Home > Enterprise Desktop Tips > > Combat security threats with user education
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Combat security threats with user education


Lindsay Mullen
03.30.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


When English philosopher Herbert Spencer wrote, "The great aim of education is not knowledge but action," he didn't have computer security education in mind. However, more than a century later, panelists at a recent New England Information Security Group (NEISG) meeting voiced such messages loud and clear.

"I think education goes a long way. If you explain user polices, there is a better chance people will follow them. They will understand the risk to the company," said James Burrell, United States FBI agent specializing in criminal computer intrusion and cyber crime, and one of the panelists at the Waltham, Mass.-based user group meeting.

The need for user education rose to the top of the agenda during the group's discussion about ethics and legal issues in the security field. Other panelists included Mark Minasi, columnist and author of Mastering Windows Server 2003, Stephen Heymann, Chief of the U.S. Attorney's Appellate and Computer Crime Section, and Sanford Sherizen, president of Data Security Systems and member of Information Security Systems Association's (ISSA) Hall of Fame.

Uneducated users are such easy targets for spammers and virus writers, according to Burrell. Most policies are implemented only after something bad happens, he said, so the key is to educate users before they become victims.

However, Burrell warned, "Polices are a balance. If you put super restrictive policies on users, they can't be productive. If you are too lax, well, we've seen what happens." IT people tend to create workarounds for overly restrictive polices. This then creates a false sense of security: Administrators have lost control of users yet continue to tell themselves everything is secure because policies are in place.

Administrators must combat ignorance by taking the time to educate users, according to Minasi. He stressed the importance of strong passwords in particular.

"The single most important thing is passwords," Minasi said. He recommend


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Intrusion detection, prevention and removal
Windows security tools for the busy desktop administrator
Check IT List: Five steps for rootkit detection
Top Windows client security tools for end users
Tools for virus removal and detection
Buffer overflows can be prevented by GS cookies
Determining the proper Microsoft malware removal tool
October patches fix four threats
Cool things about security, nothing about Britney Spears
Run third-party malware detection tools in Windows
Malware prevention and detection webcast series

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


s getting @stake LC4 (formerly L0phtCrack) and having fun at lunchtime trying to crack employees' passwords. "People love true tales of crime, and when they see how quickly a password can be cracked, they will instantly become more vigilant."

One NEISG member, an IT network administrator for a bank, agrees with Minasi's password approach. His bank is a full Windows shop slowly moving from Windows 2000 to Windows Server 2003. He currently enforces an 8-character password requirement that changes every 30 days, but he still has reservations about user enforcement: "Even when I put my stronger password requirements in place this year, I still think people will write passwords in a secret spot in the office or cubicle."

A study conducted by antivirus vendor Symantec adds gravity to this bank administrator's fears about uneducated users. According to the study, e-mail worms and viruses aimed at Windows systems rose sharply last year, with 5,000 new cases of Microsoft-targeted malicious activity from January to June. This represents a 400% jump over the same period in 2003. Such information is great incentive for Windows administrators to implement and enforce strong security policies in 2005.

In spite of the panelists' advice, one audience member was still skeptical: "I do think it's important to educate the end users," he admits, "but in reality we know that they will never truly understand computer security. Most will just come in, do their tasks and go home. All that security stuff most likely will never sink in."

Share your opinion: How important is user education in securing Windows systems? Do you educate users on Windows security issues and techniques? If so, how? E-mail us and we'll add your comments to this article.


More information from SearchWindowsSecurity.com

  • Tip: Get educated on URL spoofing scams
  • Checklist: Get Joe User to limit his own actions
  • Topics: Get tips and expert advice on end-user education


  • Rate this Tip
    To rate tips, you must be a member of SearchEnterpriseDesktop.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
    HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts