Next webcast:
"De-mystifying SharePoint Security"
Date: Tuesday, May 1, 2012, 2PM MT
CipherPoint conducts webcasts on SharePoint security and compliance topics, including HITECH compliance and SharePoint, SharePoint Defense in Depth, content security, and others. For links to replays of recent webcasts, please visit our webcasts page.
If you ever needed convincing that the insider threat is real, check this article in Infoworld out.
A few of the key findings from the study:
Not sure why the figures for UK employees are so much higher. I'll refrain from speculating lest I upset my friends in the UK.
This related article from CSO which discusses the authorized insider threat is worth a read as well.
CipherPoint's take away from this: your sensitive information/crown jewels have always been most at risk from insiders, whether authorized ones stepping out of bounds, or unauthorized ones. Despite the rash of hacking for profit, advanced persistent threat, hacktivism, etc., this is still true today, and likely always will be.
Security controls (including process ones aimed at people, like background checks, detective controls such as DLP and audit logging, and preventive controls like encryption for sensitive content) should be fundamental to your security program. If you fail to think about insiders as potential threats, you may be in for a surprise down the road. And it's not just Wikileaks and state secrets we're talking about here, it's valuable IP, customer lists, employee payroll files, EPHI, customer financial data, files containing credit card data, and other sensitive information- the stuff that all corporations have, and frequently store in unstructured data file repositories.
And yes, this includes for collaboration and content management platforms like SharePoint, and it includes cloud collaboration platforms such as Yammer, SharePoint Online, Box.net, Dropbox, and others.
JD
CipherPoint writes a regular column on SharePoint Security and Compliance on EndUserSharePoint. Check them out here.
