March 9, 2004 (Computerworld) --
"The risk of cyber attacks continues to be high. Even organizations that have deployed a wide range of security technologies fall victim to significant losses. ... The percentage of incidents that are reported to law enforcement agencies remains low ... Attackers may reasonably infer that the odds against their being caught and prosecuted remain strongly in their favor." -- Computer Security Institute/FBI 2003 Computer Crime and Security Survey
In the hit parade of security technology buzzwords, antivirus and intrusion-detection systems are in the top five. After all, there are a lot of bad guys out there writing worms and trying to break in. Stop for a second and ask yourself a question. Is intrusion your key threat just because that's what the IT vendors are selling? You know the joke about the cement factory in Poland. Every day, a worker leaves the factory at closing time with a wheelbarrow of sand. After a month of this, the guard finally says to the worker, "I know you're stealing something; I just can't figure out what the heck it is." The worker replies, "I'm stealing wheelbarrows." That's extrusion: unauthorized transfer of your assets in broad daylight. The sources of insider theft Let's examine the sources of digital asset extrusion: trusted insiders, human error and criminals. Trusted insiders are your employees, your suppliers and your customers. Employees may be the software development group that was axed or the sales representative who skims credit card transactions. Suppliers may be the courier who flirts with the receptionist or the night security guard who copies sensitive documents. Outsourcing contractors are also threats. In the quest for operational efficiency, our industry outsources IT functions, but oddly, some banks and insurance companies outsource their information security functions even though their business is the most information-intensive industry on the planet. What about human error? One extra click in Outlook, and a casual friend is on the distribution list together with the board members in the middle of due diligence. Customers may not be direct threats, but many business-to-consumer Web sites are vulnerable to credit card theft by organized crime. Tens of thousands of stolen credit card numbers are offered for sale each week on the Web. This black market e-business, where credit card prices fluctuate with supply and demand, costs the financial system more than $1 billion a year and shows how easily personal information is being stolen and traded. People do it because of anger and greed. Emotions are a powerful motivator, and anger at being terminated will cause a person to act quickly and irrationally. A supplier trying to collect money may view extrusion of digital assets
"Welcome to a special IT Blogwatch EXTRA: as Richi Jennings watches bloggers' reactions to the Russian hackers who claim to..."
Read more...
"As if taxpayers needed another reason to scorn the IRS. I read yesterday that the inspector general review of several..."
Read more... Read more Security posts or See all Blogs
One positive development stemming from the collapse of Wall Street may be a boost in interest in computer science and IT careers among students who were previously interested in financial services jobs.
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center Register for this complimentary webcast today! Go to the webcast
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs. (Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more. Download this executive briefing
Quick Sizing Guide for SAS Grid Running on HP BladeSystems and EVA Storage
Download this white paper today! (Source: HP) Designed for CIOs, IT managers, data center managers and grid computing architects seeking to improve performance, SAS Grid Computing on the HP BladeSystem c-Class helps accelerate growth and mitigate risks with a simplified, consolidated infrastructure that's agile enough to efficiently handle change. SAS Grid Manager on HP BladeSystem can lower costs through automation, virtualization and improved IT efficiency. Download this white paper
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Securing your network begins at the gateway, also called the perimeter, to keep unauthorized users, viruses and malicious code from entering your systems. Deploying multilayer technologies is your first line of defense. With the mobility of employees and the ease with which external devices can be brought in and out of a network, continuing to build your security plan for network servers and clients is a must. Fortunately, there is much that organizations can do to protect themselves from attacks - internal and external. One of the key facets of a successful security strategy is protecting the servers that run critical applications and house so much of your essential data. Having the right policies, procedures and server configurations is critical.
Fired up about IT?Join Sharkbait and share your true tales of IT. SharkBait is the place for you to sound off about everything IT the good, the bad, and the rest of the weird stuff you deal with every day.
Companies today are realizing that competitive advantage is harder to sustain when based solely on gains in productivity and cost efficiency. The focus is shifting to invest more in business optimization initiatives which rely on trusted information to develop new insights that deliver better business results. But how can this be done efficiently in a business environment across multiple applications and processes. The answer is an Information Agenda - an innovative approach to transforming business information into a strategic asset for competitive advantage.
Preston Gralla: Apple plays the bully again
Apple is once again unleashing its attack dog lawyers. This time against a college for using an apple in its logo. ... [more]