Support / Feedback
  • Edition:
  • Global
  • |
  • North America
  • |
  • Central & South America
  • |
  • UK & Ireland
  • |
  • Europe
  • |
  • Middle East & Africa
  • |
  • Australia & New Zealand
  • |
  • Asia
Over 137,000 Members
Login
Invalid Login
Username
Password

Forgot Password?

Register FREE
Over 137,000 Members
  • Groups
    • Interest Areas
    • Agent Zone
    • Association
    • Awards
    • Benchmarking
    • Best Practices
    • CRM
    • HR
    • Infrastructure
    •  
    • Legal
    • Outsourcing
    • Performance
    • Quality
    • Technology
    • Telecom
    • Training
    • Workforce Management
    • Industry Sector
    • Aerospace
    • Automotive
    • Banking / Finance / Credit
    • Charity / Not For Profit
    • Computer Hardware / Software
    • Government
    • Healthcare / Pharmaceutical
    • Insurance
    •  
    • Manufacturing
    • Retail
    • Service Industry
    • Travel / Transportation / Tourism
    • Utilities
  • Conferences & Events
    • Best Practice Conferences
    • Other Events
    Rosen Plaza Hotel. Orlando
    The best contact center practitioners from North & South America (AMERICAS) will be sharing their best practices and networking with delegates
    Hard Rock Hotel, Resorts World, Singapore
    The best contact center practitioners from all over Asia Pacific, Australia and New Zealand (APAC) will be sharing their best practices and networking with delegates
    Intercontinental Hotel, Vienna
    The best contact center practitioners from the entire region of Europe, Middle East & Africa (EMEA) will be sharing their best practices and networking with delegates
    Vdara Resort Las Vegas
    We invite award winners from around the World to share their best practices - these are the best from over 50+ nations who had to compete to earn a speaking spot! Learn from the best in the World 2013
  • Certification
    • Customer Satisfaction (For vendors)
    • TopPlace2Work
  • For Your Center
    • Global Benchmarking Study
    • Industry Solutions Directory
    • International Contact Center Week
    • Post your Jobs (free)
  • Awards
    • Best Practice Awards
    • 2012 Americas Winners
    • 2012 EMEA Winners
    • 2012 APAC Winners
    • 2012 GLOBAL Winners
    • Top Outsourcer
    • 2011 Winners
    • Industry Champion
    • 2011 Champions
    • 2010 Champions
    • Members' Choice Awards
    • Top Ranking Vendors
  • Tools & Utilities
    • Find a Career
    • Glossary
    • Link to Us
    • RSS Feeds
    • Sponsorship Opportunities
    • Submit Editorial
    • Forums/Discussions
    • Association Directory
    • Demo's and Tutorials
    • Feeds for Your Website

Article : The Security Risks Of Implicit Trust In Call Centers

Sam Fleming

Sam Fleming
Chief Technical Officer
NextSentry
Add Contact

With a recent study by the International Customer Management Institute (ICMI) and TalentKeepers stating that 70 percent of call center professionals expect unwanted turnover to increase or stay the same over the coming year, call centers could be facing an insider threat perfect storm. High turnover means low loyalty, which could indicate a risk in the call center to effectively secure customer data.

It has long been stated that the only truly secure computer is one locked up in a closet and powered off. While not a realistic objective, the data security approach in today’s call center environment parallels this with a paradigm that attempts to lock down services to the largest degree possible. This can lead to a false sense of security to the degree to which we must make services available to the end user.

A good example of this situation is with printers, which are often an underestimated risk. Either we shut printing off entirely, or leave it wide open to abuse. Ideally those users which handle customer data would still be empowered to print, but with a level of accountability. This is an objective that simply requires a deeper level of context over user data handling activity than exists in most environments today.

Problem: Lack Of Accountability Over Data Handling
This leads us to the biggest hole in security today; a broad based lack of accountability over data handling. In virtually all forms of sensitive business processes we have checks and balances, so why when it comes to data handling do we not? On the front end, at the point of access we place permissions controls but we lose all context over what happens to the data subsequent to access.

We have no visibility in to data activity at the desktop level where the data is most acted on. In most cases our breadth of understanding today is no more than a transactional log event from the source application or database at the point in which the data was accessed.

As such we have left users in control of the data from that point forward, and anytime your security model relies on end users for enforcement it is an inherently flawed strategy. Yet we continue to rely on written policy, which in effect depends on our end users to not only understand them, but to enforce them. Hardly a recipe for strong accountability.

Solution: A Holistic Approach
To begin with we have to reflect on all the possible services or vectors that we have made available to end users as potential points of dissemination. Once we have taken such an inventory we need to lock down anything that is not backed by some level of business justification.

The next step is to take a holistic approach to analyzing how data moves across all the remaining services or channels that we have exposed to our user base. Some organizations may argue against employee monitoring, but it is not necessarily what the user is up to that is so much in our interest, as much as it is auditing for where sensitive data is being moved. When it comes to endpoint data control, someone’s personal issues are the last thing we would want to have appear as a security event. In many environments an unexpected consequence can happen, as you may find users more than happy to be subjected to some additional level of accountability if it empowers them with greater access and control over computing resources.

By placing an endpoint agent on the machine that focuses on user interaction with the computer, and analyzes data as it moves from originating source to final destination we don’t get so caught up in specific protocols and low level detail. In this way we can focus our policy enforcement efforts in a more holistic fashion, covering the full breadth of user activity in a behavioral fashion.

