About
Subscribe
  • Home
  • /
  • Software
  • /
  • Internal threats could undermine your information technology security

Internal threats could undermine your information technology security

By CubicICE
Johannesburg, 20 Aug 2003

Despite a large focus on external information technology (IT) threats, research shows that around 70% of the security risk is internal - either malicious or by accident. Security management solutions from NetIQ, distributed locally by 10Net, enable companies to manage internal security, including administrator/user privileges and monitoring and enforcement of policy.

The level of IT administrative access given to persons in an organisation is an issue that can undermine security. With Windows NT, you can assign people to be account operators, administrators and server operators, etc. But many companies require a greater degree of selectivity in order to restrict which properties a person can change. Partitioning authority using Windows NT results in more administration, hardware and software. In contrast, Directory and Resource Administrator (DRA) from NetIQ enables a company to effortlessly grant limited and fine-grained administrative powers. For example, with DRA your Help Desk can reset passwords without being given any administration privileges. Together with other simple tasks like adding/removing users, these can be accomplished via an easy-to-use web interface that requires little or no training.

"DRA provides log entries detailing actions performed. For example, if one employee resets the password on another`s account, the DRA log entry will say exactly that, in plain language. This provides easy-to-follow audit trails to help you manage and secure your company`s IT infrastructure," says Neil Cosser, general manager of 10Net.

"Relying on end users to do security checking is risky. Employees cannot be trusted to update their software or even to run it. Companies need to control and enforce security processes from a central location - ensuring that vulnerability assessment and anti-virus software can be deployed, updated and monitored centrally," believes Cosser.

Often companies install ad hoc security products with no central management system, which results in a costly, complex and incomplete protection of IT infrastructure. NetIQ`s Security Manager is enterprise-scalable to thousands of servers and workstations, allowing IT professionals to fully integrate and leverage from other security solutions operating in the organisation. Suppose, for example, someone trying to crack a password moves from workstation to workstation to avoid detection. Under normal circumstances, this wouldn`t raise any alarms, because the only way to notice the intruder would be on a computer-by-computer basis. Security Manager can detect a pattern that raises an alert, as well as initiating an automated response, such as disabling user ID for a period.

Besides putting IT security systems in place, companies need to verify that they are meeting security policy and regulatory compliance requirements in all areas of the business. Vulnerability and Configuration Management Solutions from NetIQ provide multiple platform security tools that produce an audit trail depicting levels of compliance in the company.

To provide comprehensive administration and management of IT infrastructure 10Net distributes the entire range of NetIQ products namely Web Analytics, Windows and Exchange Management, Security Management and Administration, and Performance and Availability Management software products.

Share

Editorial contacts