news4geeks.net
23Jan/120

SharePoint gods peek into colleagues’ info – poll

SharePoint admins are abusing their privileged status to sneak a peak at classified documents according to a poll that shows consistent abuse of security in Microsoft's business collaboration server.

A third of IT administrators or somebody they know with admin rights have read documents hosted in Microsoft's collaboration server that they are not meant to read.

Most popular documents eyeballed were those containing the details of their fellow employees, 34 per cent, followed by salary – 23 per cent – and 30 per cent said "other."

Ironically, the poll found the jury almost split on whether the authors of documents themselves could be trusted to control the security privilege settings on their work.

IT admins are firmly in control of setting access rights within SharePoint; 69 per cent set the permission levels that say who reads what, by individual or by group.


The data comes from a Cryptzone SharePoint security survey of 100 individuals running or using SharePoint systems, which has just been released. Respondents worked for a range of companies of varying size.

The poll reveals a consistently healthy disregard for the security supposedly afforded to company documents by SharePoint. Forty-five per cent of respondents said they'd copied sensitive information to the drive of a local PC or to a USB stick; 43 per cent did it because of the need to work from home; while 55 per cent said they'd done it because the docs were needed by somebody who didn't have access to SharePoint.

Ninety-two per cent of admins said they realised their actions made the material less secure while 30 per cent said they weren't bothered because taking the information had helped them get their job done.

(Source: theregister.co.uk)

 

Apple patches Safari, blocks outdated Flash Player
Apple on Wednesday patched four security vulnerabilities in Safari and blocked outdated versions of Adobe's Flash Player from running in its browser. The Flash blocking move was similar to ...
READ MORE
Half of all Macs will lack access to security updates by summer
Unless Apple changes its security update practice, nearly half of all Mac users will be adrift without patches sometime this summer. Apple will launch OS X 10.8, aka Mountain ...
READ MORE
Avaya revs Identity Engines for more secure BYOD
Network and security vendors such as Cisco, Juniper, and Enterasys are lining up at Interop this week with products aimed at easing security admins' BYOD-spawned migraines. Also in the ...
READ MORE
Microsoft on Thursday identified a Chinese security partner as the source of a leak last March in its highly restricted vulnerability information-sharing program. The company, Hangzhou DPTech Technologies, was ...
READ MORE
Scammers create fake Instagram app on Android
According to security company Sophos, a Russian web site has sprung up which offers a fake version of the popular Instagram app for Android. The Russian language site ...
READ MORE
Apple patches Safari, blocks outdated Flash Player
Half of all Macs will lack access to
Avaya revs Identity Engines for more secure BYOD
Microsoft boots Chinese firm for leaking Windows exploit
Scammers create fake Instagram app on Android

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.