>

Buy Microsoft Office Ultimate 2007!
Showing posts with label Goals of Internet Security. Show all posts
Showing posts with label Goals of Internet Security. Show all posts

March 3, 2009

*FREE* Achieving Information Security *FREE*

Hey everyone,

I put together a white paper entitled "Achieving Information Security". Is is a compilation/rework of a series of blog posts I had done that got some good feed back.

It is now free for download, so check it out.

Feel free to pass it along to friends, colleagues, and whoever else you want, and as always, feed back is always welcome, just use the contact me link.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

March 1, 2009

Acceptable Usage Polices

An important step in preventing inappropriate use of computer equipment and time at work is to define what types of activities are acceptable. Sure, it may seem like common sense to you and I that browsing MySpace or Facebook at work is not appropriate when you are on the clock, but unless you define the behaviors that are acceptable and unacceptable, you cannot fairly expect the staff to know for sure, nor can you fairly punish them since no rule was technically broken.

A good acceptable usage policy will cover several aspects of computer usage, not just what web sites are ok to visit and which aren't.

Some things you need to remember to cover are:

  • What information can and cannot be released to the public
  • What permissions must be obtained before releasing any data to media or the public
  • Who is authorized to release data
  • Who is authorized to speak on behalf of the company
  • What type of information can be transferred or discussed via email or instant messenger.
  • Policies on employees posting on web forums about the company, or in association with the company.
  • Where can company information be stored
  • What kind of work can be taken home
  • Are USB thumb drives or other external storage devices allowed.
  • Policies on changing computer settings
  • Policies on personal data on work computers.
  • What types of web sites are appropriate
  • Acceptable usage of company equipment on personal time.

All of this needs to be discussed, and written out in a way that is easy to understand. If an employee is not told what they can and cannot do, especially when it comes to things like releasing data to the public, or speaking on behalf of the company, it can lead to mistakenly releasing information, which can lead to much bigger problems.

  • In addition to noting what type of behavior is acceptable and not acceptable, try to explain why the rules are in place.
  • Why is talking to the media a liability?
  • Why is posting on a forum while trying to defend your company dangerous?
  • How does this directly affect he employee?

If an employee has a person interest in making sure data stays secure, they are going to be much more cautious about it.

Once the rules are set, you also need to list the consequences of breaking these rules. Consequences may be applied on a case by case basis, as not all violations are equal, but there must be standards and they must apply to everyone equally, or they are useless. Once consequences are in place, they must be enforced. Having consequences in place, but only selectively applying them confuses employees, and makes it look like you are playing favorites, and this will quickly lower the respect your employees have for you.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 27, 2009

Rouge Admin or Dedicated Employee

Over the last several month, there have been many articles published about Terry Childs; the San Francisco network administrator who is img_50191_laptop_theft_wb now in jail after being accused of 'network tampering' during his tenure as Lead Network Administrator for the city of San Francisco.

For those who have not been following the story:

  • Terry Childs was the lead network administrator for the city of San Francisco, and managed a very large network responsible for the majority of government data traffic.
  • The unofficial reason for him tampering with the computer network was that he was trying to create an insurance policy of sorts for himself after he got a poor performance review and his supervisor tried to have him fired.
  • Childs' allegedly configured a single administrative username/password that only he had access to on several key pieces of equipment, and when asked for the credentials, he gave wrong info, then refused to give the correct info.
  • Child's is also accused of deleting the startup configurations on several pieces of equipment, so in the event the power went out on the device (required to reset passwords sometimes) the configuration would be lost. Password recovery features were also disabled.
  • Childs' also allegedly install data monitoring software on several supervisors computers, and was found with lists of usernames and passwords, including those of his superiors.
  • And finally, Child's is accused of setting up 'rouge' devices across the network to provide him remote access to it.

I know, this looks bad. But lets consider what his job was, the man was a network administrator, and much of the above can easily be seen as part of his job.

Things Terry did, that I do daily.

  • We have 2 administrative accounts on each computer, 1 master administrator account that stays un used, and 1 administrator account that we use for admin tasks. We do this, so in the event something happens to the one we use, we have a backup that is not used. Only we have these passwords, our clients do not. It is not rare for them to request this info, but we explain that if we provide them administrative access to servers and other equipment, we cannot be held responsible for it any longer. If they need changes made, we can do it for them. If they insist on access, we reevaluate them as customers as it is not worth our reputation to allow an untrained person admin access to a server when they have no reason for needing it.
  • Part of the service we provide is installing an application on each computer that monitors event logs, runs maintenance at night, monitors anti-virus software, provides us remote access to computers, and several other things. Monitoring computers is part of our job.
  • Configuring remote access to sites. Any network admin who has to support multiple locations sets up ways for them to access things remotely, otherwise they cant do their job. It is not rare to set up multiple methods of remote access, so in the event one fails, you have another option.

 

How do I feel about this case?

My feeling towards this are mixed. I understand that sometimes an IT admin needs to protect a company from itself. Too often company executives think that because they are high up in a company they should be allowed to do what they want on a computer and access whatever they want. This is not true. Executives are targets in the hacking world. Their information is all over the place on the web and on their company web sites because they want to be known. Because so much data about them is available, it makes it easier to exploit them. This means their accounts need to be even more tightly controlled than the average user, but this is the exact opposite of what they want, and sometimes demand.

When a CEO demands access to something, an IT professional is put in a tough position. They can give the access, and the deal with any problems created by it (and trust me, problems occur frequently when people have unneeded access), or you can stand up to the person and risk backlash.

I have been in this position in the past. A position where executives come up with inane ideas and requests, and despite the IT department explaining why the idea is bad, and the risks involved, and the potential for problems, we are pushed into making the changes. When something goes wrong, we are then looked at like we caused it, and that is not fair. I have left jobs because of situations like this.

The networks and computers we build and maintain as administrators are like a living resume. If you are named as the admin on a network with a major security breach, it can dramatically hurt your career, so when you are faced with these decisions, you are being asked to put your reputation on the line. So with every decision, you ask yourself, "is this risk worth my career?"

However, as a professional, there is a point where you just need to cave and give the boss what they want, and let them deal with the problems. When he was faced with arrest, Childs' should have left the job, and turned over all credentials and information in a proper way, there is no if ands or buts. The data belonged to the city, and while I'm sure he wanted to protect it, and while he may have thought he had been wronged, he had no legs to stand on when it came to that.

I am very interested in seeing how this will turn out.

 

More info about the case:

http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/14/BAOS11P1M5.DTL

http://www.infoworld.com/article/08/07/15/IT_admin_locks_up_San_Franciscos_network_1.html

http://www.infoworld.com/article/08/07/17/IT_administrator_pleads_not_guilty_to_network_tampering_1.html

http://weblog.infoworld.com/venezia/archives/020956.html

http://blogs.techrepublic.com.com/career/?p=555&tag=nl.e101

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 23, 2009

Microsoft Elevates America

Microsoft announced today that they will be partnering with governments, private, public and community organizations to launch microsoft_logo Elevate America; a free and low cost resources that provide the skills, training and certifications needed for people of all ages who are preparing for job opportunities in today's changing economy.

"As part of our ongoing investment in education and workforce readiness, Microsoft is providing additional support through governments and designated partners to accelerate the workforce readiness of Americans through the most relevant training and certification programs we offer."

Some of the things Microsoft will be assisting with are:

  • Expanded access to basic technological literacy and skills training.
  • Intermediate technology skills training courses, instructor-led and online, plus selected certification exams.
  • Access to a new web portal that will help guide individuals to training that positions them for success in the economy today, and tomorrow.

One of the programs I am looking forward to is an expansion on the Microsoft Second Shot Offer. In addition to Microsoft giving test takes a free retake in the event they do not pass their exam, they will also be offering a highly discounted price on e-Learning material to study for your exams. If you have not taken any of your exams yet, DO IT NOW. Check out the new ThinkSmarter Store for some recommendations on study material. As for me? Its time to get back to grinding away at those certifications.

To read more about this amazing program, or to learn what resources will be available to you, see the Elevate America Website.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 19, 2009

Top 9 Dirty Tricks Scammers Use

PC World has posted an interesting article Outlining some of the more common scams that are being used to trick hard working people out of their money.

The list contains scams that are used on Social Networking sites like Facebook and MySpace, as well as attempts to trick users by emailing them at home and at work.

Scams like this are becoming more common as unemployment rates go up and the budgets shrink because people are getting desperate and looking for an easy fix. Like everything else in life, if something seems to good to be true, it probably is. Be careful who you give your personal information to, and you will be well on your way to protecting yourself from scams like these.

Read the Full Article Here

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

July 26, 2008

Achieving Information Security: Response (3 of 3)

Given enough time and resources, any security system put in place will be over come. This is undisputed fact. Coming into the office one morning, and seeing that your network has been compromised, knowing that detailed and confidential client or patient data has now been stolen, is not the time you want to figure out how you should react to the situation. It situations like this, you need to move quickly and intelligently, and not let your emotions (fear for your business, anger for the violation) take hold of you.

One of the most important parts of planning a proper response is to understand who is at risk because of the breach. You need to understand that as violated as you feel right now, other, who don't even know they are in danger, possibly are. If you run a business who bills clients (basically every business), then that payment information is on file somewhere, and puts those clients at risk. If you are a doctor, you likely have highly personal information about your patients.

Once you established who is at risk, establish a list of who needs to be contacted, and how you plan on contacting them. The most obvious, yet over looked often, are the police. If you think or know you have had a security breach, and data has been stolen, it is time to contact the authorities. data theft is still theft, and computer crimes are a big deal. Also, check which other authorities may need to be required based on your industry.

Once the proper Authorities have been contacted, contact others who may be at rick. If patient information has been stolen, contact your patients. If billing or financial information of clients has been compromised, let them know.

Contacting a client to tell them their information may have been stolen is a difficult thing. Expect to get a lot of calls, and be ready to answer a lot of questions. And in today's world, be prepared to compensate the client for their loss. It is typical for the company responsible for the data loss to pay for identity theft insurance for their clients for up to a year following the breach, anything more than that is nice, but unless what was stolen caused direct loss to your client, then you don't own them much, in my opinion.

Now that you have contacted the proper authorities and the people affected, then last step is to find out what went wrong, and fix it. How did the thief get the data, what type of attack was used, and what can you do to prevent it from happening again.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

January 23, 2008

Achieving Information Security: Prevention (1 of 3)

The most valuable asset of most organizations is the information they hold. Whether it be top secret design plans for their next product, accounting information about future company acquisitions, or the personal information of your clients and employees. A breach in the security that protects these assets can and has resulted in companies going bankrupt due to loss of client confidence, law suits, and loss of competitive edge. There are three parts to achieving information security; they are Prevention, Detection and Response.


Prevention:
As the saying goes, an ounce of prevention is worth a pound of cure, and that is no different in the IT world. Preventing unauthorized users from gaining access to your confidential data should be priority one. There are several things that can and must be done to prevent unauthorized access to data. Not only do you need to consider digital security (passwords, user names, file permissions, etc) but also physical security.


Physical Security:
Physical security is often overlooked when we think about protecting information held on a computer, but the truth is, if somone gains physical access to your file server, they now own your data. So making sure you keep your server is protected and secured area is very important. Servers and data backups should be kept under lock and key at all times. Ideally you want a room with controlled access that is monitored electronically and by a human. Because a secure environment like this is not always available at your office, many companies choose to use data centers to house their servers. Data centers not only provide a great deal of security, but they can provide redundant power as well as fire suppression to protect your equipment. The level of security at data centers will vary based on the center you are working with, but most are very good.

For example, the data center I have used for clients in the past included the following security:

  • Biometric Palm Scanner + pin to get into the main door
  • Sign in with a security guard as you pass though the first set of doors (they check ID)
  • You go to your designated locker (they watch to be sure you are only near your lockers)
  • Key lock AND combination lock on the server rack doors.
  • Roaming security guard as well as CC security cameras.
  • After hours, before you could even enter the building, you had to be buzzed in by security
Now this may seem excessive, and it might be over kill depending on your business, but we dealt with accountants, lawyers, doctors, DOD contractors and other professions that data security was considered top priority. So it will be up to you to find a proper solution that matches the value of your data.

Digital Security:
Once you have a good physically secure location picked out and set up, you need to protect you data from people coming at it over the wire, and not through the doors. The method to which you choose to protect your data will again vary based on how valuable that data is, and it will be up to you to decide how much protection is enough. Your goal here is to make your data secure enough so those who aren't supposed to have can't, but those who need it can get it without too much trouble.

One of the easiest way to protect files in a windows domain environment, is by adding permissions to them. Not only can you select who has access to files, but you can choose what kind of access to the file they have. In some cases, many people may need to read a file, but only 1 or 2 need to be able to make changes to it, so you can give read permission to some and write or modify permissions to others. This allows a very customizable and secure security scheme. More information about windows Permissions can be found HERE.

File and folder permissions are great, but one of the major flaws in that type of set up is that the computer will assume anyone logged in as a user is indeed that person. So if Joe happens to know Susan's password and logs in as her, or Susan leaves her computer logged in and Joe sits at her desk, Joe will now have Susan's file permissions. So what we need here is called User Authentication. Essentially, user authentication is a way for a computer to verify who is actually sitting at the keyboard. The most common way to do this is via a Username/Password combination. More advanced and more secure ways include using Biometrics (fingerprints, palm prints, facial recognition) or a SmartCard. Many times people will use these different types of security in conjunction with each other (this is called multi-factor authentication) So like at my old data center, we used both Biometrics as well as a password (or PIN). This is a very common set up and the reason is it required not only two type of authentication, but two different types. So I needed something physically (my palm print) as well as something I knew (my pin). It might be easy for someone to steal a password or pin...but stealing a fingerprint or palm print is a lot more difficult.

Once you have your file security in place, you are pretty close so having a good security set up, but there is one last but very important piece of security that is constantly overlooked; The human element. In order to have any level of data security, you need to educate your staff on how to keep data secure. Employees need to know what data can be passed on to the public, what can be given to other employees or other departments and what must remain a secret or not be passed around. If you don't tell them, they wont know and the likelihood of an accidental breach is pretty big. A common way to keep track of what information can be given to different people is by giving different data a different level of clearance. For instance, in the military, and many large companies, they may label document confidential, secret, or top secret. Based on those designations, staff know that only people with top secret clearance can have access to top secret documents. Similarly, you may label some documents for "full public disclosure" where the data can be given out freely (this could be something like the phone number for the main office or a branch office) or "limited public disclosure" to control press releases and public announcements that can only be given with special permission.

Once you are able to control physical access, digital access, and are able to teach your employees on the proper way to handle data, you are well on your way to achieving a good level of information security.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google