Week 12
Over a year and a half ago, I posted a blog entitled The End. That blog discussed the class that was finishing at the time (Information Security Management). Well, it is now the end of not just another current class but also my MS in Cybersecurity degree. I have learned a lot over the course of the past 2 years. I will have to say that I have a much stronger understanding of everything that goes on behind the scenes to make a company more secure, not just in the network but as a whole. Some classes were great; others were not.
If I were to have to pick a class that was the hardest on me, it would have to be Computer Forensics. The reading and writing in that class was by far the hardest to put my head around. The class that I would have to chose as the easiest on me would have been none of them but my favorite was Risk Management Studies. Being able to look at risks in a different light than I already was really made me respect the topic much more than I already did.
Going into my final class (Current Trends in Cybersecurity), I would have to say that I wish I would have known more about threats; threat modeling in general. Jumping right into this subject in the first week got me very worried that I was not ready for it, but I overcame the fears and was able to learn the subject matter. Threat modeling was by far the hardest part of the class. I feel that if I would have had the proper text material, it would have been easier for me, but with the lack of material, it was not that fun to deal with.
If I could do it over, I would have worked it to only take Current Trends by itself in the final session rather than taking another heavily active class. Taking just the one class would have helped calm my nerves down during the weeks while doing my research for both classes. Even though all classes built up to the Current Trends class, it did work out for me in the long run taking the one I did along with it (Security Architecture & Design). The two classes built off the same scenario so I had the scenario fresh in my mind on a weekly basis.
Overall, the Cybersecurity degree at Bellevue University is not for the faint of heart, so to speak. I went into the degree thinking that it was going to be more of just IT Security subjects. Cybersecurity is an entire view of IT security. It encompasses everything dealing with IT security and even physical security. The word of advice to those that think they are getting into an easy degree; you are not. Not that I came into this degree thinking that; I just felt that with my experience with IT security, I would do just fine. I will say, though, that this was one of the best decisions I have ever made. This degree has taught me everything I wanted to know and more.
Friday, May 23, 2014
Saturday, May 17, 2014
Bring Your Own Device AKA BYOD
Week 10
Something that has been a growing trend of late is Bring Your Own Device (BYOD). Companies are allowing their employees to bring a device from home to use and connect to their network. You probably see this more than you think. Phones and tablets are two of the most used devices that people bring and use while at work. The downside to this, in my opinion, is the fact that they must use the company's wireless connections. This can open up their network for serious security threats. If a company is not set up properly, they can end up causing more damage by allowing BYOD.
I, for one, am not fond of this technology. A company network normally has some sort of confidential or sensitive information. If that part of the network is exposed to the Internet through a device, it could have huge ramifications for that business. Let me just use a specific scenario to get your attention.
Joe brings in his Samsung Galaxy 5. On his break, he decides that he wants to get on his phone and play some sort of game (app). The wireless connection allows his phone to connect to it so that his apps can process correctly. While Joe is playing an app, a link shows up offering him a game for free. Joe clicks on the link and begins the download. Little does he know, a virus is slowly making its way onto his phone. Now, the virus is on his phone and the company's network is exposed to it because the company's wireless connection was used. The virus is now slowly creeping onto the company's network. The network has now been infected with a virus. The network's data is now compromised.
Not a good scenario is it? Let's just say that this is what could happen if the company does not have a proper security process in place for BYOD. One of the first things you should do prior to allowing BYOD is to perform a risk assessment on the network to find the most vulnerable areas so those can be secured properly. You also need to ask the questions, Why should we allow BYOD? and Is it beneficial to the business? If the only answer to the first question is to allow employees to do something during break, you honestly don't need to be allowing it. If the second question's answer is, No, again, it shouldn't be allowed.
When it comes to securing BYOD, there is an awesome whitepaper written by Bradford Networks that discusses 10 steps in general to securing BYOD. The 10 steps are:
These steps will help secure BYOD better than it probably already is. You can follow the link in the reference section for more detailed information about each step. Don't just set up your network and allow employees to bring in their own devices without first going through the proper steps to secure your network. You do not want what happened to Joe's company happening to you.
Reference:
Bradford Networks. (2011). Ten Steps To Secure BYOD. Retrieved May 17, 2014 from http://www.cadincweb.com/wp-content/uploads/2012/04/CAD_BRAD_Ten_Steps_to_Secure_BYOD.pdf
Something that has been a growing trend of late is Bring Your Own Device (BYOD). Companies are allowing their employees to bring a device from home to use and connect to their network. You probably see this more than you think. Phones and tablets are two of the most used devices that people bring and use while at work. The downside to this, in my opinion, is the fact that they must use the company's wireless connections. This can open up their network for serious security threats. If a company is not set up properly, they can end up causing more damage by allowing BYOD.
I, for one, am not fond of this technology. A company network normally has some sort of confidential or sensitive information. If that part of the network is exposed to the Internet through a device, it could have huge ramifications for that business. Let me just use a specific scenario to get your attention.
Joe brings in his Samsung Galaxy 5. On his break, he decides that he wants to get on his phone and play some sort of game (app). The wireless connection allows his phone to connect to it so that his apps can process correctly. While Joe is playing an app, a link shows up offering him a game for free. Joe clicks on the link and begins the download. Little does he know, a virus is slowly making its way onto his phone. Now, the virus is on his phone and the company's network is exposed to it because the company's wireless connection was used. The virus is now slowly creeping onto the company's network. The network has now been infected with a virus. The network's data is now compromised.
Not a good scenario is it? Let's just say that this is what could happen if the company does not have a proper security process in place for BYOD. One of the first things you should do prior to allowing BYOD is to perform a risk assessment on the network to find the most vulnerable areas so those can be secured properly. You also need to ask the questions, Why should we allow BYOD? and Is it beneficial to the business? If the only answer to the first question is to allow employees to do something during break, you honestly don't need to be allowing it. If the second question's answer is, No, again, it shouldn't be allowed.
When it comes to securing BYOD, there is an awesome whitepaper written by Bradford Networks that discusses 10 steps in general to securing BYOD. The 10 steps are:
- Determine which mobile devices are allowed on the network - Are you going to allow phones only or both phones and tables? Also, are you going to allow outside laptops?
- Determine which OS versions are going to be allowed - Microsoft? Linux? UNIX?
- Determine which applications are mandatory and prohibited for each device - Are you going to allow only company apps or gaming as well?
- Determine which groups of employees will be allowed to use BYOD - All? Management? Security?
- Define the who, what, where and when of network access - Who will be able to access what content from where and when they are able to access it.
- Educate employees about BYOD - Make sure employees know the hazards of using BYOD and what they can do to defend against them.
- Inventory authorized and unauthorized devices - Find out what devices are being used and if they are authorized or unauthorized.
- Inventory authorized and unauthorized users - Determine if the users that are using the devices are authorized or unauthorized to use them.
- Control access based on the need to know - Limit access to areas just as you have it set up in your directory. Security gets to see security. HR gets to see HR.
- Continuous vulnerability assessment and remediation - Continuously monitor BYOD to make sure all policies and procedures are being followed.
These steps will help secure BYOD better than it probably already is. You can follow the link in the reference section for more detailed information about each step. Don't just set up your network and allow employees to bring in their own devices without first going through the proper steps to secure your network. You do not want what happened to Joe's company happening to you.
Reference:
Bradford Networks. (2011). Ten Steps To Secure BYOD. Retrieved May 17, 2014 from http://www.cadincweb.com/wp-content/uploads/2012/04/CAD_BRAD_Ten_Steps_to_Secure_BYOD.pdf
Saturday, May 10, 2014
Anti-Virus Software is Dead!
Week 9
According to the former U.S. Chief Technology Officer, Aneesh Chopra, anti-virus software is dead! Earlier this week, during an interview, Chopra mentioned that the technology is dead because most of the hackers are able to get into a network and its computers because the programs written for the software are too big and cumbersome. They are millions of lines of code, but yet an attacker can just right a few hundred lines and get in (Chopra, 2014).
The point to be made here is that the software is not doing its intended job. It is being found that more and more hackers are getting into networks and devices than before. Even with anti-virus software located on the devices, they are still getting in. Too many people are relying on simply that software to keep them safe. They are not doing anything on their end to keep them safe. They are relying on the software 100%.
This now brings up the question; If anti-virus is dead, why are we still buying it? This shouldn't be a hard question to answer. Devices still need to monitor the many common virus signatures that are out there. They can do this with the anti-virus software. That is what the software is for. Thing is, it isn't there to hold your hand and tell you that you don't need to do anything else to keep your computer safe because it will do everything for you. If you believe that the only thing that you need to do is to install the software and walk away, you are dead wrong. The software cannot do everything for you. Yes, you can set up the policies within the software but it will not keep you 100% secure. In fact, nothing can keep you 100% secure.
So what else do you need to do when it comes to securing your system? Chopra does mention that better password management and watching where you click on the Internet are good starts. He is right. I cannot tell you the amount of people I have spoken to in the past that have used a very easy password such as 'password' or even 'pw1234'. It is ridiculous! How can you feel safe with that password? Those are some of the first ones that a hacker will try after they have made it onto your system. If you can't think of anything good when it comes to a password, use a password generator. Set the character length and make sure it has a symbol or two and generate it. Don't write it down somewhere. Keep it in your mind and memorize it.
Clicking on links on the Internet can end up being very dangerous. 'Look, I can get a free Xbox One if I fill out this survey!' 'Let me just click this link to go and take it.' Now you have a virus installing in the background destroying everything in its path. It is that simple folks! If the deal looks too good to be true, chances are it is. If you have never heard of the site, don't go there. Research it first and determine if it has a good reputation.
I keep anti-virus software on my computer and up to date. Am I going to get rid of it or stop buying it because it is dying out? No! I am going to continue buying it, plus doing all the other things that I need to do to help take the load off of it. Managing my passwords and changing them regularly. Also, watching where I go and click on the Internet is always something that I have done and teach to others. Don't take this news as you should stop using an anti-virus software. Take it as a push to beef up the way you maintain your other security actions while you are on your computer.
