CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Security HeadLines: Protecting company data from ex-employees (recent) image
Networks
Protecting company data from ex-employees
by Eric J. Sinrod

While companies are relatively accustomed to requesting the return of building keys and ID cards from departing employees, they are less vigilant when it comes to electronic data. Can this lead to problems? Yes!

When employees are terminated involuntarily, emotions can run high on both sides of the table. The people in charge of the termination may feel quite uncomfortable. Their entire focus may be on calming the terminated employee and making sure the person leaves the building without incident. While building keys and ID cards likely will be requested for return, it is quite possible that company personnel will forget right away to disable the former employee's access rights to the company's information systems.

The danger

In a case like that, a terminated employee could sit down at an off-site computer and have remote access to the company's information system. But now there's an added factor: the terminated employee may harbor a grudge against the company or may want to take advantage of proprietary company information for career pursuits.

Terminated employees could seek revenge by attempting to delete or alter important data stored on the company's information systems. Or they could seek to steal the crown jewels of the company — its intellectual property stored on its information systems.

Once employees are terminated (or even when they depart voluntarily), companies immediately must disable their access rights to information systems. Even a lag of several days, which is not uncommon, can lead to serious consequences.

For companies of all sizes, it is important to maintain an organizational list or directory that documents the various levels of access employees have to the company's information systems. Once any of those employees departs the company, the company then should be in a position to disable all applicable access rights.

When it is known in advance that employees will be leaving on a certain date, the company can build in automatic stop dates, which ends access rights to information systems on that date.

Companies would be wise to have the manager who has supervised specific, departing employees to complete and sign off on a checklist which demonstrates that access rights to information systems have been disabled. This helps ensure that a live human being actually takes care of this before a problem occurs.

Burden vs. benefit

Of course, it is a burden to add yet another responsibility to managers when it comes to dealing with departing employees. However, the increased burden is slight when compared to the havoc that could be wreaked in its absence.

This article first appeared on Law.com.

Eric Sinrod is a partner in the San Francisco office of Duane Morris (www.duanemorris.com), where he focuses on litigation matters of various types, including information technology disputes. His Web site is www.sinrodlaw.com, and he can be reached at ejsinrod@duanemorris.com. To receive a weekly e-mail link to Mr. Sinrod's columns, please send an e-mail with the word Subscribe in the Subject line to ejsinrod@duanemorris.com.

usatech
Posted on Saturday, 27 September 2003 @ 05:00:00 UTC by phoenix22 (928 reads)
[ Trackback ]
image

"Security HeadLines: Protecting company data from ex-employees (recent)" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Intel
· HotScripts
· W3 Consortium
· More about Networks
· News by phoenix22


Most read story about Networks:
Network Troubleshooting 101 – Part 1

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer