Savvy administrators recognize that because end-users are privy to an organization’s sensitive data, they represent a significant risk factor. Security pros, however, continue to struggle with mitigating this threat. While no single solution exists, there are steps organizations can take to ensure that corporate policies are effectively enforced and insider threats are minimized.
Organizations should clearly define and publicize policies, automate policy enforcement, and provide detailed auditing and reporting. Here are some fundamental steps organizations can take:
First, accept that employees will always engage in risky behavior. They will open unsolicited attachments, browse a wide assortment of Web sites, click on links in e-mails and instant messages, utilize outdated and unpatched versions of software, and plug in personal devices or removable media without understanding the potential impact of these decisions.
In a perfect world, written corporate policy would be enough to dictate employees’ interactions with technology. While a policy is an important step, the reality is that even the most stringent policies need a solution to support and enforce them.
The second step is to provide a way to develop and enforce policies that enable users to focus on their assigned tasks, but also reduces the risk of their day-to-day decisions when they interact with technology. This includes understanding which employees need access to specific applications, devices and data.
Also, enforce policies that give users access only to what is required in order to successfully complete their job function, and ensure that the applications in use are up to date with the latest patches.
By enforcing application and device control, organizations can flexibly control execution of specific files or removable devices to the user level.
Also, by enforcing mandatory baselines for critical patches and configurations, organizations can automate the remediation process throughout the enterprise and not have to rely on users. This ensures proper security configurations are…