References:
Chopra. A. (2014). Is anti-virus dead? Former U.S. tech czar weighs in. Retrieved May 10, 2014
from http://www.cnbc.com/id/101643106
According to the former U.S. Chief Technology Officer, Aneesh Chopra, anti-virus software is dead! Earlier this week, during an interview, Chopra mentioned that the technology is dead because most of the hackers are able to get into a network and its computers because the programs written for the software are too big and cumbersome. They are millions of lines of code, but yet an attacker can just right a few hundred lines and get in (Chopra, 2014).
The point to be made here is that the software is not doing its intended job. It is being found that more and more hackers are getting into networks and devices than before. Even with anti-virus software located on the devices, they are still getting in. Too many people are relying on simply that software to keep them safe. They are not doing anything on their end to keep them safe. They are relying on the software 100%.
This now brings up the question; If anti-virus is dead, why are we still buying it? This shouldn't be a hard question to answer. Devices still need to monitor the many common virus signatures that are out there. They can do this with the anti-virus software. That is what the software is for. Thing is, it isn't there to hold your hand and tell you that you don't need to do anything else to keep your computer safe because it will do everything for you. If you believe that the only thing that you need to do is to install the software and walk away, you are dead wrong. The software cannot do everything for you. Yes, you can set up the policies within the software but it will not keep you 100% secure. In fact, nothing can keep you 100% secure.
So what else do you need to do when it comes to securing your system? Chopra does mention that better password management and watching where you click on the Internet are good starts. He is right. I cannot tell you the amount of people I have spoken to in the past that have used a very easy password such as 'password' or even 'pw1234'. It is ridiculous! How can you feel safe with that password? Those are some of the first ones that a hacker will try after they have made it onto your system. If you can't think of anything good when it comes to a password, use a password generator. Set the character length and make sure it has a symbol or two and generate it. Don't write it down somewhere. Keep it in your mind and memorize it.
Clicking on links on the Internet can end up being very dangerous. 'Look, I can get a free Xbox One if I fill out this survey!' 'Let me just click this link to go and take it.' Now you have a virus installing in the background destroying everything in its path. It is that simple folks! If the deal looks too good to be true, chances are it is. If you have never heard of the site, don't go there. Research it first and determine if it has a good reputation.
I keep anti-virus software on my computer and up to date. Am I going to get rid of it or stop buying it because it is dying out? No! I am going to continue buying it, plus doing all the other things that I need to do to help take the load off of it. Managing my passwords and changing them regularly. Also, watching where I go and click on the Internet is always something that I have done and teach to others. Don't take this news as you should stop using an anti-virus software. Take it as a push to beef up the way you maintain your other security actions while you are on your computer.
References:
Chopra. A. (2014). Is anti-virus dead? Former U.S. tech czar weighs in. Retrieved May 10, 2014
from http://www.cnbc.com/id/101643106
Wednesday, April 30, 2014
Internet Explorer Bug!
Week 8
Well, a few weeks ago, I spoke on Microsoft ending all security updates for Microsoft XP. A few days ago, the Internet was a-buzz speaking about Internet Explorer (IE) and the new vulnerability that was found. Trust me when I say this, This is NOT good news for the users that still use XP. Due to Microsoft ending support, when the bug is fixed in IE, the users still using XP will not get that update. If they continue to use both XP and IE together, they are keeping themselves open for a serious security risk.
The major information about this bug is that it allows hackers to run code on your computer to allow them to get into your computer and gain admin privileges over it. They can pretty much do anything on your computer after that. They can even create a Web page to mimic one that you normally go to so that they can get information about you such as your user ID's and passwords. The main IE versions that are affected are 9, 10 and 11. This still affects, from estimates, 300 million users. That is an astounding number. Do they really feel that there are that many users of IE out there? To be honest, most the people I know use either Chrome or FireFox. Either way, there is no doubt in my mind that there are millions out there that are still using it and those are probably the XP users as well.
What can you do about it? Well, if you still have XP, upgrade to Windows 7 or 8 and install another browser on your machine. Chrome and FireFox are the two most popular browsers available, in my opinion. I, though, use a combination of three; the two mentioned before and Torch. This is a browser built off the Chrome source code and great for any social networking freak. Anyway, back to what you can do. If you currently have IE, and have a newer version of a Windows Operating System, install a new browser and uninstall IE. I honestly don't trust it and don't have it on my machine. Haven't used the browser in several years.
If you have XP, I again stress that it is time to upgrade your system. I know that costs money but it will cost a lot less than having to get your identity back after someone steals it after hacking into your machine. If you cannot upgrade to a new OS, again, install another browser and get rid of IE. Here are some recommended OS's from me:
Google Chrome - https://www.google.com/intl/en/chrome/browser/
Torch - http://www.torchbrowser.com/
FireFox - http://www.mozilla.org/en-US/firefox/new/
Opera - http://www.opera.com/computer
Sources for Blog:
https://news.yahoo.com/video/internet-explorer-security-flaw-poses-192303274.html;_ylt=A86.J3c1jWFTiScA7PIPxQt.;_ylu=X3oDMTBscmM0aHNtBHNlYwNjZC10aHVtYgRzbGsDc25vYg--
http://gizmodo.com/new-vulnerability-found-in-every-single-version-of-inte-1568383903?utm_campaign=socialflow_gizmodo_facebook&utm_source=gizmodo_facebook&utm_medium=socialflow
Well, a few weeks ago, I spoke on Microsoft ending all security updates for Microsoft XP. A few days ago, the Internet was a-buzz speaking about Internet Explorer (IE) and the new vulnerability that was found. Trust me when I say this, This is NOT good news for the users that still use XP. Due to Microsoft ending support, when the bug is fixed in IE, the users still using XP will not get that update. If they continue to use both XP and IE together, they are keeping themselves open for a serious security risk.
The major information about this bug is that it allows hackers to run code on your computer to allow them to get into your computer and gain admin privileges over it. They can pretty much do anything on your computer after that. They can even create a Web page to mimic one that you normally go to so that they can get information about you such as your user ID's and passwords. The main IE versions that are affected are 9, 10 and 11. This still affects, from estimates, 300 million users. That is an astounding number. Do they really feel that there are that many users of IE out there? To be honest, most the people I know use either Chrome or FireFox. Either way, there is no doubt in my mind that there are millions out there that are still using it and those are probably the XP users as well.
What can you do about it? Well, if you still have XP, upgrade to Windows 7 or 8 and install another browser on your machine. Chrome and FireFox are the two most popular browsers available, in my opinion. I, though, use a combination of three; the two mentioned before and Torch. This is a browser built off the Chrome source code and great for any social networking freak. Anyway, back to what you can do. If you currently have IE, and have a newer version of a Windows Operating System, install a new browser and uninstall IE. I honestly don't trust it and don't have it on my machine. Haven't used the browser in several years.
If you have XP, I again stress that it is time to upgrade your system. I know that costs money but it will cost a lot less than having to get your identity back after someone steals it after hacking into your machine. If you cannot upgrade to a new OS, again, install another browser and get rid of IE. Here are some recommended OS's from me:
Google Chrome - https://www.google.com/intl/en/chrome/browser/
Torch - http://www.torchbrowser.com/
FireFox - http://www.mozilla.org/en-US/firefox/new/
Opera - http://www.opera.com/computer
Sources for Blog:
https://news.yahoo.com/video/internet-explorer-security-flaw-poses-192303274.html;_ylt=A86.J3c1jWFTiScA7PIPxQt.;_ylu=X3oDMTBscmM0aHNtBHNlYwNjZC10aHVtYgRzbGsDc25vYg--
http://gizmodo.com/new-vulnerability-found-in-every-single-version-of-inte-1568383903?utm_campaign=socialflow_gizmodo_facebook&utm_source=gizmodo_facebook&utm_medium=socialflow
Tuesday, April 22, 2014
Verizon's Annual Data Breach Report
Week 7
Tomorrow, we will see the release of the annual report from Verizon that compiles and analyzes security incidents that happened over the year. This year it will be a 60 page document that discusses the main security concerns. This year, Verizon is reporting that 94% of all security related incidents in 2013 can be traced to 9 specific categories. Oh, did I mention that there were more than 63,000 security incidents last year alone! That means that over 59,000 of those incidents came from one of nine categories. This should tell you that we need to concentrate on specific areas to help secure our data. Throughout the rest of this blog, I'm going to go over these 9 threats.
Tomorrow, we will see the release of the annual report from Verizon that compiles and analyzes security incidents that happened over the year. This year it will be a 60 page document that discusses the main security concerns. This year, Verizon is reporting that 94% of all security related incidents in 2013 can be traced to 9 specific categories. Oh, did I mention that there were more than 63,000 security incidents last year alone! That means that over 59,000 of those incidents came from one of nine categories. This should tell you that we need to concentrate on specific areas to help secure our data. Throughout the rest of this blog, I'm going to go over these 9 threats.
- Web App Attacks - This attack is made through, you guessed it, your apps that you use on a daily basis. This is the most common type of breach according to the report coming out. You find an app that you think sounds great and you download it. Not all apps are safe. Some make it through app inspection and have viruses attached to them. You download, click and now you have a virus. Also, you are sometimes required to put in personal information to download the app. A few guesses at your security questions and the hacker is in. Please watch what you download. Apps are scarier than you may think.
- Cyberespionage - Pretty much, hackers are gaining unauthorized access to systems and then hanging around and getting personal information and stealing data. Keep software and security software up to date. This should stop most of the hackers from getting into your system.
