CLICK HERE: Hacking Prevention
Submitted by leiron_2005 on September 10th, 2013 – Flag this news as inappropriate
Category: Cool
All companies are now using computer to improve and make their operation faster. Most of the company is hiring experts in maintaining and protecting their system from intruder and hacker. Administrators also need to take the lead in building different processes to lessen the successful attack and preventing damage from the system. Some organizations already have some protection process in place in the company and all they need to do is make it consistent. These are some things that the company should work on.
1. Knows the digital assets of the company and how do you protect it.
-It’s not only by hiring security guard’s to protect the digital assets of the company; it is also by making those digital assets unobvious. The administrator should make an inventory of the data and systems, and how it is valuable to the company. The review the people, processes and technologies that handles those assets including company partners and suppliers. Make a conceptual design on how to protect all the assets and who is responsible for protecting them.
2. Define the policies of the company
-The Administrators should explain to employees about the policies of an organization. The employees must understand what should and shouldn’t to during the processes of the system. Security policy will be hopeless if users, partners ignore it, it’s important for the company to explain its rationale for the limitations on computer usage.
3. Secure the software
-The company must demand reasonable levels of security from software vendors.
4. Identify what software is running
-Some of the companies don’t follow this rule. This is not on easy part. Some software configurations change all the time. Maybe a program isn’t running correctly or some customer demands a change, or a software vendor releases an updates. But whatever the reasons it best to document all the modification. This will serves as evidence to when and where the hacker struck.
5. Test and benchmark
-Many companies hire security professionals to penetrate their system to identify the weaknesses of their system and suggest improvements and help you decide what are the tools and protection to buy and implement.
6. Implement Root/Cause Analysis
-if security is found, they should conduct the root/cause analysis. They should implement the PDCA( Plan Do Act and Check cycles.
• Why didn't the firewall stop the unauthorized entry? Because the attacker had an authorized password.
• Why did the attacker have an authorized password? Because an employee revealed his password to someone posing as another company employee.
• Why did the employee reveal his password? Because he didn't realize the danger in doing that.
• Why didn't the employee realize the danger? Because he had not seen a security bulletin that addressed the subject.
• Why hadn't the employee seen the security bulletin? Because there was a problem in the distribution process.
No comments:
Post a Comment