Home arrow Knowledgebase arrow McKinney Way arrow The Weakest Link: Part 2 - Fighting Back
The Weakest Link: Part 2 - Fighting Back Print

 

ImageBy Rodney J. Johnson

President, Prescient Consulting, Inc.

Companies and other organizations don't have to just sit back and hope an attack won't succeed against them. They can take matters into their own hands - they can fight back. Fighting back is not something an organization can do in one day and then forget about. Fighting back means making training and a 'secure computing' mindset a part of the regular process of getting business done.

More than just getting the right tools in the door, the people component of IT security can't be an afterthought. In reality, people are the first and last lines of defense against attacks, and the element, that if unreliable, will cause the greatest damage. All parts of security are linked and inseparable. One area's weakness causes a ripple effect that causes security weaknesses in other areas. Training, physical security, and diligence are the tools of the counter fighter's trade.

Setting the right Environment - Security Policy
Creating and implementing a security policy to deal with IT security problems of all types - people and technical, has the benefit getting everyone thinking about the issues. It also brings up training, meaning everyone will get involved and at least realize that there is something to be aware of besides having the virus checker up to date.

The other main issue with security policies is in ensuring that the tough decisions are not left in the hands of those unqualified or unwilling to make them. Personnel on duty should never have to wonder if they are doing the right thing. They should know what the 'right answers' are when questions come up concerning sharing information like passwords, allowing physical and electronic access to systems, and setting up and maintaining their own machines. They should know that the right answer is usually no.

Think Like a Hacker
Training of personnel is the main weapon in fighting back against would be attackers. Untrained personnel can't defend themselves against what they don't know is coming. A little awareness of how an attacker goes about their mission does wonders for the abilities of an organization to keep their information private.

Information systems attackers are no different than any other trespasser. They are always looking for a door in - preferably the easiest one. The easiest door is the one that is unlocked. If all the doors are locked the next easiest one is the door with the key hidden under the mat sitting in front of it. To an attacker, a key is information and almost any information can be a starting point. If I want to do damage to you through your IT systems, I need to gather as much information about you as I can - that's where I'm going to start. I'm going to start by looking for information. I can find information a lot more easily by testing your non-IT security than by testing your IT security.

The fact is, an organization can't have good IT security without good physical security. Physical security is as much a part of IT security as any software or hardware. A would be attacker can gather the information necessary to initiate an attack through physical means like walking around the office, going through trash, or overhearing a conversation in the lunch room. Things as small as names, titles, and desk locations, when put together can be enough information to make a convincing phone call that leads to more and better information. Always escort visitors through the office. Always dispose of trash in a safe way. Just because the trash doesn't include any direct company secrets doesn't mean it doesn't include sensitive material.

To Hear is To Forget. To See is To Remember. To Do is To Understand.
As with many people related issues in organizations, the solution is training. Training first to learn, second to remember, and third to execute without thinking. Everyone must be trained, not just those named to protect information. Everyone must realize why information must be protected, and what information to protect. Leaving the issue to common sense is a recipe for disaster, as common sense doesn't have a lot to say about whether I should share my password with tech support supposedly calling from the floor below me. Asking an organization's people to protect themselves against trained and determined attackers without any help or guidance is ask too much. People need to be trained, and a security policy that creates the right atmosphere for secure business execution needs to be put in place. When these things are done, the weakest link is made strong.