- Point-of-sale intrusions - This is when a hacker gains access to a company's point-of-sale data. These are the systems that take the payment transactions that occur through a card transaction and submit those payments to the company. This is what happened with the Target incident this past year. Hackers gained access to the point-of-sale transactions and was able to steal millions of users data. Watch where you swipe that card. In times that there are going to be millions of people making transactions with cards in a short amount of time, for example Black Friday, I would suggest to use cash or checks during that time. Checks still have to go through a system process but it's not as unsafe as swiping that card.
- Payment Card Skimmers - This is when a hacker plants a device on a card scanner. This can be planted at a gas pump, ATM or even in Restaurants, but the later is harder to do because they could be seen planting it. Anyway, these can sit undetected and take data such as card numbers and your PIN. Watch where you swipe that card.
- Insider Misuse - This is simply put that someone on the inside (an employee) caused some sort of security issue to happen. They could have allowed the wrong person into the building, gave information out to the wrong person over the phone or they could have used the systems within in the wrong way.
- Crimeware - This is like cyberespionage but deals with more illicit activities like stealing banking or financial information. This can be done by creating fake webpages to make the user think they are on their banking site. Keep your browsers up to date and anti-virus software and firewalls up to date as well.
- Miscellaneous Errors - These are common errors that occur that open up a security concern. Nothing to do about this section other than to watch what you do when completing your job.
- Physical Theft/Loss - Of course, this is just theft and loss of equipment. Make sure you have proper physical security and insurance to help combat these losses. You don't want to lose all your computers and find out that you cannot replace them with insurance money.
- Distributed Denial-of-Service Attacks (DDoS) - Ah, the DDoS! One of the most common tools of a hacker. These attacks are a flood of attacks from multiple machines. The flood of information from the machines essentially makes the victim computer shut down and cause a denial of service and systems to the users that need that machine. For instance, several hackers can start to send requests to access a Web Server. That server gets too many of those and it shuts down. The users that really need that server cannot access it anymore, thus a DDoS has occurred. Keeping software and security software up to date can help but cannot help stop it from occurring if there are too many attacking. Software like Wireshark can help determine if there are multiple users trying to access a specific device, which can allow you to get ready and do something about the attack, but Wireshark will not help stop the attack all together.
The main point in this is, watch what you download, keep software up to date, make sure that you have proper anti-virus installed and a firewall defending your computer, and keep passwords and personal data to yourself. The Internet is a dangerous place. You are the person in charge of your security. Don't get mad when you are hacked but yet have no defense on your computer.
Get an early look at the report here - http://www.verizonenterprise.com/DBIR/2014/insider/?utm_source=earlyaccess&utm_medium=redirect&utm_campaign=DBIR
Reference:
Lev-Ram, M. (2014). New cyber-threats that go bump in the night. Retrieved April 22, 2014 from http://tech.fortune.cnn.com/2014/04/22/new-cyber-threats-that-go-bump-in-the-night/?section=magazines_fortune
Sunday, April 20, 2014
Heartbleed!
Week 6
I know I'm a bit late in discussing this topic, but I feel the need to blog about it so that my normal readers get a chance to hear from me on my feelings about it.
First off, let's start at the source, OpenSSL. This is a free and open project that collaborates to develop and implement the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols with a general cryptography library. This is opened and managed by a community of volunteers that communicate through the Internet (The OpenSSL Project, 2014). In layman terms, the two communication protocols that help people communicate across a network (SSL & TLS) are used to create an open source security library (everyone can use this code and do what they want with it to an extent). This library helps encrypt data while communicating on the Internet.
The downside with this project is that it had flaws to begin with. Supposedly, hackers have been using these flaws against the project and been able to hack into Web sites vulnerable with the OpenSSL project. Hackers can take those flaws, find out where users have been on the Internet, create fake Web sites, and then the next time the user goes to that Web site, they actually access the fake site that the hacker created for them. This then allows the hacker to gain information such as User IDs and passwords (Fung, 2014). This is honestly scarier than it sounds. If you haven't taken steps to combat this bug, you are very vulnerable to it.
People have been navigating the Internet for years under the assumption that they were safe on sites. This, as we know now, has not been the case. Many popular Web sites are vulnerable to the Heartbleed bug, and chances are, you use them even today. Sites such as: Yahoo, Facebook, Dropbox, Tumblr, Pinterest, Netflix, Amazon, Paypal, Adobe and many more were vulnerable to begin with. Many have added security patches to help keep this bug from being used against its users but many have yet to do so.
There is a great tool out there that will help you determine if the site you use is safe from the Heartbleed bug. You can go to https://filippo.io/Heartbleed/ and type in the Web page of the site you wish to check. It will link itself with that page and run a scan on it. It will then give you a message. Make sure you read that message. Not getting a green message doesn't necessarily mean that it is a bad site.
My suggestion is that if the site gives you a green light, go to that site and change your password. I also recommend that you get into a habit of changing your password once every 2 to 3 months. Yes, that does get tedious but it will save you in the long run. Also, use passwords that are not easy to guess. Suggestion, use at least 1 capital letter, 1 lowercase letter, 1 number and 1 symbol within your password (that is if the site allows the 1 symbol, some do not). The more advanced you make your password, the safer you are.
A good site to use when testing your password strength is https://howsecureismypassword.net/. You can go here, type your password in and it will tell you how long it will take a computer to crack your password. It's not 100% accurate but it at least gives you an idea of how hard it is to crack your password. Don't worry, this site does not save a password. It doesn't even know where you will be typing this password nor does it know the user IDs associated with the password. You are safe on this site, and the filippo site I provided earlier that checks for Heartbleed vulnerabilities also says it is safe. Good luck in your quest to better secure your accounts.
References:
Fung, B. (2014). Heartbleed is about to get worse, and it will slow the Internet to a crawl. Retrieved April 20, 2014 from http://www.washingtonpost.com/blogs/the-switch/wp/2014/04/14/heartbleed-is-about-to-get-worse-and-it-will-slow-the-internet-to-a-crawl/
The OpenSSL Project. (2014). Welcome to the OpenSSL Project. Retrieved April 20, 2014 from http://www.openssl.org/
I know I'm a bit late in discussing this topic, but I feel the need to blog about it so that my normal readers get a chance to hear from me on my feelings about it.
First off, let's start at the source, OpenSSL. This is a free and open project that collaborates to develop and implement the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols with a general cryptography library. This is opened and managed by a community of volunteers that communicate through the Internet (The OpenSSL Project, 2014). In layman terms, the two communication protocols that help people communicate across a network (SSL & TLS) are used to create an open source security library (everyone can use this code and do what they want with it to an extent). This library helps encrypt data while communicating on the Internet.
The downside with this project is that it had flaws to begin with. Supposedly, hackers have been using these flaws against the project and been able to hack into Web sites vulnerable with the OpenSSL project. Hackers can take those flaws, find out where users have been on the Internet, create fake Web sites, and then the next time the user goes to that Web site, they actually access the fake site that the hacker created for them. This then allows the hacker to gain information such as User IDs and passwords (Fung, 2014). This is honestly scarier than it sounds. If you haven't taken steps to combat this bug, you are very vulnerable to it.
People have been navigating the Internet for years under the assumption that they were safe on sites. This, as we know now, has not been the case. Many popular Web sites are vulnerable to the Heartbleed bug, and chances are, you use them even today. Sites such as: Yahoo, Facebook, Dropbox, Tumblr, Pinterest, Netflix, Amazon, Paypal, Adobe and many more were vulnerable to begin with. Many have added security patches to help keep this bug from being used against its users but many have yet to do so.
There is a great tool out there that will help you determine if the site you use is safe from the Heartbleed bug. You can go to https://filippo.io/Heartbleed/ and type in the Web page of the site you wish to check. It will link itself with that page and run a scan on it. It will then give you a message. Make sure you read that message. Not getting a green message doesn't necessarily mean that it is a bad site.
My suggestion is that if the site gives you a green light, go to that site and change your password. I also recommend that you get into a habit of changing your password once every 2 to 3 months. Yes, that does get tedious but it will save you in the long run. Also, use passwords that are not easy to guess. Suggestion, use at least 1 capital letter, 1 lowercase letter, 1 number and 1 symbol within your password (that is if the site allows the 1 symbol, some do not). The more advanced you make your password, the safer you are.
A good site to use when testing your password strength is https://howsecureismypassword.net/. You can go here, type your password in and it will tell you how long it will take a computer to crack your password. It's not 100% accurate but it at least gives you an idea of how hard it is to crack your password. Don't worry, this site does not save a password. It doesn't even know where you will be typing this password nor does it know the user IDs associated with the password. You are safe on this site, and the filippo site I provided earlier that checks for Heartbleed vulnerabilities also says it is safe. Good luck in your quest to better secure your accounts.
References:
Fung, B. (2014). Heartbleed is about to get worse, and it will slow the Internet to a crawl. Retrieved April 20, 2014 from http://www.washingtonpost.com/blogs/the-switch/wp/2014/04/14/heartbleed-is-about-to-get-worse-and-it-will-slow-the-internet-to-a-crawl/
The OpenSSL Project. (2014). Welcome to the OpenSSL Project. Retrieved April 20, 2014 from http://www.openssl.org/
Wednesday, April 9, 2014
The Death of Windows XP and What It Means to the Internet's Security!
Week 5
Yesterday, we all witnessed the death of probably the best Windows Operating System. Windows XP was introduced in 2001 and served most of us until the release of Windows 7. The crazy thing is, there are still close to 30% of computer owners who have XP still installed as their main OS. Who blames them though? That OS was one of a kind; flawless, dependable and secure. Now, when the patches come out next month from Microsoft, they will not be including XP. This means that for the first time in 13 years, the XP OS will not be updated or upgraded if needed. Security on that OS is now an issue. *Que intense music*
What surprises me is that even today, 30% of computer owners have XP as their main system. I don't blame them because it was a great OS. There is the word, "was". People need to understand that the Internet is changing and the source code for XP is not what it should be to defend against today's security threats. Now, with no support coming from Microsoft, security holes will be found and exploited and will not be fixed. Hackers will be able to use those holes to gain entrance into systems.
