IDG Contributor Network: The security and risk management of shadow IT
Most would agree that we in the information security industry are fighting an uphill battle. Many have even taken the extreme position that we cannot keep intruders out of our networks, so we should give up and focus on containment, an argument I strongly objected to in an earlier post, "Are we surrendering the cyberwar?" Regardless of your position on how best to control the threat, I think you will agree that it is a difficult problem to address.
In the world of corporate IT, I have seen a definite shift toward better focus on network security, vulnerability management and governance. We are having success in locking networks and data down, even as more improvement is needed. Even as we succeed in deploying better security controls for the assets we know about, we are facing a growing threat from within — the challenge of shadow IT.
To read this article in full or to leave a comment, please click here