天极Yesky
  • 笔记本电脑
    笔记本
  • 台式电脑
    台式机
  • 手机
    手机
  • 电脑硬件DIY
    DIY硬件
  • CPU
    主板
    音箱
  • 硬盘
    显卡
    键鼠
  • 内存光驱
    显示器
    机箱电源

  • 数码相机DC
    数码相机
  • MP3播放器
    MP3/MP4
  • 数码摄像机DV
    摄像机
  • 电脑外设
    外设
  • 网络
    网络
  • 服务器
    服务器
  • 数字家庭
    数字家庭
  • 群乐
    群乐
  • 产品报价 行情 商家 新闻 评测 | 软件 设计 网页 开发 安全 论坛 E时代 游戏 图片 壁纸 下载 网摘 博客 索尼专区 Vista 科技奥运
    天极网
    Managing the security of data flow in CRM systems
    作者: Diane Seddon, Industry Analyst
    出处:
    责任编辑:
    [ 2004-06-17 19:18 ]


    Customer Relationship Management (CRM) systems are cited as one of the major technology successes of the last decade. These 'super databases' enable the real-time sharing of information across global organizations, increasing the visibility of the sales pipeline and providing a central control of the customer experience. A far cry from the early databases which were supported in the locally networked environment, CRM systems have pushed database capabilities into the enterprise arena, providing accurate monitoring of customer information and enabling corporations to sell and market to customers through a centrally managed delivery mechanism.

    This increased fluidity of information across multiple interfaces effectively brings customers and suppliers closer together. By its very nature, however, such free-flowing information introduces inherent risks in system security; a fact which many developers and users of these Web-facing enterprise systems are now being forced to address.

    Globally accessible CRM systems are built on the principle that they can be operated in real time by the user and, subject of course to locally determined permissions, allow the read and write functionality of shared information. The CRM package itself is responsible for the transfer, processing and storage of this data. As a system, it is made up of several applications that sit on top of standard Web servers and database platforms, feeding information to and retrieving it from the massive database that lies behind.

    It is this Web interaction and multi-component composition that introduces the possibility of increased security risk, even if the server (or servers in a load balanced situation) upon which the CRM is installed may be hosted in a secure and regularly tested network environment.

    Many of the applications that constitute the packaged CRM solution, such as chart servers and search engines, may in fact be third party items that the CRM manufacturer has bundled with its product. Obviously, it is entirely possible that these individual products have been tested thoroughly and configured in such a way that the dataflow between them is secure. But this is not what security experts are finding.

    On the one hand, each component is susceptible to and must be secured against all the individual vulnerabilities that product may possess. Coupled with this is the interaction with the CRM software itself. If the software does not have built-in checks and regulations to secure the data flowing through it from each of its component products, then it is conceivably possible that the system may be compromised should such a weakness occur. And it only takes one 'rogue' product.

    Furthermore, if these component products were bundled into the package with their default installations, then these vulnerabilities would remain, even if patches and updates were applied.

    The packaged nature of these solutions means that the corporation that is operating the CRM system may have unwittingly relinquished control of some of its system administration procedures. Although they may be aware that the complete solution or package is of multi-vendor origin, they may not realize the possible security risk associated with this bundling. Indeed, some may even believe that they have increased the protection of their network by adopting the multi-layered security that a mixed-vendor system can offer. One of the most common vulnerabilities that security experts are finding with the multiple component bundling is that some of the gateways between the applications are deliberately left open in order that the transfer of data is expedited. As such, some of the default accounts and passwords used by the system itself (as opposed to those at the user interface) may be removed from the normal procedures stipulated by the organization's security policy. Password rotation, or indeed procedures to disable certain passwords, is an integral part of any good security policy. If these static system passwords are cracked, for example, an attacker could then have administrative access to the CRM's settings and of course the underlying database.

    Another security risk, and one that can by no means be ignored, is from the intended users of the system themselves. If the read/write permissions have not been thoroughly checked, then an employee may find that they have unauthorized access to what should be a closed area of the system. Whether maliciously intended or accidental, there is then the potential that a security breach could occur from within the organization.

    The CRM systems themselves offer massive business benefits in streamlining the sales process, efficiently connecting suppliers and customers in a global environment and allowing a central control of the customer experience. With the increased data share though, comes the increased risk. From 'holes' created in the installation and customization processes through to other errors made by the software vendor, the permutations in the possibility of weaknesses within the system then become abundant. It is only through a vigilant and regular testing of the application itself, both in isolation from and within the network environment, that these risks can be truly mitigated.

    About Corsaire
    With over six years of experience in providing network security solutions to the private, public and non-profit sectors, including the FTSE 100, Corsaire is considered a leading specialist in the delivery of network security design, implementation and management. Corsaire takes a consultative approach and combines a vendor-neutral policy with knowledge-share to deliver impartial, up-to-date advice.


    For more information, visit these other resources:
    笔名:
    请您注意:

     遵守国家有关法律、法规,尊重网上道德,承担一切因您的行为而直接或间接引起的法律责任。

     天极网拥有管理笔名和留言的一切权利。
    相关内容