The dropping of the OS actually was announced months back to allow for people to go out and upgrade their systems prior to the cut. Why did so many people and companies decide to drag their feet? No one can answer that but them. Now, companies that have XP as their OS are having to quickly find a way to migrate and upgrade their systems. Companies need to understand the importance of upgrading. If they do not, they will find themselves in hot water before too long. Their data is at risk of being stolen. IT security should be the utmost importance to them.
I found an article that discussed how the dropping of XP will help make the whole Internet safer. The article couldn't be more right. Now you wonder, how could that be if only 30% of users have XP? The thing you have to realize is that those XP systems are touching other systems. We are all connected via the Internet. An XP system sending something to a Windows 7 machine makes that Windows 7 machine vulnerable because it is now exchanging packets with the XP system. Those packets, if sniffed out and hijacked would make both systems vulnerable to the attack. This is why it is so important to get upgraded to a newer OS, preferably Windows 7 and above and not Vista! That is my own opinion, but I think many will share the same feelings toward Vista that I do.
So, in closing, get rid of XP! Upgrade soon! Don't wait until your system has been compromised! It will end up saving not only you but the rest of the Internet.
Links to sites where I got some of my information for this blog:
http://www.informationweek.com/software/operating-systems/windows-xp-diehards-face-the-music/d/d-id/1204247
http://mashable.com/2014/04/09/windows-xp-security/?utm_campaign=Mash-Prod-RSS-Feedburner-All-Partial&utm_cid=Mash-Prod-RSS-Feedburner-All-Partial&utm_medium=feed&utm_source=rss
Yesterday, we all witnessed the death of probably the best Windows Operating System. Windows XP was introduced in 2001 and served most of us until the release of Windows 7. The crazy thing is, there are still close to 30% of computer owners who have XP still installed as their main OS. Who blames them though? That OS was one of a kind; flawless, dependable and secure. Now, when the patches come out next month from Microsoft, they will not be including XP. This means that for the first time in 13 years, the XP OS will not be updated or upgraded if needed. Security on that OS is now an issue. *Que intense music*
What surprises me is that even today, 30% of computer owners have XP as their main system. I don't blame them because it was a great OS. There is the word, "was". People need to understand that the Internet is changing and the source code for XP is not what it should be to defend against today's security threats. Now, with no support coming from Microsoft, security holes will be found and exploited and will not be fixed. Hackers will be able to use those holes to gain entrance into systems.
The dropping of the OS actually was announced months back to allow for people to go out and upgrade their systems prior to the cut. Why did so many people and companies decide to drag their feet? No one can answer that but them. Now, companies that have XP as their OS are having to quickly find a way to migrate and upgrade their systems. Companies need to understand the importance of upgrading. If they do not, they will find themselves in hot water before too long. Their data is at risk of being stolen. IT security should be the utmost importance to them.
I found an article that discussed how the dropping of XP will help make the whole Internet safer. The article couldn't be more right. Now you wonder, how could that be if only 30% of users have XP? The thing you have to realize is that those XP systems are touching other systems. We are all connected via the Internet. An XP system sending something to a Windows 7 machine makes that Windows 7 machine vulnerable because it is now exchanging packets with the XP system. Those packets, if sniffed out and hijacked would make both systems vulnerable to the attack. This is why it is so important to get upgraded to a newer OS, preferably Windows 7 and above and not Vista! That is my own opinion, but I think many will share the same feelings toward Vista that I do.
So, in closing, get rid of XP! Upgrade soon! Don't wait until your system has been compromised! It will end up saving not only you but the rest of the Internet.
Links to sites where I got some of my information for this blog:
http://www.informationweek.com/software/operating-systems/windows-xp-diehards-face-the-music/d/d-id/1204247
http://mashable.com/2014/04/09/windows-xp-security/?utm_campaign=Mash-Prod-RSS-Feedburner-All-Partial&utm_cid=Mash-Prod-RSS-Feedburner-All-Partial&utm_medium=feed&utm_source=rss
Saturday, April 5, 2014
Cybergeddon!
Week 4
I had the privilege a little over a year ago to watch the series Cybergeddon, now on DVD as a move. I was absolutely in love with it so bought it when it came out on DVD and watched it just the other night, again. The plot of the movie is about a Cyber FBI agent that is being framed for unleashing a virus on a water plant, that ends up getting unleashed on the entire Internet. The "bad guy" uses bots to unleash the virus across the Internet thus ending up taking control of 1 billion devices. With a click of a button, the infrastructure of the U.S. will come crashing down. It makes you ponder if this can actually happen.
The thing you have to realize is how fake the movie actually is. Just with a few clicks here and a few clicks there and some typing here and typing there, the "bad guy" is able to defend against the "good guys" network shut downs and buffer overflows and also hack into seriously secured networks. It takes much more than a few words and clicks to hack into systems as it is portrayed in the movie. You have to realize, while watching the movie, that for suspense reasons and the time it actually takes to get into systems, things are cut. That is the case with this movie. It also shows how the "bad guy" supposedly gets into the Cyber FBI site by just scanning for open ports. Chances are, in real life, the FBI Cyber Crime Lab doesn't have any open ports.
When it comes to taking over 1 billion devices, to be honest with you, it is possible. With the new "Internet of Things" going on, this could eventually happen. You have to look at what is all connected and what will be connected in the future. Soon, your refrigerator will be able to talk to your computer, your furniture will be able to learn your sitting habits and conform to you body, and devices that help you live will be attached to your body relaying information to your computer. To be quite honest, it is a scary situation if you think about it. With some smart hacking, a "bad guy" could hack into the Internet of Things and start to take control of one device at a time. Soon enough, they could have control of 1 billion devices.
The sad thing is that this has more of a chance at happening now than it did 5 years ago. Everyone is getting contempt with using the Internet and computers for everything they do. Many do not use the proper passwords or user IDs to help keep their own system secure. Mobile devices can attach themselves to any wireless network at any given time. If the public is not educated on how serious this is, Cybergeddon is closer than it is farther away. People need to change their tune about how they play around in the Internet of Things before it is too late.
Internet of Things:
http://www.computerweekly.com/news/2240212690/Internet-at-risk-of-cybergeddon-says-WEF
Movie:
http://www.imdb.com/title/tt2189240/
I had the privilege a little over a year ago to watch the series Cybergeddon, now on DVD as a move. I was absolutely in love with it so bought it when it came out on DVD and watched it just the other night, again. The plot of the movie is about a Cyber FBI agent that is being framed for unleashing a virus on a water plant, that ends up getting unleashed on the entire Internet. The "bad guy" uses bots to unleash the virus across the Internet thus ending up taking control of 1 billion devices. With a click of a button, the infrastructure of the U.S. will come crashing down. It makes you ponder if this can actually happen.
The thing you have to realize is how fake the movie actually is. Just with a few clicks here and a few clicks there and some typing here and typing there, the "bad guy" is able to defend against the "good guys" network shut downs and buffer overflows and also hack into seriously secured networks. It takes much more than a few words and clicks to hack into systems as it is portrayed in the movie. You have to realize, while watching the movie, that for suspense reasons and the time it actually takes to get into systems, things are cut. That is the case with this movie. It also shows how the "bad guy" supposedly gets into the Cyber FBI site by just scanning for open ports. Chances are, in real life, the FBI Cyber Crime Lab doesn't have any open ports.
When it comes to taking over 1 billion devices, to be honest with you, it is possible. With the new "Internet of Things" going on, this could eventually happen. You have to look at what is all connected and what will be connected in the future. Soon, your refrigerator will be able to talk to your computer, your furniture will be able to learn your sitting habits and conform to you body, and devices that help you live will be attached to your body relaying information to your computer. To be quite honest, it is a scary situation if you think about it. With some smart hacking, a "bad guy" could hack into the Internet of Things and start to take control of one device at a time. Soon enough, they could have control of 1 billion devices.
The sad thing is that this has more of a chance at happening now than it did 5 years ago. Everyone is getting contempt with using the Internet and computers for everything they do. Many do not use the proper passwords or user IDs to help keep their own system secure. Mobile devices can attach themselves to any wireless network at any given time. If the public is not educated on how serious this is, Cybergeddon is closer than it is farther away. People need to change their tune about how they play around in the Internet of Things before it is too late.
Internet of Things:
http://www.computerweekly.com/news/2240212690/Internet-at-risk-of-cybergeddon-says-WEF
Movie:
http://www.imdb.com/title/tt2189240/
Saturday, March 29, 2014
Threats Vs Vulnerabilities
Week 3
Someone recently asked me what was the difference between a threat and vulnerability. That is honestly a good question. It was mentioned, by the person asking, that they thought they were one in the same. I asked their rational, but did not get a good explanation as to why they felt that way. These two topics are not one in the same, but they should be discussed together when looking at the security of your business.
In all my studies, I found one definition that I really enjoyed for the description of the word, threats. Michael Whitman and Herbert Mattord define a threat as "a category of objects, persons, or other entities that represents a constant danger to an asset (Whitman & Mattord, 2010)." What this means is that a threat is an actual thing that could cause a danger to something that you own. Take for example, your house. Take that definition and determine a threat to your house now. One of the biggest threats to your house is a natural disaster such as a tornado or flood. Because this represents a constant danger to your house, it is considered a threat. Need another example? Let's use a technology of some sort this time with your computer. One of the biggest threats to your computer is a hacker. They are people that love to spend their time trying to access your computer.
When it comes to vulnerabilities, I really haven't found a definition that I absolutely love. There are so many out there because it encompasses several topics not just technology. One of the best ones I have found that can be tweaked to help define vulnerability generally is from Tech Republic writer, Chad Perrin. A vulnerability is a flaw in a resource that will eventually allow an attack or damage to occur to that resource (Perrin, 2009). Let us look at the example of the house from the previous paragraph. A vulnerability of a house could be that it was built with cheaper wood than other houses. That wood could eventually break easier during a storm, thus causing it to collapse. The cheaper wood is the vulnerability. When it comes to your computer, there are many types of vulnerabilities, but one of the biggest that a hacker finds often is that a user will use a weak password. Having a password that is weak enough to let a hacker in is considered a computer vulnerability.
