<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Security Blog &#187; Security Policies</title>
	<atom:link href="http://www.it-security-blog.com/category/security-policies/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.it-security-blog.com</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 15:19:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>10 Great Tips To Protect Your Emails Accounts From Hackers</title>
		<link>http://www.it-security-blog.com/security-policies/10-great-tips-to-protect-your-emails-accounts-from-hackers/</link>
		<comments>http://www.it-security-blog.com/security-policies/10-great-tips-to-protect-your-emails-accounts-from-hackers/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 03:48:20 +0000</pubDate>
		<dc:creator>Wayne Ernest</dc:creator>
				<category><![CDATA[Security Policies]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=827</guid>
		<description><![CDATA[A lot of hackers are entering in the world of internet. Hacker’s use a lot of things like a person’s email id, PC address, password etc. They continuously update themselves with the latest technologies. Therefore people should update themselves also in order to protect their accounts from being hacked. These cyber criminals are increasing in [...]]]></description>
			<content:encoded><![CDATA[<p>A lot of hackers are entering in the world of internet. Hacker’s use a lot of things like a person’s email id, PC address, password etc. They continuously update themselves with the latest technologies. Therefore people should update themselves also in order to protect their accounts from being hacked. These cyber criminals are increasing in number day-by-day. Your email is very important whether you are a professional, student, or any other. Your email contains a lot of data and needed to be protected as it’s your personal asset.</p>
<p><img class="alignnone size-medium wp-image-828" src="http://www.it-security-blog.com/wp-content/uploads/2011/11/security-300x171.jpg" alt="" width="300" height="171" /></p>
<p>When it comes to privacy and security one should be full aware of the dangers associated with using internet. Suppose if a spouse wants to inform her husband about the keys then if she is having an easy email-id which can be easily hacked and she is using it, then there is a danger of stealing their household goods. As there id once hacked, it’s very difficult to get it back. Having one’s email encrypted is the first step for email-id protection. There are a number of companies offering such services online; they have latest technology software which can aid a person.<br />
Now the question arises how to protect them?<span id="more-827"></span></p>
<p>1. People should share their email-id only with trusted peoples. One should have two email id one for general purpose work, and other one for official purpose, or any other online transaction.</p>
<p>2. One should be careful while opening attachments or downloading the attachments of received mails. One can get viruses, worms etc. so he/she should use security software while opening attachments.</p>
<p>3. One should be careful while doing chatting, should not accept unknown friend request, so he/she should do instant messaging carefully.</p>
<p>4. Think about the legality of any website before pursuing any work. As hackers always use fake identity or website to do hacking. Specially if you use financial sites, always make sure the site is legal. </p>
<p>5. Use your email-id wisely, does not make any money transactions, or share your credit card number on mails, your password. Use it for only making personal connections with your friends and colleagues.</p>
<p>6. Use good quality security software for prevention of your mail, do not rely on any illegal software and continuously update your software for better performance.</p>
<p>7. Never reply to an unknown person, don’t entertain such peoples, as they may be hackers. Making your decision wisely can help you a lot.</p>
<p>8. People should create a complex email-id, they should not make simple-id as it can be easily hacked, use numbers, special characters, digits , along with your name to create your email-id</p>
<p>9. Your password should be a strong one. Involving a lot of mind, it should not be an easy one such as containing only numbers, it should involve a lot of tactic, and should act like a brain teaser to others mind.</p>
<p>10. One should not enter their information on screen pop-up. Hackers basically use this technique to get a person’s information completely. Never put your information when pop-ups appear on screen.</p>
<p>By followings above mentioned tips, one can easily save their account from hacking.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/security-policies/10-great-tips-to-protect-your-emails-accounts-from-hackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Security Policy for Employees</title>
		<link>http://www.it-security-blog.com/it-security-basics/it-security-policy-for-employees/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/it-security-policy-for-employees/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 04:06:44 +0000</pubDate>
		<dc:creator>Teresa</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[ensuring compliance of IT security policies]]></category>
		<category><![CDATA[IT security and employees]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=799</guid>
		<description><![CDATA[Information technology or IT continues to serve the needs of a business from start to the processes of change that it is required to go through as it expands.  It is a necessary occurrence for increased IT security to be needed as businesses grow.  Companies can protect themselves better by laying out the fundamentals of [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a title="Locked Out by Truthout.org" href="http://www.flickr.com/photos/truthout/4902199424/"><img src="http://farm5.static.flickr.com/4077/4902199424_0070aa3e2b_t.jpg" alt="Locked Out by Truthout.org" width="100" height="75" border="0" /></a></p>
