 |
 |
 |
A new study by Computer Economics, "Insider Misuse of Computing Resources," looked at security risks posted by employees who inadvertently expose their organizations to possible information loss or compromise. The survey included 100 IT security professionals and executives.
External threats to data security are clear, says Computer Economics president Frank Scavo, but the nature of internal threats may be less so.
For example, over one-third of organizations surveyed lack policies against loading sensitive data onto portable storage devices like USB flash drives.
This practice recently compromised a secure data network at the Pentagon.
|
|
- 1. Portable Storage Misuse
Organizations citing risk: 57% - 2. Software Downloading
Organizations citing risk: 56% - 3. P2P File-Sharing
Organizations citing risk: 54% - 4. Remote-Access Programs
Organizations citing risk: 53% - 5. Rogue Wi-Fi Access Points
Organizations citing risk: 48% - 6. Rogue Modems
Organizations citing risk: 47% - 7. Media Downloading
Organizations citing risk: 40% - 8. Personal Devices
Organizations citing risk: 40% - 9. Unauthorized Blogging
Organizations citing risk: 25% - 10. Personal IM Accounts
Organizations citing risk: 24% - 11. Message Board Posting
Organizations citing risk: 19% - 12. Personal Email Accounts
Organizations citing risk: 16% - 13. Non-Work Web Browsing
Organizations citing risk: 14% - 14. Business Email Misuse
Organizations citing risk: 6%
|