You have to realize that threats and vulnerabilities are every where, but they are also not one in the same. Threats are the entities that can do the damage, while vulnerabilities are the flaws that help the damage occur. When looking at your own threats and vulnerabilities, keep that in mind. Hopefully, if you have had any questions about these two, this blog has helped you understand them a bit better.
References:
Perrin, C. (2009). Understanding risk, threat and vulnerability. Retrieved March 29, 2014
from http://www.techrepublic.com/blog/it-security/understanding-risk-threat-and-vulnerability/
Whitman, M & Mattord, H. (2010). Management of Information Security. Boston, MA: Course Technology, Cengage Learning.
Someone recently asked me what was the difference between a threat and vulnerability. That is honestly a good question. It was mentioned, by the person asking, that they thought they were one in the same. I asked their rational, but did not get a good explanation as to why they felt that way. These two topics are not one in the same, but they should be discussed together when looking at the security of your business.
In all my studies, I found one definition that I really enjoyed for the description of the word, threats. Michael Whitman and Herbert Mattord define a threat as "a category of objects, persons, or other entities that represents a constant danger to an asset (Whitman & Mattord, 2010)." What this means is that a threat is an actual thing that could cause a danger to something that you own. Take for example, your house. Take that definition and determine a threat to your house now. One of the biggest threats to your house is a natural disaster such as a tornado or flood. Because this represents a constant danger to your house, it is considered a threat. Need another example? Let's use a technology of some sort this time with your computer. One of the biggest threats to your computer is a hacker. They are people that love to spend their time trying to access your computer.
When it comes to vulnerabilities, I really haven't found a definition that I absolutely love. There are so many out there because it encompasses several topics not just technology. One of the best ones I have found that can be tweaked to help define vulnerability generally is from Tech Republic writer, Chad Perrin. A vulnerability is a flaw in a resource that will eventually allow an attack or damage to occur to that resource (Perrin, 2009). Let us look at the example of the house from the previous paragraph. A vulnerability of a house could be that it was built with cheaper wood than other houses. That wood could eventually break easier during a storm, thus causing it to collapse. The cheaper wood is the vulnerability. When it comes to your computer, there are many types of vulnerabilities, but one of the biggest that a hacker finds often is that a user will use a weak password. Having a password that is weak enough to let a hacker in is considered a computer vulnerability.
You have to realize that threats and vulnerabilities are every where, but they are also not one in the same. Threats are the entities that can do the damage, while vulnerabilities are the flaws that help the damage occur. When looking at your own threats and vulnerabilities, keep that in mind. Hopefully, if you have had any questions about these two, this blog has helped you understand them a bit better.
References:
Perrin, C. (2009). Understanding risk, threat and vulnerability. Retrieved March 29, 2014
from http://www.techrepublic.com/blog/it-security/understanding-risk-threat-and-vulnerability/
Whitman, M & Mattord, H. (2010). Management of Information Security. Boston, MA: Course Technology, Cengage Learning.
Tuesday, March 18, 2014
Let's Just Use Wikipedia
I hear that many people use Wikipedia as a source to back them up. In fact, the other day someone was trying to convince me on a given topic and I asked them what their source was. He actually stated that he read it on Wikipedia. I had to go into why he shouldn't trust that page fully. He was unaware that anyone could change the information on the page. Yes, there are links that people provide at the bottom to help direct you to where they got their information, but is that creditable? The crazy thing is that in my current class, I am asked to blog about creditable sites within IT security that deal with threats, vulnerabilities and other general IT topics so here I am.
As those who have read my blogs in the past, you are aware that I have been going to school for several years for IT. There have been many papers written, but where do I get the information that I write about? For one, I do get them from my text books, but what happens when I need get information off the Internet? How do I know when a site is creditable? Over the years, I have grown to trust many sites, but I have also grown to keep away from some others.
Before I go into the creditable sites, I will make a few points about two sites that I do not feel are creditable.
- Wikipedia - If you use this site, use it as a base. Definitions are normally OK but I highly recommend that you search other sites because this site can be changed by anyone! Yes, you and I can add to the site anything we want. This makes Wikipedia un-creditable in my eyes.
- About.com - This site has some very good information, but in my views, some of it is missing information and could cost you valuable information and time having to search around to fill in the missing parts.
There have been several sites that I have grown comfortable with when it comes to the topic of IT and that I know are very creditable:
- Symantic - http://www.symantec.com/security_response/ - This site is run by the makers of Norton Security. They continue to update it with IT security information such as threats, vulnerabilities and risks. This eventually updates the source for the Norton product to help defend your computer against the known threats, vulnerabilities and risks.
- Homeland Security - http://www.dhs.gov/topic/cybersecurity - This site is maintained by the government's Department of Homeland Security. How more creditable can you get? When it comes to the general topic of Cybersecurity, this site has been there for me for the past few years. They continue to keep up with the topic of Cybersecurity and have many links available for anyone to learn about the topic.
- Dark Reading - http://www.darkreading.com/ - This site has links to everything you can imagine on all topics of IT. Professionals in the field have articles linked through this site. In my opinion, this site is the best site to find general articles for IT.
- CSO Online - http://www.csoonline.com/ - This site has information for the CSO (Chief Security Officer). Even though the CSO is general to security, this site has many links that merge into the topic of IT; data protection, business continuity and identity and access topics are all covered on this site.
- SC Magazine - http://www.scmagazine.com/ - Probably the best magazine site that discusses IT security. It has blogs about IT security and you can also read many whitepapers written by the leading professionals.
I could go on and on when it comes to the creditable sites that I use, but these are the ones I keep going back to. They are linked with professionals in the field and they are maintained by highly creditable businesses. I honestly recommend these 5 sites to anyone trying to find information out about IT. The best words of advice that I can give on whether a site is creditable or not; if you recognize the name of the site to be an important business, it is probably a very creditable site.
Tuesday, October 22, 2013
A Company's Biggest Risk!
What is your company’s biggest risk? Many would probably say that it was the fact
that they do business through the Internet.
Being connected to the Internet and making all your transactions online
is a big risk, but is it the biggest? I
recently read an article in Security magazine entitled, People – Your Most Important
Asset and a Significant Risk. This
article discusses the importance of the employees and what they do for a
company. It also discusses the fact that
due to human nature, people are a significant risk to the company. I would have to not only agree that they are
a significant risk but also the biggest.
Why? We have the ability to think
and act for ourselves.
Set back and think of how you would program a robot to guard
the front door of your company. You would
probably be able to program that robot to guard that door better than anyone
else could ever think of guarding the door.
This robot would follow the programming perfectly. It would make sure that all security
obligations are met. It would not let the person in if they were not
authorized. Now, place yourself in the
shoes of the robot. Someone comes in and
starts up a conversation with you. You,
being friendly with them, decide to communicate back and strike up a long
conversation. You begin to feel
comfortable with that person. You decide
that he or she can be let in. Even if
they were not a threat, you just committed a severe security infraction against
your company. What if that person was a
social engineer? They just did their job
and made it past you. A robot would not
allow this.
People come with flaws.
None of us are perfect. More
often than not, people make more mistakes than computers do. Company’s take a huge risk relying on people
to do their jobs for them because of the mistakes that we can and do make. People key data into databases incorrectly
more than you can imagine (trust me; I know this because I work at a DBA
helpdesk). Even though the majority of
the article in which I reference stems to the new hire employees more so than
the longer tenured employees, the article’s main point is still the fact that
employees in general are a significant risk to the company. What companies need to do when they are
looking over their risks is to not forget their employees. They are by far, in my opinion, the biggest
risk that a company has to deal with.
Reference:
Brennan, J. & Mattice, L. (2013). People – Your Most Important
Asset and a Significant Risk. Security Magazine. August 2013. Pg. 28.
Saturday, August 17, 2013
My User ID And Password Is.....
Have you ever struck up a conversation with a stranger? Someone you had no idea who they were? What if I told you that you might have given that stranger your User ID and Password to all your data! No, you didn't specifically state, This is my User ID and This is my Password! If you told this stranger anything about yourself; where you were from, what you did for a living, wife's name or other personal information, you might have started the fuse for them to find out what you use as your User ID and Password for particular sites or even for your computer. Now you are saying, Nope, I don't use personal information for that type of stuff. Well, chances are, you do! Most people use a User ID and a Password that they will remember easily. This means that they use information from their personal lives to make up that data.
There is a group of people out there that call themselves Social Engineers. They are trained in the art of human hacking. In the quoting of Star Wars, They are strong in the ways of the force of gaining as much information about someone as they can so that they can hack their way into that person's life. This might seem scary to you, but honestly, it should strike some fear into you about what you share with others. The thing is, there are several sites that help one understand Social Engineering, the tools that are used and how to defend against it. Some sites include:
(LifeHacker) http://lifehacker.com/5933296/how-can-i-protect-against-hackers-who-use-sneaky-social-engineering-techniques-to-get-into-my-accounts
(CSO Online) http://www.csoonline.com/article/514063/social-engineering-the-basics
(Cisco) http://www.cisco.com/web/about/security/intelligence/mysdn-social-engineering.html
Those are only a select few in thousands of sites. These sites above really help the reader understand what Social Engineering is and how to defend against it at a level that anyone should be able to understand. Social Engineering is a great tool for people to find out information about other people. Don't let someone hack their way into your life by figuring out your User ID and Password. Defend against Social Engineering on a personal level before you find out that you are living in another state with another spouse and kids that aren't even yours!
