<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-16596253</id><updated>2011-11-05T01:05:05.344-07:00</updated><category term='risk audit'/><category term='web application'/><category term='security assessment'/><category term='managed security services'/><category term='assessment'/><category term='it management'/><category term='facta'/><category term='document management'/><category term='risk management'/><category term='malware'/><category term='outsource security'/><category term='software as a service'/><category term='polices'/><category term='security strategy'/><category term='penetration testing'/><category term='data backup'/><category term='business continuity'/><category term='patch management'/><category term='outsourcing'/><category term='hacker tricks'/><category term='encryption'/><category term='security suite'/><category term='assessments'/><category term='information security'/><category term='e-mail'/><category term='network security'/><category term='email'/><category term='security policy template'/><category term='physical security'/><category term='personal information'/><category term='security policy'/><category term='network assessment'/><category term='incident response'/><category term='security policies'/><category term='controls'/><category term='risk treatment'/><category term='security standards'/><category term='security'/><category term='information'/><category term='security audit'/><category term='information security policy'/><category term='altiusit'/><category term='network management'/><category term='align it'/><category term='password test'/><category term='msp'/><category term='wireless security'/><category term='it alignment'/><category term='security software'/><category term='software'/><category term='red flags rule'/><category term='wireless network'/><category term='worm'/><category term='business impact analysis'/><category term='outsource it'/><category term='penetration assessment'/><category term='sensitive information'/><category term='jim kelton'/><category term='security outsourcing'/><category term='electronic documents'/><category term='anti-virus'/><category term='data security'/><category term='trojan horse'/><category term='risk analysis'/><category term='managed security'/><category term='passwords'/><category term='it governance'/><category term='policies and procedures'/><category term='bia'/><category term='procedures'/><category term='wireless security risks'/><category term='intangible assets'/><category term='retention'/><category term='data protection'/><category term='disaster recovery'/><category term='firewall'/><category term='it value'/><category term='security scan'/><category term='network security audit'/><category term='security vulnerabilities'/><category term='database'/><category term='disposal'/><category term='top 10'/><category term='security quiz'/><category term='it policies'/><category term='cloud computing'/><category term='usb'/><category term='electronic threats'/><category term='hacker tools'/><category term='penetration test'/><category term='employee'/><category term='top 10 tools'/><category term='windows vulnerabilities'/><category term='isms'/><category term='policies'/><category term='blog'/><category term='hackers'/><category term='wireless network risks'/><category term='risk assessment'/><category term='portable storage device'/><category term='equipment'/><category term='hard drive'/><category term='it strategy'/><category term='virus'/><category term='compliance'/><category term='it standards'/><category term='risks'/><category term='failure'/><category term='it outsourcing'/><category term='identity theft'/><category term='threats'/><category term='asset inventory'/><category term='network audit'/><title type='text'>IT Security Info</title><subtitle type='html'>No matter the size or age of your organization, it relies on information technology to keep it running smoothly day in and day out.  Protect your business operations with risk management and information security.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://itsecurityinfo.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>70</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-16596253.post-1071077784375680176</id><published>2011-02-03T14:47:00.000-08:00</published><updated>2011-02-03T14:50:50.025-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='blog'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Current Trends</title><content type='html'>We hope that you have found this blog to be useful.  New postings and updates can now be found on Altius IT's &lt;a href="http://www.altiusit.com/blog.htm"&gt;Information Security and Network Security Blog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Thank you for visiting,&lt;br /&gt;  Jim&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-1071077784375680176?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1071077784375680176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1071077784375680176'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2011/02/current-trends.html' title='Current Trends'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-9073399626924544502</id><published>2011-01-06T14:04:00.000-08:00</published><updated>2011-01-06T14:11:27.171-08:00</updated><title type='text'>Are you Managing your E-mail Risks?</title><content type='html'>E-mail is critical to the success and operation of most organizations.  Without e-mail, organizations are less efficient and can’t compete against larger, and more established firms.&lt;br /&gt;&lt;br /&gt;Computer users are critical to the success of an organization’s security platform.  E-mail threats such as spam, viruses, and phishing specifically target users and their end point devices.  Hand held devices put data "on the move" and the same users that are critical to the success of an organization’s security framework now present security related risks.&lt;br /&gt;&lt;br /&gt;E-mail systems require on-going IT management and monitoring.  Not only must e-mail hardware and software be periodically upgraded, these same systems must be patched on a regular basis.  &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Security response&lt;br /&gt;&lt;/strong&gt;IT departments are responding to known security threats by implementing traditional security measures:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Employee awareness - security education and training.&lt;/li&gt;&lt;li&gt;Anti-malware - anti-virus, anti-spam, anti-spyware, and anti-pop up software.&lt;/li&gt;&lt;li&gt;Patch management – keeping software and firmware patched and up-to-date.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;However, organization management must be aware of other types of risks including risks related to transmitting information:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Confidentiality - e-mail attachments can include confidential information such as customer lists and pricing that should not be sent to recipients outside of the organization.&lt;/li&gt;&lt;li&gt;Clear text – sensitive information can inadvertently be sent in clear text.&lt;/li&gt;&lt;li&gt;Traffic – e-mailing large documents creates bottlenecks and uses up valuable network bandwidth.&lt;/li&gt;&lt;li&gt;Compliance – meeting regulatory requirements related to information as it is collected, stored, archived, and secured.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Risk Assessments&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;IT risk assessments&lt;/a&gt; can help organizations evaluate additional risks such as service level performance, support (technical and user), redundancy and availability, as well as fail over and contingency plans.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-9073399626924544502?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/9073399626924544502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/9073399626924544502'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2011/01/are-you-managing-your-e-mail-risks.html' title='Are you Managing your E-mail Risks?'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-6950275001985361892</id><published>2010-12-06T11:26:00.000-08:00</published><updated>2010-12-06T11:45:32.830-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='risk treatment'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>IT Risk Management</title><content type='html'>IT risk management includes all of the activities that an organization carries out to manage information technology related risks. IT risk management is a formalized process and includes:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Risk Assessment&lt;/li&gt;&lt;li&gt;Risk Analysis&lt;/li&gt;&lt;li&gt;Risk Treatment&lt;/li&gt;&lt;li&gt;Risk Mitigation&lt;/li&gt;&lt;li&gt;Risk Review and Evaluation&lt;/li&gt;&lt;/ol&gt;1. Risk Assessment (Identify Risks)&lt;br /&gt;Risk Assessments identify possible sources of risk. They identify threats or events that could have a meaningful impact on the organization.&lt;br /&gt;&lt;br /&gt;2. Risk Analysis (Impact)&lt;br /&gt;Risk Analysis considers the probability and magnitude of each event. Risk evaluation compares the estimated risk with a set of risk criteria to determine the significance of the risk.&lt;br /&gt;&lt;br /&gt;3. Risk Treatment (Risk Response Action Plan)&lt;br /&gt;Risk Treatment identifies how each risk is to be addressed. Residual risk is the risk left over after implementing risk treatment steps that avoid the risk, transfer the risk, reduce the risk, or accept the risk.&lt;br /&gt;&lt;br /&gt;4. Risk Mitigation (Risk Control)&lt;br /&gt;Risk mitigation plans propose applicable and effective security controls that manage the risks. The plan should contain a schedule outling the tasks to be performed, individuals responsible for the actions, estimated dates, etc.&lt;br /&gt;&lt;br /&gt;5. Risk Review and Evaluation (Risk Effectiveness)&lt;br /&gt;Risk management plans change over time as the business evolves, as new threats emerge, as losses are incurred, and as management changes. Review the effectiveness of your approach and revise as necessary.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Risk assessments&lt;/a&gt; help organizations identify, manage, and reduce risks to acceptable levels.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-6950275001985361892?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/6950275001985361892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/6950275001985361892'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/12/it-risk-management.html' title='IT Risk Management'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-5287210481483969203</id><published>2010-11-03T09:51:00.000-07:00</published><updated>2010-11-03T10:17:29.068-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security policy'/><category scheme='http://www.blogger.com/atom/ns#' term='security policy template'/><category scheme='http://www.blogger.com/atom/ns#' term='information security policy'/><title type='text'>Start with Policies</title><content type='html'>Executive management knows that they need security controls to protect the organization's sensitive information and intellectual property. Unfortunately, many businesses use an ad-hoc approach to securing information, installing firewalls, anti-virus software, and other controls without a top down planned approach to managing risks.&lt;br /&gt;&lt;br /&gt;An Information Security Management Systems (ISMS) is a systematic approach to managing sensitive information so that it remains secure. An ISMS includes policies, procedures, plans, processes, practices, roles, responsibilities, resources, and structures used to protect and preserve information. It includes all of the elements that organizations use to manage and control their information security risks.&lt;br /&gt;&lt;br /&gt;ISMS security controls include administrative, management, technical, and legal approaches to managing risks. Policies, procedures, programs, techniques, technologies, guidelines, and organizational structures help organizations comply with industry standards and requirements by addressing information confidentiality, integrity, and availability.&lt;br /&gt;&lt;br /&gt;Security policies are essential to an effective security system and express management’s direction and guidance to implementing, maintaining, and improving an ISMS. Security policies include access controls, managing passwords, patch management, monitoring systems, business continuity, compliance, and many other areas.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/policies.htm"&gt;Security policy templates&lt;/a&gt; provide a top down planned approach to information security, helping organizations implement and improve their controls.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-5287210481483969203?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5287210481483969203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5287210481483969203'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/11/start-with-policies.html' title='Start with Policies'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-3690513741969612191</id><published>2010-10-20T13:58:00.000-07:00</published><updated>2010-10-20T14:06:17.050-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='it alignment'/><category scheme='http://www.blogger.com/atom/ns#' term='it strategy'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><category scheme='http://www.blogger.com/atom/ns#' term='network security audit'/><title type='text'>IT Strategy and Security</title><content type='html'>Information Technology (IT) strategy and security alignment ensures cohesive goals and results throughout the enterprise. IT strategy helps align IT to the organization, improve efficiencies, reduce costs, enhance customer service, and help the organization achieve a competitive edge in its market place.