Software developers putting data at risk

Companies using real data in application testing

Written by Ian Williams

Over half of UK companies use actual rather than disguised customer data to test applications during the development process, according to a survey by Compuware Corporation.

The report, created in conjunction with privacy management firm the Ponemon Institute, concludes that this practice compromises critical information as these environments are less secure than production environments.

Testing data may be exposed to a variety of unauthorised sources, including in-house staff, consultants, partners and even offshore personnel.

Some 35 per cent of respondents outsourced their application testing, and 38 per cent shared live data with the outsourced organisation.

"For many organisations, large customer data files represent an easy and cheap source of data to use when testing applications," said Dr Larry Ponemon, chairman and founder of the Ponemon Institute.

"But this process introduces a huge element of risk to the challenge of maintaining the integrity of sensitive information, particularly when third parties and offshore resources are involved."

The study points to a need for greater awareness and accountability over how sensitive data is used within organisations.

"Common practices as they relate to all uses of live data must be evaluated to assess risk, and safeguards implemented to ensure data security," said Dr Ponemon.
Of the 58 per cent of companies using actual customer data, 79 per cent use customer files and 68 per cent use customer lists.

Examples of the live data include employee and vendor records, customer account numbers, credit card numbers, Social Security numbers and other credit, debit or payment information.

Furthermore, 43 per cent of respondents admitted to having no way of knowing whether the data used in testing had been compromised, and 17 per cent reported not protecting live data used in software development.

The report also highlighted the confusion surrounding the ownership of sensitive test data.

Some 11 per cent of respondents did not know who was responsible for securing test data, 43 per cent believed that the development organisation is responsible and 14 per cent thought that the business units sponsoring the development were responsible.

See also:

reader comments

related articles

MPs call to criminalise data loss

Justice Select Committee demands heavy fines and/or jail terms 03 Jan 2008

 

Bank details for sale on the web

As little as £1 buys you an active bank account 03 Dec 2007

Data leakage 'always preventable'

Major survey highlights routine neglect of data protection 29 Nov 2007

Under half of IT managers using encryption

Most companies feel secure against data leaks despite HMRC breach 30 Nov 2007

Firms urged to tackle email data leaks

Half of employees have sent emails to the wrong person 19 Nov 2007

Unstructured data creating security hole

Unfettered access opens firm to insider threats 02 Jul 2008

Marketing firms routinely losing customer data

Security firms slam cavalier attitude 24 Jun 2008

EU travellers losing 3,300 laptops a week

European airports a hub for lost notebooks 31 Jul 2008

latest news

Ingram loses commercial director

Bhavesh Patel set to leave at the end of the month 09 Jan 2009

Ramesys plays IT sheriff of Nottingham

Reseller secures first contract under Primary Capital Programme 09 Jan 2009

Acquisitive Acraman snaps up Ipitomi

Buy-and-build model alive and well as private equity-backed Acraman adds voice specialist Ipitomi to VAR portfolio 09 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation