Search and DocFinder
 
Search help/advanced search
 

Vendor Product Showcase



News NetFlash: Daily News Internat'l News This Week in NW The Edge Features Research Buyer's Guides Reviews Technology Primers Vendor Profiles Forums Columnists Knowledgebase Help Desk Dr. Intranet Gearhead Careers Free Newsletters Subscription Center Seminars/Events Reprints/Links White Papers Partner with Us Site Map Contact Us Home









News

Ten low-cost ways to strengthen your internal security

1. You may need to know more about prospective employees than what they write on their job application forms, especially for mission-critical jobs such as network administration. Consider using psychological profiling to learn about candidates' ethics, morals, tendencies and proclivities.

2. Consider removing disk drives from employees' PCs, which makes it harder for them to install personal software and games, infect your system with viruses and take home proprietary information. This will curtail another potential security problem - loose disks strewn on desks.

3. Don't allow more than one user ID per machine. Deploy secure screen savers to help minimize administrative problems.

4. Confine root privileges to those administrators who really need it. Every root privilege you provide is just another weakness to be exploited.

5. Shred or burn the important stuff: personnel lists, employee IDs, human resources information, customer files, memos, manuals, network drawings and anything else of potential value to an outsider.

6. Keep your garbage inside your building where you can maintain control over its access. Outdoor storage invites dumpster diving.

7. Make your staff cooperative partners in your security endeavors, not resistant adversaries. Try participatory programs such as rewarding employees who find security problems or discover miscreant behavior.

8. Carefully evaluate a security product and make sure it does what the vendor advertises. See what other security enhancements you can make before adding technology that needs care, feeding and management.

9. Empower someone to take quick action in a security emergency, whether it involves shutting down a Web site or calling building security to remove a disgruntled employee.

10. Let your staff know that you use advanced monitoring and audit controls on the network. Explain that the tools are to catch the bad guys and not play Big Brother. This will still make workers fearful of being caught breaking your systems usage and security rules.

- Winn Schwartau

For more info:
Back to the main article

Ten ways to protect your Web commmerce sites

Five basic security necessities

Ten ways to maintain security vigilance

Security resources from Network World Today's News

ICANN board approves reform agenda

House committee subpoenas WorldCom executives

KPMG Consulting to hire Andersen IT staff, not unit

Xerox accounting troubles may total $6 billion

Analysis: Ciena/ONI deal done


All of today's news

Compendium

A good .plan
Plus: Porn credit-card site hacked.

nutter

Prioritizing voice over data in VoIP
Nutter helps a user make sure voice gets priority on a Cisco net.

Research

E-comm Innovator of the Year Award
Know someone with a groundbreaking e-commerce project? Nominate him or her for our annual award.




  Home
Contact us
Site Map
Today's news
This week in NW
Research
Free newsletters
Forums
Opinions
Careers
Terms of Service
Network World, Inc.
Seminars & Events
Advertiser Index
Product Showcase
Vendor white papers
NW Subscriptions

  Copyright, 1995-2001 Network World, Inc. All rights reserved.