|
Rising to a Higher Standard Isn't Easy |
|
|
|
Source: ComputerWorld.com - Posted by Benjamin D. Thomas
|
Some employees are held to a higher standard of behavior than most. Anyone in a position with broad powers or influence falls into this group, including accountants, managers, systems administrators -- and information security professionals.
Like systems administrators, information security professionals generally have access to a great deal of data and information. Even if they don't have direct access, they generally know how to obtain it by exploiting a weakness (like hackers, but with the opposite intent) or by simply giving themselves elevated privileges.
In our small shop, the systems administrators, help desk workers and security people all have a great deal of access. This past week, some issues arose that caused me to go back to some best practices regarding access. One is called separation of duties, and the other is called the principle of least privilege.
Read this full article at ComputerWorld.com
Powered by AkoComment! |