|
Why Threats Will Increase - The realization that it is increasingly difficult to identify, catch, and prosecute offenders. This makes the utilization o Information Technology as a weapon an appealing delivery system;
- Competitors an enemies, both foreign and domestic, are becoming more technologically sophisticated;
- The minimal cost involved to carry out an attack, when weighed against the overall effect, creates a natural inclination to utilize technology as a tool to execute an individuals, competitors, foreign governments, or terrorists agenda.
In fact, we recently interviewed a quasi-retired black-hat (by self admission) hacker who reviewed several of his last "jobs" with us. He was approached by foreign governments while performing legitimate security assessments and asked to steal confidential information and competitive information from other entities. After being offered large sums of money multiple times he finally gave in and performed the tasks they requested. This happens in governments and commercial entities quite frequently. Basic Questions To Ask Your Self Regarding Threat / Risk Management - What assets or information are important to you?
- What's the impact if these assets were jeopardized?
- What external, internal, artificial and environmental threats apply to your environment?
- What technology assets exist at your site and which of these are critical?
- What security policies have been implemented and are they being followed?
- Are you providing enough education and awareness for your employee's?
Make Sure That - Information intended for limited distribution remains limited;
- Proprietary information remains proprietary;
- Trade secrets remain secret;
- Your original, authentic documents remain the only authentic documents;
- Reduce your exposure and potential liabilities.
Important Security Measures - Security awareness education;
- Documented security policies and procedures;
- implement and maintain a reliable anti-virus solution;
- Backup and / or replicate important files and data;
- Implement insider threat counter and prevention measures;
- Automate violation detection;
- Use strong user-id and password combinations;
- Use encryption services if you want secure e-mail and data transfers;
- Perform regular security assessments.
|