Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Living with Zero-day Exploits | Main | Don't Reinvent the Wheel »

Its Time to Take User Awareness Seriously

A troubling article on recent security trends in by Marty Ijzerman in SAGE quoted a Harvard study that found most users did not detect carefully crafted phishing messages, close to one quarter ignored security warnings, and over half didn't pay attention to warnings about invalid digitial certificates. These rates should make anyone involved with security wonder just how effective their well planned, well executed measures will actually work.

What other poor practices are in play? Are users still writing down passwords, especially now that a strong password policy is in force at your site? How many scripts contain application or database passwords? Are applicaiton accounts shared among users? Pretexting worked at HP to get confidential information, will it work in your organization?

Security awareness training may be viewed as a "nice to have" by some when it comes to security but that is simply not true. Attackers will find the weakest link, whether it is technical or human, and those are the ones we need to address. Users need to be trained about social engineering techniques, careless securtiy practices they should avoid, and policies in place in an organization. There is no reason for someone getting a password over the phone by pretending to be a network admin or a service desk technician. User awareness training is a core element of defense in depth practices, not simply a "nice to have."

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/73

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net