Too much access to the Internet?

Opinion
Jun 27, 20113 mins

Thoughts on Osama Bin Laden's capture

Niky Frazier, MSIA, SEC+, has been thinking about some unusual implications of Osama Bin Laden’s communications policies. The following article is her work with minor edits.

* * *

After the President of the United States announced that Osama Bin Laden had been killed, published reports revealed how the terrorist leader accessed the Internet to send e-mails without being intercepted by U.S. intelligence services. Adam Goldman and Matt Apuzzo of the Associated Press wrote that “Bin Laden’s system …. left behind an extensive archive of email exchanges for the U.S. to scour.” There were “thousands of messages and potentially hundreds of email addresses….”

How did he use e-mail without direct access? Goldman and Apuzzo write, “Holed up in his walled compound in northeast Pakistan with no phone or Internet capabilities, bin Laden would type a message on his computer without an Internet connection, then save it using a thumb-sized flash drive. He then passed the flash drive to a trusted courier, who would head for a distant Internet cafe. At that location, the courier would plug the memory drive into a computer, copy bin Laden’s message into an email and send it. Reversing the process, the courier would copy any incoming email to the flash drive and return to the compound, where bin Laden would read his messages offline.”

Thinking about how this al-Qaeda chief eluded detection of his location for a decade despite lack of direct use of the Internet got me thinking about the ubiquity of computers and Internet access in the business world and the military.

Protecting data against unauthorized use by limiting the number of users who have access to information, while simultaneously controlling how and where our data flow, are at the core of our security business. However, we find ourselves providing network – and external Internet – access to employees who do not have a legitimate requirement for such access to perform their daily duties. When did it become essential to have a computer – and in particular, a laptop computer that can be taken out of the office – on every employee’s desk, regardless of their role in the organization? If a laptop really is necessary for a specific employee, then should it permit access to the external Internet? Why or why not?

We must manage user expectations and provide the required resources for them to function with consideration of security and cost. Some ideas for discussion:

• Identify clear user functions and limit users to need-to-know information.

• Eliminate personal Internet surfing at work: it is a threat to daily business operations.

• If personnel morale is an issue, consider establishing a small Internet café within the organization or provide a separate wireless network in the break area for employees.

• External access to the ‘Net should be strictly regulated using content controls to ensure that confidential information isn’t being leaked through portable media and that no one is accessing unacceptable sites (porn, malware, stolen intellectual property) from the organization’s systems.

We shouldn’t regard Internet access – or even internal network access – as inherent rights. We should add need-to-compute and need-to-network to the concept of need-to-know.

* * *

N. Frazier, MSIA, SEC+, is an Information Systems Analyst. She manages wireless and satellite communications for logistics systems.