Showing posts with label Employee Responsibility. Show all posts
Showing posts with label Employee Responsibility. Show all posts

Sunday, November 26, 2006

Who Is Deciding Your Information Security Policy?

If the answer to that question is that your management and your corporate security professionals are setting the standards, then you need to read no further. Have a great day, and check back soon for my next article. However, if you don’t know, or your answer is that you don’t implement in-depth security practices because your users find them too hard – in other words, your users are making your information security decisions - then read on.



First, let me say this: Implementing in-depth information security practices is hard work. In a large enterprise, it takes dedicated, trained staff, and even then your users will still find it cumbersome and inconvenient. Let me also say that most people expect things to be easy, they don’t want to be inconvenienced, and they want it when they want it, without being tied to having to wait for this, that, or the other, and without having to click on any more things than necessary. They don’t want to be bothered by their computer slowing down a little once a week while the scheduled virus scan runs. People don’t want to have to take the time to decide whether to answer “yes” or “no” when their personal firewall prompts them when it thinks something suspicious is happening on their computer. All too often, IT support staffs are saying that they don’t want to make their users do something because the user says it is inconvenient, they don’t know how to do it, and they just don’t want to have to take the extra time to learn how to do it. This is a classic example of how information security practices take a back seat to security unaware users who don’t want to make the effort to keep their company’s data safe. In other words, the end users (security unaware end users) are making the security decisions, like it or not.



Information security involves a variety of safeguards, all the way from perimeter devices guarding your network, right down to the user at the desktop. This is called “defense-in-depth,” the idea that if an attack or other malicious activity gets past one safeguard, at least one of the others will catch it and stop it. Your data is at the center of a bull’s eye surrounded by subsequently progressive outward rings. These protective rings are made up of the user, operating system patches, personal firewalls, anti-virus/anti-malware protection, server access control lists, and perimeter devices such as routers and firewalls. The user plays a very integral part in these defensive layers of information security. You can have all the firewalls, access control lists, anti-virus programs, and computer patches in the world, and still not be safe. Because if your users are willing to give away the keys to the kingdom, either through laziness, ignorance, complacency, or just plain arrogance, then nothing you can do will keep your data safe.



I have actually heard IT support people say that main the reasons why they don’t do certain things is because the procedures are too hard for their users, their users have no clue how to do these things, they have no clue why they are necessary, and that they (the IT people) don’t have time to train them. Back in my customer service days, I would listen to customers as they would go into rages about this stuff being too hard, and that they didn’t see why they had to do it. Let’s face it, people are busy, there aren’t enough hours in the day, and people often get set in their ways. Change represents a scary thing, even if it means learning a new way to keep data on a computer safe. A thing like locking a screen when the computer is going to be unattended is a habit that has to be learned and ingrained into behavior. Much of what this article is about is related to behavior and how to change that behavior. The technical part is easy. It’s changing people that is the real challenge.



Let’s take the first one mentioned above – too hard for the users. If something is too hard, it means that the user hasn’t been trained or is too lazy to learn – or both! I will repeat it again here: security is hard work. So that means that the IT support structure has to get on the ball and provide training and awareness for their users. Conversely, the end user has to get of his or her backside and realize that it is their responsibility to learn how to use the tools of their trade. The computer, after all, is a vital tool that is in use by the vast majority of people in the work force today. I don’t care if you are a doctor, lawyer, biologist, or just a clerk. The fact of the matter is that regardless of your primary specialty, you still have to use a computer to get your work done.



And I’m not even talking about people having to learn in-depth or complicated security principles. They simply have to learn what to click on, what not to click on, and when their personal firewall is telling them about a risky event. Is it really so hard, that if a user gets a message saying that some software is trying to be installed, for them to make a conscious decision that either “yes, it is OK because I am installing software” or “no, this is not OK because all I was doing was checking my email”? Make an educated decision, and click on the appropriate answer. This takes a few seconds at best – is that really taking too much precious time? If they wish to continue to do their jobs, computer users must learn how to operate them and how to interpret simple messages. It is not enough to know how to fire up Outlook and whip out an email, you must know how to interpret your environment and act accordingly.



