Skip to content.

TalkBMC

Sections
You are here: Home » Blogs » Seshadri Veeraraghavan » The Fulcrum » The Role of the End User

The Role of the End User The Role of the End User

Document Actions

Nothing much new here, but just to underscore the critical nature of education, enforcement, and effective action:

http://www.informationweek.com/blog/main/archives/2007/12/we_need_to_talk.html

John Soat talks about how end users take untold liberties with IT policies and probably take them as suggestions rather than mandatory rules. It's quite complex as to why this happens -- it's quite clear that they probably know what they're doing is wrong, but just not *so* wrong that they shouldn't do it.

See, the issue is that many of these areas are left in the gray part of 'can do or must not do' policies. And worse, I'm willing to bet that 99% of employees have NO IDEA what constitutes proper 'secure' behavior and what constitutes a violation of company policy and thus their employment contract.

Along with continual education, the only other way to make sure that corporate data doesn't leave the network is by using software to track the packets and ensuring they are not sensitive. To do that you'd have to get one of those 'anti leak' DLP software modules (like what Vontu/Symantec does) and establish clear demarcations between acceptable and non-acceptable information leaving the network.

Any practical ideas from readers?


_____
tags:
Sunday, December 16, 2007  |  Permalink |  Comments (0)
Seshadri Veeraraghavan

Subscribe to Sesh's blog Subscribe to Sesh's blog

Seshadri Veeraraghavan's Bio

The Fulcrum
« May 2008 »
Su Mo Tu We Th Fr Sa
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
2008-05-14
12:52-12:52 On SLM
 

Powered by Plone

This site conforms to the following standards: