Information Security Awareness: Tips for Securing Your Workforce

Posted: Mar 11, 2011 |Comments: 0 |

In a previous Stone Carlie blog we focused on Information Security Awareness as it relates to emerging cyber security threats, the risks they present and the financial implications cybercrime can have on you and your business.  Stone Carlie's goal in this edition, is to provide you with a top 10 list of ways to safeguard your workforce from emerging cyber threats.

Encrypt all hard drives, especially hard drives that leave your premises. One way to add an additional layer of security is to require a password to boot the computer.  As an added benefit, this additional step encrypts all information on the hard drive making it inaccessible without the password.  The hard drive is even protected if removed from the original computer.  TrueCrypt is a free open-source disk encryption program for Windows 7/Vista/XP, Mac OS X, and Linux.

Use a virtual private network (VPN).  Internet usage outside of the work place is convenient and necessary, but also makes your data vulnerable.  To protect the integrity of your  information, it is highly recommended that you use a VPN.  Wikipedia defines a VPN as a computer network that uses a public telecommunication infrastructure, such as the Internet, to provide remote offices or individual users with secure access to their organization's network.  More simply stated, a VPN encrypts all data before it leaves your laptop and keeps it encrypted until it reaches a trusted environment.  Airports, coffee shops, hotels, etc. are all potentially hazardous if a VPN isn't used.  OpenVPN, HotSpotVPN, GoToMyPC, and LogMeIn are inexpensive VPN solutions.

Run firewall and anti-virus software. Consider using supplemental firewalls and anti-virus software that offer specialized protections.  Intrusion prevention, intrusion detection, and anti-spam are recommended.

Update and patch your software.  Enable your operating system to download and patch your system automatically to ensure your software is up to date and any security vulnerabilities are fixed.

Back up your data and keep it secure.  Many companies back up their data; however the backup is often unencrypted and stored in an unsecured location.  Also, most companies are unaware of the extent to which critical data is stored locally on employee computers.   Try using an encrypted external USB drive; they are inexpensive and recommended for those who travel.

Use strong passwords.  Strong passwords should be lengthy and have complex symbols.  Passwords should contain as many as 14 characters, and the characters should include upper and lowercase, numbers, and symbols.  Instead of using your children's or pet's names or common words (such as your street name, company name, etc), try using pass phrases.  For Example: M@ryH@dA!itt!e!@mb.  Changing your password every 45 to 60 days should be company policy.

Practice safe computing.  Use caution.  Though it may seem common sense in today's world, avoid opening attachments or clicking on links from unknown senders or un-trusted websites.

Restrict access to your corporate data.  Limit the number of physical and electronic locations where your data is stored.  Keep paper records in a locked cabinet and when assigning system access use the least privilege methodology.

Adopt and enforce sound security policies.  Senior Management should set a strong tone and provide regular security awareness communications to all employees in your organization.

Start a risk assessment and vulnerability management program.  As education is probably the greatest protection against security breaches, we will devote our next blog to providing tips on how to effectively set up and implement a Risk Assessment and Vulnerability Management Program.

Questions and Answers

Ask
200 Characters left
Rate this Article
  • 1
  • 2
  • 3
  • 4
  • 5
  • 0 vote(s)
    Feedback
    Print
    Re-Publish
    Source:  http://www.articlesbase.com/accounting-articles/information-security-awareness-tips-for-securing-your-workforce-4391377.html

    Article Tags:

    cyber criminals

    ,

    cyber threats

    ,

    information security awareness

    ,

    symantecs

    ,

    underground economy

    ,

    victim of cyber crime

    ,

    accounting

    ,

    finance

    Theft of data and information is growing exponentially due to the increasing availability and sophistication of crimeware. Crimeware is designed primarily to steal financially relevant data, including credit card information, passwords, and bank account numbers. By keeping your system and all applications up-to-date and implementing cautious browsing and email habits, you can better protect your organization from cybercrime

    By: StoneCarliel Finance> Accountingl Feb 07, 2011

    Many people are looking for new business development. The establishment of new business is a very difficult task without assistance of professional adviser. It is necessary for first timers to hire contractor accountants for successful execution of business tasks.

    By: Shams Url Finance> Accountingl May 21, 2012

    In this article the author discusses the records you company should be keeping after you have registered your new company.Following your company registration there are a number of obligations and filings to Companies House that you are required to complete.

    By: John Bregarl Finance> Accountingl May 18, 2012

    In this article the author discusses the requirements for year end accountants of private limited companies.Year end accountantsare usually required to prepare annual accounts for private limited companiesat the end of each financial year.

    By: John Bregarl Finance> Accountingl May 18, 2012

    If you are finding it hard to sort out your tax returns, it may be time you hired an accountant to help you out with them. Here are a few ways that an accountant can turn out to be an excellent investment.

    By: Rob Hurrenl Finance> Accountingl May 18, 2012

    First of all, let us consider the financial impact of employing a virtual accountant. Organizations can get the same quality of work done by outsourcing with lesser costs attached.

    By: accelcial Finance> Accountingl May 18, 2012

    As a result of last year's health care reform legislation, the simple task of purchasing a new office desk and chair for your business would have required filing a 1099 form. The 1099 Expansion Repeal eliminates the need for excessive bookkeeping and paperwork required by previous 1099 reporting acts.

    By: StoneCarliel Finance> Accountingl Apr 25, 2011

    Stone Carlie focuses on the fundamentals behind the research and development tax credit and reviews the four-part test on which activities meet the criteria for qualified research expenses.

    By: StoneCarliel Finance> Taxesl Apr 13, 2011

    Implementing a risk assessment and vulnerability management program is vital to securing your corporate confidential data. The intent of a vulnerability management program is to ensure that current security issues within the company are identified, evaluated using a risk management approach, and dealt with in a cost-effective and efficient manner.

    By: StoneCarliel Business> Managementl Mar 30, 2011

    Initiative that offers taxpayers an opportunity disclose their unreported offshore accounts. In exchange for participating in the OVDI, taxpayers with undisclosed offshore accounts can avoid criminal prosecution for their unpaid taxes and may be subject to significantly reduced penalties.

    By: StoneCarliel Finance> Accountingl Feb 21, 2011 lViews: 212

    Discuss this Article

    Author Box
    Articles Categories
    All Categories
    Quantcast