On to the second idea previously mentioned – users have no clue. No, I’m not saying that people are all a bunch of clueless drones. Well – actually - yes I am. The average computer user doesn’t know much about computer security, and quite frankly, they don’t want to know. All they know is that they have to use the darn thing (the computer) and if anything goes wrong it isn’t their problem. It is IT’s problem to fix. If the computer lets sensitive information get away, then that is the computer’s problem, right? Wrong! The people in IT didn’t click on the malicious link in the email joke that they just received, and the IT staff didn’t leave the user’s computer unlocked when the user got up to go to a one hour lunch break. Not only is it just too hard to resist the temptation to click on that link, but it is also too hard to press the Windows key and the “L” key to lock the screen when they get up. And quite frankly, most people just don’t understand why it even matters. All that hype about computer security, malicious links in emails, and spies wandering the company looking for unlocked screens is just a bunch of rubbish, right? Wrong! The threats are very real and present. Users need to get a clue that they fit in to all this in a very important way. The why? That’s easy – the data they are working with is not theirs. It belongs to a company who can suffer embarrassment, loss of business, or loss of trade secrets of the information gets out. Companies can suffer from loss of business. Governments can suffer from the loss of sensitive information. In either case, it can be disastrous. Even if just a user at home – would the normal person want to risk having their personal and bank account information getting loose on the Internet? Certainly not! Care in computing must be exercised everywhere. The good security habits that one gets into will be useful at work and at home.



Hmmm… so finally, the last point - no time to train the users. All of the problems discussed up to this point can be boiled down to training. Not knowing how to do something or being clueless is not entirely the end user’s fault. Sure, the user has to get over their own laziness and arrogance, but they have to have knowledge to be able to act on it. But I have seen too many IT staffs who think they are protecting their users by not exposing them to complicated or extra tasks. Well – they are just making themselves feel good by trying to make their users like them and trust them. But sometimes good security practices involve a bit of “tough love” and forcing people to do things that seem hard at first. The IT staff can either make the choice to take the time to train their users, or take the time to clean up after their mistakes – it’s a clear choice in my mind. Take the time up front to train users, and keep them knowledgeable through constant awareness activities. Eventually, the training and awareness will sink in. By that time, your users will know what needs to be done (or what not to do) and they will now have a clue why this is all so important.



This may seem like one of my typical rants – you’re right – I’m busted. But how many more times do we have to hear in the news about breaches of corporate information security because of someone who lost a laptop or gave away information. You will notice that most of these events are due to someone doing something stupid – not being aware, not following directives and policies, or being just plain lazy. IT Staffs: train your users, keep barraging them with tid-bits of security awareness, and make them do the things that will keep your company’s data safe. End users: Get off your @$$ and learn why you are the most important link in information security. Security is everyone’s business. The management and security professionals in your company have the education, experience and know-how to make policies that will keep data safe. Don’t second guess them with your lack of knowledge – follow the directions. It’s not that hard!

Thursday, August 31, 2006

Who’s Computer is it, Anyway?! (Part 2)

Okay – here’s the scenario (again): Same as Part 1 - Corporate environment, computer is provided by the company, all of the initial software on the computer is installed by the company. The user signed an Acceptable Use Policy statement acknowledging their responsibilities with regard to computer use and security. The company’s acceptable use policy says something about “…only approved software…” The end user is the only user of the computer. Employees are allowed to use the Internet (i.e. the web browser), applications, and email for business purposes and for limited personal use.

