ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Scaling your security strategy

Deb Shinder

Published: 11 Aug 2005 13:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The foundation of any computer or network security strategy is access control — providing those who should have it with access to resources on the network and keeping everyone else out. The basis of controlling access is to be able to verify the identities of those authorised users; otherwise any intruder can pretend to be chief executive John Smith or Mary Jones in accounting, and sign onto the network.

The simplest way of authenticating network users is to require that they enter a unique password tied to their user accounts. Theoretically, each user is the only person who knows his/her password so if the correct password is given, the user's identity is proven.

Password authentication is the method used by most small businesses. It's easy and cheap and built into the operating system. You don't have to buy anything extra to implement it. And it works — most of the time.

Most of the time is enough for many small companies with low security needs. If you don't have any important trade secrets, confidential client information (such as credit card numbers or credit histories), sensitive employee information (such as medical histories or social security numbers), etc. on the network, you might not need to spend money on a more secure authentication method.

Organisational growth increases security needs
The problem is that as companies grow, their security needs often increase. More and more of your business records are digitised; you get government contracts or move into regulated fields such as health care, financial services, etc. You incorporate and become subject to a whole new level of regulatory requirements, privacy protections, and so forth. Your organisation's profile becomes higher, so you become more of a target for hackers and attackers who had no interest in your network before. The company spreads out geographically and hires more personnel, and implements remote access solutions to allow employees to connect from home or on the road, so that it becomes easier for a stranger to blend in and penetrate the network.

At this point, you've probably begun to think about network security. You may invest in expensive firewalls and intrusion detection systems to thwart attacks. However, it doesn't take a genius hacker with top skills to get into your network. Many intruders do so not by writing exploit code but by using social engineering (people skills) to find out legitimate user names and passwords.

A technical solution for a social problem
Con men (and women) have been with us since the beginning of civilised society. Social engineering is not a technical problem — the software is working exactly as it's supposed to, allowing access only after identity has been verified with the correct password. It's a people problem: people can be intimidated, charmed, or tricked into revealing their passwords, either directly or indirectly. Education can help reduce instances of social engineering, but as long as human nature remains the same, some folks will always be vulnerable to it. There is, however, a technical solution.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
110 out of 236 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Test Consultant

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Data Governance Architect

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Financial Services - Finance Transformation Consultant

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments