Case study: Royal London to be better prepared for misconduct
By Steve Ranger
Published: 7 March 2006 13:15 GMT
Insurer Royal London is testing security software which could allow its IT security team to monitor staff use of PCs.
Royal London has so far installed 3ami's Monitoring and Audit System (MAS) on a small number of machines used by the company's security team. The system monitors the behaviour of a PC and stores this information on a database which can be interrogated by IT staff.
The MAS package uses a software agent to capture data such as applications opened, files saved or printed, and whether devices such as USB memory sticks have been attached. The software will not save usernames or passwords but will record text typed into documents or emails, and screen grabs of what is on the screen.
For example, the system would be able to show what someone typed in - such as a website address - and what appeared on the screen as a result.
Royal London's group IT security manager Nick Harwood said that while the software won't stop misconduct, such as visits to inappropriate websites, it will help the company find out later.
He said: "We will not be looking through this for things, we will be looking to react to incidents - but we've been proactive in our reacting."
And while some of the data the agent collects can be found in other places, that involve lots of effort, Harwood told silicon.com.
He explained: "You can go into the internet logs or dredge through email. That can be very time consuming."
To allay staff concerns about such a technology, the insurer has included its Staff Consultative Committee in discussions ahead of deployment, and by making it clear to staff that the company reserves the right to monitor activity.
The insurer is now discussing the benefits of the software with its business units before rolling it out further.
Technical Skills (Must Have): SQL 2000, SQL 2005, SQL 2008, SSIS, T-SQL/PL-SQL design and development Knowledge of SQL Server system Tables SQL Agent ...
Including:- DDI/Trunk, Agent, ringing group setup. Maintain PC and Peripherals, including replacement toner, general cleaning of printers and house ...
To resolve and close Incidents to user/business satisfaction* To update customers on status of Incidents* Be aware and follow procedures at all ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Beecham and Belinda Doshi
No more tax breaks for offshoring?
Financial services firms must prepare now for 2010 legal changes
Tim Ferguson
On a new Voyager, tackling fraud and the intellectual challenge
Interview: Nationwide IT director, Peter Stafford
Nick Heath
David Lister on smart grids and why he left RBS
Interview: National Grid CIO
Andy Jones
Why banks will push ahead with offshoring
Comment: Even if they don't want to
Catherine Stagg-Macey
Legacy IT holding back insurers
Comment: Economic crisis means finance giants must step lively
Julian Goldsmith
The City fund manager with no IT department
Q&A: How asset management is embracing the cloud...