• Skip Navigation |
  • Accessibility 
Sustainable Manufacturing Summit (19-21 Nov, Belgium)
IT-Director.com Logo
  • What is Symantec's vision?
  • MarketSight 7.0 - Survey Analysis Made Simple
  • Learning from the credit crunch to avoid a broadband crunch
 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • RESEARCH
  • EVENTS
  • NEWSWIRE
  • BLOGS
  • POLLS

  

Member Login | Become a Member

 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • Storage Expo 2008
    15th October - 16th October
    London, United Kingdom
  • Virtual Worlds London
    20th October - 21st October
    London, United Kingdom
POPULAR PAPERS
  • Keep Talking Not Spending by Quocirca
  • Remote IT Management by Quocirca
  • We are all IT users now by Quocirca
TRANSLATE PAGE



USEFUL LINKS
  • Last 7 Days
  • Archives
  • Market Place
  • Top Articles
  • Hall of Flame
INTERACT
  • Advertising
  • About IT-Director.com
  • Site Feedback
  • Newsletters
  • Contact Us
  • Registration
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "I've just learned about his illness. Let's hope it's nothing trivial." - Irvin S. Cobb

ADVERTISEMENT
Blogs > Nigel Stanley

DBA snaffles data - the Inside Threat continues

Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 5th July 2007
Copyright Bloor Research © 2007
Logo for Bloor Research
Page Tools

Request Reprints
Tell A Friend
Contact Author

Recent Blog Posts
  • PGP and IBM Supporting Bletchley Park
  • The importance of saving Bletchley Park
  • The real cost of data loss is down to butterflies
  • Glengarry Glen Ross - Old Fashioned Inside Threat
  • Symantec Spammers Rock 'n' Roll
  • Crap Government IT Rules OK? Oh well, pass the biscuits.
Blog Archive
  • September, 2008
  • July, 2008
  • March, 2008
  • January, 2008
  • December, 2007
  • November, 2007
  • October, 2007
  • September, 2007
  • May, 2007
  • April, 2007
  • January, 2007
  • November, 2006
Syndication
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon

Fidelity National Information Services, a provider of financial processing services to institutions in the US, recently announced that an employee who was employed as a database administrator (DBA) made off with 2.3 million records comprising banking and credit card data.

It would appear that the data ended up with a marketing agency that used it to solicit new business.

Apparently the former DBA had worked there for 7 years and was deemed to be a mid-level employee. From my studies of the Inside Threat this is the ideal profile of an internal security risk—the competent and malicious employee whose motives I'll never know but could take a good guess at.

Of course it is troubling that the data was misappropriated, and indeed more interesting in this case as the data was physically removed rather than transferred electronically.

But at the heart of the issue is why has so much power been vested in one individual? Clearly there was no separation of duties being implemented. If it was then no one person could access so much data by themselves.

I am guessing, but as the data was physically removed from the premises I would imagine that it went in the form of a backup tape, slipped into a briefcase and walked out the door. I would also guess that the backup data was either insecure or the DBA knew the password.

Of course separation of duties is a complete logistical nightmare. Very difficult to set up and very difficult to police without very expensive systems and procedures.

But surely reputational risk is even more costly?

Reader Comments

We are no longer accepting comments against this item. We suggest contacting the author directly.

  • Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)203 051 5760 | F: +44 (0)870 345 9922