&lt;br /&gt;&lt;br /&gt;To ensure IT and enterprise alignment, analyze the organization’s markets, target audiences, products, services, and locations where the business competes. Review the critical success factors that determine the organization’s success and core competencies that provide the organization with a niche and competitive edge. Don't forget to review government regulations and analyze your organization's relationships and alliances with strategic partners.&lt;br /&gt;&lt;br /&gt;IT strategy should consider important information applications and technologies. Analyze important competencies to create and achieve the organization’s vision and strategy. Review your resources, risks, conflict resolution, responsibility, business partners, IT management, service providers, and project selection processes.&lt;br /&gt;&lt;br /&gt;IT strategy should include quality control and &lt;a href="http://www.altiusit.com/assessmentnetworksecurityaudit.htm"&gt;network security audits&lt;/a&gt; that help provide IT and executive management with appropriate feedback mechanisms.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-3690513741969612191?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/3690513741969612191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/3690513741969612191'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/10/it-strategy-and-security.html' title='IT Strategy and Security'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-3642494180154720579</id><published>2010-09-09T11:31:00.000-07:00</published><updated>2010-09-09T11:51:35.276-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='top 10'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='windows vulnerabilities'/><title type='text'>Top 10 Windows Vulnerabilities</title><content type='html'>By understanding Windows based vulnerabilities, organizations can stay a step ahead and ensure information availability, integrity, and confidentiality.  Listed below are the Top 10 Windows Vulnerabilities:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;em&gt;Web Servers&lt;/em&gt; - misconfigurations, product bugs, default installations, and third-party products such as php can introduce vulnerabilities.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Microsoft SQL Server&lt;/em&gt; - vulnerabilities allow remote attackers to obtain sensitive information, alter database content, and compromise SQL servers and server hosts. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Passwords&lt;/em&gt; - user accounts may have weak, nonexistent, or unprotected passwords.  The operating system or third-party applications may create accounts with weak or nonexistent passwords.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Workstations&lt;/em&gt; - requests to access resources such as files and printers without any bounds checking can lead to vulnerabilities. Overflows can be exploited by an unauthenticated remote attacker executing code on the vulnerable device.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Remote Access&lt;/em&gt; - users can unknowingly open their systems to hackers when they allow remote access to their systems.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Browsers&lt;/em&gt; – accessing cloud computing services puts an organization at risk when users have unpatched browsers.  Browser features such as Active X and Active Scripting can bypass security controls.  &lt;/li&gt;&lt;li&gt;&lt;em&gt;File Sharing&lt;/em&gt; - peer to peer vulnerabilities include technical vulnerabilities, social media, and altering or masquerading content.&lt;/li&gt;&lt;li&gt;&lt;em&gt;E-mail&lt;/em&gt; – by opening a message a recipient can activate security threats such as viruses, spyware, Trojan horse programs, and worms. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Instant Messaging&lt;/em&gt; - vulnerabilities typically arise from outdated ActiveX controls in MSN Messenger, Yahoo! Voice Chat, buffer overflows, and others.&lt;/li&gt;&lt;li&gt;&lt;em&gt;USB Devices&lt;/em&gt; - plug and play devices can create risks when they are automatically recognized and immediately accessible by Windows operating systems.&lt;/li&gt;&lt;/ol&gt;&lt;a href="http://www.altiusit.com/assessmentnetworksecurityaudit.htm" target="_blank"&gt;Security assessments&lt;/a&gt; help organizations identify, manage, and reduce their risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-3642494180154720579?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/3642494180154720579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/3642494180154720579'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/09/top-10-windows-vulnerabilities.html' title='Top 10 Windows Vulnerabilities'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-5908226592604748949</id><published>2010-08-03T15:20:00.000-07:00</published><updated>2010-08-03T15:37:23.310-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hacker tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='hacker tools'/><category scheme='http://www.blogger.com/atom/ns#' term='top 10 tools'/><title type='text'>Top 10 Hacker Tools</title><content type='html'>By understanding how hackers gain access to systems, organizations can stay a step ahead and ensure information availability, integrity, and confidentiality. Listed below is Altius IT's list of the Top 10 Hacker Tools and Techniques:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;em&gt;Reconnaissance&lt;/em&gt;. Hackers use tools to get basic information on your systems. Tools like Netcraft and PCHels to report on your domain, IP number, and operating system. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Network Exploration&lt;/em&gt;. The more information the hacker knows about your system the more wanys he can find vulnerabilities. Tools such as NMap identify your host systems and services. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Probe Tools&lt;/em&gt;. Some tools were initially designed to be used by system administrators to enhance their security. Now, these same tools are used by hackers to know where to start an attack. Tools like LANguard Network Scanner identify system vulnerabilities. &lt;em&gt;&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;Scanners&lt;/em&gt;. Internally, sniffer tools analyze network performance and applications. Hacker reconnaissance tools such as AET Network Scanner 10, FPort 1.33, and Super Scan 3 scan your devices to determine ports that are open and can be exploited. &lt;/li&gt;&lt;li&gt;Pass&lt;em&gt;word Cracker&lt;/em&gt;. Password tools are used by security administrators to find weak passwords. These tools may also be used by hackers. Password crackers include LC5, John The Ripper, iOpus Password Recovery XP, and LastBit. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Remote Administration Tools&lt;/em&gt;. Tools such as AntiLamer and NetSlayer are used by hackers to take partial or complete control of the victim's computer.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Backdoor&lt;/em&gt;. Backdoor tools and Trojan Horses exploit vulnerabilities and open your systems to a hacker. KrAIMer and Troj/Zinx-A can be used by hackers to gain access to your systems .&lt;/li&gt;&lt;li&gt;&lt;em&gt;Denial of Service (DoS)&lt;/em&gt;. Denial of service attacks overload a system or device so it can't respond or provide normal service. Hackers use tools such as Coldlife and Flooder overload a system.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Recover deleted files&lt;/em&gt;. Once hackers are inside your perimeter, they can use tools like Deleted File Analysis Utility to scan your hard drive partitions for deleted files that may still be recoverable.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Web Site Tools&lt;/em&gt;. Hackers use tools such as Access Diver and IntelliTamper to index your web site pages and directories. These tools can download your site to the hacker's local hard drive. Once on his system, the hacker analyzes the web site to identify and exploit security vulnerabilities.&lt;/li&gt;&lt;/ol&gt;&lt;a href="http://www.altiusit.com/"&gt;Security Assessments&lt;/a&gt; help organizations identify, manage, and reduce their risks from hackers and their emerging tools.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-5908226592604748949?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5908226592604748949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5908226592604748949'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/08/by-understanding-how-hackers-gain.html' title='Top 10 Hacker Tools'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-905335690227610174</id><published>2010-07-01T13:40:00.000-07:00</published><updated>2010-07-01T13:45:26.144-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wireless network risks'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless security risks'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless security'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless network'/><title type='text'>Top 10 Wireless Network Risks</title><content type='html'>Many organizations are installing and implementing wireless networks. To help business managers make informed decisions, Altius IT provides this list of the Top 10 wireless network risks:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;em&gt;Bandwidth Stealing&lt;/em&gt; – Outside intruders can connect to wireless access points. By using the Internet connection to download music, games, and other software, they reduce employee productivity.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Criminal Activity&lt;/em&gt; - An unauthorized user can use the Internet connection for malicious purposes such as hacking or launching Denial of Service Attacks.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Masquerade&lt;/em&gt; – By using the Internet line, an intruder “hides” under protective cover and appears to be a part of your organization.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Litigation Risks&lt;/em&gt; – Organizations are at risk if the intruder is doing illegal activity such as distributing child pornography. If the criminal activity is discovered and investigated, the origin of the attack will be traced back to the organization.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Reputation&lt;/em&gt; - An organization’s image and reputation is at stake if the wireless network was used as the initial access point to hack into restricted government networks.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Financial risks&lt;/em&gt; - Most ISP's not only reveal customer information to the authorities to assist with legitimate criminal investigations, but also hold the organization responsible for any and all activities related to the Internet connection.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Confidentiality&lt;/em&gt; – Wireless networks tend to be connected to in-house private networks. This may allow an intruder to completely bypass any hardware firewall protective devices between the private network and the broadband connection.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Evil Twins&lt;/em&gt; - Most new laptops include the ability to connect to wireless networks. Laptop computers may accidentally connect to fake (“evil twin”) networks. Employees believe they are connected to the authentic network however they are actually connected to a fake network that steals ids, passwords, and other confidential information.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Clear text&lt;/em&gt; – Some network information is transmitted in clear text and is not encrypted. Once inside your network, an intruder can install a network sniffer and gain access to confidential information without the victim’s knowledge.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Information Sensitivity&lt;/em&gt; – Not all data has the same sensitivity. Due to the risks involved with wireless networks, confidential data such as client lists, trade secrets, etc. should not be stored on or accessible by wireless networks.&lt;/li&gt;&lt;/ol&gt;&lt;a href="http://www.altiusit.com/assessmentnetworksecurityaudit.htm"&gt;Security Assessments&lt;/a&gt; help organizations identify, manage, and reduce their wireless network risks. For more information please visit us at &lt;a href="http://www.altiusit.com/"&gt;http://www.altiusit.com/&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-905335690227610174?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/905335690227610174'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/905335690227610174'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/07/top-10-wireless-network-risks.html' title='Top 10 Wireless Network Risks'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-310606957060343966</id><published>2010-06-08T15:15:00.000-07:00</published><updated>2010-06-08T15:53:38.823-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security suite'/><category scheme='http://www.blogger.com/atom/ns#' term='security software'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Suite or Best of Breed?</title><content type='html'>When choosing an enterprise security solution for your organization is it better to choose an all encompassing security suite from one vendor or select the best software in each class even if it means using a number of different vendors?&lt;br /&gt;&lt;br /&gt;Security software tends to come in modules with each module protecting against a specific type of threat. Different types of Internet threats include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Viruses, worms, Trojans&lt;/li&gt;&lt;li&gt;Spyware&lt;/li&gt;&lt;li&gt;Adware&lt;/li&gt;&lt;li&gt;Spam&lt;/li&gt;&lt;/ul&gt;Organizations such as Symantec, Trend Micro, McAfee and others offer security suites that protect against a wide range of threats. By using a security suite from one vendor your organization:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Reduces IT time - dealing with one vendor reduces IT time to install and maintain the software.&lt;/li&gt;&lt;li&gt;Reduces administrative time - by purchasing from one vendor, your organization reduces your number of vendors, checks produced, approvals needed, etc.&lt;/li&gt;&lt;li&gt;Reduces conflicts - in theory, by purchasing a security suite from one vendor, the vendor has tested its code and has fewer software conflicts.&lt;/li&gt;&lt;/ul&gt;There may be downsides, however, to limiting your security software to one vendor:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Single point of failure - should the security suite not function as designed (software expires, not licensed, bug or error in the code, etc.), your organization may be vulnerable to a wider range of threats.&lt;/li&gt;&lt;li&gt;Best of breed - by choosing a security suite, software modules from the chosen vendor may not be up to par with competing packages. For example, a security suite from a specific vendor may offer overall protection, however one component, say anti-spyware, may not offer the same level of protection as a best of breed anti-spyware software package.&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Risk assessments&lt;/a&gt; help provide answers to questions such as "Should we purchase a security suite from one vendor or purchase security software modules from a number of different vendors?" Risk assessments identify an organization's assets, threats to the assets, vulnerabilities that exist as a result of the threats, and the resulting impact on the organization. The risk assessment helps priortize risk areas so that the organization can make an informed decision when deciding between one vendor's security suite or electing best of breed software packages from a variety of vendors.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-310606957060343966?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/310606957060343966'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/310606957060343966'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/06/suite-or-best-of-breed.html' title='Suite or Best of Breed?'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-7275889809412687611</id><published>2010-05-19T09:41:00.000-07:00</published><updated>2010-05-19T09:59:27.522-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='physical security'/><title type='text'>Don't Forget Physical Security</title><content type='html'>Many business executives are concerned about protecting their sensitive data and intellectual property. They ask IT to address threats to these assets by implementing firewalls and anti-virus solutions to protect the organization's electronically stored information. What many executives don't know is that their major risks come from internal threats.&lt;br /&gt;&lt;br /&gt;Employees already have a sign-on ID and password to the network. By having this basic information, your staff already has access to resources such as customer data and email. However, the greatest risk may be physical access to IT systems.&lt;br /&gt;&lt;br /&gt;By having physical access to data centers, servers, backup tapes, laptop computers, flash drives, etc., employees can inadvertently, or on purpose, damage or destroy sensitive data. Contractors, service providers, and other personnel may also be granted physical access to sensitive data.&lt;br /&gt;&lt;br /&gt;Altius IT recommends that a physical security review be performed on a regular basis:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The first step in the physical security review is an inventory of your assets. &lt;/li&gt;&lt;li&gt;Then determine who has physical access to the assets. &lt;/li&gt;&lt;li&gt;Evaluate access and the risk to the organization. &lt;/li&gt;&lt;li&gt;Make changes as appropriate.&lt;/li&gt;&lt;/ul&gt;In many cases, it may make sense to bring in an outside consultant who specializes in this area, both to protect your sensitive assets plus ensure that your organization is minimizing its legal liability risks.  The International Association of Professional Security Consultants (&lt;a href="http://www.iapsc.org/"&gt;www.iapsc.org&lt;/a&gt;) has many members that can assist you.  Or, &lt;a href="http://www.altiusit.com/contactus.htm"&gt;contact us&lt;/a&gt; and we'll refer you to someone who can help.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-7275889809412687611?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7275889809412687611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7275889809412687611'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/05/dont-forget-physical-security.html' title='Don&apos;t Forget Physical Security'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-7612928847525376222</id><published>2010-04-08T13:08:00.000-07:00</published><updated>2010-04-08T13:45:20.621-07:00</updated><title type='text'>Penetration Test - Do you Know the Question?</title><content type='html'>An information security penetration test (pen test) is a systematic probing of a system for vulnerabilities. In most instances, the penetration test is performed externally, from a remote location, testing your systems much like a hacker would, looking for weakpoints.&lt;br /&gt;&lt;br /&gt;Penetration tests are used to evaluate network entry points such as a firewalls, routers, and other equipment for mis-configurations and other issues that can allow hackers access to internal systems. In some cases, testing can evaluate web servers and web site code for risks. Since web sites tend to have a lot of custom code, they are subject to a variety of risks including SQL injection attacks, cross site scripting, and many other vulnerabilities.&lt;br /&gt;&lt;br /&gt;Security risks develop on a daily basis. A system that is secure one day may be wide open the next. Penetration tests are a means of evaluating your systems to ensure information remains secure and your systems are available when they are needed.&lt;br /&gt;&lt;br /&gt;Penetration tests can range from simple automated tools that look for the most basic issues to more comprehensive approaches that rely on the expertise of the person performing the test. These higher end approaches typically emulate the process used by hackers, scanning systems for vulnerabilities, evaluating the results, running other tools to make additional inroads into the network, evaluating and responding as necessary to get deeper and deeper into the system being evaluated.&lt;br /&gt;&lt;br /&gt;The approach you use should consider the sensitivity of the information you are collecting and storing, the nature of your business, and the size of your organization. Most of all, the approach taken should answer your most basic question.&lt;br /&gt;&lt;br /&gt;The lowest cost approach typically answers the question "Are there any major security holes?" A comprehensive approach takes more time and relies on the knowledge and experience of the person performing the penetration test. The comprehensive approach answers the question "Is our information secure from hackers?"&lt;br /&gt;&lt;br /&gt;Before you choose your approach, make sure you know your question. It will help you properly align the right penetration test with your specific needs.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/assessmentpenetration.htm"&gt;Penetration tests&lt;/a&gt; help protect your intellectual property, reduce your risks, improve your competitive position, and enhance your image and reputation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-7612928847525376222?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7612928847525376222'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7612928847525376222'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/04/penetration-test-what-question-are-you.html' title='Penetration Test - Do you Know the Question?'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-8607454320069678650</id><published>2010-03-04T12:40:00.000-08:00</published><updated>2010-03-04T13:30:01.173-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='threats'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud computing'/><category scheme='http://www.blogger.com/atom/ns#' term='risks'/><title type='text'>Cloud Computing - Top 10 Threats</title><content type='html'>With 24x7 availability and accessible by almost any device with a browser, cloud computing allows organizations to scale their IT infrastructure and software applications as needed. However, like any technology, cloud computing has its risks.&lt;br /&gt;&lt;br /&gt;#1) Changes the business model. Cloud computing changes the way IT services are delivered. No longer delivered from an on-site location, servers, storage, and applications are provided by external service providers. Organizations need to evaluate the risks associated with the loss of control of the infrastructure.&lt;br /&gt;&lt;br /&gt;#2) Abuse. Initial registration with a cloud computing service is a pretty simple process. In many cases, the service provider even offers a free trial period. Organizations should consider their risks due to anonymous signup, lack of validation, service fraud, and ad-hoc services.&lt;br /&gt;&lt;br /&gt;#3 Insecure interfaces. Application programming interfaces (API) are used to establish, manage, and monitor services. These interfaces may be subject to security vulnerabilities that put your users at risk.&lt;br /&gt;&lt;br /&gt;#4 Malicious insiders. One of the benefits of cloud computing is that your organization doesn't need to know the technical details of how the services are delivered. The provider's procedures, physical access to systems, monitoring of employees, and compliance related issues are transparent to the customer. Without full knowledge and control, your organization may be at risk.&lt;br /&gt;&lt;br /&gt;#5 Shared technology. Cloud computing allows multiple organizations to share and store data on the servers. However, the original server hardware and operating systems were most likely designed for use by a single tenant (one organziation). Organizations should ensure the appropriate controls are in place to keep your data secure.&lt;br /&gt;&lt;br /&gt;#6 Data loss and leakage. With shared infrastructure resources, organizations should be concerned about the service provider's authentication systems that grant access to data. Organizations should also ask about encryption, data disposal procedures, and business continuity.&lt;br /&gt;&lt;br /&gt;#7 Account hijacking. Organizations should be aware that account hijacking can occur. Simple Internet registration systems, phishing and fraud schemes can allow a hacker to take over control of your account.&lt;br /&gt;&lt;br /&gt;#8 Risk profile. For many service providers, the focus is on functionality and benefits, not security. Without appropriate software updates, intrusion preventation, and firewalls, your organization may be at risk.&lt;br /&gt;&lt;br /&gt;#9 Users. When using cloud services, your users' activities such as clicking links in e-mail messages, Instant Messaging, visiting fake web sites, etc. can download malware to a local workstation. Once installed, the malware can launch attacks against your internal network.&lt;br /&gt;&lt;br /&gt;10# Browsers. Several years ago, hackers used to attack software operating systems. More recently, hackers have shifted their attacks to target user browsers. By exploiting browser vulnerabilities, hackers have access to the same applications and data that your users access.&lt;br /&gt;&lt;br /&gt;Internet cloud computing services provide both business and technical benefits. &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Risk assessments&lt;/a&gt; help organizations identify, manage, and reduce their cloud computing risks so that they may achieve the greatest benefits at the lowest level of risk.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-8607454320069678650?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8607454320069678650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8607454320069678650'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/03/cloud-computing-top-10-threats.html' title='Cloud Computing - Top 10 Threats'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-1719853828095971491</id><published>2010-02-02T10:08:00.000-08:00</published><updated>2010-02-02T10:55:05.634-08:00</updated><title type='text'>Justifying a Security Audit</title><content type='html'>How do you justify hiring an outside, independent security auditor to perform an assessment of your organization's technology systems?  