<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shadow IT happens in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20456#M1037</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/637665353"&gt;@iluom&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose IT departments in organizations are not able to pickup the pace to embrace digitization to support staff and employees. It has become a common&amp;nbsp;phenomena in all types and sizes of organizations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Or it may just mean that people just chase the latest fads and tools. A few things done well is a much better than a mish mash&amp;nbsp;of resources that no one can keep track of, but it is too easy for someone to see some app that makes life "so easy" for them that they insist everyone else has to use. Here's a simple case in point: Venmo. People seem to be flocking to the thing and what's its selling point over Paypal or (heaven forbid) sending a check? It's integration with social media. Yes, by all means, announce to the world the bill you just split. I can sincerely say that 90 percent of the "technology" that comes across my desk each day is pure crap. That doesn't stop the lemmings from buying it, downloading, using it, and getting bitten by it.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Mar 2019 20:49:49 GMT</pubDate>
    <dc:creator>JoePete</dc:creator>
    <dc:date>2019-03-25T20:49:49Z</dc:date>
    <item>
      <title>Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20425#M1034</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Shadow IT a positive sign?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does it mean by the rapid growth of shadow IT ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose IT departments in organizations are not able to pickup the pace to embrace digitization to support staff and employees. It has become a common&amp;nbsp;phenomena in all types and sizes of organizations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's being a commonplace to use opensource and SaaS application at work without ITs approval&lt;/P&gt;&lt;P&gt;somehow they are helping to increase the productivity, but there are risks as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 13:05:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20425#M1034</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-03-25T13:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20445#M1035</link>
      <description>&lt;P&gt;Shadow IT happens when other departments feel like IT isn't moving fast enough for them or IT security has become too restrictive AND they have access to their own budgets to procure the items needed to accomplish their IT needs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shadow IT can also happen when IT does not understand the customer requirements. One of the commonly overlooked pitfalls of Shadow IT is the lack of lifecycle maintenance. One example I had from a few years ago (2016). We had one department come to IT and ask for a new computer as their old computer had died and they needed a replacement. The IT shop did not have anything in their database showing they had any equipment in that particular shop. so they went down there and found a computer that was running WINDOWS MILLENIUM EDITION (ME) in 2016!!!!!! The only purpose of this computer was to print labels for pipes. The shop had purchased it 17 years ago and IT didn't even know it existed. It was not being maintained, secured or anything. No one knew about it so no one though to include it in a lifecycle refresh plan. The software wouldn't run on a Windows 10 machine. And to top it off they were mad at the IT shop for not being able to come in and replace it right away. Keep in mind this was government so procurements are regulated and not something that can always be done in a hurry. We eventually found out from the company that we could pay to have some new printer software shipped for about $1000 that would run on Windows 10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I told my guys to go through the entire 11 acre industrial plant and find every computer that was there in every building and document it. I left the job before the task was complete but at the 50% mark we had found over 100 computers that:&lt;/P&gt;&lt;P&gt;1) The IT shop didn't know anything about,&lt;/P&gt;&lt;P&gt;2) The were not being updated,&lt;/P&gt;&lt;P&gt;3) They were out of security compliance,&lt;/P&gt;&lt;P&gt;4) They may or may not have had any AV products or security software on them&lt;/P&gt;&lt;P&gt;5) They were not on any lifecycle replacement plan&lt;/P&gt;&lt;P&gt;6) No one was responsible for watching/maintaining them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you see there are a lot of ways Shadow IT can come into an organization and there are a lot of problems that can develop. Luckily we were an industrial plant so we did not have a lot of network access that the Shadow IT could connect to the main network, but as we began modernizing the plant it became more of a risk. We also discovered several rogue networks with access to the Internet which was problematic for industrial security secrets.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 17:01:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20445#M1035</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2019-03-25T17:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20447#M1036</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/637665353"&gt;@iluom&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Shadow IT a positive sign?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does it mean by the rapid growth of shadow IT ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose IT departments in organizations are not able to pickup the pace to embrace digitization to support staff and employees. It has become a common&amp;nbsp;phenomena in all types and sizes of organizations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's being a commonplace to use opensource and SaaS application at work without ITs approval&lt;/P&gt;&lt;P&gt;somehow they are helping to increase the productivity, but there are risks as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Shadow IT is not a positive sign. It is a sign that things are not working in your organization. It is a sign that either IT is not communicating well with the organization (could be either party, IT or the business) or that IT is not able to meet the customer requirements of the business.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rapid growth of Shadow IT means that IT cannot meet the business needs therefore the business units are turning to other means of getting it done. It also could reflect bad IT procurement policies, bad security policies (no security policy, poor security policy. too restrictive security policy, etc.), poor understanding of customer requirements, poor budget management policies (i.e. each department has their own budget and lacks IT controls/oversight over what they can purchase), poor IT security posture or poor IT security relationships, or several other things.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 17:58:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20447#M1036</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2019-03-25T17:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20456#M1037</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/637665353"&gt;@iluom&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suppose IT departments in organizations are not able to pickup the pace to embrace digitization to support staff and employees. It has become a common&amp;nbsp;phenomena in all types and sizes of organizations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Or it may just mean that people just chase the latest fads and tools. A few things done well is a much better than a mish mash&amp;nbsp;of resources that no one can keep track of, but it is too easy for someone to see some app that makes life "so easy" for them that they insist everyone else has to use. Here's a simple case in point: Venmo. People seem to be flocking to the thing and what's its selling point over Paypal or (heaven forbid) sending a check? It's integration with social media. Yes, by all means, announce to the world the bill you just split. I can sincerely say that 90 percent of the "technology" that comes across my desk each day is pure crap. That doesn't stop the lemmings from buying it, downloading, using it, and getting bitten by it.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 20:49:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20456#M1037</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2019-03-25T20:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20458#M1038</link>
      <description>&lt;P&gt;I started working for an organization that actually had split their IT functions due to Shadow IT.&amp;nbsp; It stated with the IT folks not being responsive enough to the needs of the development teams.&amp;nbsp; As this happened a Shadow IT department sprung up and finally became recognized as an official IT supplier.&amp;nbsp; So there were two sets of Computer Operations folks, development teams, support people and networking folk.&amp;nbsp; Unfortunately, there were still a few shadow IT groups so there was no real Architecture or Strategy (long or short term).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a few years, this came under review and found to be "unhealthy" to the organization due to duplication of systems, people, multiple computer rooms, etc.&amp;nbsp; At this point, it was decided to merge the groups into one (fortunately no jobs were lost) and the coming together proved beneficial to the organization.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So yes Shadow IT does happen, sometimes for the good of the department and sometimes to the detriment of the organization.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Folks in IT are concerned with keeping the organization functioning and secure (payroll, ordering, customer service) while departments want the latest tech (ipads, smart phones, surfaces) and the latest apps (Docusign, skype for business, etc.).&amp;nbsp; Sometimes the two are at odds as IT doesn't have time but the department has one or two techies who are more than fill the empty slot and bring in tech that IT must now scramble to support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shadow IT is now bad when done correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my nickel Canadian.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 21:27:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20458#M1038</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-03-25T21:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20464#M1039</link>
      <description>Yes, I agree with you. I tool felt the same.</description>
      <pubDate>Tue, 26 Mar 2019 01:25:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20464#M1039</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-03-26T01:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20465#M1040</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess DevOps has potential to address the issues with Shadow IT. isn't it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 01:34:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/20465#M1040</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-03-26T01:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/21046#M1096</link>
      <description>&lt;P&gt;DevOps can make Shadow IT far worse.&amp;nbsp; The tools and resources associated with DevOps, cloud, SaaS, etc. are a credit card and expense report away for any developer.&amp;nbsp; One of the many problems is that then there is a potential back door to Internet for data loss, incoming malware, etc.&amp;nbsp; Systems "out there" are probably also not well configured or protected, which means they are at a high risk of compromise, if for nothing else than to mine cryptocurrency.&amp;nbsp; But in the end, the company is probably paying for that usage.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well done, DevOps is a great strategy. Done poorly, it is an awful mess for all those involved, exponentially increasing the headaches for IT and IS teams.&amp;nbsp; Although, I must agree with some earlier comments, if you have a significant shadow IT presence, find out why.&amp;nbsp; IT and IS should be enabling the business, if they have to be gone around to get things done, something is wrong, and needs to be fixe&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 10:33:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/21046#M1096</guid>
      <dc:creator>mgorman</dc:creator>
      <dc:date>2019-04-10T10:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/21051#M1097</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is ample scope for reducing the danger of shadow IT with DevOps for sure. DevOps brings&amp;nbsp;IT Out of the Shadows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are two benefits that DevOps brings to the table that minimize the potential for shadow IT.&lt;/P&gt;&lt;P&gt;More rapid development and empowering individuals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reality is, you can either declare your organization will never do shadow IT and lose the battle, or you can recognize its proliferation and start putting some governance around it. Here’s how DevOps can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DevOps is all about fostering better communication and collaboration between teams and across platforms. it’s all about including people from different areas of the business, even outside IT, from the beginning development stages of new software to the end. If you’re going to “okay” certain projects under shadow IT, there should be communication and transparency about what’s occurring.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another important aspect of DevOps is enabling people with the tools they need. If people are sharing data on Google Docs, why isn’t your organization providing them with an excellent collaboration tool like Atlassian Confluence?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With DevOps, you prevent shadow IT groups from scouting and using unapproved open-source tools that may not integrate well with your environment or that aren’t properly secured or licensed. Instead, you provide good tools that help people be productive and successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fighting shadow IT is a battle no organization will ever completely win, but letting it run amok is financially dangerous and unsecure. The best tactic for organizations is to control their shadow IT activity by improving their own development, operations and security organizations through DevOps best practices and being willing to address small but high-priority business initiatives quickly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 13:17:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/21051#M1097</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-04-10T13:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/21063#M1098</link>
      <description>Who knows what evil lurks in the hearts of systems?&lt;BR /&gt;&lt;BR /&gt;The Shadow IT knows!&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;In order to make anything a reality, you have to dream about it&lt;BR /&gt;first. - Adora Svitak&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 10 Apr 2019 18:05:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/21063#M1098</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-04-10T18:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow IT happens</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/21304#M1148</link>
      <description>&lt;P&gt;fully agree, DevOps makes things so much harder, as well as shadow IT is a symptom of other problems a company. Be it badly implemented change control or general IT management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I have seen developers launching containers hosting applications such as NextCloud to make their lives easier, introducing new tech and features in an unmanaged&amp;nbsp;fashion, making applications easy to deploy and fast, such as having docker nodes for devs to test on, means there is temptation to implement stuff and services quickly as POC'ss that become mission critical running on test nodes or on servers under desks or in labs, unmanaged and insecure.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I think the crunch of this is! SHADOW IT is a sign of poor Management, everything starts at the top with policy if company policy is not enforced by the managers than it's only a slippery path down to major problems, eventually a security issue. Failure in policy, failure in management and us security people are putting up wall and barriers to this fast productive new wave of IT!&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2019 14:45:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Shadow-IT-happens/m-p/21304#M1148</guid>
      <dc:creator>Wayne_Evans</dc:creator>
      <dc:date>2019-04-17T14:45:03Z</dc:date>
    </item>
  </channel>
</rss>

