Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Registry Mechanic - Free Scan Now

Cyber Security Awareness Tip #4: Enabling the Road Warrior, (Thu, Oct 4th)

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 10-04-2007
Steve's Avatar
Steve Steve is offline
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 46,133
Steve is a jewel in the roughSteve is a jewel in the roughSteve is a jewel in the rough
Thanks: 7
Thanked 24 Times in 11 Posts
Cyber Security Awareness Tip #4: Enabling the Road Warrior, (Thu, Oct 4th)
Those pesky mobile users.

They are all too often the bane of security folks everywhere as they regularly seem to be system 0 for malware infections, tend to be administrative users on their systems more frequently, can go months (or years) at a time between office visits and of course, can never be without their systems as no laptop = no productivity and since many times they are the ones who sell the goods and provide the services that provide for our (or at least my) paycheck ...

So how to let them do what they need to do while making sure their system is secure as is the corporate network they VPN into?

Unless you have great policies including enforceable HR policies that make users accountable for thier actions, and a defense in depth approach that ensures AV and patches are up to date and checked before connecting to the network, renamed administrative accounts, proper file system permissions etc... you are at some level at the mercy of the action(s) of your users.

If you find yourself short a few policies and technical controls, user education becomes key.

Message #1 - With great power comes great responsibility. Sure, it's kind of corny and maybe being a local admin on your own system isn't great power but you get the idea. Educating your mobile users as to what is acceptable and allowed (policy or no policy) can bring a big return on a small investment assuming they actually do as you request.

because ...

Message #2 - Just because you can, doesn't necessarily mean that you should. Yes mister user, I know you're an admin on your machine. Yes I understand you're experiencing poor performance but that doesn't mean you should uninstall your AV software, install every spyware remover, registry cleaner and any other widget guaranteed on some web page somewhere to do what you want. For the record, you can format your hard drive. I wouldn't suggest it though.)

Of course many of us are mobile users and we would never do anything insecure, right?

So what are your tips and tricks for keeping your mobile workforce working and not bringing down the rest of the network? If you have any good stories surrounding mobile users, send them in as well and we'll publish the best ones changing the names as needed to protect the innocent -and- the guilty.

-Christopher Carboni

More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cyber Security Awareness Tip #3: Getting the Boss Involved, (Wed, Oct 3rd) Steve Security News 0 10-03-2007 15:40
Cyber Security Awareness Tip #2: Multimedia Tools, Online Training, and Useful Websites, (Tue, Oct 2nd) Steve Security News 0 10-02-2007 19:53
Cyber Security Awareness Tip #1: Penetrating the This Does Not Apply To Me Attitude, (Mon, Oct 1st) Steve Security News 0 10-01-2007 01:41
The fragility of road-warrior security Steve Security News 0 05-20-2007 11:49
The fragility of road-warrior security Steve Security News 0 05-18-2007 10:25


All times are GMT +1. The time now is 05:48.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119