Skip the navigation
Opinion

Condition Orange: What to do now to secure your systems

By Peter H. Gregory
March 18, 2003 12:00 PM ET

Computerworld - On the Internet, national sovereignty knows no boundaries. Our storefronts, factories, government offices and military installations have rolled out the virtual welcome mat, inviting passers-by to come in and wander around their Web sites.
But many site operators have figured out that during times of international conflict, hackers come out of the woodwork and try to deface and/or sabotage prominent U.S. Web sites. Most often targeted are sites in the .gov and .mil domains and the best-known private-sector companies. However, many hackers scan virtually every site looking for easily exploited vulnerabilities.

Anyone needing historical examples needs to go back only to 2001 during the Hainan Island spy plane incident where a midair collision between a Chinese fighter jet and a U.S. intelligence-gathering aircraft forced the U.S. plane to make an emergency landing on Chinese soil (see story). The frequency of hacking attempts originating from China to U.S. Web sites skyrocketed during and after the incident.


As I write this, diplomacy between the U.S., the UN and Iraq is drawing to a close. If there was ever a time when we could expect hacking attacks to increase, this is it. Hacking attacks on Web sites associated with the U.S. and its allies are going to spike. You can take this opinion to the bank.


Prudence and caution


In my estimation, we're in for some rough weather. I'm not suggesting that you board up your virtual windows and leave town as though a Category 5 hurricane were approaching. Rather, there are steps you can take to reduce the risk of trouble should a hacker decide to spend time rattling your doorknobs and locks.












Peter H. Gergory




The tasks below are intentionally designed to be of minimum impact to most organizations. At this late hour, it probably doesn't make sense for most organizations to drop everything and circle the wagons. Most senior managers probably wouldn't support a mass mobilization anyway.


Set up SWAT teams


Assemble two small teams (in your organization, this might be only one or two people each), one to examine the corporate firewall, the other to inspect public-facing servers.


The firewall team should carefully examine the rule sets that govern access from the outside world to select servers and networks. If you can, print out the rule set and examine it line by line. Logically divide access rules into two or three categories: rules that are absolutely essential to company operations and one or two levels of lesser importance. For instance, you may have rules associated with vendor access to systems that they need for support now and then. If you find rules that you know are obsolete or whose purpose is unknown, consider turning those off immediately.




Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs