• Was this page helpful?
Intuit Blog
|
Support
GoPayment
|
Payroll
|
QuickBooks Online
|
QuickBooks
|
Website Services
Intuit
Sign In
Register
QuickBooks General Forum QuickBooks Payroll 3rd Party Apps that work with QuickBooks QuickBooks Accountant Edition QuickBooks Online for Accounting Professionals QuickBooks Enterprise Solutions QuickBooks Point of Sale
ProAdvisor Program & Certification
ProSeries DMS ProSeries Community
Lacerte DMS Lacerte Community
Intuit Tax Online Tax Research for Lacerte and ProSeries Tax Import for Lacerte and ProSeries Intuit Practice Management EasyACCT Intuit Statement Writer
Starting and Managing Your Practice Classifieds Intuit ProConnection Newsletter Intuit Academy Training Your Peers Recommend
  • QuickBooks & Payroll
  • ProAdvisors
  • Lacerte
  • ProSeries
  • Productivity Tools
  • Training & Resources
Leaderboard
Hide Advanced Search
 
All of these words
Any of these words
This exact phrase
None of these words
In this forum
With posts written by
With posts from
to
mm/dd/yy
mm/dd/yy
Show Advanced Search
Home   Help for Accountants   Lacerte   Lacerte DMS  
hide
05/24/2012 at 04:51PM PDT
Important Announcement! A planned system-wide upgrade will take place over the Memorial Day Weekend in the US (From Thurs, May 24, 2012 at 6 pm PDT thru Tues, May 29, 2012 at 5 am PDT). This includes QuickBooks, QuickBooks Payroll, Point of Sale, & Salesforce.com. This is only for US based products. This does not affect QuickBooks Online customers! During this time, you can shop, but can’t place orders online, activate products or update account info. We apologize for the inconvenience & thank you for patience while we improve our infrastructure to better serve you. International versions are unaffected. For more info, see our community discussion.
1
9
a5mcQa-Qur4kKlacwZ5xHE
Subscribe RSS
waytogoidaho
waytogoidaho
Questions asked: 4
Questions answered: 16
Points earned: 16
ProAdvisor
ProAdvisor
Members of the QuickBooks ProAdvisor Program
waytogoidaho
waytogoidaho
Questions asked: 4
Questions answered: 16
Points earned: 16
Contributor
10/19/11 4:04pm PDT
Viewed by asker 04/05/12 4:30am PDT

DMS Security Flaw - Can I get some help?

Lacerte

I have given input to Lacerte over the last several months to try to fix what I consider to be a fatal security flaw in DMS but so far have not heard when or if this will be fixed. I would prefer not to post this type of item on a general forum but I am doing so now to 1) warn those decision makers that have or are considering adopting the DMS system, and 2) to bring attention to the flaw to try and get Lacerte to fix the flaw.

The security flaw is that currently anyone with access to the system (rouge employee, janitor, etc) can simply drag and drop (cut/paste) all client information out of DMS to a USB drive, Dropbox, etc. The effect is that this allows anyone with access to the DMS system to move the sensitive client information off-site.

Now I am going to get really extreme to make my point - suppose somehow that information then makes its way to a Wiki type site out of the country for the world to see. The world now has your client’s bank accounts numbers, social security numbers, etc. etc. Imagine the problems that would create! Is this to extreme? Then let’s just say the rouge employee goes across the street and sets-up shop as your competitor. Also extreme since this would be professional theft. My point is the ability to even do this is a major security flaw.

My conclusion is that Lacerte needs to tighten up this whole security hole as soon as possible. I realize you can set-up security rights within DMS to restrict a user’s ability to transfer files out of DMS. However that same restriction limits the user’s ability to transfer files between folders within DMS which makes this restriction unworkable. This problem is further exacerbated by the fact that the activity log does not record transfers out of the DMS system.  Thus there is NO AUDIT TRAIL of who moved the information out of the DMS system.

I consider this to be a major security flaw and would appreciate help in highlighting the importance of getting this flaw fixed.
 

Submit a reply to this question
Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
 Report Abuse
10 Replies
Taxguy21
Taxguy21
Questions asked: 8
Questions answered: 18
Points earned: 38
Certified ProAdvisor
Certified ProAdvisor
Certified ProAdvisors have successfully completed an extensive and rigorous QuickBooks certification program.
ProAdvisor
ProAdvisor
Members of the QuickBooks ProAdvisor Program
Taxguy21
Taxguy21
Questions asked: 8
Questions answered: 18
Points earned: 38
Contributor
10/20/11 11:27am PDT
Best Answer - Chosen by the Community

Unfortunately, there are no real simple answers I can offer you. Some things that came to mind are below:

A simple solution would be to force logouts over night for the cleaning crew. Also, setting login hours by employee may give you some additional comfort as the rogue employee could do this after hours.

There is an activity log feature that allows for tracking the saving out of DMS located in Document activities.

Also, monitoring the system event log on the server would be advisable.

Maybe setting the rights on the indiviudal pdf files inside DMS would be of use. Adobe allows for password protection of pdfs.

PS - Go Broncos !! ( Also in Idaho)

Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
5
Reply to this Answer
 Report Abuse
 
 
 
waytogoidaho
waytogoidaho
Questions asked: 4
Questions answered: 16
Points earned: 16
ProAdvisor
ProAdvisor
Members of the QuickBooks ProAdvisor Program
waytogoidaho
waytogoidaho
Questions asked: 4
Questions answered: 16
Points earned: 16
Contributor
10/20/11 3:31pm PDT

Thanks for the suggestions taxguy21.

We do force logouts overnight which does prevent the cleaning crew issue. Part of my objective in the post was highlighting the security issues to people who had not yet considered them and to also solicit ideas regarding possible methods for minimizing the risks. So again thanks for your suggestions.
Monitoring the system event log on the server is a good idea. I am not sure how much of the transfer out of the DMS and onto a USB drive or Dropbox account activity would be logged but I will check into this.

Setting the rights on individual pdf files seems too cumbersome and unworkable.

Although there is an activity log feature that appears to allow tracking of “Saving out of DMS” activity, as of version 8.0.5 it doesn’t appear to track dragging and dropping items to your desktop or elsewhere. If I drag and drop a client folder, file, etc. out of DMS and then go to the activity report and check to look for “Saving out of DMS” activity, nothing shows up. Please give it a try and let me know if any “Saving out of DMS” activity shows up under your activity log.

In any event, all of the solutions I have found so far provide for the possible tracking of the activity but don't allow for the prevention of the activity. This is analogous to a solution that says to just leave the door open and set up a camera to see who is walking out the door with your valuables.

It appears to me that DMS should allow for security rights that prohibit moving items out of the DMS system while still allowing the ability to move files and folders within the DMS system. In other words, once data is in the DMS system a user should be able to do anything they want to the data including deleting the data (since a recovery of deleted data option is available) with the exception of moving data out of the DMS system. If data is moved out of the system then at a minimum the activity should be recorded.

Although this post shows as “answered” I do not consider this security hole to be fixed.


By the way taxguy21, yes Go Broncos, but let's keep it on the low for our Idaho Vandal friends who are having a hard time this year.
 

Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
Reply to this Answer
 Report Abuse
 
 
 
FredKCPA
FredKCPA
Questions asked: 26
Questions answered: 46
Points earned: 103
FredKCPA
FredKCPA
Questions asked: 26
Questions answered: 46
Points earned: 103
Contributor
10/21/11 4:24am PDT

A somewhat simple solution is to any client in DMS, right-click on the client & it gives you the option to select all clients which you can do.  Then, to the right comes up some choices with one of the choices being password protect.  We can then assign an overall password to all of the clients.  For those clients who you want to have a different password, we simply put them in a separate database with their own specific password.  Hope this helps alleviate some of your security concern. 

Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
Reply to this Answer
 Report Abuse
 
 
 
Taxguy21
Taxguy21
Questions asked: 8
Questions answered: 18
Points earned: 38
Certified ProAdvisor
Certified ProAdvisor
Certified ProAdvisors have successfully completed an extensive and rigorous QuickBooks certification program.
ProAdvisor
ProAdvisor
Members of the QuickBooks ProAdvisor Program
Taxguy21
Taxguy21
Questions asked: 8
Questions answered: 18
Points earned: 38
Contributor
10/21/11 8:47am PDT

Last night I thought of one other possible solution for your USB issue. In Windows, there are security policies that can be be created to prevent the use of local USB drives.  I am a self taught Windows guy, so I can't really be more specific on this, but the idea is to restrict the use of resources available. In a windows domain, you should be able to create the security policy and push it out to all users logged into the network resources.  If you restrict all usb activity and then use an exception based office policy with only certain users able to create files on a USB drive, again, some compensating controls are possible.  A headache maybe, but if the need is sufficient to justify the security restriction, do it.

Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
Reply to this Answer
 Report Abuse
 
 
 
ScottBonacker
ScottBonacker
Questions asked: 151
Questions answered: 1969
Points earned: 2488
Allstar
Allstar
Advisory council of community power users.
ProAdvisor
ProAdvisor
Members of the QuickBooks ProAdvisor Program
ScottBonacker
ScottBonacker
Questions asked: 151
Questions answered: 1969
Points earned: 2488
Allstar
10/24/11 7:19am PDT

In any data system limiting physical access to the devices or storage location is a key component of security procedures.

Even with full disk encryption, once a device is removed from the premises risks rise dramatically.

But within the walls of the castle, smooth functioning often requires that restrictions to access be as unobtrusive as possible.

You have looked at restricting the things you mention I imagine, disabling external storage devices on workstations - USB ports and CD writers? Software firewalls can block access to DropBox or similar sites. Email controls can prevent sending of attachments except for those who are authorized.

Scott

http://www.bankinfosecurity.eu/articles.php?art_id=556

 

Scott Bonacker CPA
Springfield, MO

Please post additional questions or else click SOLVED.
Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
 Report Abuse
 
 
 
waytogoidaho
waytogoidaho
Questions asked: 4
Questions answered: 16
Points earned: 16
Contributor
10/24/11 8:16pm PDT

Can anyone get any "Saving out of DMS" activity to show up in their DMS activity log?  If yes, please describe what type of activity? 

 

If no, please comment. I haven't been able to get any cut and paste or move files/folders out of DMS activity to show up in the activity log so I am wondering what time of "Saving out of DMS activity" is reported here.

 

Lacerte you can add your two cents here also anytime!

Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
 Report Abuse
 
 
 
Taxguy21
Taxguy21
Questions asked: 8
Questions answered: 18
Points earned: 38
Contributor
10/25/11 8:43am PDT

I tested this am on an export to a file outside of DMS. I could not see in the activity log under Document Activities and group by activity. I can see previous actvitiy, but not for today. It seems it may be broken in the current release. I am showing other activity in the saving out of DMS, but I beleive it is prior to 8.04 release.

Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
Reply to this Answer
 Report Abuse
 
 
 
ScottBonacker
ScottBonacker
Questions asked: 151
Questions answered: 1969
Points earned: 2488
Allstar
Allstar
Advisory council of community power users.
ProAdvisor
ProAdvisor
Members of the QuickBooks ProAdvisor Program
ScottBonacker
ScottBonacker
Questions asked: 151
Questions answered: 1969
Points earned: 2488
Allstar
10/28/11 9:41am PDT

This isn't necessarily a response to the issues you raise, but I want to throw this in the mix to add an additional resource for anyone that sees this:

http://www.techrepublic.com/blog/10things/10-security-problems-you-might-not-realize-you-have/2768?tag=nl.e042

 

Scott

Scott Bonacker CPA
Springfield, MO

Please post additional questions or else click SOLVED.
Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
Reply to this Answer
 Report Abuse
 
 
 
waytogoidaho
waytogoidaho
Questions asked: 4
Questions answered: 16
Points earned: 16
ProAdvisor
ProAdvisor
Members of the QuickBooks ProAdvisor Program
waytogoidaho
waytogoidaho
Questions asked: 4
Questions answered: 16
Points earned: 16
Contributor
01/05/12 4:05pm PST

I will provide an update with an answer to the original question - Can I get some help? And the answer is still NO.  Not at least at this time from Lacerte in their most recent version 9.0.

I never dreamed that fixing the lack of an audit trail (activity log) for client documents leaving the document management system would take so long and that this would not be addressed in a new version release.

Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
Reply to this Answer
 Report Abuse
 
 
 
ScottBonacker
ScottBonacker
Questions asked: 151
Questions answered: 1969
Points earned: 2488
Allstar
Allstar
Advisory council of community power users.
ProAdvisor
ProAdvisor
Members of the QuickBooks ProAdvisor Program
ScottBonacker
ScottBonacker
Questions asked: 151
Questions answered: 1969
Points earned: 2488
Allstar
01/16/12 11:06am PST
Latest post

Came across an article this morning that reminds me of your question -

http://www.healthleadersmedia.com/content/MAG-275301/Dealing-with-Data-Breaches

The print edition of the article mentions a proposed HIPAA rule that would require that if a patient asked for a report disclosing who had looked at their PHI the provider will be required to provide it.

http://www.hhs.gov/ocr/privacy/hipaa/news/hitechnewsonaccountingdisclosure.html

Considering that many tax firms also sell investments and insurance, and therefore fall under HIPAA and HITECH, I wonder how strong the linkage to the tax practice is or will be?

In any case, if a tax firm has celebrity clients or other high visibility clients then what the clients want is probably more than any government agency would require.

Scott

(PS - looked at www.waytogoidaho.com and have a question - which is better Vodka from potatos or Vodka from grain?)

Scott Bonacker CPA
Springfield, MO

Please post additional questions or else click SOLVED.
Type of Abuse
Abusive behavior
 
Inaccurate information
 
Other (add details below)
 
Add Details
Cancel_sm Submit_sm
This helped me! Add 1 point.
0
Reply to this Answer
 Report Abuse
 
 
 
   
 
Submit a reply to this question
 
Subscribe RSS
Tags for this topic
  • lacerte
Use commas to add multiple tags
Add tags
Latest Site Activity
Pause Feed
Rhondah
30 secs ago
Rhondah
needs more help on
Renewal quote
franciscoramos06
1 hr ago
franciscoramos06
has a new Spotlight
construction loan charlesto...
Adityaa
4 hrs ago
Adityaa
has a new Spotlight
Commodity brokers
TaxAcct1
7 hrs ago
TaxAcct1
posted
AQMD Truck Grant 2010
Screennamenotalreadytaken
13 hrs ago
Screennamenotalreadytaken
replied to
Renewal fee increase 20% ?!...
Product Resources
QuickBooks Tax Products Payroll ProAdvisor Program Training and Certification Feedback Survey
Resources: Find Local ProAdvisor Tax Almanac Practice Resources
Support: QuickBooks Lacerte ProSeries EasyACCT
Community Home Help with Intuit Products Start & Grow Your Business Help for Accountants Small Business Blog Join us on Facebook Follow us on Twitter Watch us on YouTube Meet us on LinkedIn
About Intuit | Careers | Register Your QuickBooks | QuickBooks Affiliate Program | Privacy | Legal | Contact Us | Our Hosts
© 2012 Intuit, Inc. All rights reserved. Intuit and QuickBooks are registered trademarks of Intuit, Inc.
Terms and conditions, features, support, pricing and service options subject to change without notice.
TRUSTe - Privacy Standards and Principles
Intuit Websites - Create the perfect site
Intuit Small Business
QuickBooks Accounting Software
Small Business Grants
QuickBooks Online Accounting
Intuit Payroll Services
Intuit Credit Card Processing
Intuit Business Directory
Intuit GoPayment
Intuit Small Business Education
Intuit Small Business Blog
Love a Local Business