There is a group of people out there that call themselves Social Engineers. They are trained in the art of human hacking. In the quoting of Star Wars, They are strong in the ways of the force of gaining as much information about someone as they can so that they can hack their way into that person's life. This might seem scary to you, but honestly, it should strike some fear into you about what you share with others. The thing is, there are several sites that help one understand Social Engineering, the tools that are used and how to defend against it. Some sites include:
(LifeHacker) http://lifehacker.com/5933296/how-can-i-protect-against-hackers-who-use-sneaky-social-engineering-techniques-to-get-into-my-accounts
(CSO Online) http://www.csoonline.com/article/514063/social-engineering-the-basics
(Cisco) http://www.cisco.com/web/about/security/intelligence/mysdn-social-engineering.html
Those are only a select few in thousands of sites. These sites above really help the reader understand what Social Engineering is and how to defend against it at a level that anyone should be able to understand. Social Engineering is a great tool for people to find out information about other people. Don't let someone hack their way into your life by figuring out your User ID and Password. Defend against Social Engineering on a personal level before you find out that you are living in another state with another spouse and kids that aren't even yours!
Sunday, April 28, 2013
What is Information Warfare?
Throughout the last six weeks in my current class at Bellevue University, Information Warfare, I have been asked to look at and compare a few of the many definitions of warfare to each other and also compare each of them to that of information warfare (if they weren't already definitions of information warfare). It has got me wondering; why are there so many views and definitions of warfare and information warfare for that matter? Is it because one person just doesn't like the definition that another person has given? Is it due to the topic area being so vast? Shouldn't warfare be simply the conflict between two or more parties? You would think that so many definitions would cause an issue in to understanding what warfare and information warfare really is.
Let's look at it in a history standpoint. A hundred years ago, we did not have the weapons we have today. All they had were guns and cannons and some road horseback into battle while others ran in on foot. Over the years, war has added many different types of weapons; vehicles, bigger guns, tanks, planes, nuclear weapons and now computers. Yes, computers are now being used as weapons. Remember Stuxnet? This was a virus that was instructed to find turbines within a plant overseas and destroy them. It did so through a flash drive and made its way through the network even when some computers were not even on the network (New York Times, 2011). The fact is, weapons are getting bigger and better. As long as the weapons are changing, so should the definition of warfare and now information warfare, which Stuxnet was.
My honest opinion is that warfare and even that of information warfare is changing so much because the area (warfare) changes constantly and these definitions are just trying to keep up with the times. There are some, in my opinion, that do not do the topic justice, but there are also some that put the whole topic into perspective. I'm not going to add them here for there are just too many. Just do a Google search for "Information Warfare" AND "Definition" and you will come up with many results. Decide for yourself on which is the best. My instructions to you, the reader, keep an open mind about the definitions you find. Information warfare is something that happens on a daily basis. Computers attack computers. Information in some way, shape or form is used in these attacks.
If I were to give my own definition of information warfare, I would have to encompass both information and computers in one definition. Something such as; Using the software and hardware on a computer to attack hardware or software of another computer. Some would say that this definition wasn't fulfilling the entire topic of information warfare. Some would probably say that it is lacking the ability of non computer information. Well, take this into consideration, how can a paper document attack another paper document? It physically cannot. What is written on one paper might defend a topic while the other paper might dispute the same topic. Is it information warfare? It could be. The thing is, in this writers mind, it does not encompass the true meaning of warfare; war against an enemy. I'm not quoting anyone there for it is a general definition found in the dictionary. This is also not war; conflict through the force of arms between multiple people. Again, this is one that can be found in the dictionary. Because the topic of warfare leads to conflict between people with force, I am not going to agree that a paper can attack a paper.
In conclusion, it is all up to the reader on whether they want to agree with my feelings on information warfare. Everyone will have their own opinion, and they are entitled to it. Keep in mind when you are reading about information warfare what warfare really is. This will allow you to read the definition and determine if it truly is a good definition for information warfare. Yes, the times have changed, but the major weapon that is being used is the computer. They are the ones used for attacking and defending important information. This is the true nature of information warfare.
References:
Let's look at it in a history standpoint. A hundred years ago, we did not have the weapons we have today. All they had were guns and cannons and some road horseback into battle while others ran in on foot. Over the years, war has added many different types of weapons; vehicles, bigger guns, tanks, planes, nuclear weapons and now computers. Yes, computers are now being used as weapons. Remember Stuxnet? This was a virus that was instructed to find turbines within a plant overseas and destroy them. It did so through a flash drive and made its way through the network even when some computers were not even on the network (New York Times, 2011). The fact is, weapons are getting bigger and better. As long as the weapons are changing, so should the definition of warfare and now information warfare, which Stuxnet was.
My honest opinion is that warfare and even that of information warfare is changing so much because the area (warfare) changes constantly and these definitions are just trying to keep up with the times. There are some, in my opinion, that do not do the topic justice, but there are also some that put the whole topic into perspective. I'm not going to add them here for there are just too many. Just do a Google search for "Information Warfare" AND "Definition" and you will come up with many results. Decide for yourself on which is the best. My instructions to you, the reader, keep an open mind about the definitions you find. Information warfare is something that happens on a daily basis. Computers attack computers. Information in some way, shape or form is used in these attacks.
If I were to give my own definition of information warfare, I would have to encompass both information and computers in one definition. Something such as; Using the software and hardware on a computer to attack hardware or software of another computer. Some would say that this definition wasn't fulfilling the entire topic of information warfare. Some would probably say that it is lacking the ability of non computer information. Well, take this into consideration, how can a paper document attack another paper document? It physically cannot. What is written on one paper might defend a topic while the other paper might dispute the same topic. Is it information warfare? It could be. The thing is, in this writers mind, it does not encompass the true meaning of warfare; war against an enemy. I'm not quoting anyone there for it is a general definition found in the dictionary. This is also not war; conflict through the force of arms between multiple people. Again, this is one that can be found in the dictionary. Because the topic of warfare leads to conflict between people with force, I am not going to agree that a paper can attack a paper.
In conclusion, it is all up to the reader on whether they want to agree with my feelings on information warfare. Everyone will have their own opinion, and they are entitled to it. Keep in mind when you are reading about information warfare what warfare really is. This will allow you to read the definition and determine if it truly is a good definition for information warfare. Yes, the times have changed, but the major weapon that is being used is the computer. They are the ones used for attacking and defending important information. This is the true nature of information warfare.
References:
New York Times, (2011).
Israeli Test on Worm Called Crucial in Iran Nuclear Delay. Retrieved
June
19, 2012 from http://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html?pagewanted=all
Thursday, January 24, 2013
Security!
My current class dabbles in the topics of physical, personnel and operations security. Throughout this class, I have touched on several subjects that I have already been introduced to in my current job. The discussions are about security in fields other than that of the cyber field, so far! I am accustomed to questions now a days as to why this class is even a requirement of my current degree (questioned about it when I tell family and friends what class I am in and what degree I am pursuing). It has been asked so much in the past month that I have finally decided to type up a blog on why this is so important to the Cybersecurity field.
Security of all shapes and sizes is needed to help secure your business or home all together. In your home, you probably have 1 computer at least. Would you leave the doors unlocked? No, you would lock them so that no one will steal your computer. This is physical security. Even though you have an id and password on your computer, you need that physical security to keep the computer safe from theft. Departments throughout a business have different types of security that they must follow as well. You can't just expect them to put your information in a file and put it on the cabinet so that someone can just walk in and look through it. They also must follow specific security laws such as keeping your information private such as your address and social security number. Cybersecurity wouldn't be what it is without multiple types of security in place to also keep it safe.
Laws must be followed. Laws are a part of security. Laws are introduced in these fields. You can't have Cybersecurity without laws. You get where I am going? Laws need to be first followed before you can secure anything; personnel files, computers, and even a building. When learning about these types of securities, I am also learning the laws behind what is right and what is wrong. Let's take a quick example. Let's say you want to put up Closed Circuit Television (CCTV) on your businesses public lot. You have to look into and read the laws behind using CCTV before you can place the cameras on your lot. Remember, security can't happen on its own; it needs the people within it to understand the laws that make it possible!
Security of all shapes and sizes is needed to help secure your business or home all together. In your home, you probably have 1 computer at least. Would you leave the doors unlocked? No, you would lock them so that no one will steal your computer. This is physical security. Even though you have an id and password on your computer, you need that physical security to keep the computer safe from theft. Departments throughout a business have different types of security that they must follow as well. You can't just expect them to put your information in a file and put it on the cabinet so that someone can just walk in and look through it. They also must follow specific security laws such as keeping your information private such as your address and social security number. Cybersecurity wouldn't be what it is without multiple types of security in place to also keep it safe.
Laws must be followed. Laws are a part of security. Laws are introduced in these fields. You can't have Cybersecurity without laws. You get where I am going? Laws need to be first followed before you can secure anything; personnel files, computers, and even a building. When learning about these types of securities, I am also learning the laws behind what is right and what is wrong. Let's take a quick example. Let's say you want to put up Closed Circuit Television (CCTV) on your businesses public lot. You have to look into and read the laws behind using CCTV before you can place the cameras on your lot. Remember, security can't happen on its own; it needs the people within it to understand the laws that make it possible!
Thursday, October 18, 2012
Cyber-Security
It has been a while since my last blog, but I felt that today would be the day that I needed to add to it. Earlier today, for a split second, I witnessed on Yahoo, the word "Cybersecurity" as a top searched word. I'll be honest, I had never seen the word as a top searched word on Yahoo, ever! This actually gave me chills. What prompted people to start searching for that word in particular? Why has it never come up before, or at least that I have seen?
About a month ago, GoDaddy was hacked. This took down many sites, including some of the servers that my school has hosted through GoDaddy. For about 4 hours, I was without access to my school site. Believe me when I say that I was panicking, though, not from the actual outage, but not being able to gain access to my school. Now we are hearing of banks getting hacked. If you type, "Site Hacked" in the yahoo search bar (make sure you add the quotation marks) and click to filter by time of past month, and you will get 150 results. Look through them. It is amazing how many sites have been hacked and how they were hacked. Many of these resulted in data being released to the public.