<p>Information technology or IT continues to serve the needs of a business from start to the processes of change that it is required to go through as it expands.  It is a necessary occurrence for increased IT security to be needed as businesses grow.  Companies can protect themselves better by laying out the fundamentals of IT security through policies.</p>
<p>Every company operates on its own level of security in the aspect of technology use so it would be impossible to have complete uniformity between company policies.  The most basic components however are essentially the same.  Such components deal with maintaining data security discipline among employees and providing for the official use of the business equipments provided. </p>
<p>Electronic mail or simply email is deemed an official form of communication between the company and the customers thus it is important that those who are sending it are authorized to do so.  Companies generally have the right to review online communication of employees done through company facilities which give them the chance to intercept and prevent communication which are contrary to company policy or puts the company at risk or danger.  This right however has to be legally backed up by carefully worded terms and conditions.  Most companies also include automatic disclaimer in email contents. </p>
<p>Employees need to know what constitutes transgression of company security if they are to be expected to act accordingly.  There is also a need for policies to undergo periodic checking and evaluation to ensure that they are current to existing conditions and technologies.  Employers must have access to sanctioning violators of IT security policies so that employees fully understand the consequences of their actions.  Clear-cut written words that have sound legal basis provides the foundation of every IT security policy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/it-security-policy-for-employees/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Telecommuting Woes???</title>
		<link>http://www.it-security-blog.com/uncategorized/telecommuting-woes/</link>
		<comments>http://www.it-security-blog.com/uncategorized/telecommuting-woes/#comments</comments>
		<pubDate>Wed, 27 Jul 2011 08:23:45 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Privacy & Anonymity]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Mobile-Workforce]]></category>
		<category><![CDATA[Telecommuting]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/uncategorized/telecommuting-woes/</guid>
		<description><![CDATA[Research has shown that a survey conducted within a large company shows that although telecommuting is very much productive for many firms it tends to be on the downside for those employees who do stay within the physical office itself. This can be in the areas of personal assistants/secretaries and other office workers who are [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.it-security-blog.com/wp-content/uploads/2008/01/telecommute.jpg' title='telecommute.jpg'><img src='http://www.it-security-blog.com/wp-content/uploads/2008/01/telecommute.thumbnail.jpg' alt='telecommute.jpg' /></a>Research has shown that a survey conducted within a large company shows that although telecommuting is very much productive for many firms it tends to be on the downside for those employees who do stay within the physical office itself.  This can be in the areas of personal assistants/secretaries and other office workers who are left to run the office in the absence of their counterparts/coworkers. This leads to dissatisfaction in the workplace hence lowering productivity and encouraging home-bodies to engage in dangerous liaisons from within and outside of the office. </p>
<p>The hatred felt is seen in the rising occurrences of these same people becoming the entry point for attacks on corporate networks when they visit social sites to pass on the otherwise boring day. This is also counterproductive for their attention to work and the other nuances such as physical security and IT security is so much a threat that it is under study on how to improve the working conditions for these people. They are distracted and left to do almost anything they please which is where the security gap seems to be, using the corporate network to access social sites to which they are members of. Even the installation of hardware and software security measures cannot guarantee security coverage at all angles for the main security risk is still the human behind the keyboard who does the typing and not on the structure of the system itself. It might be helpful to get them out more often to allow their facilities more practice letting the steam and pressures/boredom to dissipate. Role rotation may be a key but is not always feasible for there are certain knowledge associated issues that have to be addressed to be able to do that. Training and re-training people allows them to sharpen skills and add new knowledge to their already bored lives. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/telecommuting-woes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Complacency – the IY industry’s Worst Enemy</title>
		<link>http://www.it-security-blog.com/uncategorized/complacency-%e2%80%93-the-it-industry%e2%80%99s-worst-enemy/</link>
		<comments>http://www.it-security-blog.com/uncategorized/complacency-%e2%80%93-the-it-industry%e2%80%99s-worst-enemy/#comments</comments>
		<pubDate>Wed, 20 Jul 2011 12:49:34 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Privacy & Anonymity]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/uncategorized/complacency-%e2%80%93-the-it-industry%e2%80%99s-worst-enemy/</guid>
		<description><![CDATA[This has been proven true by incidents broadcast around the world in minutes or hours after they have happened. Many have suffered the consequences of such incidents in the UK, US and mostly each and every place on earth where people have had their information taken and used for no good before there was even [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.it-security-blog.com/wp-content/uploads/2008/01/complacency.jpg' title='complacency.jpg'><img src='http://www.it-security-blog.com/wp-content/uploads/2008/01/complacency.thumbnail.jpg' alt='complacency.jpg' /></a>This has been proven true by incidents broadcast around the world in minutes or hours after they have happened. Many have suffered the consequences of such incidents in the UK, US and mostly each and every place on earth where people have had their information taken and used for no good before there was even a sign that there was a problem.</p>
<p>Big business has been reminded again and again that complacency is it’s worst enemy and they have failed again and again at the area. Why? Well first, total protection is almost always imperfect and somebody out there with enough intent and resources can break-in however expensive the protection methods may be. Next is that the best systems for protection is always the ones that cost too much yet they still remain vulnerable and hackable.  Contrary to most ad’s you see in print, the internet or your Television there is no one true solution to protection, for if the hardware and software measures succeed in protecting you, the human behind the computer/s are always the biggest risk. That is why even the most expensive solutions are used in conjunction with other solutions to provide the best of both worlds combining physical and software solutions hoping that combination will be enough protection from the continuous influx of attacks from the web and elsewhere. Encryption is nice but it takes a lot of computing power to implement making it too expensive for implementation on all levels of the company. All of these high-tech solutions and hardware would be nothing if the people using the various computer systems in the said organization fail to use them so the weakest link in every system is still the human. Strict adherence and compliance is the key with systems that process information somewhat autonomously already in use doing the searching and classification of information without the user’s input. This uses the latest in Artificial Intelligence with minimal intervention or input from the users.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/complacency-%e2%80%93-the-it-industry%e2%80%99s-worst-enemy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Biometrics + Physical security = Next best thing to unbreakable?</title>
		<link>http://www.it-security-blog.com/uncategorized/biometrics-physical-security-next-best-thing-to-unbreakable/</link>
		<comments>http://www.it-security-blog.com/uncategorized/biometrics-physical-security-next-best-thing-to-unbreakable/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 13:24:02 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[identity-theft]]></category>
		<category><![CDATA[Secure workplace]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/uncategorized/biometrics-physical-security-next-best-thing-to-unbreakable/</guid>
		<description><![CDATA[Biometrics is seen as the next step in computer systems security and access control due to the failure of more primitive and fundamental security systems. Fingerprint scanners, passwords, security keys and even smartcards have failed miserably in providing the ultimate and most secure intrusion prevention method for just about anything. From your home, car, computer [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.it-security-blog.com/wp-content/uploads/2008/02/bio.jpg' title='bio.jpg'><img src='http://www.it-security-blog.com/wp-content/uploads/2008/02/bio.thumbnail.jpg' alt='bio.jpg' /></a><br />
Biometrics is seen as the next step in computer systems security and access control due to the failure of more primitive and fundamental security systems. Fingerprint scanners, passwords, security keys and even smartcards have failed miserably in providing the ultimate and most secure intrusion prevention method for just about anything. From your home, car, computer terminal at work to just about anything else that needs security, it has be come more and more of a must due to the increasing threat of identity theft and other computer related crimes in and out of the workplace.</p>
<p>Biometrics are security systems that are based on the differences the human body manifests in terms of eye structure, facial features and now vein geometry. We’ve all heard of <strong><a href=' http://www.dnai.org/'>DNA</a></strong> or the so-called blueprint for life and the way it makes each and every human different from everyone else on this earth (well, except for some genetic disorders and diseases that changes the DNA makeup). That is what biometrics takes advantage of as a source of a very unique key or method of identifying one from another person. </p>
