| Security
Basics
First of all, lets talk about passwords. Many of these tools that I have mentioned will expose null passwords. This means that if you do not enter a password when you log in, these scanners will show that to the potential offender, and then the hacker can easily take control of your system. Its
time to find out what works what doesnt work on your site - all
in easy-to-implement and easy-to-use solutions. Another thing to keep in mind is default user accounts. Disable or delete all default user accounts that you can, and then set up real user accounts (with passwords) for all of your users. Be sure that all of your users can log on properly and that at least one of those users has administrative privileges before deleting or disabling the default accounts. In summary, make up your own password policy and make sure that your users follow it. The next item up for discussion is email attachments. I have two points that I can't emphasize enough: 1). Install antivirus software. (Ahem, INSTALL ANTIVIRUS SOFTWARE.) Also, keep it up to date. Most new viruses are aimed at the corporate giants who seem to find a remedy very quickly. Thus by the time you receive any given virus you will probably have the appropriate software already installed. 2). Save
the attached file in a folder before opening. I leave a folder on the
desktop just for this. My reasoning behind this is that nine times out
of ten your antivirus software will recognize the infected file when
you attempt to copy it. In summary, always check attachments and verify that they are clean before opening. It is also a good idea to ask people that you know that do send you attachments to send an email ahead of time to inform you that the next email will contain an attachment and that it is safe and not a virus. Last but certainly not least is the physical security of your machines. Keep them locked up as much as is practical. Lets face it, anyone with a bootdisk can have control of an unlocked computer. Machines with sensitive data should always remain under lock and key. Many hackers can exist inside of your network. It is better to keep the honest people honest than to have to recover from data loss, especially when that loss is a direct result of someone having access and/or privileges that they did not need and obviously did not deserve. For the truly paranoid (although this does not really affect your end users), be aware of where your network cabling is. It is not that difficult to hide a laptop with a packet sniffer running in a crawlspace. In conclusion, all of the best firewalls and security software in the world are not going to help you if your users are leaving machines wide open to anyone who wants access to them. If you can educate your users on the importance of security (i.e. there is no business if all of your trade secrets have been leaked out...) and what they need to do to keep their individual systems secure, you have just reduced the potential success of a majority of attacks.
|
|
_____________________________________________________________________________________________________________ |