Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Countering Botnets with Botnet-Like Design | Main | Localized Malware »

Mortgage Broker Bitten by Access Control Lapse

Provisioning user accounts is a pain and de-provisioning can be a bigger pain. There are any number of reasons to automate user provisioning, from the savings of lost productivity, service desk overhead to just avoiding user frustration. Unfortunately, there aren't so many business pressures to smooth out the deprovisioning process. Once someone leaves, they aren't likely to complain about there accounts still being active. That's too bad for LendingTree which was just bitten by former employees who had active accounts exploited.

Other lenders, not part of the LendingTree network, were able to get customer information and solicit those clients because of stale accounts left active. LendingTree internal security discovered the breach which lasted from October 2006 to early 2008.

With so much news about malware, compromised Web sites, and other external threats it is easy to forget about threats from the inside. Protecting individual assets is essential and part of that is authentication and authorization control. The perimeter is now so intentionally permeable in some organizations that adding more defenses there does little to improve the overall risk level. SearchSecurity quotes on vendor on the imbalance of where mitigation efforts are placed:


Insiders are involved in about half of all data breach cases, but many firms are so focused on hardening the perimeter that insider threats are neglected, said Brian Cleary, vice president of marketing at access management vendor, Aveksa Inc.

Granted, this is coming from a vendor in the access control market but there is enough truth to the statement to warrant our attention.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/712

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net