ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

The five reasons you're not secure

John McCormick

Published: 05 Apr 2005 10:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

2. Ignoring new vulnerabilities
Second on my list of the worst security mistakes is failing to take appropriate action when new vulnerabilities surface.

Most security managers receive automatic notification of new patches and/or monitor at least one security Web site. A significant number even subscribe to security-related newsletters which attempt to filter out the noise and focus on serious problems.

But there is simply so much information available that many people don't even bother to read the alerts they subscribe to. A far smaller number actually adjust policy or perform updates to fix the problems they do learn about.

3. Relying too much on technology
Another big mistake is relying excessively on technological fixes and paying too little attention to actually using them.

For example, if you tell upper management that you've installed the top antivirus software or the latest star in the firewall world, they'll think you've done your job. But unless you've carefully configured that firewall and maintained the antivirus software, you really haven't done much of anything.

Setting up a firewall properly in some environments can be as much art as science. It isn't a set-it-and-forget-it task any more than installing antivirus software ends all your malware worries. Instead, you have to keep tweaking the firewall to meet new needs, sometimes even blocking some ports for a few weeks after a new port scanning epidemic surfaces.

And that goes back to the second biggest mistake — you have to pay attention to new security updates and vulnerabilities as they emerge. For example, to keep track of the top 10 ports that would-be attackers are targeting, bookmark this SANS Web page. For antivirus programs, you not only need to update signature files; you must also monitor the need for patches to fix newly disclosed vulnerabilities in the antivirus software itself.

Anti-spyware software is much less complex than antivirus programs, so patches are seldom necessary. However, they require as much attention to downloading the latest database information as do antivirus programs.

Finally, don't forget that all these security utilities become worthless if you ignore the reports they generate.

4. Failing to thoroughly investigate job candidates
The fourth biggest mistake is failing to properly screen job candidates for criminal records or even poor financial decisions, particularly for candidates outside of the IT department.

In America recently, it has been questioned whether it's reasonable to use a person's financial history as a tool in deciding if he or she would make a dependable employee.

Many readers questioned this practice despite the fact that companies have widely employed it for two simple reasons. First of all, if people are careless with their own finances, how well will they protect yours? Second, if someone's under financial pressure, he or she is more subject to outside pressures to indulge in activities that compromise security.

Whether it's due to poor planning, poor impulse control, or simple carelessness, a recent bankruptcy in someone's financial history is always a big red flag unless there's a very good explanation. It may be sad, it may be unfortunate, but it's a common practice because it works.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
157 out of 330 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

1 comment

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment