DMS Security Flaw - Can I get some help?
LacerteI have given input to Lacerte over the last several months to try to fix what I consider to be a fatal security flaw in DMS but so far have not heard when or if this will be fixed. I would prefer not to post this type of item on a general forum but I am doing so now to 1) warn those decision makers that have or are considering adopting the DMS system, and 2) to bring attention to the flaw to try and get Lacerte to fix the flaw.
The security flaw is that currently anyone with access to the system (rouge employee, janitor, etc) can simply drag and drop (cut/paste) all client information out of DMS to a USB drive, Dropbox, etc. The effect is that this allows anyone with access to the DMS system to move the sensitive client information off-site.
Now I am going to get really extreme to make my point - suppose somehow that information then makes its way to a Wiki type site out of the country for the world to see. The world now has your client’s bank accounts numbers, social security numbers, etc. etc. Imagine the problems that would create! Is this to extreme? Then let’s just say the rouge employee goes across the street and sets-up shop as your competitor. Also extreme since this would be professional theft. My point is the ability to even do this is a major security flaw.
My conclusion is that Lacerte needs to tighten up this whole security hole as soon as possible. I realize you can set-up security rights within DMS to restrict a user’s ability to transfer files out of DMS. However that same restriction limits the user’s ability to transfer files between folders within DMS which makes this restriction unworkable. This problem is further exacerbated by the fact that the activity log does not record transfers out of the DMS system. Thus there is NO AUDIT TRAIL of who moved the information out of the DMS system.
I consider this to be a major security flaw and would appreciate help in highlighting the importance of getting this flaw fixed.


