![]() ![]()
|
|
| |||
|
Ten low-cost ways to strengthen your internal security 1. You may need to know more about prospective employees than what they write on their job application forms, especially for mission-critical jobs such as network administration. Consider using psychological profiling to learn about candidates' ethics, morals, tendencies and proclivities. 2. Consider removing disk drives from employees' PCs, which makes it harder for them to install personal software and games, infect your system with viruses and take home proprietary information. This will curtail another potential security problem - loose disks strewn on desks. 3. Don't allow more than one user ID per machine. Deploy secure screen savers to help minimize administrative problems. 4. Confine root privileges to those administrators who really need it. Every root privilege you provide is just another weakness to be exploited. 5. Shred or burn the important stuff: personnel lists, employee IDs, human resources information, customer files, memos, manuals, network drawings and anything else of potential value to an outsider. 6. Keep your garbage inside your building where you can maintain control over its access. Outdoor storage invites dumpster diving. 7. Make your staff cooperative partners in your security endeavors, not resistant adversaries. Try participatory programs such as rewarding employees who find security problems or discover miscreant behavior. 8. Carefully evaluate a security product and make sure it does what the vendor advertises. See what other security enhancements you can make before adding technology that needs care, feeding and management. 9. Empower someone to take quick action in a security emergency, whether it involves shutting down a Web site or calling building security to remove a disgruntled employee. 10. Let your staff know that you use advanced monitoring and audit controls on the network. Explain that the tools are to catch the bad guys and not play Big Brother. This will still make workers fearful of being caught breaking your systems usage and security rules. - Winn Schwartau |
![]() Back to the main article Ten ways to protect your Web commmerce sites Five basic security necessities Ten ways to maintain security vigilance
Security resources from Network World
| Copyright, 1995-2001 Network World, Inc. All rights reserved. |
|