Frequent system changes without documentation or audit processes can cause system downtime and security breaches from internal and external threats, while decreasing overall operational efficiency.
A Netwrix survey collected data from 577 IT professionals in organisations across multiple industries and range of sizes. Key study findings show that of the respondents:
- 65% have made changes that caused services to stop
- 52% make changes that impact system downtime daily or weekly
- 39% have made a change that was the root cause of a security breach
- 40% make changes that impact security daily or weekly. Interestingly, industries with higher regulations are making changes that impact security more often, including healthcare (44%) and financial (46%).
- 62% have little or no real ability to audit the changes they make, revealing serious gaps in meeting security best practice and compliance objectives
- Just 23% have an auditing process or change auditing solution in place to validate changes are being entered into a change management solution.
"With roughly 90% of outages being caused by failed changes, visibility into IT infrastructure changes is critical to maintaining a stable environment. Change auditing is also foundational to security and compliance requirements," said David Monahan, Research Director, Security and Risk Management, Enterprise Management Associates.
“Auditing changes in enterprise class environments requires the ability to get a high level strategic view without sacrificing the tactical system level detail and insight extended throughout the whole system stack. Netwrix Auditor excels at acquiring information from a broad coverage of Windows and ESX based systems, including systems that don’t generate native audit trails. The product collects alerts in a non-intrusive way providing insights to those changes with a consolidated reporting engine," Monahan added.