I recently read somewhere that the field of Cybersecurity will be looking for employees in the future but will not have enough to fill the jobs available. Come on people! Understand that this field will be needed. The hacking that is going on and what is being released to the public just has to stop or at least be slowed. The country and even the world cannot have this happening on a daily basis. If none of you have had a chance to watch Cybergeddon by Yahoo & Norton, you need to find it and watch. Here is the link: http://cybergeddon.yahoo.com/#home One might think it is all fiction, well, the story might be but what is going on could in fact happen in the future. If you like the CSI shows, you should like this because it is produced by none other than Anthony Zuiker, who produced the original CSI's. If I have some facts incorrect there, please feel free to correct me.
What this all boils down to is managing your security on your computer properly. As I have mentioned in my previous posts; use strict passwords, firewall, anti-virus software, keep your computer up to date with all updates needed and keep all your information you use on the computer confidential. Follow these rules and you will help keep these types of attacks from happening.
About a month ago, GoDaddy was hacked. This took down many sites, including some of the servers that my school has hosted through GoDaddy. For about 4 hours, I was without access to my school site. Believe me when I say that I was panicking, though, not from the actual outage, but not being able to gain access to my school. Now we are hearing of banks getting hacked. If you type, "Site Hacked" in the yahoo search bar (make sure you add the quotation marks) and click to filter by time of past month, and you will get 150 results. Look through them. It is amazing how many sites have been hacked and how they were hacked. Many of these resulted in data being released to the public.
I recently read somewhere that the field of Cybersecurity will be looking for employees in the future but will not have enough to fill the jobs available. Come on people! Understand that this field will be needed. The hacking that is going on and what is being released to the public just has to stop or at least be slowed. The country and even the world cannot have this happening on a daily basis. If none of you have had a chance to watch Cybergeddon by Yahoo & Norton, you need to find it and watch. Here is the link: http://cybergeddon.yahoo.com/#home One might think it is all fiction, well, the story might be but what is going on could in fact happen in the future. If you like the CSI shows, you should like this because it is produced by none other than Anthony Zuiker, who produced the original CSI's. If I have some facts incorrect there, please feel free to correct me.
What this all boils down to is managing your security on your computer properly. As I have mentioned in my previous posts; use strict passwords, firewall, anti-virus software, keep your computer up to date with all updates needed and keep all your information you use on the computer confidential. Follow these rules and you will help keep these types of attacks from happening.
Wednesday, August 8, 2012
The End!
Well, this is the final week of my class in which this blog is a requirement. I had to discuss on the discussion board what I had spoke about over the past several blogs. I have to admit, I don't think I did too bad on the blogs. It helped that I had a good blogging background before I started, though. I have taken a lot away from doing this blog. I know it will help get me out to the Information Security world and will do good for me in the future for applying for jobs. I can just point them to this blog, which hopefully can help me score some brownie points with them. Any future employers reading this right now, please take into consideration my previous blogs and how well I did discussing each topic and not what I just posted about brownie points :)
I feel that everyone should blog. Blog about anything that interests you. Blog about your personal life to your family. In fact, I recommend that topic to any newcomers to blogging. Just tell your family what is going on in your life. It makes it much easier to ease into other topics of blogging. Be open when blogging. Don't worry about your readers. Blogging allows you to get your opinion out there. I'm not saying to go out there and go off on a person to the point where you are wishing them to not be here. That is wrong. Go out there and just give your opinion.
When it comes to Information Security, I am not as advanced in the subject as many might think that I am, but I am getting there. The class that I am taking has opened my mind to many aspects of the topic that I was unaware of, but has also touched on topics that I have come to love in the past several years. I feel that everyone should be knowledgeable in Information Security if they have their own computer. You need to have the base knowledge so that you can help secure your computer and data from the outside world. I suggest that if you are not planning on entering the IT world to go out and find a book on IT security and read it from front to back. Get the know-how to secure your computer or you will regret it. Thanks to all of you who have read my blog. Look for future posts, though, I am unsure when I will post next.
I feel that everyone should blog. Blog about anything that interests you. Blog about your personal life to your family. In fact, I recommend that topic to any newcomers to blogging. Just tell your family what is going on in your life. It makes it much easier to ease into other topics of blogging. Be open when blogging. Don't worry about your readers. Blogging allows you to get your opinion out there. I'm not saying to go out there and go off on a person to the point where you are wishing them to not be here. That is wrong. Go out there and just give your opinion.
When it comes to Information Security, I am not as advanced in the subject as many might think that I am, but I am getting there. The class that I am taking has opened my mind to many aspects of the topic that I was unaware of, but has also touched on topics that I have come to love in the past several years. I feel that everyone should be knowledgeable in Information Security if they have their own computer. You need to have the base knowledge so that you can help secure your computer and data from the outside world. I suggest that if you are not planning on entering the IT world to go out and find a book on IT security and read it from front to back. Get the know-how to secure your computer or you will regret it. Thanks to all of you who have read my blog. Look for future posts, though, I am unsure when I will post next.
Tuesday, July 31, 2012
Certifications!
I'll be the first one to tell you that I don't like the idea of getting certified on anything in the IT world. Don't get me wrong, I understand why one needs to be, but I don't like what you have to go through to get certified. You have to take a test and pay money for that test. Many will argue that the benefits of having the certificate out-way the costs. This, I feel, stems back to possibly the company in which people work in help pay for the tests. Heck, if my company offered to help pay for my testing, I would be certified out the ying-yang. Thing is, there are also a lot of employers that do not participate in this type of help.
What chaps my hide is the fact that there are many jobs now that state you must have a certificate to be hired. Even the entry level positions such as help desk support or desktop support are requiring some sort of certification such as CompTIA A+ (basic computer skills over hardware and operating systems). My argument is that many people with multiple years of computer usage already have the majority of the knowledge to pass the A+ exam. I feel that employers are taking advantage of people when asking them to have the A+ before getting even looked at and interviewed. This test is basic. If you have an Associate and Bachelor degree in IT, chances are that you have enough knowledge to pass the A+. Thing is, the cost associated with it. At the current time, it costs $178 to take the test. Other than their fundamental tests, this is by far the cheapest test that they offer (CompTIA, 2012). I don't know about you, but that is too much just to have someone state that I am certified to play around on a computer.
Now, their other tests such as their Security+ and Network+ are a little more detailed and require one to have knowledge in that specific area. I can understand if you are applying for a job in that field (Networking or Security) that you need to have such qualifications. I can not tell you how many times I have been turned down by a job because I do not have the A+ certification. I live paycheck to paycheck and have a problem with forking out that much money to get a certification.
Now, with that off my chest, I want to take the time out to actually state that in today's economy, you need to get certified if you plan on getting into a specific area of IT. I completely agree with this notion. Here are a few suggestions for you if you are planning on the Network or Security specific IT areas of work:
Security - CompTIA Security+ or the Certified Information Systems Security Professional (CISSP) or both
Networking - CompTIA Network+ or the Cisco Certified Network Associate (CCNA) or both
You can do searches for the above tests to find them and to read more about them. I have no problem with getting certified in these areas, but when it comes to that general A+ certification, I am a bit peeved that it is a requirement to many entry level jobs. Good luck in your certification search. I know I will be getting my CISSP once I am done with school and possibly the others up there as well.
Reference
CompTIA. (2012). Exam Prices. Retrieved July 31, 2012 from http://certification.comptia.org/Training/testingcenters/examprices.aspx
What chaps my hide is the fact that there are many jobs now that state you must have a certificate to be hired. Even the entry level positions such as help desk support or desktop support are requiring some sort of certification such as CompTIA A+ (basic computer skills over hardware and operating systems). My argument is that many people with multiple years of computer usage already have the majority of the knowledge to pass the A+ exam. I feel that employers are taking advantage of people when asking them to have the A+ before getting even looked at and interviewed. This test is basic. If you have an Associate and Bachelor degree in IT, chances are that you have enough knowledge to pass the A+. Thing is, the cost associated with it. At the current time, it costs $178 to take the test. Other than their fundamental tests, this is by far the cheapest test that they offer (CompTIA, 2012). I don't know about you, but that is too much just to have someone state that I am certified to play around on a computer.
Now, their other tests such as their Security+ and Network+ are a little more detailed and require one to have knowledge in that specific area. I can understand if you are applying for a job in that field (Networking or Security) that you need to have such qualifications. I can not tell you how many times I have been turned down by a job because I do not have the A+ certification. I live paycheck to paycheck and have a problem with forking out that much money to get a certification.
Now, with that off my chest, I want to take the time out to actually state that in today's economy, you need to get certified if you plan on getting into a specific area of IT. I completely agree with this notion. Here are a few suggestions for you if you are planning on the Network or Security specific IT areas of work:
Security - CompTIA Security+ or the Certified Information Systems Security Professional (CISSP) or both
Networking - CompTIA Network+ or the Cisco Certified Network Associate (CCNA) or both
You can do searches for the above tests to find them and to read more about them. I have no problem with getting certified in these areas, but when it comes to that general A+ certification, I am a bit peeved that it is a requirement to many entry level jobs. Good luck in your certification search. I know I will be getting my CISSP once I am done with school and possibly the others up there as well.
Reference
CompTIA. (2012). Exam Prices. Retrieved July 31, 2012 from http://certification.comptia.org/Training/testingcenters/examprices.aspx
Tuesday, July 24, 2012
Why Firewall?
Many people I have spoken to in the past about security on their computers have asked me about the same question; If I have anti-virus software on my computer, why should I even bother getting a firewall? It isn't that tough of a question to answer. Yes, you should use an anti-virus software, but what good is it without a firewall? Without a firewall, your computer is just setting out there on the Internet saying; here I am come and get me. You need that firewall!