You can think of the computing environment in terms of a series of trusted and non-trusted destinations. Destinations can include web site URL’s, email addresses or domains, applications, or file stores. If a user is to move sensitive customer data from a core banking application to an outlook window, and then send that data to a non trusted email location, that is something worth raising a security event about for review. It is all about having the capacity to first identify what sensitive data is, and then understanding the context of the situation and how the data is moving. Only then can we begin to establish true policy enforcement, and real world accountability.

Expand the scope of capability for a user to include a web browser or email and your lock down approach is eroded by orders of magnitude. Email has become less popular as a vector as it is known to be frequently filtered and more often than not recorded. While web content filtering is a common paradigm its focus tends to remain on what content is reachable, and what we should really be interested in is what data is going out via remote posts and file uploads. It’s easy enough for a perpetrator to send one of your users a web chat link and have them start posting sensitive data back via a browser based interface.


About Sam Fleming:
Sam Fleming is a software technologist driving the development of NextSentry's flagship security products. Fleming is a natural leader with an instinct for building powerful, versatile technology platforms that support solutions that can serve flexibly across a range of business segments. His work has contributed to the development of ContextIQ, the core context-based engine behind StealthAgent, the desktop resident client that monitors activity and protects confidential information.

About NextSentry:
NextSentry offers a new approach that prevents employees from accidentally or maliciously distributing private data or intellectual property to the outside world. ActiveSentry delivers the real-time desktop awareness necessary to protect a company’s sensitive data and ensure that employees follow corporate security policies. ActiveSentry offers unobtrusive desktop monitoring across a broad array of potential distribution methods including email, instant messaging, blogs, file transfer, printing, and removable storage devices such as USB drives, CDs, or iPods.

Published: Thursday, May 03, 2007

Printer Friendly Version Printer friendly version
 Recommend to a friend

Editorial Comments

Reply
Username:
Email:
Password:
Forgot Password?
Don't have a current membership with ContactCenterWorld.com?

become a member and connect with the rest of the Contact Center Industry at ContactCenterWorld.com here
Forum Profile
Job Title:(Display this on the Forum)
Company:(Display this on the Forum)
 
Neither the Administrators of these forums, or the Moderators participating, are responsible for the privacy practices of any user. Remember that all information that is disclosed in these areas becomes public information and you should exercise caution when deciding to share any of your personal information. Any user who finds material posted by another user objectionable is encouraged to contact us via e-mail. We are authorized by you to remove or modify any data submitted by you to these forums for any reason we feel constitutes a violation of our policies, whether stated, implied or not.

This site may contain links to other web sites and files. We have no control over the content and can not ensure it will not be offensive or objectionable. We will, however, remove links to material that we feel is inappropriate as we become aware of them.

By pressing the "Agree" button, you agree that you, the user, are 13 years of age or over. You are fully responsible for any information or file supplied by this user. You also agree that you will not post any copyrighted material that is not owned by yourself or the owners of these forums. In your use of these forums, you agree that you will not post any information which is vulgar, harassing, hateful, threatening, invading of others privacy, sexually oriented, or violates any laws.

If you do agree with the rules and policies stated in this agreement, and meet the criteria stated herein, proceed to press the "Agree" button below, otherwise press "Cancel".

If you have any questions about this privacy statement or the use of these forums, you can contact the forum administrator at: rajw@contactcenterworld.com

Your comments on this item:

Related Editorial

  • World’s Best Contact Centers and Contact Center Practitioners Announced at Stunning Gala Awards Gala
  • Letter to ContactCenterWorld from an Award Winning Contact Center Professional
  • 2012 Best in Americas Awards Gala Rocks Orlando
  • IVR: Pet Peeve or Dealbreaker?
  • 2011 Best in The Contact Center World Revealed!
  • Best In Americas Honored at Best Practices Conference

Members Online

« PreviousNext »
Wally MacTavish
Anna Megrabyan National Recovery Service
Kern Carson NETCAST BPO Services
Raj Wadhwani ContactCenterWorld.com
Aqeel Jatoi MCR Pvt. Ltd Franchisee of PizzaHut in Pakistan
John Dill Humana, Inc.
Randall Anderson Listen Up Espanol
Lajaun Case Staples
Teresa Jose Altitude Software
Bridgett Oldman Optus Inc
Natalia Izmaylova UkrSibbank BNP Paribas Group
Michael DeSalles Frost & Sullivan
Sharon Price ContactCenterWorld.com
Tyler Zawacki contactcenterworld.com
Daniel Persuitte MassMutual
Renate Rohde arvato
Kevin Hill Symon Dacon Ltd
Aida Kamber AVOXI
Katie Sheridan Interact Incorporated
John Ruby GCOM (Global Communications Network Systems)
Showing 1 - 20 of 51541 items

Newsletter Registration




RSS FeedLinkedinFacebookTwitter
About ContactCenterWorld
Advertise CRM & Contact Center Solutions | Link to this site
Submit CRM and Contact Center Content | Contact Us | Privacy Policy
Recommend this site to other CRM & Contact Center Professionals | Disclaimer

ContactCenterWorld.com 1999 - Present The Global Support Organization For Contact Center Professionals & the place for information on:
Cost per Call, CRM, Customer Interaction Management (CIM), Customer Measurement, Customer Satisfaction, Dialers, Disaster Recovery, Do Not Call (DNC), e-Learning, E-mail, e-support, Erlang, First Call Resolution, Headsets, Help Desk Software, Internet Telephony (IP), IVR, Knowledge Management (KM)