Sophos booklet helpful in corporate security awareness

Opinion
Aug 25, 20103 mins

As I wrote in the previous column, I recently received word of a simple, short summary of some basic Web safety information freely available from Sophos: “10 myths of safe web browsing.” This document can help raise security consciousness and involvement.

Each of the following myths is discussed in a short paragraph of simple, clear writing. Here, I will simply quote each myth with its first sentence (or the first two) without using quotation marks:

• Myth No.1: The Web is safe because I’ve never been infected by malware

• You may not even know you’re infected….

• Myth No.2: My users aren’t wasting time surfing inappropriate content

Without any kind of Web filtering, you really have no idea what users are doing with their Internet connection….

• Myth No.3: We control Web usage and our users can’t get around our policy

Anonymizing proxies make it easy for employees to circumvent your Web filtering policy and visit any site they like….

• Myth No.4: Only porn, gambling, and other “dodgy” sites are dangerous

Hijacked trusted sites represent more than 83% of malware hosting sites….

• Myth No.5: Only naive users get infected with malware and viruses

Malware from drive-by downloads happens automatically without any user action, other than visiting the site….

• Myth No.6: You can only get infected if you download files.

Most malware infections now occur through a “drive-by” download….

• Myth No.7: Firefox is more secure than Internet Explorer

All browsers are equally at risk because all browsers are essentially an execution environment for JavaScript, which is the programming language of the Web and therefore used by all malware authors to initiate an attack….

• Myth No.8: When the lock icon appears in the browser, it’s secure.

The lock icon indicates there is an SSL encrypted connection between the browser and the server to protect the interception of personal sensitive information…

• Myth No.9: Web security requires a trade-off between security and freedom

While the Internet has become a mission critical tool for many job functions, whether it’s Facebook for HR or Twitter for PR, it’s completely unnecessary to create a trade-off between access and security….

• Myth No.10: Endpoint security solutions can’t protect against Web threats

Typically, this has been the case because the Web browser is essentially its own execution environment: it downloads content, renders it, and executes scripts all without any visibility outside the browser to endpoint security products. However, this is changing….

This booklet would make a perfect subject for a brown-bag lunchtime discussion among the IT staff; it could be used as the basis for a user-education session (keep it short!) to spark discussion of the issues.

Although the copyright restriction on the document states that the file may not be reproduced, stored or distributed without written permission from the publisher, I spoke with Jennifer Torode, senior public relations manager at Sophos, and was assured that Sophos would be happy to grant such permission on demand. Just write to Ms. Torode and she will send back an e-mail permitting you to attach the file to your internal e-mail instead of having to make your employees download it one by one.

Good work, Sophos!

[Disclaimer: I have no financial or professional involvement whatever with Sophos other than liking their stuff and being grateful for their prompt and helpful responses to my requests for clarification when I was writing this article.]