- Information wants to be free. Once data lands on the endpoint, it’s free. There is a much higher likelihood that data will end up in the wrong hands if it’s on an endpoint. Consequently, be careful about what you allow to be stored on the endpoint. Implement policies that restrict data leakage on endpoints and USB devices.
- Code wants to be wrong. No matter how hard developers and engineers try, code always has flaws and bugs that open up vulnerabilities. Frequent and consistent patching is essential to keep your network protected to the highest degree possible.
- Services want to be on. Employees, partners, and customers all want access to your network. Self-service utilities and applications are no doubt a great resource but they can also be the point of vulnerabilities. Frequently test and probe the security capabilities of these types of applications, and regularly look for vulnerabilities and weaknesses that may be exploited by any external or internal user.
- Users want to click. Whenever users see a button, they click on it! Email borne viruses and malicious websites are the source of many viruses and breaches to network security. Educating your end users is an ongoing effort. People forget. They get lazy and have to be reminded about the dangers that lurk on the internet.
- Security features want to be bypassed. Sometimes a security feature can be bypassed (even when enabled) depending upon if the state of a laptop is in standby mode, for example. Always review with your IT staff if any security feature can be bypassed by any means.
Showing posts with label standards. Show all posts
Showing posts with label standards. Show all posts
Monday, September 20, 2010
Five Irrefutable Laws of Information Security
Apparently these come from the CISO of Intel. Look pretty good to me.
Friday, September 3, 2010
Interesting article
I came across this article as a great metaphor for how people think about security. Original post from http://erratasec.blogspot.com/
Thursday, September 02, 2010
A False Sense of Security
Posted by Robert Graham at 5:14 PM
This article describing Hurricane Earl shows a woman putting a pattern of duct tape on the window. Does this duct tape really help?
No, of course not. Duct tape does nothing to stop the glass for shattering, and does almost nothing to stop fragments flying around.
What it does give people is a false sense of security. For whatever reason, they’ve decided not to buy hurricane shutters (even though they live in a hurricane zone) and not board up their windows with plywood. But they can’t just do nothing, so they resort to sympathetic magic like taping up windows. At least they are putting something on their windows.
Such ignorance is not just useless, but in some cases, can be harmful. Some people believe they should leave their windows open a crack during a hurricane, in order to equalize pressure. The opposite is true: this makes it more likely that the hurricane will pop your roof off. The reason is that wind traveling over your roof creates low pressure above, and wind entering your house creates high pressure inside. This lifts your roof off, in precisely the same manner it lifts an airplane wing when flying.
There are obvious analogies with cybersecurity. People do things, like install anti-virus, firewalls, or WEP, because “doing something” makes them feel good. But they haven’t thought through the cause-and-effect whether doing such things actually work.
0 comments:
Post a Comment
Links to this post
Create a Link
Older Post Home
Subscribe to: Post Comments (Atom)
Thursday, September 02, 2010
A False Sense of Security
Posted by Robert Graham at 5:14 PM
This article describing Hurricane Earl shows a woman putting a pattern of duct tape on the window. Does this duct tape really help?
No, of course not. Duct tape does nothing to stop the glass for shattering, and does almost nothing to stop fragments flying around.
What it does give people is a false sense of security. For whatever reason, they’ve decided not to buy hurricane shutters (even though they live in a hurricane zone) and not board up their windows with plywood. But they can’t just do nothing, so they resort to sympathetic magic like taping up windows. At least they are putting something on their windows.
Such ignorance is not just useless, but in some cases, can be harmful. Some people believe they should leave their windows open a crack during a hurricane, in order to equalize pressure. The opposite is true: this makes it more likely that the hurricane will pop your roof off. The reason is that wind traveling over your roof creates low pressure above, and wind entering your house creates high pressure inside. This lifts your roof off, in precisely the same manner it lifts an airplane wing when flying.
There are obvious analogies with cybersecurity. People do things, like install anti-virus, firewalls, or WEP, because “doing something” makes them feel good. But they haven’t thought through the cause-and-effect whether doing such things actually work.
0 comments:
Post a Comment
Links to this post
Create a Link
Older Post Home
Subscribe to: Post Comments (Atom)