Follow this blog:
RSS
Email Alert

TR Dojo

Video: Five ways to keep your own IT staff from stealing company secrets

Takeaway: The arrest of a network administrator who hijacked the city of San Francisco’s network brought attention to a dangerous and often ignored threat–your own admins. In this IT Dojo video, Bill Detwiler discusses security practices to protect company secrets from the very people who should be keeping them safe.

High-profile breaches of private data are often the results of lost or stolen equipment, malicious hackers, or improperly disposed of storage devices. Yet, the July 2008 arrest of a network administrator who hijacked the city of San Francisco’s network focused the spotlight on a potentially more dangerous threat–your own admins.

In this IT Dojo video, I discuss the following five security practices that will help protect your company secrets from the very people who should be keeping them safe:

  1. Follow the rule of least privilege
  2. Not all IT staff should be domain admins
  3. Monitor additions to admin-level groups
  4. Log all administrative activity
  5. Immediately revoke admin rights for terminated IT staff

After watching the video, you can read more on these five security suggestions in Tom Olzak’s article, “How do you keep your sys admins from stealing company secrets?”–the basis for this video.

Get IT Tips, news, and reviews delivered directly to your inbox by subscribing to TechRepublic’s free newsletters.

Bill Detwiler

About Bill Detwiler

Bill Detwiler is Head Technology Editor of TechRepublic. Previously, he worked as a Support Tech and IT Manager in the social research and energy industries.

Bill Detwiler

Bill Detwiler
Bill Detwiler is Head Technology Editor for TechRepublic. Previously he worked as a Technical Support Associate and Information Technology Manager in the social research and energy industries. Bill is a Microsoft Certified Professional with experience in Windows administration, data management, desktop support, and system security.

Bill Detwiler

Bill Detwiler
Bill Detwiler has nothing to disclose. He doesn't hold investments in the technology companies he covers.
33
Comments

Join the conversation!

Follow via:
RSS
Email Alert