unpopular with employees.
Another solution for organizations that don't want to impose repeated log-ins on their staffs are authentication systems such as proximity tokens. Such systems are able to automatically disconnect and reconnect users depending on how close they are to their workstations. Logging in requires having a physical token, which can reduce the risk of unauthorized access.
Those options, however, can add cost and management overhead, and the tokens themselves could be stolen -- though many systems can be configured to require passwords as a backup.
If timeouts are used, they should always be shorter for devices connecting through risky technologies such as VPNs. Gartner suggested 15-minute time-outs as a useful guide for PCs, 10 minutes for a laptop and five minutes for a handheld computer. But those time-out proposals depend on location.
Reprinted with permission from
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
IDC White Paper: CCM for IT Compliance and Risk Management
Learn from industry analysts how IT organizations are using configuration management to meet compliance requirements and instill best practices. Find out how these...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Keep it Clean: Maintaining the Integrity of your CMDB through Change Detection
Learn how configuration drift can challenge configuration management database (CMDB) integrity and how a configuration audit tool and an effective change management process...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
HIPAA requires businesses that handle personal health information (PHI) to set up strong controls to ensure the security and integrity of that information....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Configuration Assessment: Choosing the Right Solution
Configuration assessment lets businesses proactively secure their IT infrastructure and achieve compliance with important industry standards and regulations. Learn why configuration assessment is...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
