Showing posts with label computer security policy. Show all posts
Showing posts with label computer security policy. Show all posts

Thursday, June 11, 2009

Corporate data security: You’re gonna need more than a policy

An alarming number of employees are ignoring data security policies and are routinely engaging in activities that could put their employer at risk, according to a survey released by Ponemon Institute Wednesday.

According to survey results, the most frequent data security offenses were employees copying secure data to USB drives, turning off security settings in mobile devices like laptops and sharing passwords. All offenses that have the potential to put a company’s data at risk.

Of the 967 IT professionals surveyed, around 69% said they copied confidential company data to USB sticks, even though they knew it was against the rules. Still worse, some employees admit that they lost USB sticks housing company data, but failed to report it immediately.

Another disturbing trend is the amount of workers engaging in online activities that raise the risk of infecting company computers with malicious software.

About 31% of respondents engaged in social-networking practices on the Web from work PCs and around 53% said they downloaded personal software on company PCs, increasing the risk of spreading malware in the workplace, according to the research.

“Mobile technologies that let employees do more while on the road are contributing to the issue, said Larry Ponemon, chairman and founder of Ponemon Institute, in a blog entry. As the use of mobile devices grows, the inability to enforce data security policies could increase the possibility of data breaches. "I’m seeing a confluence of conditions that appear to be contributing to this challenge to data integrity," he said.


Over half (58%) of the IT professionals surveyed put the blame on companies for failing to provide employees with adequate data security awareness and training. About 57% also said their company’s data protection policies were ineffective and 43% said there was poor communication and enforcement of data security policies.

“The Ponemon Institute believes these results show overall lack of urgency by companies on the need to address data security. Unfortunately, our studies have also shown that it often takes a data breach incident before an organization will finally get their wake-up call and take data security seriously.” (Dr. Ponemon’s blog)


Like the survey results showed, it’s going to take more than just a policy to ensure that your company’s data is secure and protected. Read some of these past posts for more information on not only setting up a data security policy, but also training employees on how to keep your company safe:

Employee anti-phishing training, one scam at a time


Six tips for setting up a computer security policy


Employee security training: Spam 101

Employee security training: How to catch ‘phish’

Disgruntled Chrysler employee fired after Internet post

Thursday, April 16, 2009

Domino’s employee video goes viral, is poor training to blame?

When you order a pizza you generally trust that none of the toppings have landed in someone’s nose before they made it on your pizza. Right?

Sadly, there’s a new viral video sweeping the Internet that has seriously damaged customers’ trust in one of the country’s most popular pizza chains and two employees are to blame.

A couple of Domino’s employees are now unemployed and facing felony charges after posting videos of themselves defacing food while preparing it for delivery. The videos show an employee breaking various health-code standards including sticking cheese up his nose, putting nasal mucus on sandwiches and passing gas on salami before it made it onto a sandwich.

“We got blindsided by two idiots with a video camera and an awful idea,” said a Domino’s spokesman, Tim McIntyre, who added that the company was preparing a civil lawsuit. “Even people who’ve been with us as loyal customers for 10, 15, 20 years, people are second-guessing their relationship with Domino’s, and that’s not fair.” (New York Times)


Company President Patrick Doyle has posted a YouTube video of his own apologizing for the unacceptable behavior of these two infamous employees and asks that customers continue their support, despite the embarrassment it has brought to the company.

"You can be the safest driver, you know," McIntyre said. "But there's going to be that Friday night someone's drunk and comes from out of nowhere. You can do the best you can, but there's going to be the equivalent of that drunk driver that hits the innocent victim." (Advertising Age)


You hope that most employees would have enough common sense to refrain from illegal activity at work, let alone film it and post it on YouTube, but some may need a reminder from time to time.

A great way to remind employees how to act online when representing the company is through regular training. After you’ve developed a sound social media policy (read our guidelines for social media use), it’s time to explain the policy and consequences for not following that policy to employees.

How formal or informal your employee social media use training will vary depending on the nature of your business, but should give employees a clear understanding of what is considered acceptable online behavior when representing the company.

There’s no doubt that your policies and social media guidelines will change as new technologies and social networking tools emerge, so it’s best to provide training on an on-going basis.

The best way to defend your company against an unfortunate situation like what Domino’s is going through right now is through preparation. It’s impossible to control what employees will say about you online, but with clear policies, employee training and the proper planning, you’ll be in a much better place to handle any issue.

Do you think poor training could have played a role in Domino’s current dilemma? Does your organization train employees on how to represent the company online?

Monday, February 9, 2009

Six tips for setting up a computer security policy

We talked last week about the lengths some organizations will go to train employees to avoid phishing scams. Before you start sending test scams to everyone in your network, you should have the right computer safety policy in place for employees to follow.

In a recent Business Week tip, security evangelist Ryan Naraine shared some helpful information on setting up computer security policies. The information came out of a conversation with a friend who was in the process of establishing an online printing business and looking for ways to keep his business safe from online intruders.

“The nature of Web-based threats, drive-by malware downloads, and clever social engineering attacks make it nearly impossible to be fully secure,” wrote Naraine.


After acknowledging that fact, there are six “must-do” tasks that can help strengthen your defense:

  1. Invest in security software and make sure signature databases are current. When you’re exploring security options, ask the vendor about approaches to “whitelisting” (application control), “behavior blocking,” and the use of “herd-intelligence.”
  2. Stay on top of the latest patches for Web server and desktop software programs. Set limitations as to what employees are installing on their computers and avoid programs that lack auto-update mechanisms. Keep an eye on patching known vulnerabilities in applications that are constant hacker targets, including applications like Adobe PDF, Adobe Flash Player, Apple QuickTime, RealPlayer and WinZip.
  3. Make it a policy for employees to use the safest Web browser for certain sensitive transactions. Avoid using Microsoft’s Internet Explorer for high-value transactions since it is a popular target for hackers.
  4. Establish strong password policies. A strong password should be between 8 and 20 characters, have a mix of upper- and lower-case letters, numbers and symbols. The longer and more complex a password is, the harder it is to crack.
  5. Block access to unnecessary network services and social networking sites. Hackers prey on the trusted nature of sites like Facebook and MySpace to trick users into installing malware on their computers. If an employee doesn’t require Internet access to do their job, don’t give it to them.
  6. Have a system in place to deal with accounts of former employees. Make sure that e-mail accounts and access to sensitive parts of the network are shut off as soon as they lave the company.

Remember that your first line of defense against an online attack is your employees. Employees who are trained on the threats of online dangers are your best asset.

Keep employees trained on the latest online threats and give them the necessary tools to protect their computers and you’ll be taking two big steps to improving the security of your company. Ensure your network remains safe by periodically retraining employees to keep up with hakers’ evolving tactics.

Brought to you by www.gneil.com