null

More on those neat little freebies – but this time, it is not just a seemingly innocent browser toolbar. There are other free tools out there, commonly known as “peer-to-peer” (P2P) applications. Seems our carefree and gadget crazy employee from last time really likes music, so I will just concentrate on the P2P apps that allow you to download music files (MP3s), but there are many others. The way these applications work is that you install some software (free of course) on your computer, which then has the ability to connect to everyone else on the Internet who has that same software. The reason they call it peer-to-peer is because users don’t actually download the files from a central source, but from each other. The user enters the search terms of the music they are looking for, and the P2P software finds the other users who are online that have that music. The user can then choose to download the files they want. When the download is started, parts of the file can actually come from multiple peer users, speeding up the download process. Downloading MP3 files is great – the users can listen to them on their computer at work, providing they aren’t distracting coworkers, and they can even take them home at the end of the day. Ah, piracy has never been so easy!

Well, here’s the catch: For one thing, downloading copyrighted files from any source without paying for them is illegal. Remember last time I mentioned getting your employer in trouble by installing supposedly “free” software that actually had to be licensed? Well P2P software opens your employer up to a whole new batch of liabilities. We can safely assume (my opinion here) that most people that use P2P software to download music know it is illegal, but do it anyway. This makes the crime more blatant and premeditated, in my mind, and seems to result in harsher consequences. Since you are on company time and on company property, you are now (using a legal term here) under the “scope of employment” which allows prosecuting parties to hold your employer accountable as well as you. The employer should have known that the employees were using company network resources and company computers for downloading illegal music. If the employer is practicing due diligence, they would be checking their network for P2P traffic and scanning their servers for potentially illegal file types.

Even if you are using one of the new and improved “pay as you go” services and pay for the music instead of committing piracy, you are still creating problems on a networking infrastructure. So now let’s take the whole “who’s computer is it anyway?” question a little further and ask who’s network is it anyway?” The other thing about P2P software is that it creates network traffic – a LOT of network traffic. When I was teaching, our students were all required to have laptop computers in support of the curriculum. We had full Internet access for them, email, and wide open – no restrictions. Very early on in our experience with student laptops, we found that it didn’t take them long to discover Napster and Kazaa. While teaching class, I could look out and see the sea of dopey looks as these people were downloading tune after tune (not paying attention to the Instructor, of course). The magic question of “Hey!!! How come the network is so slow between the hours of 11:00am and 3:00pm??” popped up. It was because several hundred students were all downloading massive volumes of MP3 files and choking our network. Not only that, but our file servers hard drives were swiftly running out of space because of all the MP3’s being stored in student Home folders. Imagine that same problem, not in an academic setting, but in a business setting where real work is supposed to be getting done. These types of activities have the potential to hog bandwidth, take up valuable file server space, and are probably robbing employers out of productivity from their employees.

So now for the security aspects of this issue: P2P software is known to be a large source of security vulnerabilities and exploits. Software like this creates a pretty big opening into the hosting computer making it possible to spread viruses, WORMS, denial of service attacks, and other attacks that allow full control of a compromised computer. In fact, having this type of software may cause your company to fall out of compliance for various legislative act requirements such as those contained in HIPAA, Sarbanes-Oxley, or GLB.

Again, as in the case of the company owned computer – it’s not the employee’s network, it is the company’s network. The employer has the right – scratch that – the obligation to protect their network from performance degradation and unauthorized use. They also have a legal requirement to ensure that all of their information technology resources are in compliance with various regulations – and that includes making sure that the software installed on company owned workstations isn’t causing security or performance problems. Be a good employee – do what you want to your computer at home (you’re going to anyway), and leave your company resources for doing business. Failure to keep this stuff of your employer’s machines has the potential to hurt them, but also has the potential to hurt you more than you can imagine.


More Information:

SearchSecurity.Com Article: Are P2P Applications Worth the Risk?

DHS: Unauthorized P2P Programs on Government Computers

Article: Instant Messaging and P2P Vulnerabilities in Health Organizations

Who’s Computer is it, Anyway?! (Part 1)

Tuesday, August 29, 2006

Who’s Computer is it, Anyway?! (Part 1)

Okay – here’s the scenario: Corporate environment, computer is provided by the company, all of the initial software on the computer is installed by the company. The user signed an Acceptable Use Policy statement acknowledging their responsibilities with regard to computer use and security. The company’s acceptable use policy says something about “…only approved software…” (more on that in a bit). The end user is the only user of the computer. Employees are allowed to use the Internet (i.e. the web browser), applications, and email for business purposes and for limited personal use.