It is an easy decision if you've been hacked and you want the peace of mind knowing that your systems are now secure.  It is also an easy decision if you are in a compliance related industry that mandates annual security audits.  What do you do if you don't fall into one of these categories?  How do you justify bringing in an outside auditor?&lt;br /&gt;&lt;br /&gt;In many instances, security audits provide both tangible and intangible benefits.  For example, an outside security audit of your systems demonstrates to prospects your commitment to protecting their data.  By being proactive, you gain a competitive edge which helps you close more deals.  If, in talking with your prospects, you find you can close 5% more deals, you can quantify the benefit of the security audit as it relates to your sales and marketing activities.&lt;br /&gt;&lt;br /&gt;Security audits can also help protect your intellectual property (IP).  For example, if you have a staff of programmers and estimate the value of your custom code at millions of dollars, you'll want to ensure that the proper controls are in place and working with sufficient effectiveness to protect your IP assets.  A loss of your IP could result in significant damage to your company, resulting is a drop in revenues of 25% or greater.&lt;br /&gt;&lt;br /&gt;Many organizations are only worried about hackers and external threats.  However, studies have shown that your employees are your greatest risk since they already have access to your systems.  By reducing your internal security risks, you lower your costs and increase employee efficiency.  Management also has the peace of mind knowing that your information is secure from both internal and external threats. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Security audits&lt;/a&gt; provide a bottom line return on the investment by increasing your revenues, protecting your intellectual property, reducing your risks, and enhancing your image and reputation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-1719853828095971491?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1719853828095971491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1719853828095971491'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/02/justifying-security-audit.html' title='Justifying a Security Audit'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-2537960251618391764</id><published>2010-01-13T11:14:00.000-08:00</published><updated>2010-01-13T11:19:41.658-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asset inventory'/><category scheme='http://www.blogger.com/atom/ns#' term='assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>Information Security Tip #1: Inventory Your Assets</title><content type='html'>Understanding your information assets and access to information is essential to assessing security vulnerabilities.  Whether you are an industry giant or a lean-and-mean one-person shop, here are some tips on conducting your own internal investigation:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Inventory. Inventory all servers, computers, flash drives, disks, and other equipment to find out where your company stores sensitive data.  Also include laptops, employees’ home offices, cell phones, and e-mail.  No security audit is complete until you check everywhere sensitive data might be stored.&lt;/li&gt;&lt;li&gt;Interview. Track personal information through your business by talking with your technology staff, human resources office, accounting personnel, and outside service providers.  Get a complete picture of who sends your company sensitive data.  Do you get it from customers?  Call centers?  Credit card companies?  Banks or other financial institutions?  What about affiliates and contractors? &lt;/li&gt;&lt;li&gt;Forms.  How does sensitive data come in to your company?  Via your website? E-mail?  Through the mailroom?  What kind of information is collected at each entry point?  Customers’ credit card, debit, or checking account numbers?  Do you receive sensitive health or financial data?&lt;/li&gt;&lt;li&gt;Access. Who has, or could have, access to the information?  Which of your employees has permission to look at or view sensitive data?  Could anyone else get a hold of it?  What about vendors who supply and update software you use to process credit card transactions?  Do you have contractors that run your call center, distribution, or fulfillment operations?&lt;/li&gt;&lt;li&gt;Storage.  Different types of data present varying risks.  Pay particular attention to how you store personally identifying information such as Social Security numbers, credit card numbers, checking account, or other financial information.  Determine if the data you store can facilitate fraud or identity theft if it fell into the wrong hands.&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://www.altiusit.com/"&gt;Network security assessments&lt;/a&gt; help identify, manage, and reduce your IT related risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-2537960251618391764?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2537960251618391764'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2537960251618391764'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2010/01/information-security-tip-1-inventory.html' title='Information Security Tip #1: Inventory Your Assets'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-2026371199120930852</id><published>2009-12-03T09:54:00.000-08:00</published><updated>2009-12-03T09:57:08.671-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='retention'/><category scheme='http://www.blogger.com/atom/ns#' term='disposal'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Information Security Tip #2: Less is More</title><content type='html'>Protect your customers and employees by securing sensitive data in your possession.  Keep only what you need for business:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Eliminate.  If you don’t have a valid business reason to collect personal information, don’t collect or gather such information.  Once you gather information it must be stored, archived, protected, and disposed.  By not collecting the information, you save your organization a lot of unnecessary work.  Review the forms you use to gather data (applications, fill in web site forms, etc.) and revise them to eliminate requests for information you don’t need.&lt;/li&gt;&lt;li&gt;Archive. Unless you have a legitimate business justification, don’t store and retain sensitive information.  Keeping sensitive data longer than necessary creates an unwarranted risk for fraud.&lt;/li&gt;&lt;li&gt;Defaults.  Sometimes the software you use is preset to store information permanently. Check your settings to make sure you’re not inadvertently keeping more than you need.&lt;/li&gt;&lt;li&gt;Compliance.  Ensure your organization meets required compliance privacy and security requirements. &lt;/li&gt;&lt;li&gt;Retention. If you must keep information for business reasons or to comply with the law, develop a written records retention policy to identify what must be kept, how to secure it, how long to keep it, who’s authorized to access it, and how to dispose of it securely when you no longer need it.&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Risk assessments&lt;/a&gt; help organizations identify, manage, and reduce their information risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-2026371199120930852?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2026371199120930852'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2026371199120930852'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/12/information-security-tip-2-less-is-more.html' title='Information Security Tip #2: Less is More'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-8968239732870304074</id><published>2009-11-09T11:58:00.000-08:00</published><updated>2009-11-09T12:03:26.577-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='policies and procedures'/><category scheme='http://www.blogger.com/atom/ns#' term='polices'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Information Security Tip #3: Procedures</title><content type='html'>Policies and procedures help you meet your obligation to your customers, affiliates, and employees.   Protect your electronic information with these simple steps:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Physical security.  Network defenses can be critical, but when it comes to protecting personal information, don’t forget physical security.  Ensure access to network servers is restricted to authorized personnel.  &lt;/li&gt;&lt;li&gt;Encryption.  Use encryption to protect sensitive data such as credit card numbers, social security numbers, driver’s license numbers, etc.&lt;/li&gt;&lt;li&gt;Viruses.  Viruses, spyware, and other malware can compromise your systems and your data.  Ensure your anti-virus and anti-spyware software is updated on a regular basis.&lt;/li&gt;&lt;li&gt;Passwords.  Most organizations use an ID and password to grant access to your data.  Ensure your passwords are long and complex and changed on a regular basis.&lt;/li&gt;&lt;li&gt;Education.  Remind your employees that electronic security is everybody’s business.  Hackers certainly pose a threat, but sometimes the biggest risk to a company’s security is an employee who hasn’t learned the basics.&lt;/li&gt;&lt;li&gt;Access.  Provide access to sensitive information only on a “need to know” basis.  Have a procedure in place for making sure that workers who leave your employ or move to another part of the business no longer have access to off-limits information.&lt;/li&gt;&lt;li&gt;Detection.  Intrusion detection systems can alert you to breaches in your network security.  IT should monitor incoming and outgoing traffic for higher-than-average use at unusual times of the day.  &lt;/li&gt;&lt;li&gt;Patching.  Check expert resources like www.sans.org and your software vendors’ websites for alerts about the latest vulnerabilities and vendor-approved patches.&lt;/li&gt;&lt;li&gt;Providers.  Ensure security practices of your contractors and service providers.  Before outsourcing business functions, ensure agreements define security requirements. &lt;/li&gt;&lt;li&gt;Documentation.  Organization policies give direction and guidance but generally lack sufficient details to describe how things should be done.  By documenting your detailed procedures, your organization can ensures consistent and sustainable protection of your information assets.&lt;/li&gt;&lt;/ul&gt;Not all risks are created equal and &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;risk assessments&lt;/a&gt; help firms reduce their costs while increasing protection of their “information assets”.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-8968239732870304074?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8968239732870304074'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8968239732870304074'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/11/information-security-tip-3-procedures.html' title='Information Security Tip #3: Procedures'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-4171122574120951230</id><published>2009-10-01T13:27:00.000-07:00</published><updated>2009-10-01T13:46:33.556-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='equipment'/><category scheme='http://www.blogger.com/atom/ns#' term='disposal'/><category scheme='http://www.blogger.com/atom/ns#' term='hard drive'/><category scheme='http://www.blogger.com/atom/ns#' term='information'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><title type='text'>Information Security Tip #4: Disposal</title><content type='html'>&lt;strong&gt;Disposal&lt;/strong&gt;. Ensure your organization takes the following precautions when disposing of workstations, laptops, USB flash drives, and other devices that may contain sensitive information:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Delete&lt;/em&gt;. Deleting a computer file doesn’t mean that the information has been permanently removed from your system. The data may continue to exist on the computer’s hard drive and could be easily retrieved. Ensure your employees request assistance from your IT department when permanently deleting data.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Disposal&lt;/em&gt;. When getting rid of old computers, laptops, hard drives, portable storage devices, cell phones, etc., use wipe utility programs or physically destroy the media. Wipe utility programs are inexpensive and overwrite the contents so that the files are no longer recoverable.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Remote&lt;/em&gt;. Whether working from home or on the road, ensure telecommuters and business travelers maintain your company’s high security standards. Remind employees and contractors to be as careful when disposing of sensitive documents off-site as they are when creating them.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Compliance&lt;/em&gt;. If you use consumer credit reports in your business, you may be subject to the FTC’s Disposal Rule. The Rule requires companies to adopt reasonable and appropriate disposal practices to prevent the unauthorized access to, or use of, information in credit reports. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Papers&lt;/em&gt;. Effectively dispose of paper records containing sensitive data. Having shredders available throughout the workplace helps ensure employees understand the need to properly dispose of sensitive information.