IT-Analysis.com
IT-Analysis.com Logo
Enterprise SME Business Issues Technology Services Channels
Module Header
Neil Ward-DuttonMWD Advisors
Neil Ward-Dutton
9th March - Keynoting at CloudSlam '10
Laurie McCabeLaurie McCabe
Laurie McCabe
9th March - What is Social Media Management, and Why Should You Care?
David TebbuttTeblog
David Tebbutt
6th March - Are multi-touch surfaces heading your way?
Fern HalperFern Halper
Dr Fern Halper
5th March - My Take on the SAS Analyst Conference
Laurie McCabeLaurie McCabe
Laurie McCabe
3rd March - NetSuite's SP 100 Program: An Offer VARs Can't Refuse?
Module Header
Q. What features do you want to see on this site?
 
Blogs > Nigel Stanley
DBA snaffles data - the Inside Threat continues
Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 5th July 2007
Copyright Bloor Research © 2007
Logo for Bloor Research

Fidelity National Information Services, a provider of financial processing services to institutions in the US, recently announced that an employee who was employed as a database administrator (DBA) made off with 2.3 million records comprising banking and credit card data.

It would appear that the data ended up with a marketing agency that used it to solicit new business.

Apparently the former DBA had worked there for 7 years and was deemed to be a mid-level employee. From my studies of the Inside Threat this is the ideal profile of an internal security risk—the competent and malicious employee whose motives I'll never know but could take a good guess at.

Of course it is troubling that the data was misappropriated, and indeed more interesting in this case as the data was physically removed rather than transferred electronically.

But at the heart of the issue is why has so much power been vested in one individual? Clearly there was no separation of duties being implemented. If it was then no one person could access so much data by themselves.

I am guessing, but as the data was physically removed from the premises I would imagine that it went in the form of a backup tape, slipped into a briefcase and walked out the door. I would also guess that the backup data was either insecure or the DBA knew the password.

Of course separation of duties is a complete logistical nightmare. Very difficult to set up and very difficult to police without very expensive systems and procedures.

But surely reputational risk is even more costly?

Reader Comments

We are no longer accepting comments against this item. We suggest contacting the author directly.

Advertisement



Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761
Email: