FOR IMMEDIATE RELEASE
CONTACT:
Survey of More Than 800 IT Personnel and Executives
Exposes Ubiquity of Orphaned Accounts as a Critical
IT Security Vulnerability
Leading Provider of Identity and Access Management Solutions Selected as the Winner in the Privileged Access Management Category
AGOURA HILLS, Calif. - May 19, 2008 - Symark
International, developer of the PowerSeries information
security solutions for managing privileged account
access, today announced the results of a survey
of more than 850 security, IT, HR and C-level
executives across all industries. Conducted by
eMediaUSA, the survey focused on orphaned accounts
user accounts that remain active after an employee
has left a companyand the processes organizations
have in place to locate and terminate them. The
study revealed that 42 percent of businesses do
not know how many orphaned accounts exist within
their organization, and 30 percent of respondents
said they have no procedure in place to locate
orphaned accounts.
Orphaned accounts represent a significant problem among organizations across all industries. Unfortunately, many IT staffs tend to be overworked and as a result, these open accounts are often overlooked, said Sally Hudson, research director, security products and services, IDC. Whenever an employee leaves an organization, IT and security administrators should make it a priority to shut down their access immediately. Failure to do so creates gaping holes through which hackersor malicious insiders who are familiar with the IT environmentcan access and pilfer sensitive material.
Other key findings from the survey include:
Controlling access to proprietary systems and
information continues to present an IT security
challenge. In fact, in our upcoming research report
entitled IT Governance, Risk and Compliance Management
in the Real World, gaps in access and entitlements
controland the significant audit defects resulting
from themare one of the concerns most frequently
mentioned in focus interviews, said Scott Crawford,
research director at Enterprise Management Associates.
The significant threat posed by the existence
of orphaned accounts contributes to this issue,
and our findings on this topic align with the
results of Symarks survey. For example, one IT
auditor revealed that in a 5,000-employee financial
services firm, 43 percent of existing access rights
were either excessive or should have been retired.
By now, most security professionals understand that a vast majority of data breaches involve some sort of insider impropriety. However, the threat from within continues to remain a major hurdle, largely due to the sheer number of avenues available to an employee to carry out malicious activity, said Bob Farber, chief executive officer at Symark International. As the sobering results of this study demonstrate, orphaned accounts represent a major security and compliance challenge and are often overlooked as a potential threat vector. It is clear that organizations must implement polices and technologies to ensure that user accounts are terminated swiftly as soon as the employee leaves the company, especially for large, international enterprises managing locations across the globe.
About Symark International
Symark International is the leading provider of
systems access management solutions for heterogeneous
IT environments. Symark PowerBroker enables granular
delegation of administrative privileges while
restricting UNIX/Linux root account access. Symark
PowerPassword provides UNIX/Linux user account
management along with login and password security
policies. Symark PowerKeeper controls access
to shared administrative accounts for servers,
applications, and network devices for multiple
platforms. Symark PowerADvantage extends Microsoft
Active Directorys centralized authentication,
authorization, account access, policy enforcement
and infrastructure management functionality to
UNIX and Linux systems. All products offer a non-intrusive
architecture, central administration, accountability
at the systems level and detailed audit logs.
Symark offers extensive expertise in enterprise
computing security, and its products are backed
by unmatched technical support. For more information,
visit us at www.symark.com.
###
NOTE TO EDITORS: If you would like additional information on Symark and its products, please view the Symark web site at www.symark.com. Symark, the Symark logo, PowerPassword, PowerBroker, and PowerKeeper are trademarks or registered trademarks, in the United States and certain other countries, of Symark Software. Additional company and product names may be trademarks or registered trademarks of the individual companies and are respectfully acknowledged. © 1985-2008 Symark International, Inc. All rights reserved.
Site MapContact UsPrivacy Policy/ California Privacy RightsHome
|
