news4geeks.net
23Jan/120

SharePoint gods peek into colleagues’ info – poll

SharePoint admins are abusing their privileged status to sneak a peak at classified documents according to a poll that shows consistent abuse of security in Microsoft's business collaboration server.

A third of IT administrators or somebody they know with admin rights have read documents hosted in Microsoft's collaboration server that they are not meant to read.

Most popular documents eyeballed were those containing the details of their fellow employees, 34 per cent, followed by salary – 23 per cent – and 30 per cent said "other."

Ironically, the poll found the jury almost split on whether the authors of documents themselves could be trusted to control the security privilege settings on their work.

IT admins are firmly in control of setting access rights within SharePoint; 69 per cent set the permission levels that say who reads what, by individual or by group.


The data comes from a Cryptzone SharePoint security survey of 100 individuals running or using SharePoint systems, which has just been released. Respondents worked for a range of companies of varying size.

The poll reveals a consistently healthy disregard for the security supposedly afforded to company documents by SharePoint. Forty-five per cent of respondents said they'd copied sensitive information to the drive of a local PC or to a USB stick; 43 per cent did it because of the need to work from home; while 55 per cent said they'd done it because the docs were needed by somebody who didn't have access to SharePoint.

Ninety-two per cent of admins said they realised their actions made the material less secure while 30 per cent said they weren't bothered because taking the information had helped them get their job done.

(Source: theregister.co.uk)

 

NSA’s lax ban on USB drives may have contributed to PRISM leaks
News about the NSA and FBI's surveillance programs doesn't just have privacy advocates wringing their hands in consternation; IT security analysts have raised the critical question as to ...
READ MORE
Oracle to ship 40 security fixes for Java SE
Oracle is set to release a patch set for Java SE that targets 40 security vulnerabilities. Thirty-seven of the weaknesses can be exploited over a network without requiring an ...
READ MORE
Microsoft late Friday confirmed that a "zero-day," or unpatched, vulnerability exists in Internet Explorer 8 (IE8), the company's most popular browser. According to multiple security firms, the vulnerability ...
READ MORE
If you run a bank and use an IP video camera from D-Link, you may want to pay attention to this. A number of IP-based surveillance video cameras made by D-Link ...
READ MORE
McAfee said it has found a vulnerability in Adobe Systems' Reader program that reveals when and where a PDF document is opened. The issue is not a serious problem and does ...
READ MORE
NSA’s lax ban on USB drives may have
Oracle to ship 40 security fixes for Java
Microsoft admits zero-day bug in IE8, pledges patch
D-Link firmware flaws could allow IP video stream
McAfee spots Adobe Reader PDF-tracking flaw

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.