Earthweb
Images Events Jobs Premium Services Media Kit Network Map E-mail Offers Vendor Solutions Webcasts
 SUBJECTS:
 FEATURES:
IT Management Webcasts:
The Role of Security in IT Service Management

Preparing for an IT Audit

More Webcasts


Search EarthWeb Network

internet.commerce
Be a Commerce Partner
GPS Devices
KVM Switch over IP
Holiday Gift Ideas
Imprinted Promotions
Promos and Premiums
PDA Phones & Cases
Car Donations
Online Universities
Online Education
Condos For Sale
Compare Prices
Rackmount LCD Monitor
KVM Switches
Shop

Linked Data Planet Conference & Expo

IT Management : Security: Teaching Employees New Security Tricks

Install What You Need with Windows Server 2008
Windows Server 2008 is Microsoft's most full-featured server operating system yet, so it's ironic that one of its most exciting new features is an install option that cuts out most of the other features. Paul Rubens explores why a Server Core installation makes a great deal of sense in many instances. »

 
Identify Hardware and Software That Meet Microsoft Standards
The "Certified for Windows. Server 2008" logo identifies hardware and software solutions that meet Microsoft standards for compatibility and best practices with the Windows Server 2008 operating system. »

 
Windows Server Catalog: Certified Hardware Devices
Search the Windows Server 2008 catalog to find solutions to deploy with confidence. »

 
Windows Server Catalog: Certfied Servers
Search the Windows Server 2008 catalog to find servers you can deploy with confidence. »

 
Download the Windows Server 2008 Trial
With Windows Server 2008 you can develop, deliver, and manage rich user experiences and applications, provide a secure network infrastructure, and increase technological efficiency and value within your organization. »

Related Articles
A Better Way to Deal With Vulnerabilities
Instant Messaging Can Usher in Instant Problems
Nothing is Secret with Spyware Lurking in PCs
College Hacking Course Kindles Fiery Debate
Survey: Workers Say It's Easy to Steal Data
- ITSMWatch Newsletter -
Tech Focus: Security

Cybersecurity: Laws Only Go So Far

Mozilla Firefox vs. Internet Explorer: Which is Safer?

Is Your Blog Leaking Trade Secrets?

The Las Vegas Counterfeiting Story: Is Your Privacy Worth More Than a Poker Chip?

Stopping Spammers at The Point of Sale

Product Watch
IOGEAR KVM - Includes Audio/Peripheral Sharing
Coverity Prevent / Coverity Thread Analyzer - Analyze Source Code For Defects, Security Vulnerabilities
USSD Series - SDRAM-Based Solid State Drives to 256 GB
UltraSMS - Send SMS From Your PC
Sentinel Sensors - Wi-Fi Based Temperature Monitoring Especially For Cold Storage

more products >>

Datamation Definitions
data mining
ERP
extranet
grid computing
intranet
network appliance
outsourcing
storage
VPN
virus
FREE Tech Newsletters

Tips for Operating System Deployments. Listen to an audio cast about operating system deployment.

Teaching Employees New Security Tricks
July 15, 2003
By Sharon Gaudin

To help fend off spam, viruses, identity theft and corporate sabotage, IT managers need to train company employees to protect themselves and the corporate network.

The problem is that is simply isn't happening.

Budget cuts and staffing shortages are making it difficult for IT managers to focus on anything beyond putting out daily fires and staying current with software updates, patches and security alerts. It's no wonder, say industry analysts, that there's no time to hold training sessions to teach people in finance, marketing and human resources to not fall prey to identity theft or the latest virus.

But the lack of training is causing those same IT managers even more headaches and even longer hours in the office.

''It's critical that IT managers focus on education, despite the constant pressure,'' says Chris Belthoff, a senior security analyst with Sophos, Inc., an anti-virus software company based in Lynnfield, Mass. ''Training, in the end, is going to benefit their department. Educated end users will reduce the amount of issues and fires they have to put out.''

Those daily fires are definitely torching any ideas of IT managers having enough time to hold training sessions, or even simply send out email alerts when new viruses or hoaxes rear their ugly heads.

An estimated 90 percent of IT managers reported in a recent survey that they provide no employee training on how to manage spam and junk mail, according to a report from SurfControl Plc, a Web and email filtering company with a U.S. base in Scotts Valley, Calif. And the report shows that they're forgoing training despite the fact that many employees may be dealing with more than 1,500 pieces of junk email each year -- and that's just from people they know.

''It's not just up to the IT people to keep the network secure anymore,'' says Susan Larson, vice president of global product content at SurfControl. ''This is a dynamic process of keeping employees aware... Several years ago, Internet use policies were not even in place. Now, 75 percent of companies have policies. But now they feel they can hand out the policies and that's enough.

''If employees don't understand how they can help, they become part of the problem,'' adds Larson. ''Employees are ultimately critical. It's not just 'my mailbox'. Multiply that by 10,000 users. Obviously, they shouldn't be answering spam. They shouldn't be using Outlook's Preview page because that sends tracking information back. There's a lot to it.''

And Dan Woolley, a vice president at network security company SilentRunner, says employees are a huge part of the problem. Workers use their corporate systems to shop online, fill out surveys and generally do things that spread their work email address around to be scooped up and used by spammers. They also are still being fooled by email chain letters promising them riches and airplane tickets if they forward the email on to 10 of their most gullible friends. They're still clicking on attachments infested with viruses and they're still sending out inappropriate email jokes and IMing with their mothers.

''We just don't do a good job of telling people how to avoid risks,'' says Woolley. ''They arrive at a new job. We hand them a system and expect them to know how to use it... Challenge them to think about these risks before you turn them loose in the office.''

Woolley says basic training needs to start with teaching people how to recognize spam, fraud and hoaxes. Then, he says, teach them about viruses, worms and Trojans. When employees hear these terms, what do they mean? What should they be alert for? What should they do when they think they've encountered one?

Social engineering is the next thing workers need to learn about. Someone intent on stealing corporate information is often quick to make employees unwitting accomplices. People need to know that they shouldn't leave their passwords written on Post-It notes stuck to their monitors. They should never give user names or passwords over the telephone. They shouldn't talk about network critical information when they're in the parking lot or smoking area.

''We need to talk about security on a routine basis,'' says Woolley. ''It needs to be a top priority for every corporation and it needs to come from the top down. People need to see that the CEO and CFO are concerned about it.''

Tony Magallanez, a systems engineer at F-Secure, Inc., a data security and anti-virus company, says training can't be a one-time proposition. He says security awareness needs to be part of new employee orientation and then training sessions for all employees should be held periodically. Add to that, email alerts to end users, keeping them updated about the threat of new viruses, spam tactics and hoaxes.

Larson adds that end users need to understand about tracking methods. When they click on an ad, it could have sophisticated tracking mechanisms that will add to the amount of spam coming in. She also notes that employees need to know that they shouldn't be shopping online with company equipment because company account information could be harvested.

''Every company should be working this into their schedule as best they can,'' says Larson. ''Make employees understand they are a valuable part of the solution. You need to get them invested in protecting the network.''

Tools:
Add itmanagement.earthweb.com to your favorites
Add itmanagement.earthweb.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

Security Archives



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: HyperV-The Killer Feature in WinServer ‘08
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Win Server ‘08
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES