Home > Enterprise Desktop Tips > > Protect desktop files and folders from inside snoops
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Protect desktop files and folders from inside snoops


Tony Bradley
05.24.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In the second of this two-part series, below, Tony Bradley offers step-by-step advice on how to configure Windows file and folder security. In part one, he identified three internal controls you must have in place to prevent internal hacking.

Security is often a game of perception. A mysterious combination of smoke and mirrors creates the illusion of security while reality remains unprotected. With information security, the majority of security tools and utilities are designed to keep outsiders from gaining access to internal resources. The "us vs. them" mentality fits well with most perceptions, but it does not mesh with the reality that most attacks and security breaches occur from the inside.

I recently wrote about the disparity of inside jobs vs. external threats and provided some tips to protect computer systems in Guard against internal hackers. In this tip, I cover specific steps you can take to secure your Windows desktop files and folders and prevent even internal prying eyes from viewing them.

1. Use third-party tools to secure Windows 9x files and folders
Older versions of Windows such as Windows 95, 98 or Me are inherently insecure when it comes to files and folders. To protect individual files and folders, you must install a third-party utility, such as Everstrike Software's Protect Folder 98 or WinAbility Software Corp.'s Folder Guard Classic Edition. Keep in mind that these operating systems are based on a DOS foundation, and even these third-party tools are not impenetrable.

2. Share only what is necessary
When creating shares on your computer, restrict the share to only information that is necessary. S...


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Windows legacy operating systems
Windows 7 launches, offers salvation from Vista
Admins can wear many hats using Netcat
Choosing the best way to install images
Ten ways to sell security to management
Improve Windows security with our top 10 tips
Windows Vista management tutorial
Ten ways to selling security to management
Vista security option changes to named pipe access
Minasi talks Vista security, Windows Server 2008 features
Troubleshooting IEEE 1394 bus devices for Windows machines

User passwords and network permissions
20 days to a more secure enterprise
Eight is too many characters for strong passwords
Nine common password oversights to avoid
Secure your Windows systems with proper password practices
Managing multiple passwords in Windows
Windows desktop endpoint security challenges podcast series
How to strike a balance between Windows security and business needs
Managing single sign-on security burdens in Windows
Build secure computer password policies
Remote user security checklist

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
drive-by download  (SearchEnterpriseDesktop.com)
Error messages for Windows 2000  (SearchEnterpriseDesktop.com)
IO.SYS  (SearchEnterpriseDesktop.com)
MS-DOS  (SearchEnterpriseDesktop.com)
remote desktop  (SearchEnterpriseDesktop.com)
W2K  (SearchEnterpriseDesktop.com)
Windows 2000  (SearchEnterpriseDesktop.com)
Windows 98  (SearchEnterpriseDesktop.com)
Windows Remote Desktop  (SearchEnterpriseDesktop.com)
Windows XP  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


haring out an entire drive or partition is probably too broad. Even sharing out the My Documents folder may allow access to too much data, depending on how you use it. You may consider creating a special folder just for shared files and only sharing out that individual folder.

3. Use discretion setting permissions
Just as you need to use discretion in choosing which files and folders should be accessible, you should also limit who has access or what level of access they have. If you just grant Full Control to the Everyone group for your shared resources, it will be hard to manage or control access. Even for resources that you want to share, you should give some thought to who should have access and whether they should be able to delete or edit the files or simply be able to view them.

4. Encrypt confidential or sensitive information
Once you limit what information is shared out and further restrict access and file permissions, then your desktop data should be fairly well-protected. However, if you have confidential or particularly sensitive information, you may want to go one step further and encrypt it. In Windows 2000 or XP you can use the built-in Encrypted File System (EFS). You can also turn to third-party encryption tools such as PGP Corp.'s PGP Desktop Home 9.0.

Click for part one to find out which three internal controls you must have in place to prevent internal hacking.

About the author:Tony Bradley is a consultant and writer with a focus on network security, antivirus and incident response. He is the About.com Guide for Internet/Network Security, providing a broad range of information security tips, advice, reviews and information. Tony also contributes frequently to other industry publications. For a complete list of his freelance contributions, visit Essential Computer Security.


More information from SearchWindowsSecurity.com

  • Tip: Check out Tony's tip on how to guard against internal hackers
  • Tip: Know how to Google hack your own Windows systems before a bad guy does
  • Checklists: Harden Windows with this collection of Windows security checklists by Roberta Bragg


  • Rate this Tip
    To rate tips, you must be a member of SearchEnterpriseDesktop.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
    HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts