<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Software Associates. &#187; Varonis</title>
	<atom:link href="http://www.software.co.il/tag/varonis/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.software.co.il</link>
	<description>Security and compliance specialists for medical device and healthcare companies</description>
	<lastBuildDate>Wed, 08 Feb 2012 06:36:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The effectiveness of access controls</title>
		<link>http://www.software.co.il/2010/03/2281/</link>
		<comments>http://www.software.co.il/2010/03/2281/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 07:49:30 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Information security]]></category>
		<category><![CDATA[Data classification]]></category>
		<category><![CDATA[data governance]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Information assurance]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Sharepoint]]></category>
		<category><![CDATA[Varonis]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2281</guid>
		<description><![CDATA[With all due respect to Varonis and access controls in general (Just the area of Sharepoint is a fertile market for data security), the problem of internally-launched attacks is that they are all done by the &#8220;right&#8221; people and / or by software agents who have the &#8220;right&#8221; access rights. There are 3 general classes ...]]></description>
			<content:encoded><![CDATA[<p>With all due respect to <a title="Varonis -  the leading innovator and provider of comprehensive data governance software" href="http://www.varonis.com" target="_blank">Varonis </a>and access controls in general (Just the area of Sharepoint is a fertile market for data security), the problem of internally-launched attacks is that they are all done by the &#8220;right&#8221; people and / or by software agents who have the &#8220;right&#8221; access rights.</p>
<p>There are 3 general classes of internal attacks that are never going to be mitigated by access controls:</p>
<p><span style="text-decoration: underline;">Trusted insider theft</span></p>
<p>A trivial example is a director of new technology development at a small high-tech startup who would have access to the entire company&#8217;s IP, the competitive analyses, patent applications and minutes of conversations with all the people who ever stopped in to talk about the startup&#8217;s technology. That same person has access by definition but when he takes his data and sucks it out the network using a back-door, a proxy, an HTTP GET or just a plain USB or Gmail account &#8211; there is no way an Active Directory access control will be able to detect that as &#8220;anomalous behavior&#8221;.</p>
<p><span style="text-decoration: underline;">Social engineering</span></p>
<p>Collusion between insiders, gaming the system, taking advantage of friends and DHL messengers who go in and out of the office all the time with their bags.</p>
<p><span style="text-decoration: underline;">Side channel attacks</span></p>
<p>Detecting data at a distance with acoustic or Tempest attacks &#8211; for example. or watching parking lot traffic patterns&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2010/03/2281/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

