If you see more world cybercrime, it had weaknesses that resulted from the fact people in or from officers who attacked the company. John N. Stewart, the head of security from Cisco has been conducting the survey through InsightExpress, a market research company responsible for the security of the data business observed the behavior of employees and work environment. Survey conducted on 1,000 employees and 1,000 IT professionals from various industries and companies that are scattered in 10 countries, namely, the United States, Great Britain, France, Germany, Italy, Japan, China, India, Australia and Brazil, in which each country has differences social cultural, economic, and the adoption of the Internet. The following observation from InsightExpress lifestyle and professional IT staff of potential harm to the company:Changing the security settings on the computer. One of the five employees have to change security settings for the computer to go through the existing rules so that they can access a website that does not have authorization. This often happens in China and India, and there are more than 52 percent said they only want to access the curious website.
Using applications that do not have the authority. Seven out of ten IT professionals said that employees have Unauthorized use applications and websites, such as downloading music and shopping online, which resulted in more than half the company's data lost in these incidents. This is common in the United States around 74 percent and India, 79 percent.
Using the network or facilities that do not have the authority. Two of the five employees who have access to IT network or facilities that are not legitimate. This is common in China, and about 14 percent of the incidents occurred in this month.
Sharing confidential corporate information. One of the four employees, or about 24% admitted that they have a verbal sharing sensitive information with non-employees, such as friends, family or strangers. When the investigation, they reasoned, need friends to share ideas, and most of them do not realize that all that is wrong.
Sharing devices from the company. Around 44 percent of IT employees have been sharing tools work with non-employees, without the permission of the company.
Can not differentiate work and personal devices. Two of the three officers have admitted using the office computer every day for personal purposes, including music downloads, online shopping, banking, news, chat, and so forth. More than 60 percent of them have been using a personal email to serve customers and colleagues.
Using a device that is not Protected. At least one of three employees who leave their computers to log on and unlocked, when they are not in their desks. Computers are the worst, especially without the log og, can create a data theft incident, access to corporate data, and personal data.
Login and password theft. One of the five IT employees save login and password data in their computer and write, and then leaving them in the table, or in the Cabinet that is not locked, or was in front of the computer. About 28 percent occurred in China, and because of this they lost the login and password data for personal financial accounts.
Invite friends or strangers into the area office. More than one of five IT professionals in Germany, or approximately 22 percent of the incoming call was non-employees in the office environment. Approximately 18 percent, the employee was not allowed to use corporate facilities at the request of staff.
Loss of portable storage media. Around 22 percent or one of the four officers have been carrying corporate data in portable media, outside the office. This is 41 percent common in China, and has created a risk for loss or theft of company data.
John N. Stewart recommends some step to prevent loss of data:
- Identify the data, with a good set of data, know how the data are stored, accessed and used
- Maintain the data, whether corporate or personal, such as maintaining the money
- For the owner of the company, tell employees how to protect data as well as to get their money
- Create a global policy objectives in order to feel comfortable when employees - should report incidents so that problems can be resolved more quickly
- Develop security awareness, education and training, teamwork also for data protection company.

0 comments:
Post a Comment