Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, February 17, 2011

Using Bug Detectors to Guard Against Spying


If you need to secure your office, home or hotel room from wireless microphones and transmitters, there are bug detectors that can pinpoint the location of these concealed transmitters using an audio alarm or a LED display.

Did you know that bugging and eavesdropping is a common practice? And it is not just the police, FBI or CIA who are doing the bugging. When you use special bug detectors on your telephone lines, you can easily determine virtually any type of equipment that is being use to bug your telephone, whether your phone is off or on the hook.

There are such nifty, hidden bug detectors that they can even look like an innocuous smoke alarm, yet, should anyone enter your presence carrying a hidden radio transmitter, these pretend smoke alarms will alert you to their presence by flashing a red LED two times per second.

Other bug detectors come very compact, and can tell you if someone is carrying a hidden spy camera. It can also tell you if one is hidden on the premises. Such devices were formally only sold to the U.S. government, but now are available for public use and can guarantee you and others, who may have that concern, peace of mind.

Other bug detectors come with a 2.5 inch monitor display that not only finds multiple hidden cameras, but will show you exactly what is being displayed on them, and the time it takes to scan for these hidden cameras is only five seconds. These devices run on double A batteries, too.


Saturday, February 12, 2011

Developing a Standard AUP

Developing an Acceptable Usage Policy (AUP) requires organizations to utilize a process that can ensure their AUP, once implemented, is as effective as possible. One popular method for this sort of Management Assessment is called RISK, an acronym that stands for requirements, identify, select and know. Employing RISK to build an effective AUP is important whether an organization is publicly or privately held. Even family-owned businesses need an AUP if their employees have access to the Internet.

RISK

The requirement of their RISK policy includes understanding that the company's reputation and assets could be endangered by employee abuse or misuse of the company's network or computers. When a company understands that email, instant messaging, peer-to-peer and web surfing technology can leave them vulnerable to exploitation or network and system damage, they have identified the key elements around which they must design their AUP.

Once the basic requirements have been identified, the next step is to construct a policy that will protect both their network security and the company's reputation. Since breaches in computer network security can lead to substantial regulatory fines judicial settlements that can cost billions and negative media attention that can seriously damage a company's reputation, the design of a comprehensive and relevant AUP is more important than ever.

Design & Educate

First of all, the AUP should be explicitly written and clearly presented to all employees. It should be comprehensive, covering all rules, polices and procedures appertaining to P2P, Internet, Instant Messaging and email activities. The use of any vague language should be strictly avoided in an effective AUP. For example, stating that email is to be used for business purposes can leaves wiggle room for an employee to state he was using his email for business when he actually means "personal" business rather than correspondence pertaining to his job.

Instead, the AUP should detail exact use and abuse terms. For example, the company should detail that downloading music, video and other copyrighted materials is expressly forbidden. Employees should be notified that all communications whether of a personal or business nature are monitored and stored. The need for such monitoring should be explained as well as the penalty for employee abuse. Employees should be made to understand that use of company computers and protocols such as email, IM and P2P are not rights, but rather privilege given to them by the company.

Penalties ranging from written warnings all the way up to termination should be clearly explained. The comprehensive nature of the policies and procedures should be updated regularly in order to govern developing concerns such as blogging. New technologies and communication protocols are appearing daily – a company's best acceptable usage policy should be flexible enough to accommodate these emerging threats.
Monitor & Enforce

Developing the AUP and educating employees is only the first step. The implementation system should also include how the company will monitor and enforce their internal AUP. In an ideal world, simply telling an employee to not exercise bad judgment might be enough. But employees can be mislead themselves and endanger a host network security system despite good intentions.

Whether a company chooses a hardware or software solution will affect how well they are able to monitor and enforce their AUP. Although the education of employees will assist in the enforcement of the AUP because the judicial system could find that a corporation has made a reasonable effort to keep their corporation free of hostility, harassment and other abusive behaviors, it will not be enough to keep your networks safe from outside intrusion, whether intentional or not

The AUP will reduce the vicarious liability that a company may endure but the vicarious liability factor is further protected when the written AUP is enforced through disciplinary actions and filtering solutions. A filtering solution can prevent employees from accessing sites, software and other connections that may violate the company's AUP and endanger its networks and systems. This will eliminate employee error on many levels.

Whatever the chosen filtering solution, it should also monitor behavior in order to provide for disciplinary action on the part of the company as needed. As previously mentioned, disciplinary action can be applied in stages from written warnings to suspensions to termination of employment. These rules should be detailed specifically in the AUP and presented clearly to the employees so that expectations and rulings are clearly defined prior to any action being taken.

The Solution is the Solution

Defining the AUP requires identifying the risk management issues, key software vulnerabilities and required employee behavior. When an effective AUP is combined with disciplinary action that is clearly stated and effectively enforced, companies are protecting their employees, networks and finances. However, an AUP's ultimate success will hinge a great deal on the type of filtering solution a company chooses.

A filter that not only enforces the AUP, but also monitors the behavior of the employees provides a double layer of protection.. A powerful and effective filtering solution is the final piece of the puzzle to developing, maintaining and enforcing the company AUP.

Thursday, February 10, 2011

Your Next PR Nightmare Could Be Only a Click Away

In the age of Enron and failed intelligence, scandals remain the rage of the front page. Companies want to see positive spin and not scandal related material published. Imagine for a moment the educational software site where employees are identified as regular visitors to pornography websites. The effect to such a company's image could be devastating.

Leaks, Peeks & Sneaks

There are numerous security risks facing companies with internal networks. Primary among their concerns are stifling leaks and backdoors that allow hackers to penetrate their firewalls. But the threat from within the company may prove to be more devastating to a company's reputation and subsequently their stock value and much more.

Employees face a four-pronged attack from blended threats across the board. Phishing and pharming are two of the more popular attacks that face Internet users everyday. Typically sent via email, phishing attacks depend on the concern of an employee to take care of matters ranging from personal to financial. The uneducated user will click an embedded link and leave the network vulnerable to an attack.

The sophistication of these attacks can penetrate even the most complex of security systems unless user error can be compensated for. The most popular forms of phishing involve instant messaging and emails. Despite the widely known understanding of spoofing, most users do not expect to receive messages from spoofed accounts.

Increasing a systems security perimeter can block instant messaging ports and prevent such external security breaches. Network security devices can also block web requests to URLs presented in instant messages. Better still, URLs or web requests from internal users can be compared to a database of acceptable websites and disallowed or denied if they do not match.

Living on the Fringe

Installing spyware and malware is another by-product of visiting less than secure websites. Internet users are often besieged by offers for free software, free access and freebies. The lure of the freebie is as potent if not more so on the Internet than it is in real life. Downloading such freebies can come with passenger programs designed to record keystrokes and much more
The least of the problems that spyware can commit is to tie up bandwidth and computer memory. The worst is that it can actually spawn Internet attacks to other sites, download critical data and send it elsewhere. Employees do not have to be lured just by a freebie either. They can simply make a typo in submitting a URL and find themselves in the wrong Internet neighborhood. Clever programmers can generate pop-up windows and disguise a button with a simple label like 'close' and the user will click it, thinking they will only close the nuisance window. Some programs on high-speed network access can be downloaded in the blink of an eye, compromising the computer and potentially the network.

One-Click Scandals

Scandals need very little fuel to fire. A user who chooses to go to a website of questionable integrity and intent and a user who is lured there by a bad link or a typo offer the same type of danger to a company. Scandals do not have to make the front page to generate reputation-damaging issues for a company.

Word of mouth is as fast a delivery service for reputation sabotage as press reporting is. A network security company that cannot protect against hacking of their website does not engender trust or confidence. A financial investment firm that is accused of insider trading when emails and instant messages from employees are subpoenaed and found to be questionable will likely lose clients, capital and more.

The Burden of Responsibility

Scandal can be generated by an innocent act as easily as by one of guilty intent. Corporations are responsible for the actions of their employees. Questionable Internet behavior and activity can and will affect a company's reputation, financial standing and potentially their legal standing as well.

A corporation bears the burden of responsibility for its employees and their actions. By employing network security devices to monitor and restrict Internet activity, a corporation not only relieves a large measure of their burden, but also protects their interests on numerous fronts. Without such protection, a company is courting disaster and inviting scandal.

Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Powered by Blogger