<p>Your fingerprint is mapped when it is initially scanned into a computer system which convert’s your analog (actual) print into a digital map that is as unique as you are an individual. Iris scanners take into account the differences the iris has from each and every individual (through the use of a low powered light and scanner to obtain a picture of the eye’s iris which is also unique). <strong><a href='http://www.it-security-blog.com/uncategorized/more-on-biometrics-%e2%80%93-voice-recognition/'>Voice recognition</a></strong> takes into account, the differences our voices have from everybody else also converting it into a digital map or password of sorts. <strong><a href='http://science.howstuffworks.com/biometrics5.htm'>Vein geometry</a></strong>, uses a thermal imaging camera to take a picture of your hand or whole body which is sensitive to heat showing all the blood vessels which show as hotspots thus giving you a unique id of sorts as that is also mapped and converted into digital form. All of the above biometrics systems rely on our individual differences which are quite unique to us and add onto it, other more basic security measures such as a physical key (password, key or other devices) to give the ultimate security system preventing intrusion. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/biometrics-physical-security-next-best-thing-to-unbreakable/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cyber Wars: A Lost Cause</title>
		<link>http://www.it-security-blog.com/it-security-basics/cyber-wars-a-lost-cause/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/cyber-wars-a-lost-cause/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 11:10:20 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[cyber wars]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=517</guid>
		<description><![CDATA[We know for a fact that the battle towards malicious software and viruses released on the web has caused a lot of pain as far as pinpointing and remedying them but apparently nothing has been done to really resolve them. We buy licensed software but we have to ask ourselves on the extent of their [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://www1.istockphoto.com/file_thumbview_approve/349458/2/istockphoto_349458_computer_hacker.jpg"><img src="http://www.it-security-blog.com/wp-content/uploads/2008/12/ist2_349458-computer-hacker-292x300.jpg" alt="" title="ist2_349458-computer-hacker" width="292" height="300" class="alignnone size-medium wp-image-518" /></a></center></p>
<p>We know for a fact that the battle towards malicious software and viruses released on the web has caused a lot of pain as far as pinpointing and remedying them but apparently nothing has been done to really resolve them. We buy licensed software but we have to ask ourselves on the extent of their coverage. Are they up to date and can they really save us from all these uncertainties of getting online?</p>
<p>Microsoft has been a prime target, being one of the widely used operating systems we know of today. But while Bill Gates and company are doing their part in being able to address the various intrusions and headaches that they can do with a simple click, you just don’t know who to trust these days. Even the software companies have the ability to manipulate and do some foul work and they are occurring right under our very noses. </p>
<blockquote><p>Security researchers concede that their efforts are largely an exercise in a game of whack-a-mole because botnets that distribute malware like worms, the programs that can move from computer to computer, are still relatively invisible to commercial antivirus software.</p></blockquote>
<p>So with all these things set on the table, is the <a href="http://www.blogherald.com/2008/12/08/bbc-mumbai-twitter-debacle/">cyber world</a> safe for anyone? We can fend off threats but the question is are we resolving the situation or merely providing a temporary solution to the problem? Sad to say, it is the latter. We are content with detecting them but it is really the cleaning and protection part that needs improvement.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/cyber-wars-a-lost-cause/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Be Wary of Giving out Your Email Address</title>
		<link>http://www.it-security-blog.com/it-security-basics/be-wary-of-giving-out-your-email-address/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/be-wary-of-giving-out-your-email-address/#comments</comments>
		<pubDate>Wed, 25 May 2011 09:14:00 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[emal]]></category>
		<category><![CDATA[explosion]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=511</guid>
		<description><![CDATA[Emails are supposed to make life easier but sometimes, it may be wise to choose who you give out your email to. Today, a lot of mischief can be done and normally this comes in forms of email attacks or email bombs. In such scenarios, don’t be surprised if you find your email downloading hundred [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://www.brainmaggot.co.uk/wp-content/uploads/2007/10/hacker-bomb.jpg"><img src="http://www.it-security-blog.com/wp-content/uploads/2008/11/hacker-bomb-300x255.jpg" alt="" title="hacker-bomb" width="300" height="255" class="alignnone size-medium wp-image-512" /></a></center></p>
<p>Emails are supposed to make life easier but sometimes, it may be wise to choose who you give out your email to. Today, a lot of mischief can be done and normally this comes in forms of email attacks or email bombs. In such scenarios, don’t be surprised if you find your email <a href="http://www.downloadinglegally.com/applications/download-songs-from-lastfm/">downloading</a> hundred to a thousand emails in one sitting. That is not the best part. You would be lucky if this was done only once since others would schedule it daily. </p>
<p>Why do they do it? One is for trials of these foolish software and the other can perhaps be for malicious reason. It is a fact that while many people on the web cannot be harmed physically, they can create <a href="http://www.thehealthblog.net/exercise-and-fitness/10-tips-for-optimum-brain-health-minimal-headaches/">headaches</a> for you in the form of discomforts from the privileges you get from the web. One of the main elements an online user would need to use is his email and by doing these email attacks, it burdens the person on how to get important information usually sent through the web. </p>
<p>One cannot avoid such instances. But the best way to prevent it is to choose the people you give it too. For people you meet on the web, it would be wise to use free mail accounts from Gmail or Yahoo over your personal one. Avoid the troubles of such since it will not only be a discomfort, but a forgettable experience as well. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/be-wary-of-giving-out-your-email-address/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scheduling Change of Passwords</title>
		<link>http://www.it-security-blog.com/it-security-basics/scheduling-change-of-passwords/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/scheduling-change-of-passwords/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 08:48:59 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[systems]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=514</guid>
		<description><![CDATA[If you are in charge of network security, one thing you may want to consider as far as laying down the law in safeguarding your network is the regular change of user passwords to avoid potential hackers and cracks based on how their passwords can be easily guessed. For some users, it is easy to [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://support.netmail.sg/images/changepwd_owa2.gif"><img src="http://www.it-security-blog.com/wp-content/uploads/2008/12/changepwd_owa2-300x268.gif" alt="" title="changepwd_owa2" width="300" height="268" class="alignnone size-medium wp-image-515" /></a></center></p>
<p>If you are in charge of network security, one thing you may want to consider as far as laying down the law in safeguarding your network is the regular change of user passwords to avoid potential hackers and cracks based on how their passwords can be easily guessed. </p>
<p>For some users, it is easy to figure out their passwords. The normal passwords that people use include:</p>
<p>1.	Birthdays<br />
2.	Anniversaries<br />
3.	<a href="http://www.studydriving.com/basic-driving-techniques/avoid-the-traffic-tickets-through-wise-driving/">Car Plate Numbers</a><br />
4.	Mobile Phone Numbers<br />
5.	Adding 123 to their names, or<br />
6.	Using “PASSWORD” as their password</p>
<p>Now there will be a lot of potential combinations depending on the length of the password. That is why the longer passwords (8 alphanumeric characters) are encouraged for users who access the network. </p>
<p>But while the probabilities of guessing or cracking passwords offer a lot possibilities, employing a regular maintenance as far as changing them is indeed something ideal to combat these hackers or malicious people from gaining access to the network and the programs in use. </p>
<p>Once cannot avoid the fact that some people’s curiosity and call for fame are the main reasons for wanting to be a hacker or code cracker. It is evident in people who are looking to try out their skill. They don’t think of the outcome which can cause a lot of problems. </p>
<p>So one good tip to avoid being hacked is to think like one. Once you do, think of security policies that can make it hard for you to breach a system. That is the best way to stay efficient in your line of duty in any organization. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/scheduling-change-of-passwords/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>An Internet of Criminals</title>
		<link>http://www.it-security-blog.com/uncategorized/an-internet-of-criminals/</link>
		<comments>http://www.it-security-blog.com/uncategorized/an-internet-of-criminals/#comments</comments>
		<pubDate>Mon, 17 Jan 2011 06:59:46 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Real-World Issues]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=610</guid>
		<description><![CDATA[The world of cyber-crime has grown so much in these past few years due to the explosion of growth with respect to the number of internet users the world over. It has not only expanded on the side of normal people but on the side of cyber-criminals who now operate on their own networks, spanning [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://tbn0.google.com/images?q=tbn:aEmocfWt6x7fiM:http://static.flickr.com/113/317179397_1cc756037c.jpg" alt="Hacker Network" />The world of cyber-crime has grown so much in these past few years due to the <a href="http://www.physorg.com/news151162452.html">explosion of growth</a> with respect to the number of internet users the world over. It has not only expanded on the side of normal people but on the side of cyber-criminals who now operate on their own networks, spanning the globe and ready to spread their products, malicious code that first scans the globe for weak points in the<a href="http://http://www.symantec.com/about/news/release/article.jsp?prid=20070319_01"> security net</a> that we all put up to somewhat give us a sense of security from the ever-growing threat which is actually futile to some extent.<span id="more-610"></span><br />
This was admitted by a renowned security expert who worked for one of the biggest security firms the world over for a new infection tends to be a game of <a href="http://www.avertlabs.com/research/blog/index.php/2008/01/23/anti-virus-testing-20/">cat-and-mouse</a> that begins when a new threat is detected. The game begins with experts dissecting the captured malicious program and then they race to create a cure, much like the race to come up with a vaccine for the quickly spreading <a href="http://www.webmd.com/cold-and-flu/news/20090626/swine-flu-vaccine-the-race-is-on?src=rss_investeap">&#8220;swine-flu&#8221;</a> virus that caught the human race off-guard. Once the malicious code is understood, a cure is issued and is swiftly sent out to allow the installed security software to cope with the infection. By this time, the infection has already spread and the cure is not to reverse any damage already done but to halt the spread and prevent infection of still un-hit computers.<br />
