IT firms report widespread data risks
Firms are offloading data risk to IT providers, according to a new survey by data research institute Ponemon and governance software provider Aveksa
WALTHAM, MA & TRAVERSE, MI – IT providers are not being given enough information to mitigate the data risks of their clients, says a new study by data research institute Ponemon commissioned by governance software firm Aveksa.
The study, The 2008 National Survey on Access Governance, questioned 700 US IT practitioners on their information management relationships with their clients – the two largest employers being the financial services industry (21%) and government institutions (18%).
The survey says 78% of respondents thought employees are granted access to data for which they have no need, with inadequate tools in place to inform and update IT providers of employees’ specific and often evolving responsibilities.
“The IT security organisations are judged on how quickly they deliver access. There’s no automated process to engage a business unit to regularly review users’ access to different information resources. They’re using a manual approach – spreadsheets and email – and it is very inefficient,” says Brian Cleary, Aveksa’s vice-president of marketing.
IT practitioners cannot easily automate policy enforcement and require collaboration to understand what information is relevant for user access. It is not the job of a bank’s IT team to understand what information is pertinent for a retail teller’s role, says Cleary.
“They are not regulatory compliance experts. They need audit, risk and compliance to create a better collaborative framework for governing access.”
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@risk.net or view our subscription options here: http://subscriptions.risk.net/subscribe
You are currently unable to print this content. Please contact info@risk.net to find out more.
You are currently unable to copy this content. Please contact info@risk.net to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net
More on Regulation
Stablecoin consortia may be ‘interim’ step to solo bank issuance
Former Citi payments head and Ubyx founder says all G-Sibs will issue their own coins
Report once: will Esma’s €1bn reforms deliver the full picture?
Critics say plan to merge three reporting regimes will see scant returns, and won’t mesh with single-sided reporting
CFTC accused of ‘double standards’ on compute futures
Duffy questions ‘long review’ of CME’s contract when Kalshi already offers similar product
Europe’s banks can’t agree on how to fix the output floor
Some want market risk excluded, while others push for greater savings from credit modelling
SEC gunning to take over Cat in 2027
Regulator's bid for control of market surveillance apparatus splits industry participants
FCMs back CFTC proposal granting opt-out from CME oversight
New rules aim to address conflicts of interests at vertically integrated exchange groups
Banks urge Singapore to relax exposure limit on crypto assets
Lower capital for tokenisation and stablecoins welcomed, but cap will curb bank involvement for now
Larger EU players move slower on clearing relocation, says Esma
Active accounts rule driving smaller firms onshore; regulator ready for bigger role if lawmakers want