Protect you computer and your data


Some of the Best Ways to Lose Your System Data

Have you ever thought about the best ways tostore  them  on  publicly accessible servers.
be negatively affected by a disaster, get
hacked, or otherwise part with data stored on13) Run your business without disaster
your computers? Here are some of the bestrecovery and business continuity plans. After
ways to lose system security, in noall, you can think clearly and make critical
particular  order:decisions  under  pressure,  right?
1) When an employee quits or is let go, leave14) Don't monitor your systems. They'll be
his network log-ins and e-mail accountsfine running by themselves, and if anything
enabled. You never know when he might want tomajor happens with the integrity or
check  in  on  things.availability of your information, you'll be
notified  automatically,  won't  you?
2) Rely solely on technology. Firewalls,
encryption and antivirus software are all you15) Don't back up your data, but if you must,
need  to  protect  your  information.don't test your backups. Also, leave your
backup media on-site -- preferably sitting on
3) Completely outsource your informationtop  of  an  uninterruptible  power  supply.
security initiatives. There's no need for
anyone inside your organization to worry16) Don't create any security policies that
about  such  matters.document how you're safeguarding your
information to protect your organization and
4) Leave your operating systems and softwareclients from information disasters and legal
applications with the default settings.liabilities.
System  hardening  is  for  the  birds.
17) Apply the principle of greatest
5) Don't train your users on your securityprivilege. Give all users the greatest amount
policies and what to look out for, such asof access to your information systems.
unsolicited e-mail attachments and commonEveryone should have access to everything --
hacker activities. Your users can't beit's  only  fair,  right?
burdened  with  more  training.
18) Don't subscribe to security bulletins and
6) If you do happen to have a securitymailing lists, and don't ever read
policy, never refer to it, enforce it, updateinformation  security  trade  magazines.
it  or  do  what  it  says.
19) Don't, under any circumstances, get upper
7) By all means, don't take an inventory ofmanagement involved in information security
your information systems or document yourinitiatives. They're business-focused and
network.shouldn't be bothered or even care about
technology or the liabilities associated with
8) Don't pay attention to or even bother totheir  information,  right?
understand  what  you're  trying  to protect.
20) Use passwords that consist of your pet's
9) Don't patch your software or update yourname, your name, your mom's maiden name, or
virus signatures, and never, ever runyour birthday. That way, you won't forget
vulnerability assessments to detect newlythem. Better yet, just use "password" for
discovered software flaws and systemyour passwords. Also, don't forget to write
misconfigurations. It's just toothem down and post them on your monitor or
time-consuming.keyboard.
10) Respond to hacker attacks, viruses andAnd,  last  but  not  least:
other intrusions as they happen -- don't be
proactive  in  dealing  with  them.21) Leave your servers and network equipment
in a room to which everyone, including
11) Ignore all known best practices andoutsiders  off  the  street,  has  access.
international information security standards
from the International StandardsBy following these practices you can be sure
Organization, Internet Engineering Taskthat your computers will be an easy target
Force, SANS Institute and your localfor viruses, disgruntled employees, hackers,
information security consultant, to name aand others. You can show up to work each day
few.with the pride of knowing that there's an
excellent chance that your business data will
12) Leave your databases, especially thosebe missing when you arrive. It's just a
containing credit card or other confidentialmatter of time, and it's all easily achieved.
information, unencrypted. And be sure to



1 A B C 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 96 97 98 99 100 101 102 103 104 105