Meanwhile, the cure the <a href="http://latestwebsecurity.com/">anti-virus programmers</a> are not always perfect, so it can be considered a first response which may not fully contain the situation. This is where people make the biggest mistake in their security platform, that the programs they have installed are there to protect and prevent whilst the truth cannot be farther from the truth for the infection has already been active, way before it was detected. The follow-up security updates to security software makes the necessary adjustments enough to cope with the spread, halting it in it&#8217;s track, hopefully. The false security we feel works only if the threat is known which is true for variants of already known threats. New viruses are only known as much as the programmers who race to find a cure for it can work.<br />
The internet of criminals is here and is currently working, ready to exploit the latest security flaw left un-patched by the millions of developers the world over. The threat is real and the well publicized closure of an <a href="http://voices.washingtonpost.com/securityfix/2009/06/ftc_sues_shuts_down_n_calif_we.html?hpid=sec-tech">identified malware spreading site</a> and the arrest and <a href="http://www.securityinfowatch.com/root+level/1310031">conviction of a bot net creator/manager</a> is only the tip of the iceberg. Even the experts know of this which makes knowledge the key to surviving the internet and the malware it brings to our doors. Our saying that security software is quite futile doesn&#8217;t say it is totally useless, but rather to provide us with better chances of surviving the problems we face each day. having security software is only effective against known threats but at least it&#8217;s a start.<br />
The internet will never be truly a safe place for any of us mere humans who are becoming victims of the technology we ourselves have created.  Having security is a start, but knowing what to do and to help make the better world by reporting malware sites and spam is another little way we can all help each other, to survive the monster and friend we all use everyday, the monster that is the internet that brings harm to our desktops each and every minute of the connected day.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/uncategorized/an-internet-of-criminals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Implement a Strict IT Policy</title>
		<link>http://www.it-security-blog.com/it-security-basics/implement-a-strict-it-policy/</link>
		<comments>http://www.it-security-blog.com/it-security-basics/implement-a-strict-it-policy/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 16:34:29 +0000</pubDate>
		<dc:creator>Saran</dc:creator>
				<category><![CDATA[IT Security Basics]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Privacy & Anonymity]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.it-security-blog.com/?p=462</guid>
		<description><![CDATA[It is perhaps the headache of any IT head when it comes to implement policies to have a smooth running network and department. But while the essence of a good security system is evident, it is really the implementation part that is hard to accomplish. For one, the transition and building of security awareness from [...]]]></description>
			<content:encoded><![CDATA[<p><center><a href="http://www.it-security-blog.com/wp-content/uploads/2008/09/nsa-web-artwork.gif"><img src="http://www.it-security-blog.com/wp-content/uploads/2008/09/nsa-web-artwork-300x182.gif" alt="" title="nsa-web-artwork" width="300" height="182" class="alignnone size-medium wp-image-463" /></a></center></p>
<p>It is perhaps the <a href="http://www.thehealthblog.net/womens-health/female-incontinence-symptoms-and-causes/">headache</a> of any IT head when it comes to implement policies to have a smooth running network and department. But while the essence of a good security system is evident, it is really the implementation part that is hard to accomplish. </p>
<p>For one, the <a href="http://www.wallstreetfighter.com/2008/09/ratigan-explains-markets-with-sushi.html">transition and building</a> of security awareness from various threats that can easily make their way towards an acclaimed secure network is abundant. Manually or transmitted, suspicious files will always find a way especially if you are not that adamant towards making sure that all bases are covered as far as the security of your system and data is concerned. </p>
<p>Many people fail to appreciate that value of the data they have gathered. They fail to appreciate the value of a strict IT policy mainly because all they care about is a workstation to use and opening files (both internal and external) as they please. So if you put all these things together, you can imagine the problems that an IT guy has to work with. But to some, taking the initiative such as passwords and some hardware exclusions has to be made. </p>
<p>If you notice, some drives like the usual floppy drives or even USB ports are either missing or disabled. To make them work, certain permissions and passwords are set for them to be enabled. Only the IT administrator would know these <a href="http://www.bizcrunch.net/news/cutting-the-cost-of-business-travel/">security measures</a> and basic as they may seem, they really help a lot. </p>
<p>This is just a basic but effective way that IT personnel use. There are the usual network policies but for the sake of people who want to making it doubly sure, old and basic practices such as this is perhaps the best way to go.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-security-blog.com/it-security-basics/implement-a-strict-it-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