&lt;/li&gt;&lt;/ul&gt;IT security audits and assessments help organizations identify, manage, and reduce their security risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-4171122574120951230?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4171122574120951230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4171122574120951230'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/10/information-security-tip-4-disposal.html' title='Information Security Tip #4: Disposal'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-8177313303871953717</id><published>2009-09-10T16:17:00.000-07:00</published><updated>2009-09-10T16:25:12.710-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='incident response'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Information Security Tip #5: Incident Response</title><content type='html'>&lt;p&gt;&lt;strong&gt;Incident Response&lt;/strong&gt;. Taking steps to protect personal information in your files and on your network can go a long way toward preventing a security breach. Nevertheless, breaches can happen. That’s why Altius IT recommends that organizations have a plan in place to respond to security incidents. Altius IT's tips on customizing your company’s security response plan include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Team&lt;/em&gt;. Senior management sets the tone for an organization’s commitment to data security. Designate a well-respected senior official to head up your response team.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Plan&lt;/em&gt;. Once you’ve put together your response team, have them draft plans for how your business will respond to different types of security incidents. Sample scenarios may include a lost laptop, servers hacked, internal theft of data, etc. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Timely&lt;/em&gt;. If your staff suspects a breach, investigate it immediately. Waiting days to convene a committee can waste precious time.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Disconnect&lt;/em&gt;. If you suspect a computer breach, immediately sever the compromised computer’s access to the Internet and to your network. To assess the impact, ask your IT staff to preserve any available network logs, file transfer logs, system logs, and access reports. Also investigate if intruders opened files or placed new programs on your computer.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Contact&lt;/em&gt;. Consider whom to inform in the event of an incident, both inside and outside your company. You may need to notify consumers, law enforcement agencies, customers, credit bureaus, and other businesses that may be affected by the breach. In addition, about 40 states have laws addressing data breaches. Have that information on file before you need it.&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Security assessments&lt;/a&gt; help organizations identify, manage, and reduce their risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-8177313303871953717?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8177313303871953717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8177313303871953717'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/09/information-security-tip-5-incident.html' title='Information Security Tip #5: Incident Response'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-7297807556808139459</id><published>2009-08-04T15:13:00.000-07:00</published><updated>2009-08-04T16:20:48.737-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='assessments'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic threats'/><category scheme='http://www.blogger.com/atom/ns#' term='intangible assets'/><category scheme='http://www.blogger.com/atom/ns#' term='information'/><category scheme='http://www.blogger.com/atom/ns#' term='risks'/><title type='text'>Protecting Intangible Assets</title><content type='html'>As recently as 1982, tangible equipment such as buildings, facilities, furniture, computer hardware, etc. comprised 62% of an organization's business value. Unfortunately, large buildings and facilities were expensive to acquire and maintain. Over time, organizations adopted a new business model, relying on technology to deliver products and services at a lower cost.&lt;br /&gt;&lt;br /&gt;By reworking their business model, firms automated many of their manual processes and migrated from manufacturing plants and equipment to the electronic delivery of products and services. This transition shifted organization value from tangible to intangible assets. By 2002, tangible assets were only 12% of an average company's market value. 88% of the value of the organization was attributed to intangible assets such as intellectual property and "information assets".&lt;br /&gt;&lt;br /&gt;With the change in business model from tangible equipment to "information assets", organizations experienced a new type of business risk, electronic threats. Electronic threats included viruses, hackers, data theft, and many others. Without proper protection, organizations found that their market value was at risk. Over time, organizations implemented security in a reactive manner, first installing anti-virus software and later implementing firewalls as Internet risks increased. Unfortunately, this ad-hoc approach wasn't sufficient and many firms experienced downtime, lost employee efficiency, and reduced market value.&lt;br /&gt;&lt;br /&gt;Leading organizations took a different approach, realizing that security needed to be implemented according to the value of their intangible assets. Since many threats were hidden, a proactive approach of using risk assessments helped these organizations identify hidden threats, implement steps to manage these risks, and eliminate or reduce threats to acceptable levels.&lt;br /&gt;&lt;br /&gt;Not all risks are created equal and &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;risk assessments&lt;/a&gt; help firms reduce their costs while increasing protection of their “information assets”.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-7297807556808139459?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7297807556808139459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7297807556808139459'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/08/protecting-intangible-assets.html' title='Protecting Intangible Assets'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-8351668838826964483</id><published>2009-07-15T09:45:00.000-07:00</published><updated>2009-07-15T09:59:36.273-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='risk analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Risk Analysis</title><content type='html'>Risk analysis helps organizations secure sensitive information, protect its image and reputation, and meet compliance requirements. A formal risk analysis process includes identifying risk areas and implementing controls to reduce risks to acceptable levels.&lt;br /&gt;&lt;br /&gt;The first step in the process is to identify assets that need protection. The assets can be tangible or intangible and generally provide value to the organization. Examples of tangible assets include buildings, employees, computer and network servers, etc. Examples of intangible assets may include intellectual property, custom software presently installed and under development, customer lists, goodwill, etc.&lt;br /&gt;&lt;br /&gt;Once the assets have been identified, you will want to identify threats to the assets. The threats can be unintentional or intentional and may include:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Natural threats (acts of God)&lt;/li&gt;&lt;li&gt;Accidental or unintentional threats (worker illness, equipment failure)&lt;/li&gt;&lt;li&gt;Intentional threats such as asset theft and asset tampering (malicious damage)&lt;/li&gt;&lt;/ul&gt;For each threat, there may be one or more specific vulnerabilities. Vulnerabilities may be based upon location, employee skill sets, network access controls, network monitoring, etc. Examples of vulnerabilities include lack of employee security related education, user knowledge, security functionality, poor password selection by employees, etc. Once a vulnerability has been identified, you should determine how likely it is to occur (probability).&lt;br /&gt;&lt;br /&gt;Once your assets, threats, and vulnerabilities have been identified, you can then evaluate the potential impact or loss. Examples of impact can include the cost of downtime, loss of information, breach of legislation, impact on reputation, loss of opportunity, etc. For each asset, consider the asset value, specific vulnerability, and probability of the event.&lt;br /&gt;&lt;br /&gt;The next step in the risk analysis process is to develop controls that help eliminate risks or reduce them to an acceptable levels.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Risk assessments&lt;/a&gt; help organizations identify, manage, and reduce their risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-8351668838826964483?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8351668838826964483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8351668838826964483'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/07/risk-analysis.html' title='Risk Analysis'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-2820648715199389695</id><published>2009-06-16T10:24:00.000-07:00</published><updated>2009-06-16T10:38:41.902-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic documents'/><category scheme='http://www.blogger.com/atom/ns#' term='document management'/><title type='text'>Proactive Document Management</title><content type='html'>As organizations review their business processes and make them more efficient, document management solutions help automate the process of electronically capturing, storing, and securely managing business information.&lt;br /&gt;&lt;br /&gt;Benefits of electronic document management solutions include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Centralized storage of information leads to increased employee productivity&lt;/li&gt;&lt;li&gt;Enhanced levels of customer service through improved access to information&lt;/li&gt;&lt;li&gt;Reduced costs by instantly locating documents&lt;/li&gt;&lt;/ul&gt;Document management solutions do have their risks.  If documents are not filed using a formal methodology, document management solutions can reduce employee productivity and increase your costs. In addition, failure to manage and secure your documents may increase your liability to lawsuits.&lt;br /&gt;&lt;br /&gt;A proactive approach to managing electronic files protects your documents and helps meet compliance requirements. Many firms are using &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;security audits&lt;/a&gt; to help them identify, manage, and reduce their document management risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-2820648715199389695?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2820648715199389695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2820648715199389695'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/06/proactive-document-management.html' title='Proactive Document Management'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-1486527901286851707</id><published>2009-05-14T14:35:00.000-07:00</published><updated>2009-05-14T14:49:19.469-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='employee'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Security During Tough Economic Times</title><content type='html'>&lt;strong&gt;Employee risks.&lt;/strong&gt; Although many decision makers are focused on getting through tough economic times, security experts say that management needs to be weary of employees, who fearful that their jobs could be on the cutting block, could take actions that potentially jeopardize the physical and logistical security of the company. As companies automate manual processes and adapt to the changing economic environment, merge IT departments, and cut back on controls, organizations face greater threats.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Risk assessments&lt;/a&gt; can help identify sensitive and proprietary information, risks to the data, and relevant state and federal compliance requirements. Everyone is concerned about security and protecting sensitive information. Once sensitive data and compliance requirements have been identified, the organization can leverage the information from the risk assessments to build in security structures that protect against IT, people, and process threats.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Network and security assessments&lt;/a&gt; help protect your sensitive information and provide peace of mind.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-1486527901286851707?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1486527901286851707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1486527901286851707'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/05/security-during-tough-economic-times.html' title='Security During Tough Economic Times'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-9005771972801619290</id><published>2009-04-09T13:52:00.000-07:00</published><updated>2011-05-11T14:46:47.376-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='penetration test'/><category scheme='http://www.blogger.com/atom/ns#' term='penetration assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='penetration testing'/><category scheme='http://www.blogger.com/atom/ns#' term='security scan'/><title type='text'>Automated Scans Aren't Sufficient</title><content type='html'>&lt;strong&gt;Automated scanners&lt;/strong&gt;. If automated vulnerability scanners caught all security risks, hackers would be out of business and security personnel wouldn't have much to do. In reality, automated vulnerability scanners are only one tool used in the process of identifying and managing security risks.