That has absolutely nothing to do with preventing insider access. Where there's smoke screen, there's fire.
That has absolutely nothing to do with preventing insider access. Where there's smoke screen, there's fire.
This bit stood out to me (emphasis mine):
> Uber says employees don't receive across-the-board access to customer data and there are several controls in place to ensure that employees only access that data for work purposes.
The choice of the word "control" in this context I think gives away a little bit here, it's auditor-speak.
This word does not always mean to an auditor what it means to you or I. Having a written policy that says "Don't access X unless it's required for your job" and keeping access logs can satisfy a "control" from an auditor's perspective, depending on the certification.
That's better than nothing, but back to your point, you're right that it doesn't prevent insider access. Which isn't something I worry about normally...
Edit: Typo
The usual process for such a control should be:
* Is there a requirement for a log?
* Does that log exist?
* Can the system(s) that write to the log be prevented from doing so/tampered with? (branch here to system security review)
* How are the contents of that log secured against tampering? (branch here to security review of logs)
* Who is responsible for reviewing it?
* Where is the evidence that such reviews occurred?
* What violations of policy were found during those reviews? (branch here to a review of the follow-up process)
* Can I, the auditor, find violations that were not found during the reviews? (if yes, branch here to figuring out why not)
This is not an especially complex script to follow, and winning at that last step is the kind of thing that gets you nice fat bonuses and happy bosses, because suddenly the auditee needs remediation consulting services. Especially as the cost of "taking a complete sample" (i.e. reviewing every entry in the log) goes down to nearly zero, this kind of review gets easier and easier (and is often automated by the company being audited, which just shifts the focus slightly... with no change to the last step).