 
< Prev   Next >
Copyright 2006-2008, McKinney Consulting, Inc.
#821 Gwanghwamun Officia Bldg., 163 Shinmunno 1-Ga, Jongno-Gu, Seoul, 110-999, Korea
TEL: +82.2.725.3830, FAX: +82.2.725.3802, EMAIL: business@mckinneyconsulting.com
80rfskihhr6alapha blueblood bulldog effects of mixing risperdal with zoloft baby sitter masturbate 2006 jeep commander lean adjustable ecu aic imperial 500 000 guaranteed visitors bon voyage anything goes adjustment disorder with mixed emotional features 2002 plush cherrished teddies chilis kendall drive antenna cell flashing motorola phone v180 20 person rotating schedule 4x4 evolution requirements 1962 vw front end 2.24 sacred trainer underworld 175 s range colby ks 67701 difficult airway management emt acrylic binding vs satin cooks baking supply west allis animated gifs chicken hen rooster asymetrical hair cuts for women 2007 fleetwood discovery motorhome 4-ingredient diabetic cookbook alternate deposit methods online casinos 10 code police across body handbags boise home inspector charmed chris wyatt fanfiction 110 card stock pin feed easy layered biscuit recipes beauty college wausau wi a pizza stayton or 50 carmel glaze loreal andrea collier king website 1796 light cavalry sword deaf dominatrix madtv apple pigeon forge tn 1-888 meditub 633-4882 address 0x800c0019 error and fix 1994 lexus es300 blown motor .223 green tip captain robert holt usn retired banker beacon coldwell realty bulgarian translations agarose base pair range 4 mm cyst in breast aero grow garden kit aeg american express bon jovi presale blogathon blogging for a cure caps and home infusion 2007 derby post positions archies clyde did it braes of fife actors agents ireland circumcision and cervical cancer car insurance hagerstown md coffee banana peanut butter smoothie bolens mtd cultivator a to z hobbies model rockets arranging fractions least to greatest 09 this love mp3 7324 sw freeway houston texas black emo backround bendix tru flo 550 aimer arena download jusqua limpossible tina bike and gary fischer and tarpon 400 n lake shore drive add stealing frisbee by the masters california pantry classic ceramic muggs ar10 grip od green cheapest airfars cheapest airfares oman a friend in need lyrics placebo 1300 am baltimore agriculture and education anti spy ware free cnet dbz quizes army recruiter polk county fl 10x10 pe gazebo biscayne bay abortion rights coalition of canada blueberry pie filling congealed salad andrus family travels adult superhero footed pajamas fixed income housing in hoboken nj bdsm street fairs amazon com cradle bedding bedding baby elvis presley frankie 1 kelsey road st pauls cray a scenic attraction in bankok afn podcast 12v com apct refrigerator rv airforce and marijuana ashtabula house pendleton sc 4 winds interactive doppler heartbeat ranges asia pacifics phuket aunty lou im gonna fuck activities for kindergarten children 2007 feng fax numbers bait launcher .22 commando tactical quad rail system 44 by nucleus poker powered remember biofeedback music hypertension 16x32 inground pool liner dennis banks longest walk 2008 1963 fairlane hobby toy betty winslow 400 drink machine vision aloha airlines flight 243 photo 1995 pontiac bonneville service brendan benson 8 bacillus subtilis race molecular weight bc glory engineered wood floor aphabet bingo absolute value and or statements aquifer information plains cala nova ibiza alvin and the chimpunks chirstmas sonf achromycin give with milk a blizzard bathroom remodeling hubbard tx actress kristin thomas 10t6 tv arthur morton eos russia fond brandon and marianne stories disney princess magical throne basement slab waterproofing are airbags dangerous 105 opal st walterboro sc bobs outdoor sportswear complete concordance to miscellaneous writings check air india partners arc 1701 family handyman magazine web site 07 avalanche water leak 3 recommendations avoid negligent hiring american dj dr dmx 15v dual power supply 2006 united states government employees ets springboard walkthroughs a1 tank nicknames body smash training flex chase durer typhoon 1980 s dude ranches california alyssa tower om blizzard 1917 1858 remington pistol birdie ashcraft niles michigan astrology reading tarot relationships accommodation dublin serviced amd 64 heat sinks dolce amp gabbana shoes adventure cheat four sword zelda 2006 care conference wound 105mm self propelled gun rca 121 flight plane snake crime stopper safety tips 761 ch des sources montreal qc 50 000 signature loan claude alexander dance 98 infinity 340 b drug pricing adding to my network places billow cremation services akron ohio act american diagram disability airedale breeders california dog in terrier barcode recognition systems for laptops be a man hulk 5 gallon quick dry cement captain scarlet and the mysterons army jag internship agricultural pollution due to pesticides 401k pasco county biomechanics relative phase analysis 8407 appalachian dr caloric stimulation for unilateral neglect 1960s pepsi logo 10 trends windows images tips top converting a drive to ntfs dragon quest monsters joker synthesizing guide all-american rejects ends tonight 50 largest colleges 1905 men nurse training 55 communities in kentucky aluminum compass charm 231233330 cell free nokia phone air tatum thong hacked by powerful analysis sir philip sidney sonnet 31 4 tier pineapple fountain corey aldridge 2 blue controller dualshock ps2 sony 206 shiloh station 62269 cape breton pork pies boris vallejo girl pics anchor resorts destin alojamiento en punta del este activites to do in madrid spain bahrain bars f1 2002 and 1977 ncaa championship game bleachers chapter summaries absenttee vote in jackson co missouri atrazine selectively toxicity weeds not corn claudia maurice green barry fruendel homosexuality 2006 3 month calendar free templates 6 round sofa leg set 2001 auto center arlington heights diana l fritz appleton wi trane granny is a hippie arts beats ans eats acute megakaryoblastic leukemia survivors aerobics for great legs boethius de musica afroman nobody knows your name 10 vent hood wall cap ada showers and supplies diversified arts chatsworth california box ea live sports x 22 mag banana clip 18 volt cordless drils 24 top load washing aircraft inventory systems adavantages nic accent pillow shapes dr zeus mp3 wma african adventures uninstall issue carbamazepine and minors bebo is blocked absence seizures and l taurine anet morales manila adjusted serum calcium level ctdirect magazine tomb editorial slippery slope 108th div it unit crest bollinger band squeeze amibroker agrizzi enterprises corp husqvarna 1 embroider cheap magazine subscriptions m ernie alderete 1000w amplifier audio circuit diagram fin inn grafton il 24 hour military clocks compatibility matches of signs 2009 ford gt 350 sr af chiefs 10meg free sex vids ames 202 dial indicator 1500 john f kennedy blvd alcoholism and gender genetics alpine cda 9853 eq access boardwalk chevrolet