Let's tackle a quick question here. What is a firewall? A firewall is what it sounds like. It is a wall, but it isn't made of fire. It is a device, albeit a hardware or software device, that sets on a computer or network and prevents or blocks information from entering or leaving it (Whitman & Mattord, 2010). There are many types of firewalls out there on the market, but it would take too much time to discuss them all here so I am just going to stick with the basics.
(Smart PC Support, 2012)
Take a look at the above picture. This gives a general idea of what a firewall does. The Earth is pictured here as the Internet. There is a wall (firewall) and then your computer behind it. A firewall has rules or in this case bricks that define how it is to react to certain information. If the information trying to get in has been deemed inappropriate or unwanted by your computer, it will deflect it and keep it out (red arrows). If the information coming in is wanted, it will get through (green arrow).
OK, now that you understand what a firewall does, can you see why you need it? An anti-virus tool can only set behind that firewall. It waits to see if anything does get through that is not allowed and then it takes care of it. Without a firewall, all information will get in. There is no wall. There is no deflection. It doesn't take me long to describe this to my friends and family that ask why they really need a firewall. Without it, your computer will let everything in. Do you want that? I don't think so!
I'm not going to go into detail about what kind of firewall you should get because chances are if you have an anti-virus software, you might just have that firewall. Most firewalls now a days come bundled with an anti-virus software. Check the case that you got your anti-virus software in and see. If it does not, then I do advise to buy one preferably from the same manufacturer of your anti-virus software. Just go to their site and find a way to get it because you need it.
If you want more information on firewalls and to get an idea of what product to pick up, you can go to think I provide here: http://personal-firewall-software-review.toptenreviews.com/. This is packed with more information and an interactive graph that will allow you to choose what ratings you want to see. Just click on the Firewall Performance link. Check it out and get that firewall!
References
Smart PC Support (2012). Image borrowed from their site @ http://www.smartpcsupport.net/firewall.html
Whitman M. & Mattord, H. (2010). Management of Information Security. Boston, MA: Course Technology, Cengage Learning.
Wednesday, July 18, 2012
Risk Control!
Last week, my blog spoke on identify and assessing risks that you have on your computer. Hopefully, you have gone through and done just that. Now is the time to control those risks. You can do this by one of four strategies; avoidance, transference, mitigation, or acceptance. These four are in order on a proactive (taking care of a problem before it happens) stance for strongest security to weakest:
Avoidance is the strategy that uses safeguards to help eliminate or reduce your uncontrolled risks.
Transference is the strategy that allows you to shift risks to other areas.
Mitigation is the strategy that helps reduce impact if an attacker successfully exploits a vulnerability.
Acceptance is the strategy, well; it isn't even a strategy in my opinion because it is understanding the consequences of deciding not to control your vulnerabilities.
(Whitman & Mattord, 2010).
My honest opinion is to use the strategy of avoidance. Within this strategy, you apply some sort of policy. This helps control and manage procedures that everyone must follow. You also allow and apply education and training to all those involved with the security of your computer. Within this strategy, you counter your threats by using defense mechanisms such as your security controls and safeguards (Whitman & Mattord, 2010).
Transference and mitigation both come with risks. Transference allows you to take your problems and push them somewhere else. The main concern is outsourcing. Are you going to trust your risks in the hands of someone else? I sure won't. I plan to manage them myself. Mitigation just allows you to plan for issues through the use of specific plans such as an incident response or disaster recovery plan (Whitman & Mattord, 2010). I don't know about you, but I want to make sure those risks are taken care of now and not find out that a control did not work. Don't get me wrong, I am all for creating these plans, but you need to be proactive and reactive not just reactive.
If you decide to go with acceptance as your strategy, be forewarned that you will be susceptible to attacks. This is, in my opinion, a choice to do nothing in protection of your assets. If you chose to go this route, say hello to hackers such as Anonymous taking control of your system. You will be very easy to hack. I will be honest, I will not be sorry for anyone taking this route and then losing all their important data. Control your risks by implementing a secure strategy.
Reference
Whitman, M & Mattord, H. (2010). Management of Information Security. Boston, MA: Course Technology, Cengage Learning.
Avoidance is the strategy that uses safeguards to help eliminate or reduce your uncontrolled risks.
Transference is the strategy that allows you to shift risks to other areas.
Mitigation is the strategy that helps reduce impact if an attacker successfully exploits a vulnerability.
Acceptance is the strategy, well; it isn't even a strategy in my opinion because it is understanding the consequences of deciding not to control your vulnerabilities.
(Whitman & Mattord, 2010).
My honest opinion is to use the strategy of avoidance. Within this strategy, you apply some sort of policy. This helps control and manage procedures that everyone must follow. You also allow and apply education and training to all those involved with the security of your computer. Within this strategy, you counter your threats by using defense mechanisms such as your security controls and safeguards (Whitman & Mattord, 2010).
Transference and mitigation both come with risks. Transference allows you to take your problems and push them somewhere else. The main concern is outsourcing. Are you going to trust your risks in the hands of someone else? I sure won't. I plan to manage them myself. Mitigation just allows you to plan for issues through the use of specific plans such as an incident response or disaster recovery plan (Whitman & Mattord, 2010). I don't know about you, but I want to make sure those risks are taken care of now and not find out that a control did not work. Don't get me wrong, I am all for creating these plans, but you need to be proactive and reactive not just reactive.
If you decide to go with acceptance as your strategy, be forewarned that you will be susceptible to attacks. This is, in my opinion, a choice to do nothing in protection of your assets. If you chose to go this route, say hello to hackers such as Anonymous taking control of your system. You will be very easy to hack. I will be honest, I will not be sorry for anyone taking this route and then losing all their important data. Control your risks by implementing a secure strategy.
Reference
Whitman, M & Mattord, H. (2010). Management of Information Security. Boston, MA: Course Technology, Cengage Learning.
Tuesday, July 10, 2012
Identifying Risks!
I have hacked your system and I have all your information. I'm looking at your SSN, address, credit card numbers, and all other personal data. I'm laughing at that picture of you at what looks like a company party. Your system was just too easy to hack. Why did you allow me into your system? Did you not assess your data and realize that you had very personal and confidential data on your system? Of course, the preceding sentences are not true. I am just trying to get your attention. Did I? Good! Let's proceed.
I bet the majority of you reading this blog have some very important information and data stored on your computers. In fact, there is probably some very confidential data there as well. You don't want that data stolen do you? What you need to do is a Risk Identification. This is where you go through all your data stored on your computer and prioritize them based on their importance to you. Thing is, it is very tedious due to all the data on your computer, but it is absolutely necessary to help you identify any weaknesses with that data and the threats that are present that threaten that data (Whitman & Mattord, 2010).
First, look at all your data that is located on your computer. Don't start prioritizing the list, just jot down the data. You should have information jotted down such as your files, pictures, personal information among many other things. Now, look at the list and start classifying that data as either confidential (pretty much for your eyes only), sensitive (could harm you if the wrong person gets a hold of it but not quite confidential), and public (everyone can view this data). You should now have two columns with your data along with its classification. The last column you should make is the impact that data has on you. It can be critical (will harm you if in the wrong hands), high (potential to harm you still very high in the wrong hands), medium (not too harmful, but watch who you give it to), and low (shouldn't hurt you if put in anyone's hands). Examples follow:
Picture at company party - Sensitive - Medium
SSN - Confidential - Critical
I'm hoping that if you have your SSN on your computer you are treating it as a confidential and critical piece of information because if you are not, you are in for a rude awakening if you are hacked.
Now that you have an understanding of what you need to do, take the steps to help secure it. Go out and buy a security software that includes a firewall and anti-virus tool. Most of these tools will also come with an intrusion detection service; use it! If you are using a standard Microsoft office tool to save the data, use the encryption tool option within the save as method to help encrypt your data. Of course, there are other means of securing your data and this is a little tip. This blog was meant to give you the basics of assessing risks. Remember, a hacker can get into your system and gain all this information. Assess the data and the risks and help secure them.
References:
Whitman, M. & Mattord, H. (2010). Management of Information Security. Boston, MA: Course Technology, Cengage Learning.
I bet the majority of you reading this blog have some very important information and data stored on your computers. In fact, there is probably some very confidential data there as well. You don't want that data stolen do you? What you need to do is a Risk Identification. This is where you go through all your data stored on your computer and prioritize them based on their importance to you. Thing is, it is very tedious due to all the data on your computer, but it is absolutely necessary to help you identify any weaknesses with that data and the threats that are present that threaten that data (Whitman & Mattord, 2010).
First, look at all your data that is located on your computer. Don't start prioritizing the list, just jot down the data. You should have information jotted down such as your files, pictures, personal information among many other things. Now, look at the list and start classifying that data as either confidential (pretty much for your eyes only), sensitive (could harm you if the wrong person gets a hold of it but not quite confidential), and public (everyone can view this data). You should now have two columns with your data along with its classification. The last column you should make is the impact that data has on you. It can be critical (will harm you if in the wrong hands), high (potential to harm you still very high in the wrong hands), medium (not too harmful, but watch who you give it to), and low (shouldn't hurt you if put in anyone's hands). Examples follow:
Picture at company party - Sensitive - Medium
SSN - Confidential - Critical
I'm hoping that if you have your SSN on your computer you are treating it as a confidential and critical piece of information because if you are not, you are in for a rude awakening if you are hacked.
Now that you have an understanding of what you need to do, take the steps to help secure it. Go out and buy a security software that includes a firewall and anti-virus tool. Most of these tools will also come with an intrusion detection service; use it! If you are using a standard Microsoft office tool to save the data, use the encryption tool option within the save as method to help encrypt your data. Of course, there are other means of securing your data and this is a little tip. This blog was meant to give you the basics of assessing risks. Remember, a hacker can get into your system and gain all this information. Assess the data and the risks and help secure them.
References:
Whitman, M. & Mattord, H. (2010). Management of Information Security. Boston, MA: Course Technology, Cengage Learning.
Subscribe to:
Posts (Atom)