&lt;br /&gt;&lt;br /&gt;For many organizations, web applications are a vulnerable element of an organization’s IT infrastructure. As your organization uses the Internet for customer, supplier, employee, and vendor interactions, Internet technologies and database interfaces become complex and require additional security.&lt;br /&gt;&lt;br /&gt;Automated web site scans provide little defense against knowledgeable hackers and full scale web attacks. Hackers don’t rely exclusively on automated scanners and neither should you. Organizations should use manual tools and experienced professionals to find technical vulnerabilities as well as identify risk areas created during the design, programming, installation, and maintenance phases of a software development lifecycle.&lt;br /&gt;&lt;br /&gt;By emulating the approach used by hackers, organizations can better protect themselves and the sensitive information stored on servers. Altius IT recommends &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;network and security audits&lt;/a&gt; that can assess internal &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;network security&lt;/a&gt;, &lt;a href="http://www.altiusit.com/assessmentpenetration.htm"&gt;firewalls&lt;/a&gt;, and &lt;a href="http://www.altiusit.com/assessmentwebapp.htm"&gt;web application&lt;/a&gt; vulnerabilities.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-9005771972801619290?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/9005771972801619290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/9005771972801619290'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/04/automated-scans-arent-sufficient.html' title='Automated Scans Aren&apos;t Sufficient'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-1071825754231006586</id><published>2009-03-03T14:31:00.000-08:00</published><updated>2009-03-03T14:40:27.706-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><category scheme='http://www.blogger.com/atom/ns#' term='security quiz'/><title type='text'>Small Business Security Quiz</title><content type='html'>&lt;strong&gt;Take this quiz to determine your Security Quotient.&lt;/strong&gt;  Preparation is the key to protecting your company’s information assets.  Take this security quiz to determine your Security Quotient.&lt;br /&gt;1) We have recent off-site computer backups.  Yes/No&lt;br /&gt;2) We have updated anti-virus software on all computers/servers.  Yes/No&lt;br /&gt;3) We restrict employee access to confidential information.  Yes/No&lt;br /&gt;4) All of our policies are documented and in written form.  Yes/No&lt;br /&gt;5) We have a firewall to protect us.  Yes/No&lt;br /&gt;6) We encrypt confidential documents/E-mail.  Yes/No&lt;br /&gt;7) We have a formal electronic document archiving procedure.  Yes/No&lt;br /&gt;8) We monitor and restrict Internet access.  Yes/No&lt;br /&gt;9) We performed a security assessment of our IT systems.  Yes/No&lt;br /&gt;10) We can distinguish an intruder from normal Internet traffic.  Yes/No&lt;br /&gt;&lt;br /&gt;Score one point for each Yes answer. &lt;br /&gt;  8 or more points - You are well on your way to securing your IT systems.&lt;br /&gt;  6 to 7 points - keep working, you may need assistance to reduce risks.   &lt;br /&gt;  5 or fewer points - you need to make security a priority and get assistance as soon as possible.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Network and security assessments&lt;/a&gt; help protect your sensitive information and provide peace of mind.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-1071825754231006586?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1071825754231006586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1071825754231006586'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/03/small-business-security-quiz.html' title='Small Business Security Quiz'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-4200593315198331292</id><published>2009-02-03T13:06:00.000-08:00</published><updated>2009-02-03T13:32:28.482-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='managed security services'/><title type='text'>Managed Security Services</title><content type='html'>Leading firms are taking a proactive approach to security and using managed security services to reduce their IT related risks. Managed security services typically provide traditional forms of security protection:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Network Infrastructure&lt;/em&gt; - Physical access to servers, system backups with off-site rotation, encrypting the backup media, and protecting wireless networks.&lt;br /&gt;Internet Connectivity - protection can include firewalls &amp;amp; Virtual Privacy Network (VPN), intrusion detection and prevention, and remote connectivity.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Management&lt;/em&gt; - incident response plans, patch management, and change management processes.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Employee Management&lt;/em&gt; - policies and procedures, passwords, protection against social engineering, locking down USB thumb drives, handheld PDA's, encrypting laptop hard drives, etc.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Document Management&lt;/em&gt; - protection includes access privileges, document retention and archiving, encryption, etc.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Electronic threats&lt;/em&gt; - protection from anti-virus, anti-spyware, anti-popup, etc.&lt;/li&gt;&lt;li&gt;&lt;em&gt;E-mail &amp;amp; Communications&lt;/em&gt; - anti-spam, e-mail archiving, instant messaging (IM), and archiving.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Risk Management&lt;/em&gt; - risk evaluation, business continuity planning, testing, etc.&lt;/li&gt;&lt;/ul&gt;While managed security services provide the initial layers of protection against IT related threats, they should be supplemented with security assessments and audits. Assessments and audits help ensure the organization's security expenditures are properly allocated to the most important areas. In addition, &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;assessments and audits&lt;/a&gt; help protect the organization's intellectual property and its image and reputation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-4200593315198331292?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4200593315198331292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4200593315198331292'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/02/managed-security-services.html' title='Managed Security Services'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-7765622065274070600</id><published>2009-01-06T15:11:00.000-08:00</published><updated>2009-01-06T15:23:53.112-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><title type='text'>Security Assessments – A Subscription Service</title><content type='html'>&lt;strong&gt;A matter of priority.&lt;/strong&gt;  Not every security risk is created equal.  Some risks have a greater impact than others.  In addition, some threats are more likely to occur than others.  Security assessments help organizations allocate their budget to the areas that reduce risks.&lt;br /&gt;&lt;br /&gt;Security is an on-going process and leading organizations are taking a subscription approach to security assessments.  With new vulnerabilities discovered on a daily basis, a system that is secure one day may be completely wide open the next.  Much like regular anti-virus updates, subscribing to recurring security assessments helps your organization identify weaknesses before they can be exploited.  Security assessments provide specific knowledge about your system, allowing you to more effectively allocate your security budget.&lt;br /&gt;&lt;br /&gt;Don’t wait for an unwanted intruder to discover your network vulnerabilities. A comprehensive network &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;security assessment&lt;/a&gt; helps:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Protect your image and reputation&lt;/li&gt;&lt;li&gt;Reduce your costs by cost effectively allocating your security budget to the most important areas&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-7765622065274070600?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7765622065274070600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7765622065274070600'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2009/01/security-assessments-subscription.html' title='Security Assessments – A Subscription Service'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-7376536668855772814</id><published>2008-12-04T11:46:00.000-08:00</published><updated>2008-12-04T11:56:46.293-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Mitigating Risks</title><content type='html'>&lt;p&gt;Organizations are finding that IT systems are a double edge sword. Not only do they increase employee productivity and reduce costs, they also increase risks as intellectual property and sensitive information are stored in a central location. &lt;a href="http://www.altiusit.com/assessmentsoverview.htm"&gt;Assessments&lt;/a&gt; can help organizations identify and manage risks. Once risk areas have been identified, organizations have a number of ways to mitigate or reduce their risks. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Risk Assumption&lt;/em&gt;. Accept the potential risk and continue operating the IT system or implement controls to lower the risk to an acceptable level. Administrative, physical, and technical controls help lower the organization's risks. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Risk Avoidance&lt;/em&gt;. Avoid the risk by eliminating the risk and/or consequence. For example, bypass or eliminate certain functions of a system or shut down the system when risks are identified. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Risk Limitation&lt;/em&gt;. Limit the risk by implementing controls that minimize the adverse impact of the risk. For example, implement preventive controls such as Intrusion Prevention Systems (IPS) that actively identify and restrict access to information. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Risk Planning&lt;/em&gt;. Manage risks by developing a risk mitigation plan that prioritizes, implements, and maintains controls. Implement managed services to minimize risks. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Risk Research&lt;/em&gt;. Lower the risk of loss by acknowledging the vulnerability or flaw and researching controls to correct the vulnerability. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Risk Transference&lt;/em&gt;. Compensate for the loss by transferring the risk to another party. In addition to securing systems,organizations have the option to insure against security breaches. For example, insurance can cover the cost of regulatory mandated notifications that a security breach has occurred as well as fines, fees, or penalties arising from privacy or consumer protection errors. &lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-7376536668855772814?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7376536668855772814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7376536668855772814'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/12/mitigating-risks.html' title='Mitigating Risks'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-5278362784218929578</id><published>2008-11-11T15:21:00.000-08:00</published><updated>2008-11-11T15:28:40.550-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='database'/><title type='text'>Database Regulatory and Compliance Issues</title><content type='html'>Sarbanes-Oxley (SOX), the Health Insurance Portability and Accountability Act (HIPAA), and the Gramm-Leach-Bliley (GLB) Act were all enacted to help protect information.  These acts require internal controls to protect information integrity, confidentiality, availability, and accountability.  While accountants and auditors are familiar with internal controls, many IT departments lack the the knowledge and controls needed to safeguard information.  Even sophisticated databases, managed by Database Administrators (DBAs), lack secure controls and and connectivity to information.&lt;br /&gt;&lt;br /&gt;Many DBAs have complete access to all of your organization's data.  While complete access helps manage and minimize downtime, it also puts your organization at risk as the DBA has access to all information and log files.  Your management must determine the minimum amount of access needed to allow the DBAs to perform job duties.  For example, must the DBA have access to confidential or sensitive data such as payroll, protected health information (PHI), or other types of confidential information?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Assessments&lt;/a&gt; help ensure your internal controls provide the appropriate reporting and procedures, detect unauthorized use of systems, and meet compliance requirements.