Articles by "Assignment"
Showing posts with label Assignment. Show all posts
It is an exclusive e-Learning Blog that has been dedicated to help keen learn students to boost their knowledge in different subjects.

How to Keep Our Business Computers and Online Information Secure:

Make Staff Aware Of The Important Role They Play In Security:

Our staffs are our front line of defense when it comes to security. Sure, hackers can access our network remotely and siphon off data without setting foot in our office. However, vigilant employees (consultants, partners, and vendors, too) can ensure that human error—which is a big cause of data security breaches is minimalized.

Educate Our Employees:

If a computer on our network becomes compromised--whether the intrusion came from an internal fantasy-football e-mail or through a nefarious Facebook app that an HR administrator clicked on during lunch our entire operation is at risk. "You shouldn't be the only one vigilant about protecting your and your customers' information," Symantec's Cullen says. "Your employees should all be on the lookout, and you as a small-business owner should be there to give them some guidelines."
Keep employees informed about threats through brief e-mails or at periodic meetings led by our IT expert. The first step, however, is to write out a formal company internet policy, setting acceptable and prohibited online activities for employees an exercise that a distressingly small 10 percent of companies follow, according to Symantec/NCSA. For example, prohibit employees from opening e-mail attachments or clicking on links that don't pertain to company business. Or limit personal e-mail access to personal Smartphone via the employee's wireless connection, not the company Wi-Fi.

Use Strong And Multiple Passwords:

Too many of us use simple passwords that are easy for hackers to guess. When we have complicated passwords, a simple “dictionary attack”—an attack by a hacker using an automated tool that uses a combination of dictionary words and numbers to crack passwords can’t happen. Don’t write passwords down; commit them to memory.

Encrypt Our Data:

Encryption is a great security tool to use in case our data is stolen. For example, if our hard disk is stolen or we lose our USB thumb drive, whoever accesses the data won’t be able to read it if it’s encrypted.

Use Encryption Software To Protect Customers’ Financial Information From Theft During Transactions:

Visa USA and MasterCard International Inc. require most businesses operating online to verify that we have taken a number of steps, including data encryption, to protect customers who use their credit cards. If we meet those requirements, our online operation is likely to be fairly secure.

Complying with the letter of those standards can be challenging for small businesses, which generally don’t have the resources or the security expertise of larger operations. So it can be a good idea to outsource payment processing to a company like eBay Inc.’s PayPal unit. Ensuring compliance for in-house payment processing can cost at least twice as much as outsourcing.

Encryption is also important for protecting a company’s internal information personnel files, financial accounts and product information and other data. It can foil a hacker who has gotten into the company’s computer system but can’t decipher the information.

Back Up:
Security is important, but if our data is not backed up, we will lose it. Ensure that our data is properly backed up, and test the backup to ensure that our data can be recovered when we need it.

Lock Filing Cabinets And Rooms Where We Keep Sensitive Data, And Only Give Keys To Trusted Employees.
"Oftentimes locked boxes keep people honest," said Sileo. "They're a great way to take away the crime of opportunity."

Institute A Good Privacy Policy, And Make Protecting Sensitive Data A Part Of The Company Culture:

Security policies especially regarding the use of social media are vital, according to security and privacy consultant John Sileo. If we allow employees to use sites like Facebook and Twitter at work, make sure they keep their personal life separate from their work-related social media use and monitor what they say online.

It’s one thing to ask employees to work securely, but we must also have clear and simple policies in place for them to follow to ensure that they are working in a secure environment. For example, insist that all notebook computers connected to the corporate network have security software. Mandate that no security information ever be given over the phone. Policies like this and more will help ensure that our staffs are doing their part to be security aware.

Secure Our Web Browser:

Web browsers installed on new computers usually don’t have secure default settings. Securing our browser is another critical step in improving our computer’s security because an increasing number of attacks take advantage of web browsers. Before we start surfing the internet, secure our browser by doing the following:
- Disable mobile code (that is, Java, JavaScript, Flash, and ActiveX) on websites we’re not familiar with or don’t trust. While disabling these types of code on all sites will significantly reduce our risk of being attacked, the websites we visit may not function as they normally do.
- Disable options to always set cookies. A cookie is a file placed on our computer that stores website data. Attackers may be able to log onto a site we’ve visited (like a banking site) by accessing the cookie with our login information. To prevent that, configure the browser to ask for permission before setting a cookie, allow cookies for sessions only, and disable features that keep us logged in to a site or that retain information we’ve entered, such as text we type into forms and the search bar.
- If we’re using Internet Explorer, set the security levels for trusted sites (websites we most often visit and trust) to the second highest level. At the highest level, websites may not function properly.

Make Sure Us And Our Employees Only Download Applications That Come From Reliable Sources:

Because applications (e.g., games, mobile apps) may contain viruses, spy ware or Trojan horses, it's important to know and trust the source of an application before downloading it.

Protect Mobile Work Force:

Our sales team of 10 years ago is probably nothing like our sales team of today. With the proliferation of the BlackBerry, iPhone, and other mobile devices, more of our staffs are working away from the office and away from the protection of our network security. They are operating “in the open” on our customers’ networks, public networks at coffee shops, or free networks in the park. It is important to ensure that their mobile technology, often connected wirelessly, is as secure as possible.

Implement A Multiple-Security-Technology Solution:

Viruses that corrupt data are not the only security threat. Hackers, and their attacks, are more sophisticated than ever, and it is critical to have multiple layers of security technology on all our different devices (including each desktop, mobile device, file server, mail server, and network end point) to comprehensively secure our data. This multiple security will block attacks on our network and/or alert us to a problem so that our (or our IT expert) can take the appropriate action.

Consider Outsourcing Security Or Hiring A Consultant To Make Sure Our Business Is Safe And Secure:

"You might consider, for instance, outsourcing firewall management, intrusion testing, vulnerability management, compliance management, especially when related to financial services (PCI) or to healthcare (HIPAA and HITECH)," said Heimerl. "Chances are that a qualified managed security service can provide better security than you … and do so at a lower cost, while allowing your IT staff to concentrate on the business."

Conclusion:
Securing our business’s data is not easy, and it takes expertise. However, we can implement very practical and simple solutions (such as these tips) to ensure that when a hacker sniffs around our network or computers, he (or she) will move on to another victim because our infrastructure is not worth the trouble of hacking into it. Think about our average street mugger. They want to steal a purse or wallet from the victim they think is most vulnerable, so they can get away with their crime as easily as possible. One of the most important things we can do is to educate our employees in security best practices and ensure that they know how important their role is in securing business data.

Recommendations:

The followings are some of the recommendations that will ensure the smooth functioning to keep business (our) computers and online information secure:
- Reserve necessary Data on DropBox or Google Drive.
- Don’t use free software.
- Use Best Antivirus: Bitdefender, Norton, TrendMicroTitanium, Kaspersky, Eset …..
- Don't play Social Media on business used computer.
- Must learn before using any software and device of computers.

» » » To continue reading, Click here corresponding: A, BC and D.

References:
US-CERT (from Carnegie Mellon University): www.us-cert.gov/sites/default/files/publications/TenWaystoImproveNewComputerSecurity.pdf
Small Business Computing: www.smallbusinesscomputing.com/webmaster/article.php/3908811/15-Data-Security-Tips-to-Protect-Your-Small-Business.htm
Small Biz Technology: www.smallbiztechnology.com
Entrepreneur: www.entrepreneur.com/article/225468
It is an exclusive e-Learning Blog that has been dedicated to help keen learn students to boost their knowledge in different subjects.

How to Keep Our Business Computers and Online Information Secure:

Following important things we can do to make our business computer (and DATA) more secure. While no individual step will completely eliminate our risk, together these practices will make our business computer’s defense strong and minimize the threat of malicious activity.

Conduct A Security Audit:

If we don’t know what parts of our business are vulnerable or what data we have that needs to be protected, we can’t properly secure it. It is critical that we work with a professional to audit our entire IT infrastructure computers, network, and mobile devices—to determine what we need to do to prevent hackers from accessing our network.

Secure Our Hardware:

Of the Seattle-area companies that were hacked, more than 40 had their physical premises broken into by burglars who grabbed electronic equipment. In one case, the gang snatched more than $300,000 in servers, laptops, cell phones and other items. Security cameras recorded those using handcarts to haul loads of equipment to a van over a four hour span.

For burglars who are not scared off by security alarms and motion detectors, physically locking down computers makes their job tougher. Few people feed a cable through their computer's Kensington lock port (the small metal loop found on most laptop and desktop devices) to secure it to their desk. Sure, they're relatively easy for a thief to circumvent, but the extra effort could tip the odds in our favor. "That little bit of time is something criminals usually don't want to take," Cullen says. "Time is the enemy for anyone breaking into a physical premise."

Make network storage safer by using Kensington locks or employing more robust solutions, like rack-mounting hardware and keeping server room doors closed and locked. Vancouver, Wash.-based CRU-Data Port makes several servers that can be secured with locks, USB security keys and even hardware-based encryption, ensuring that if drives are stolen, they will be unusable to the thieves.

There's also tracking software--important if our business runs on mobile laptops in the field. The tracking firm Prey uses a variety of methods to locate anything from a cell phone to a server, password-securing the machine if it goes missing and even snapping and sending pictures of the thief if the stolen device has a webcam. Low per-month rates make the small, covert program a must-install for any device that can access business data and company networks.

