Search

  
 
Study reveals major security flaws in most enterprises


October 03 2006

Study reveals major security flaws in most enterprises

 


Privileged passwords are the non-personal passwords that exist in virtually every device or software application in an enterprise, such as root on a UNIX server, Administrator on a Windows workstation, and Cisco Enable on a Cisco device.

Completed by more than 140 IT professionals, the 2006 Privileged Password Survey reveals that privileged passwords are far more common in enterprises than previously thought: approximately one-half of all enterprises contain more privileged passwords than individual ones. Second, although these privileged passwords provide "super-user" system access, the survey exposes that up to 42% are never updated, a frightening prospect in today's environment of increased audits and hacker attacks. In fact, half of the IT professionals surveyed reveal that they're concerned about audits, and 6 out of 10 state that their organization has been hacked.

Often, the reason privileged passwords are rarely updated is a simple one: many enterprises still manually change these key passwords and as one IT Executive from a Fortune 500-sized company states: "manually changing thousands of passwords across hundreds of databases is simply impractical."
Approximately half of all enterprises have more privileged passwords than personal ones

According to the 2006 Enterprise Privileged Password Survey, the typical enterprise contains:


Although privileged passwords provide "super-user" access to a target system, the survey shows they are far less likely to be updated. Respondents report that 99% of individual passwords are updated, however for privileged passwords:


The survey not only revealed that privileged passwords are rarely changed, it also supports that this is a dangerous practice in today's environment of hacker attacks and increased audit pressure. For example, in survey results:


 

Reproduced from an article published by Help Net Security
© Help Net Security

The original article can be viewed here:
http://www.net-security.org/secworld.php?id=4258

 Bookmark Digg this story

RSS feed  |  About RSS feeds

Get the Industry's top stories delivered straight to your inbox...
Firstname:

Surname:

Email:

Frequency:
 Daily  Weekly