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-5278362784218929578?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5278362784218929578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5278362784218929578'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/11/database-regulatory-and-compliance.html' title='Database Regulatory and Compliance Issues'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-7287720472511037547</id><published>2008-10-02T11:03:00.000-07:00</published><updated>2008-10-02T11:10:56.038-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='facta'/><category scheme='http://www.blogger.com/atom/ns#' term='red flags rule'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>FACTA Identity Theft Red Flags Rule</title><content type='html'>&lt;strong&gt;FACTA&lt;/strong&gt; - the Fair and Accurate Credit Transactions Act of 2003 requirement, known as the “Identity Theft Red Flags Rule”, became effective January 1, 2008, with compliance mandatory by November 1, 2008. It requires certain organizations to adopt a written identity theft prevention program approved by the Board of Directors.&lt;br /&gt;&lt;br /&gt;The Identity Theft Prevention Program must include reasonable policies and procedures for detecting, preventing, and mitigating identity theft. The regulation requires an institution to have:&lt;br /&gt;1) An established written Identity Theft Prevention Program approved by the Board&lt;br /&gt;2) Initial Risk Assessment&lt;br /&gt;3) Policies and procedures for detecting, preventing, and mitigating identity theft.  This includes identifying patterns of activity that are signals for possible identity theft, monitoring and detecting “red flags”, responding appropriately to any red flags, policies and procedures to verify address changes&lt;br /&gt;4) Regular compliance reporting&lt;br /&gt;5) Oversight of service providers&lt;br /&gt;6) Mandatory staff training&lt;br /&gt;7) Ensure the Program is reviewed and periodically updated to reflect changes&lt;br /&gt;&lt;br /&gt;Find out more information on complying with FACTA and the initial &lt;a href="http://www.altiusit.com/riskassessmentsfacta.htm"&gt;risk assessment&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-7287720472511037547?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7287720472511037547'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7287720472511037547'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/10/facta-identity-theft-red-flags-rule.html' title='FACTA Identity Theft Red Flags Rule'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-3297223014467352311</id><published>2008-09-09T09:46:00.000-07:00</published><updated>2008-09-09T10:01:25.088-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='software as a service'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud computing'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Cloud Computing – Thunder and Lightening on Your Horizon?</title><content type='html'>&lt;strong&gt;Cloud Computing&lt;/strong&gt;&lt;br /&gt;As organizations automate more and more of their manual processes, the Internet is increasingly becoming an important tool in the delivery of IT services.  Several years ago, organizations purchased software on CD-ROMs and DVD media.  Today, users have the choice of downloading software from the Internet or using their browser to access software that runs outside the organization on Internet servers.  The use of external software on Internet servers is called Software as a Service (SAAS). &lt;br /&gt;&lt;br /&gt;Instead of writing software for a workstation, software developers are now writing software programs that run on Internet servers.  This software may run on servers outside the organization on other companies’ data centers.  Familiar examples include web sites such as Amazon.com and Salesforce.com.&lt;br /&gt;&lt;br /&gt;In the past, individual applications ran in the Internet cloud.  Now, entire data centers are moving to the cloud, accessible by a wide range of users.  Cloud computing describes a grouping of service offerings that includes application software, data storage, and computing.  The computing can be delivered over the Internet (public cloud computing) or within an organization (private cloud computing).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Cloud advantages over desktop software&lt;/strong&gt;&lt;br /&gt;Many SAAS applications are available at little to no cost.  In addition to lower software costs, IT administration labor costs are reduced as software does not need to be installed and constantly patched.  SAAS applications tend to be supported by paid advertisers, thus subsidizing the cost to the software user.&lt;br /&gt;&lt;br /&gt;Another benefit is group collaboration.  In the past, software was loaded on many distributed devices.  With the Internet cloud, software and data can be stored on centralized servers facilitating access to data by a large group of users.&lt;br /&gt;&lt;br /&gt;Cloud computing offers almost unlimited storage of applications and data.  No longer must users and IT staff be concerned about collecting and archiving volumes of data.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Mobile applications&lt;/strong&gt;&lt;br /&gt;Employees want functionality and access to data from a number of different locations.  The Internet cloud allows hand held Personal Digital Assistants (PDAs) and laptop users to access applications and data from a variety of locations.  Internet cloud computing allows information to be accessed by a number of different devices (desktop, laptop, mobile phone, GPS, etc.) since the applications and data are stored at Internet data centers.&lt;br /&gt;&lt;br /&gt;Mobile computing will drive more applications to the Internet cloud.  The cloud is an ideal way of supplying software and data to small computing devices that don’t have the storage and processing power to hold volumes of applications and information.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Application interfaces&lt;br /&gt;&lt;/strong&gt;Internet applications leverage the power of end user devices by introducing to browsers features commonly found in the graphical interfaces on desktop applications.  Better software development tools support applications that can run on a wide range of devices from desktop browsers to smart phones.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Pubic cloud computing risks&lt;/strong&gt;&lt;br /&gt;As with any other form of technology, organizations must address a wide range of cloud computing risks:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;User traffic&lt;/em&gt; – in the past, applications and data were stored locally.  With Internet cloud information accessed via Internet lines, connectivity and bandwidth usage may become a critical issue if Internet users create Internet access bottlenecks.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Internet connectivity&lt;/em&gt; – connectivity to the Internet increases in importance.  If Internet connectivity is down for an extended period of time, employee productivity will drop.  Redundant high speed Internet lines may be needed to help mitigate this risk.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Employee productivity&lt;/em&gt; – applications and data that are stored on user hard drives tend to have fast response times with little impact on the employee.  Internet applications may experience delays and not be able to manage volumes of data.  Service Level Agreements (SLAs) with the cloud computing vendors can provide response time, throughput, and other metrics that help protect the organization.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Lack of availability&lt;/em&gt; – there are risks related to having a critical software application programmed and managed by an outside entity.  If a vendor’s software application ceases to function, the organization may experience financial losses as well as damage to its image and reputation. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Confidentiality&lt;/em&gt; – SAAS vendors may store data in a central repository.  This repository may hold data from many different businesses, even competitors.  The organization should determine if it is appropriate to store the type of information (client lists, pricing, intellectual property, etc.) on external servers.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Integrity&lt;/em&gt; – since data is stored on outside servers, the organization must ensure information integrity.  Balancing controls, managing information stored on external servers, monitoring, and other controls must be used to protect the organization.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Compliance&lt;/em&gt; – information collected, stored, archived, and secured must meet regulatory requirements.&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;Privacy issues&lt;br /&gt;&lt;/strong&gt;In exchange for lower cost service delivery, users may have to provide personal information.  This information is often used to deliver custom advertisements.  The cloud model may require sharing of information with other marketing alliances in exchange for the convenience and low cost of using Internet cloud applications. &lt;br /&gt;&lt;br /&gt;Many SAAS vendors focus on one area of specialty, storage, e-mail applications, on-line backups, etc.  Organizations must rely on the vendor’s security solutions to protect their information.  Unfortunately, for many SAAS vendors, their focus is on service functionality, not security.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Private cloud computing&lt;/strong&gt;&lt;br /&gt;Organization data centers adopting the technologies and practices of public cloud infrastructures can be considered private clouds.  Private clouds are data centers within the corporate perimeter, within the firewall. &lt;br /&gt;&lt;br /&gt;Software applications can be designed for both the public and private cloud infrastructure.  Tools such as systems management software, clusters, grid technology, and load balancing permit private clouds to employ utility like environments with computing resources and applications provisioned with greater efficiency.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Cloud computing service delivery considerations&lt;/strong&gt;&lt;br /&gt;IT managers should take professional care and due diligence when evaluating cloud computing applications:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Service levels&lt;/em&gt; - your organization should determine if the outsourced provider has professional, high performance infrastructures that can guarantee levels of performance delivery. &lt;/li&gt;&lt;li&gt;&lt;em&gt;Support &lt;/em&gt;– user and technical support must be determined up front.  Will first level user support be provided by their staff or yours?&lt;/li&gt;&lt;li&gt;&lt;em&gt;Redundancy&lt;/em&gt; – organizations should have redundant solutions that allow systems to continue operating even during single component failure.  This includes the Internet software application as well as the organization’s connectivity to the Internet.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Contingency plans&lt;/em&gt; – business continuity and disaster recovery plans must be updated and tested on a regular basis.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Private clouds&lt;/em&gt; – IT departments have the administration costs and responsibilities of acquiring, installing, managing, and securing data centers.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Security &lt;/em&gt;– public and private clouds must ensure information availability, confidentiality, and integrity.&lt;/li&gt;&lt;/ul&gt;&lt;strong&gt;Summary&lt;br /&gt;&lt;/strong&gt;While outsourcing software applications to the Internet cloud isn’t for every organization, many firms have found that cloud computing can be a simple, reliable, and cost effective solution. &lt;br /&gt;&lt;br /&gt;Both the Internet cloud vendors (SAAS) and the organization should have audits performed on a periodic basis. &lt;br /&gt;&lt;ul&gt;&lt;li&gt;SAAS vendors - audits help ensure system availability, information confidentiality, and data integrity. &lt;/li&gt;&lt;li&gt;Organizations - audits ensure organization management that the firm is managing its cloud computing risks. &lt;/li&gt;&lt;/ul&gt;&lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Risk assessments&lt;/a&gt; and audits help organizations identify, manage, and reduce their risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-3297223014467352311?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/3297223014467352311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/3297223014467352311'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/09/cloud-computing-thunder-and-lightening.html' title='Cloud Computing – Thunder and Lightening on Your Horizon?'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-82057442929608467</id><published>2008-08-07T12:27:00.000-07:00</published><updated>2008-08-07T12:43:33.624-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='jim kelton'/><category scheme='http://www.blogger.com/atom/ns#' term='network audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='altiusit'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>New and Emerging Threats</title><content type='html'>One way organizations manage new and emerging threats is by performing network and security assessments and audits on a periodic basis. By reviewing your systems, people, and processes, assessments helps determine the areas that create the greatest risk.