Its the Databases, Stupid! - You can't say you don't have one somewhere in your enterprise
Monday, June 15th 2009 @ 7:14 PM (not yet rated)
This article has a good summary of the motivations and mechanisms that are causing social networking sites to be a threat to enterprises.
http://www.threatpost.com/blogs/social-networking-attacks-target-enterprise-data
It does cover some fundamental problems that IT security managers need to be concerned with. However, one mechanism they don't discuss is weak passwods on multiple accounts at work and at home.
Either way, the article uncovers the most likely ultimate target in your enterprise - your databases.
Most organizations have at least one database, whether it's for client lists, orders, inventory, financial accounts... anything hackers can use to make money. The database is where most of the valuable information is, and it's pretty easy to find if there are insufficient safeguards in place.
The article also points out the need for security fundamentals within the enterprise, including layered security policies and proper access controls. Security awareness is essential, especially if social networks or any outsourced Web 2.0 enterprise services on are accessible.
But, even personal Facebook pages that are only accessed from home can contain clues that allow attackers to piece together enough information to gain a foothold in an enterprise network, all in the name of getting access to your data, conveniently stashed in giant heaps within your databases.

| | Is your security awareness training just a set of old Powerpoint slides that you pull out once a year and present at an all-hands meeting? You can now provide much more effective security awareness training for your staff, for much less cost than you think. Contact me if you'd like to discuss how you can create a culture of security through a variety of live programs, and modern e-Learning techniques.
Scott Wright
The Streetwise Security Coach
Join the Streetwise Security Zone at: http://www.streetwise-security-zone.com/join.html
Phone: 1-613-693-0997 Email: scott@streetwise-security-zone.com Twitter ID: http://www.twitter.com/streetsec
To receive weekly security tips and other notices about helpful content available on this site, please make sure you are on my list by clicking HERE, and entering your name and email address.

|