Case study: Royal London to be better prepared for misconduct
By Steve Ranger
Published: 7 March 2006 13:15 GMT
Insurer Royal London is testing security software which could allow its IT security team to monitor staff use of PCs.
Royal London has so far installed 3ami's Monitoring and Audit System (MAS) on a small number of machines used by the company's security team. The system monitors the behaviour of a PC and stores this information on a database which can be interrogated by IT staff.
The MAS package uses a software agent to capture data such as applications opened, files saved or printed, and whether devices such as USB memory sticks have been attached. The software will not save usernames or passwords but will record text typed into documents or emails, and screen grabs of what is on the screen.
For example, the system would be able to show what someone typed in - such as a website address - and what appeared on the screen as a result.
Royal London's group IT security manager Nick Harwood said that while the software won't stop misconduct, such as visits to inappropriate websites, it will help the company find out later.
He said: "We will not be looking through this for things, we will be looking to react to incidents - but we've been proactive in our reacting."
And while some of the data the agent collects can be found in other places, that involve lots of effort, Harwood told silicon.com.
He explained: "You can go into the internet logs or dredge through email. That can be very time consuming."
To allay staff concerns about such a technology, the insurer has included its Staff Consultative Committee in discussions ahead of deployment, and by making it clear to staff that the company reserves the right to monitor activity.
The insurer is now discussing the benefits of the software with its business units before rolling it out further.
Production and interpretation of credit risk management information to monitor the impact of risk decisions on customer and portfolio behaviour 4. ...
Resolve incidents affecting the operation/availability of systems. Monitor and test system backups. Monitor vendors release notes and plan necessary ...
1st/2nd Line Technical Support/Helpdesk Agent/Analyst/Engineer HR.net, SQL, IIS, RDBMS, .NET Salary up to 21,000 - Worle, Weston-Super-Mare Nr ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Steve Boyle
Woolly risk analysis is hastening a housing crash
Comment: Lenders need a sane approach to avert a crisis
Carol Wheatcroft
Will consumers always want free banking?
Targeted, bundled services will be the way to profit...
Steve Boyle
Are rogue traders an inevitable evil?
Opinion: Managers must increase diligence to beat fraud
Julian Goldsmith
Profile: Nottingham Building Society head of IT Jack Cutts
'On the wide accountancy'...
Steve Boyle
Why you should be outsourcing your data centres
Concentrate on the core business...
Bob McDowall
Fixed-income electronic trading faces bleak 2008
Trading platforms likely to draw in their horns for downturn