<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Most IT staffers ignore security policies</title>
	<atom:link href="http://www.docucrunch.com/most-it-staffers-ignore-security-policies/feed" rel="self" type="application/rss+xml" />
	<link>http://www.docucrunch.com/most-it-staffers-ignore-security-policies</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Mon, 08 Aug 2011 21:53:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: printer cartridge supplies</title>
		<link>http://www.docucrunch.com/most-it-staffers-ignore-security-policies/comment-page-1#comment-180</link>
		<dc:creator>printer cartridge supplies</dc:creator>
		<pubDate>Fri, 28 Aug 2009 11:36:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.docucrunch.com/?p=1074#comment-180</guid>
		<description>I guess they&#039;re too confident that they can outwit hackers and virus. Nice attitude!</description>
		<content:encoded><![CDATA[<p>I guess they&#8217;re too confident that they can outwit hackers and virus. Nice attitude!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeffrey</title>
		<link>http://www.docucrunch.com/most-it-staffers-ignore-security-policies/comment-page-1#comment-87</link>
		<dc:creator>Jeffrey</dc:creator>
		<pubDate>Thu, 09 Jul 2009 17:01:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.docucrunch.com/?p=1074#comment-87</guid>
		<description>Seems fashionable to blame it on training. Supervisors and managers are the key. The training department can help to develop the knowledge and skill. Application on-the-job  and complying with the rules is another matter.</description>
		<content:encoded><![CDATA[<p>Seems fashionable to blame it on training. Supervisors and managers are the key. The training department can help to develop the knowledge and skill. Application on-the-job  and complying with the rules is another matter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JParr</title>
		<link>http://www.docucrunch.com/most-it-staffers-ignore-security-policies/comment-page-1#comment-85</link>
		<dc:creator>JParr</dc:creator>
		<pubDate>Thu, 09 Jul 2009 15:29:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.docucrunch.com/?p=1074#comment-85</guid>
		<description>IT people are usually tinkerers by nature.

A good way to handle this is to set up a common &quot;lab&quot; area, which nowadays can be in the form of a virtual environment, that the IT folks can use to tinker with new software or procedures.  By policy, IT leadership must enforce desktop standards, and the IT folks have to adhere to those standards as well.  One of the best arguments for this, is that if the IT staff are not running a standard image, how can they effectively troubleshoot an end-user issue?  Meanwhile, the lab can be a sandbox for tinkering.

There needs to be a policy in place against privileged access of confidential information, except in the case that it&#039;s work-related.  In the &quot;bad old days&quot; of the early to mid 90&#039;s, there were lots of IT folks, especially at smaller companies, that would go in and read the CEO&#039;s e-mail or other documents, because they figured no one would ever find out.  The good news is that Sarbanes-Oxley, GLB, PCI, HIPAA, and a host of other regulatory measures have forced a level of maturity on the IT industry as a whole.  A true IT professional would NEVER breach the company&#039;s trust by accessing confidential data without authorization, but having audit measures in place helps &quot;keep the honest people honest&quot;.

Speaking from an IT leadership role, the IT folks need to be informed of the policy, informed of a zero-tolerance disciplinary policy, and FIRED immediately (with immediate termination of access) if they break the policy.  There should be a special onboarding process for IT folks, and a yearly general review of departmental policies and procedures.

Many times, IT folks use their personal memory sticks or USB drives to copy data because it&#039;s expedient, not for any other reason.  It is a minor investment to purchase small form factor (known as 2.5&quot;) USB hard drives for every IT staffer, which can be reformatted so that it can use Microsoft (EFS) encryption, or purchase a 3rd-party encryption tool.  If you give the IT staff effective tools that simplify their job, they will use them, and keep the company&#039;s data safe at the same time.

Sometimes there is a huge disconnect between IT and the rest of the business.  Helping every IT staffer understand how the company makes money, their role in the company, and how they contribute to revenue is vital.  Helping them understand the value of the data they protect and the role in protecting that data allows people to see the &quot;big picture&quot;.  Once IT feels that it has a &quot;stake&quot; in the business (&quot;....and THAT&#039;s how you get your paycheck....&quot;), then IT will be more proactive in practicing security rather than just IMPLEMENTING it, and often they will find innovative ways to help protect the company&#039;s data.</description>
		<content:encoded><![CDATA[<p>IT people are usually tinkerers by nature.</p>
<p>A good way to handle this is to set up a common &#8220;lab&#8221; area, which nowadays can be in the form of a virtual environment, that the IT folks can use to tinker with new software or procedures.  By policy, IT leadership must enforce desktop standards, and the IT folks have to adhere to those standards as well.  One of the best arguments for this, is that if the IT staff are not running a standard image, how can they effectively troubleshoot an end-user issue?  Meanwhile, the lab can be a sandbox for tinkering.</p>
<p>There needs to be a policy in place against privileged access of confidential information, except in the case that it&#8217;s work-related.  In the &#8220;bad old days&#8221; of the early to mid 90&#8242;s, there were lots of IT folks, especially at smaller companies, that would go in and read the CEO&#8217;s e-mail or other documents, because they figured no one would ever find out.  The good news is that Sarbanes-Oxley, GLB, PCI, HIPAA, and a host of other regulatory measures have forced a level of maturity on the IT industry as a whole.  A true IT professional would NEVER breach the company&#8217;s trust by accessing confidential data without authorization, but having audit measures in place helps &#8220;keep the honest people honest&#8221;.</p>
<p>Speaking from an IT leadership role, the IT folks need to be informed of the policy, informed of a zero-tolerance disciplinary policy, and FIRED immediately (with immediate termination of access) if they break the policy.  There should be a special onboarding process for IT folks, and a yearly general review of departmental policies and procedures.</p>
<p>Many times, IT folks use their personal memory sticks or USB drives to copy data because it&#8217;s expedient, not for any other reason.  It is a minor investment to purchase small form factor (known as 2.5&#8243;) USB hard drives for every IT staffer, which can be reformatted so that it can use Microsoft (EFS) encryption, or purchase a 3rd-party encryption tool.  If you give the IT staff effective tools that simplify their job, they will use them, and keep the company&#8217;s data safe at the same time.</p>
<p>Sometimes there is a huge disconnect between IT and the rest of the business.  Helping every IT staffer understand how the company makes money, their role in the company, and how they contribute to revenue is vital.  Helping them understand the value of the data they protect and the role in protecting that data allows people to see the &#8220;big picture&#8221;.  Once IT feels that it has a &#8220;stake&#8221; in the business (&#8220;&#8230;.and THAT&#8217;s how you get your paycheck&#8230;.&#8221;), then IT will be more proactive in practicing security rather than just IMPLEMENTING it, and often they will find innovative ways to help protect the company&#8217;s data.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- This site's performance optimized by W3 Total Cache. Dramatically improve the speed and reliability of your blog!

Learn more about our WordPress Plugins: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (user agent is rejected)
Database Caching 5/12 queries in 0.015 seconds using disk

Served from: lamp06.pbp.com @ 2012-02-11 08:54:56 -->