Having remembered all that (yeah - right!), the employee is out cruising the Internet. They haven’t broken any company policies yet, they come across this site with a really cool toolbar for the browser, and best of all, it is FREE! It blocks pop-ups, gives enhanced search capabilities, even has a news feed reader and chat client. So they install that neat toolbar – free download, couldn't possibly be a problem, who’s gonna know? They may have just crossed over the line with company policy, it’s probably a minor infraction, no big deal.

Now it gets better: One day shortly after installing that cool new toolbar for the web browser, the employee tries to access a web site that they normally need to access to do their job. Certain functionality of that web site depends on scripting and pop-ups (authorized ones), but strangely they don’t work right. Hmmm – they reload the web site, check access to other web sites, and if they’re really savvy, they check pop-up settings and security settings in the native browser. All good, what can be the problem? Frustrated by this time, the angry employee finally calls the company’s help desk and reports the problem. The technician, having seen this problem before, and after checking the normal browser settings that the user just checked themself, asks the five dollar question: “Do you have any other browser toolbars or pop-up blockers installed?” Let’s just assume this employee is at least an honest person and reports the Google or Yahoo toolbar that they just installed. The technician states that the employee will have to uninstall the toolbar for the web site that they are trying to access to work. This infuriates the employee and they state that there must be SOME way to make it work with that toolbar. The technician promptly replies that the toolbar is NOT supported software, and that it is in fact NOT even approved software (remember that acceptable use policy?). “NO! %$#@&* - it, this is MY computer and I will do what I want with it!!!” shouts the now livid end user.

Here’s the bad news, folks: It is NOT the employee’s computer. It is the company’s computer. Those neat little toolbars and all those other cool freebies on the web are great for the computer at home, but have no place on computers at work. And here are the issues: 1) By having to muck about through trying to fix unsupported and unapproved software, we are making our help desk people do extra work that they shouldn’t have to do, and is probably against the service level agreement that the business unit has with the company. 2) By installing these things, we are possibly creating a security risk for our system and our corporate network by inviting in spyware and potential vulnerabilities. 3) We are opening our company up to all kinds of liability issues regarding software licensing (“FREE” does not necessarily mean free for use in a corporate environment), and information assurance (the spyware in that free toolbar may be a blatant violation of security policies).

The reason why there is an approved software list is because some pretty smart people figured out 1) What software licensing would cost for the organization to have certain software, 2) They have a pretty good idea what software works with all the other software on the machine, and 3) They know that there are certain information security “best practices” that need to be followed.

My final rant in today’s post is that the above scenario is all too common in today’s corporate environment. I am sick and tired of hearing about people bitching and whining because their computer is “…always broken,” and that “…these ^&%$#@ computers are no good.” Let me give you my $.02 worth: The reason they are always broken is because of security unaware and clueless computer users constantly installing this kind of crap on their company’s computers, and then ragging on tech support for not fixing it for them. I take exception to some blathering idiot taking out their rage on tech support people who had nothing to do with that user mindlessly horking up their computer. These morons break their computers, some do it every time they touch one – the help desk should make THEM re-image and reconfigure that machine once. That will give these people a good idea what it’s like to have to deal with and clean up after clueless people who break computers because of their own ignorance and gadget lust. Go see my "Know Your Computer" and "Are You a 'Responsible' Computer User?!" articles for more about what users can do to improve their own computing experience.

Disclaimer: I used the term “Help Desk” in this article ONLY because it is the term that most people are still familiar with. The correct term is “Service Desk.” I mention this disclaimer lest the ITIL folks come find me and revoke my ITIL certification :) For more information on ITIL, please go here. You will find a wealth of things in the ITIL world about service desks, service support and delivery, and best of all service level agreements, service security, and service management. Solid ITIL practices are why the service desk people are not your enemy - they are doing their job!