Update Our Computer Operating Systems:


Manufacturers upgrade security safeguards often. Sign up for the automatic updates that install security patches. Hackers often are on the lookout for systems that don’t have the latest safeguards. And look into anti-virus software, again with automatic updates. Software should also be put in place to block spam and detect spyware, the programs that can be surreptitiously installed from outside a computer system and feed sensitive information to the intruder.

Lock Our Network:

Many hacking victims are compromised via Wi-Fi networks, through a technique called "wardriving". In cars outfitted with high-powered antennas, hacker gangs drive around cities, scanning for unlocked or poorly protected networks. Once a vulnerable Wi-Fi hot spot is found, the crooks are as good as in the company's front door, scouring machines on the network for passwords and financial data.

The best defense against exploits like wardriving is to have no wireless network at all. Wired networks, while less versatile, are more secure, because users have to access them by either plugging into physical outlets or hacking modem ports. But if our company must have a wireless network, disable the service set identifier (SSID) broadcasting function on the wireless router. This creates a cloaked or hidden network, invisible to casual Wi-Fi snoops and accessible only to users with the exact network name. Small businesses like coffeehouses can also do this just periodically change the network's information and place a small sign near the register with the current network name and pass code.

If we're using Wi-Fi, update it to the latest encryption standard. Some Seattle wardriving victims had enabled Wired Equivalent Privacy (WEP), an easily cracked algorithm that fell out of favor almost 10 years ago, and thought their networks were secure. WPA2, the current standard, has a longer encryption key that is more difficult to break into. To make our data even safer, create a nonsense password with numbers, special characters and capital letters. Says Cullen, "They'd need a computer working on it for a million years to crack the code."

Install Anti-malware And Anti-virus Protection:

When wardrivers are successful in cracking a wireless network, they can log in and infect connected computers with malicious software or viruses. But it doesn't take a Wi-Fi connection to plant this software; spam e-mails and harmful websites push it to computers all the time, and if the efforts are successful, the malware can install code that runs in the background, capturing keystrokes and login information and relaying it to the hackers. According to Verizon's study, malware was used in nearly half of data breaches in 2010 and was responsible for almost 80 percent of records stolen.

"That's probably the No. 1 money-generating technique the bad guys use," SANS Institute's Spitzner says. "Anytime you visit any type of website that requires a login and password Facebook, your bank, payroll, whatever--malware will harvest your information and send it to the bad guy," he says. "The bad guy will turn right around, log in as you and do all his evil stuff."

Most malware is installed through network security hacks, but being vigilant about cybercrime is as much about anticipating tomorrow's threats as it is defending against todays. E-mail phishing, spoofing and apps that access social media accounts are popping up with increasing regularity. Loading anti-malware and anti-virus protection on our machines--that goes for mobile devices as well and running it after every software install can help ensure these threats don't take. Also, keeping programs and hardware up to date from upgrading to newer routers and computers to immediately installing browser updates blocks malicious worms that thrive in older equipment and out-of-date software.

» » » To continue reading, Click here corresponding: A, BC and D.

References:
US-CERT (from Carnegie Mellon University): www.us-cert.gov/sites/default/files/publications/TenWaystoImproveNewComputerSecurity.pdf
Small Business Computing: www.smallbusinesscomputing.com/webmaster/article.php/3908811/15-Data-Security-Tips-to-Protect-Your-Small-Business.htm
Small Biz Technology: www.smallbiztechnology.com
Entrepreneur: www.entrepreneur.com/article/225468
It is an exclusive e-Learning Blog that has been dedicated to help keen learn students to boost their knowledge in different subjects.

Computer Security Supports the Mission of the Organization

The purpose of computer security is to protect an organization's valuable resources, such as information, hardware, and software. Through the selection and application of appropriate safeguards, security helps the organization's mission by protecting its physical and financial resources, reputation, legal position, employees, and other tangible and intangible assets.

Unfortunately, security is sometimes viewed as thwarting the mission of the organization by imposing poorly selected, bothersome rules and procedures on users, managers, and systems. On the contrary, well-chosen security rules and procedures do not exist for their own sake they are put in place to protect important assets and thereby support the overall organizational mission. Security, therefore, is a means to an end and not an end in itself. For example, in a private- sector business, having good security is usually secondary to the need to make a profit.

Security, then, ought to increase the firm's ability to make a profit. In a public-sector agency, security is usually secondary to the agency's service provided to citizens. Security, then, ought to help improve the service provided to the citizen.

To act on this, managers need to understand both their organizational mission and how each information n system supports that mission. After a system's role has been defined, the security requirements implicit in that role can be defined. Security can then be explicitly stated in terms of the organization's mission.

The roles and functions of a system may not be constrained to a single organization. In an inter-organizational system, each organization benefits from securing the system. For example, for electronic commerce to be successful, each of the participants requires security controls to protect their resources. However, good security on the buyer's system also benefits the seller; the buyer's system is less likely to be used for fraud or to be unavailable or otherwise negatively affect the seller. (The reverse is also true.)

» » » To continue reading, Click here corresponding: A, BC and D.

References:
US-CERT (from Carnegie Mellon University): www.us-cert.gov/sites/default/files/publications/TenWaystoImproveNewComputerSecurity.pdf
Small Business Computing: www.smallbusinesscomputing.com/webmaster/article.php/3908811/15-Data-Security-Tips-to-Protect-Your-Small-Business.htm
Small Biz Technology: www.smallbiztechnology.com
Entrepreneur: www.entrepreneur.com/article/225468
It is an exclusive e-Learning Blog that has been dedicated to help keen learn students to boost their knowledge in different subjects.

Why Businesses Need to Secure Our Computers (and How to Do it!)

The use of personal computers in industry and commerce has expanded dramatically in the last decade. Large gains in employee productivity are possible as a result of this technology. However, ensuring the security of the processes and the privacy of data that these machines access is a very hard problem. Solutions that ensure security by preventing access by legitimate users are inconsistent with the gains in productivity that are possible. The general problem of computer security is being attacked by government and by academic and industrial research with some notable success.

The aim of this research’s is to review the principles behind these successes, to describe some of the remaining problems and to discuss their application in industry and commerce.

What is Computer Security?

Computer security is frequently associated with three core areas, which can be conveniently summarized by the acronym "CIA":
- Confidentiality: Ensuring that information is not accessed by unauthorized persons
- Integrity: Ensuring that information is not altered by unauthorized persons in a way that is not detectable by authorized users
- Authentication: Ensuring that users are the persons they claim to be

Computer security is not restricted to these three broad concepts. Additional ideas that are often considered part of the taxonomy of computer security include:
- Access Control: Ensuring that users access only those resources and services that they are entitled to access and that qualified users are not denied access to services that they legitimately expect to receive
- Non-repudiation: Ensuring that the originators of messages cannot deny that they in fact sent the messages
- Availability: Ensuring that a system is operational and functional at a given moment, usually provided through redundancy; loss of availability is often referred to as "denial-of-service"
- Privacy: Ensuring that individuals maintain the right to control what information is collected about them, how it is used, who has used it, who maintains it, and what purpose it is used for

Simply, we can say, Computer Security is a set of policies, procedures, tools and techniques, to protect computer assets from accidental, intentional, or natural disasters. It covers all components of a company’s hardware, software, networks, physical facilities, data and information and personnel.

Why Should I Care About Computer Security?


Our computers help us stay connected to the modern world. We use them for banking and bill paying, shopping, connecting with our friends and family through email and social networking sites, surfing the internet, and so much more. We rely so heavily on our computers to provide these services that we sometimes overlook their security. Because our computers have such critical roles in our lives and we trust them with so much personal information, it’s important to improve their security so we can continue to rely on them and keep our information safe.

Attackers can infect our computer with malicious software, or malware, in many different ways. They can take advantage of unsafe user practices and flaws in our computer’s programs (flaws including vulnerabilities and unsecured services and features) and use social engineering (in which an attacker convinces someone to perform an action such as opening a malicious email attachment or following a malicious link). Once our computer is infected, intruders can use the malware to access our computer without our knowledge to perform unwanted actions. They can steal our personal information, change computer configurations, because our computer to perform unreliably, and install even more malware they can use to leverage attacks or spread malware to others.

One of the most well-known attacks was the Conficker malware detected in late 2008. This malware grew to become one of the largest malware infections, affecting millions of computers and causing billions of dollars in damage across the world. The Conficker malware had the ability to steal and relay personal information to attackers, disable existing security measures like Windows Automatic Updates and antivirus software, and block internet access to popular security websites. Attackers could use infected computers as part of a botnet, or a collection of compromised computers connected to the internet, to leverage additional attacks against other computers. The Conficker malware took advantage of three separate security flaws on Microsoft Windows computers: the enabled file sharing service, the default AutoRun setting, and a vulnerability in the Windows Server network service.

» » » To continue reading Part - B, Click here.

References:
US-CERT (from Carnegie Mellon University): www.us-cert.gov/sites/default/files/publications/TenWaystoImproveNewComputerSecurity.pdf
Small Business Computing: www.smallbusinesscomputing.com/webmaster/article.php/3908811/15-Data-Security-Tips-to-Protect-Your-Small-Business.htm
Small Biz Technology: www.smallbiztechnology.com
Entrepreneur: www.entrepreneur.com/article/225468