More ITIL Links

Who's Computer is it, Anyway?! (Part 2)

Upgrade to Firefox 1.5!

Saturday, July 22, 2006

Are You A "Responsible" Computer User?!

By “responsible,” I mean do you take the time to understand that your computer is only a machine that can do work for you? In other words, the computer can’t read your mind, it can’t open your documents just by you thinking of them, it has no way of guessing where you want them kept, and it has no way of predicting what catastrophe is going to wipe out the last four hours of your work. Do you take the time to understand what you need to do to keep your computer in tip-top running order?

You do read your car’s owner’s manual right? I mean, you took the time to find out what the little buttons on the dashboard do, and what it really means when that funny light turns on? Well – that little piece of electronic real estate on your desk is more sophisticated and more powerful than the computer that put a man on the moon. You should probably get to know it little. Read the instructions, use the embedded “help” tools that came with it (Start --> Help and Support), buy a book (even if it has “…For Dummies” in the title), explore online news groups, read my blogs. Whatever it takes, but do some homework.

Visit the "Computers" section of my web site: http://www.wflinn.com/computers/

Okay – you’re up and running now. Do you know how to save your documents? Did you know that when you hit the “save” icon you actually have to take the time to find out where it is saving the document to? You can also choose an alternate location to which to save it. I have seen many people frantically call their IT support people and rant about how they can’t find their documents – the computer obviously lost them! “Where did you save them to?” the IT person asks. “I don’t know!” (Translation - "that's not my problem, the computer was supposed to figure that out!") replies the frantic customer. Take the time to know where your documents are being saved. Explore ways to organize your “My Documents” folder so that you can easily find things.

“Oh -$#@&-, the power just went out!” That’s OK – when you power your computer up after the outage is over, your document will magically reappear and all will be well. In your dreams, perhaps. Another crazy thing about these electronic gadgets is that they can’t tell the difference between a quick note you are typing up (that you have no intention of saving) and an elaborate spreadsheet with the past million and six lines of data and formulas that you need to keep forever and a day. While you are working on these precious documents – save them! Save them immediately upon creation so that the document gets named and properly saved to a location of your choosing. Save frequently as you go along. Then when the power goes out, you may lose a little of your work, but not the whole last four hours worth. In Microsoft Office products, you can also go to “Options” and tell it to save “AutoRecovery Information” every “x” minutes. I have mine set to 10 minutes.


Being a responsible computer user, particularly if you are in a corporate setting, also means watching what you install on your (er-uh, your company’s computer). Is your computer always broken and you can’t figure out why? Does it seem like your computer never seems to work right? Let me ask a follow-up question: Are you one of those people who always downloads and installs every “free” toolbar, game, or other neat looking gadget? This is one of the leading causes (in my opinion) of computers not working correctly with corporate applications and needless calls to the service desk. You have a responsibility NOT to install unauthorized software at work, and you have a responsibility to yourself to be a little more discerning at home not to install every cool gadget that comes along. Your corporate service desk will tell you it’s unauthorized, and when you call tech support for your home computer’s woes, they may not support you either.

Finally, your computer, again using the car analogy, needs maintenance. You wouldn’t drive your car 100,000 miles without changing the oil would you? Do a periodic “Disk Cleanup” and “Defrag.” These simple tools will help your computer run as efficiently as possible. You can even automate them. Use antivirus software, personal firewalls, and for Pete’s sake – stay patched. Here are some procedures to help you get your maintenance routine started:



Your computer, for all its sophistication, is nothing more than an expensive doorstop – until you bring it to life and put it to work. You have to know at least a few fundamentals about it, and you have to know how to take care of it. You and you alone are responsible for where you put things in a computer – I mean you don’t blame your house when you forget where you put your keys, do you?