&lt;br /&gt;&lt;br /&gt;Once the assessment has identified risk areas, the organization can quantify the likelihood of the event and implement corrective action to mitigate and reduce IT related risks. This prioritized Action Plan is a risk response mechanism that addresses the risks according to the importance to the organization.&lt;br /&gt;&lt;br /&gt;By allocating IT funds to areas that are most critical, assessments and audits &lt;a href="http://www.altiusit.com/whyus.htm"&gt;add value&lt;/a&gt; to the organization by:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Helping align IT with the business&lt;/li&gt;&lt;li&gt;Prioritize security spending&lt;/li&gt;&lt;li&gt;Allocating resources to areas with the greatest impact&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-82057442929608467?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/82057442929608467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/82057442929608467'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/08/new-and-emerging-threats.html' title='New and Emerging Threats'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-4291595631307561325</id><published>2008-07-01T10:51:00.000-07:00</published><updated>2008-07-01T11:05:21.610-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>Security Assessments</title><content type='html'>&lt;strong&gt;The assessment difference.&lt;/strong&gt; Many organizations wait until it is too late, either they've been hacked or they are mandated by regulations to have an outside, external security assessment. Leading organizations don't wait and are proactive, using outside security assessments to help the firm leverage its IT investment to enhance employee productivity, reduce costs, improve customer service, and achieve a competitive edge.&lt;br /&gt;&lt;br /&gt;As organizations automate manual processes, information systems and the data they manage become a corporate asset. In addition to increasing value, these same information systems create additional risk for the organization and create a single point of failure.&lt;br /&gt;&lt;br /&gt;Network and security assessments help organizations identify, manage, and reduce their risks. In addition to technical configurations, security assessments can also be used to review your staff, how they work, and their procedures.&lt;br /&gt;&lt;br /&gt;Find out more information about various &lt;a href="http://www.altiusit.com/assessmentsoverview.htm"&gt;types of assessments&lt;/a&gt; that help manage firewall, user, web application, database, and compliance related risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-4291595631307561325?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4291595631307561325'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4291595631307561325'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/07/security-assessments.html' title='Security Assessments'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-4830916642358761431</id><published>2008-06-11T08:16:00.000-07:00</published><updated>2008-06-11T08:22:15.843-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='it standards'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security standards'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><title type='text'>Overview of Security Standards</title><content type='html'>&lt;strong&gt;Standards help protect information.&lt;/strong&gt;  All organizations, regardless of size, need to secure their data and intellectual property.  Standards provide organization management information security guidance and direction.  Each standard, when applied effectively, helps an organization address security related issues.  Standards represent the knowledge of a large number of experts and provide security implementation recommendations.  However, by their nature, standards cannot exactly match the requirements of every organization and care must be taken when determining the appropriateness for each organization.&lt;br /&gt;&lt;br /&gt;Various Standards&lt;br /&gt;&lt;ul&gt;&lt;li&gt;ITIL - Information Technology Infrastructure Library is not focused on security.  Instead, it provides a foundation for managing IT infrastructure with a primary focus on service support and service delivery.&lt;/li&gt;&lt;li&gt;COBIT - Control Objectives for Information and related Technology focuses on controls that provide management with assurance that IT is operating in a controlled manner. &lt;/li&gt;&lt;li&gt;NIST - the National Institute of Science and Technology develops and issues standards, guidelines, and other publications to assist federal agencies in implementing the Federal Information Security Management Act (FISMA) of 2002 and aims to protect information and information systems.&lt;/li&gt;&lt;li&gt;ISO - the International Organization for Standardization (ISO) is the world’s largest developer of standards (over 15,000 in total), including the 27000 series focused on information security.&lt;/li&gt;&lt;/ul&gt;When combined with &lt;a href="http://www.altiusit.com/assessmentsoverview.htm"&gt;assessments&lt;/a&gt;, standards can help you identify, manage, and reduce your security risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-4830916642358761431?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4830916642358761431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4830916642358761431'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/06/overview-of-security-standards.html' title='Overview of Security Standards'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-5198862382505133490</id><published>2008-05-21T09:54:00.000-07:00</published><updated>2008-05-21T10:04:20.153-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='anti-virus'/><category scheme='http://www.blogger.com/atom/ns#' term='software'/><category scheme='http://www.blogger.com/atom/ns#' term='patch management'/><title type='text'>Software Updates</title><content type='html'>&lt;strong&gt;When is it time to upgrade your computer your software?&lt;/strong&gt; Software tends to drive changes in hardware. You'll know it is time to upgrade your software when:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Your current software can't handle your transaction volumes or isn't flexible to meet your needs&lt;/li&gt;&lt;li&gt;You need to share or collaborate with others that have newer software&lt;/li&gt;&lt;li&gt;You are concerned about new and emerging security threats&lt;/li&gt;&lt;/ul&gt;Data protection software should always be kept up-to-date. This includes:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Backup software&lt;/li&gt;&lt;li&gt;Anti-virus software&lt;/li&gt;&lt;li&gt;Anti-spware software&lt;/li&gt;&lt;/ul&gt;Some vendors bundle software into protection suites. For example, Symantec's Endpoint Protection software includes both virus and spyware protection. Keeping software updated (patch management) should be a formal methodology that includes a review and testing process before the changes are moved into your production environment.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/"&gt;Assessments&lt;/a&gt; identify risk areas and help allocate your funds to the most important areas. This way you get the biggest bang for the buck.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-5198862382505133490?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5198862382505133490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5198862382505133490'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/05/software-updates.html' title='Software Updates'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-5406645006192771983</id><published>2008-04-10T14:25:00.000-07:00</published><updated>2011-05-11T14:50:02.184-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='web application'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><category scheme='http://www.blogger.com/atom/ns#' term='database'/><title type='text'>Web Application Security</title><content type='html'>&lt;strong&gt;Web applications&lt;/strong&gt; are the most vulnerable element of an organization’s IT infrastructure. As your organization uses the Internet for customer, supplier, employee, and vendor interactions, Web technologies and database interfaces become more complex and require additional security. Web application and database assessments are ideal for:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Web sites that interface with database systems &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Ensuring compliance (HIPAA, Sarbanes Oxley, GLB, etc.) &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Emerging and fast growing firms Businesses concerned about security &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Organizations in the financial and health care industries &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Buffer overflow, SQL injections, cross site scripting, JavaScript, and other programming concerns &lt;/li&gt;&lt;/ul&gt;&lt;a href="http://www.altiusit.com/assessmentwebapp.htm"&gt;Web application security assessments&lt;/a&gt; help your firm manage a range of vulnerabilities including buffer overflow, SQL injection, cross site scripting, Google hacking, authentication risks, JavaScript, Common Gateway Interface (CGI), PHP, broken links, authentication hacking, and many other types of web related vulnerabilities.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-5406645006192771983?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5406645006192771983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/5406645006192771983'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/04/web-application-security.html' title='Web Application Security'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-1875933089284268093</id><published>2008-03-06T10:44:00.000-08:00</published><updated>2011-05-11T14:51:30.683-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='procedures'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='policies'/><category scheme='http://www.blogger.com/atom/ns#' term='controls'/><title type='text'>Controls Help Mitigate and Reduce Risks</title><content type='html'>&lt;strong&gt;Controls&lt;/strong&gt; are administrative, management, technical, and legal methods that are used to manage risk. Controls include policies, procedures, programs, techniques, technologies, guidelines, and organizational structures. They help an organization comply with standards by addressing information security risks, information confidentiality, integrity, and availability.&lt;br /&gt;&lt;br /&gt;Security policies and control objectives express management’s commitment to the implementation, maintenance, and improvement of its information security management system. Leading organizations use best-practice information security control measures to satisfy the stated control objectives. Standards frequently do not mandate specific controls, but leave it to the users to select and implement controls that suit them, using a risk-assessment process to identify the most appropriate controls for their specific requirements. Organizations are typically free to select controls as long as their control objectives are satisfied.&lt;br /&gt;&lt;br /&gt;Leading organizations follow a Plan, Do, Check, and Act process:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Plan – planning&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Do – implement, operate, and maintain &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Check - monitor, audit, and review &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Act – continual improvement &lt;/li&gt;&lt;/ul&gt;An example of a control standard is ISO/IEC 27002:2005 Information technology -- Security techniques -- Code of Practice for Information Security Management. &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Network and security assessments&lt;/a&gt; are part of the "Check" process and help ensure you have the proper controls in place and they are functioning as desired.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-1875933089284268093?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1875933089284268093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1875933089284268093'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/03/controls-help-mitigate-and-reduce-risks.html' title='Controls Help Mitigate and Reduce Risks'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-7772395101361493200</id><published>2008-01-04T10:01:00.000-08:00</published><updated>2011-05-11T14:52:33.074-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bia'/><category scheme='http://www.blogger.com/atom/ns#' term='business impact analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='disaster recovery'/><category scheme='http://www.blogger.com/atom/ns#' term='business continuity'/><category scheme='http://www.blogger.com/atom/ns#' term='failure'/><title type='text'>Business Continuity - more than disaster recovery</title><content type='html'>&lt;strong&gt;Business continuity&lt;/strong&gt; requires more than just a plan to recover from a disaster. Business continuity policies, planning, and activities allow an organization to continue critical operations even during a business disruption. Business continuity generally consists of three areas:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Business resumption planning (business operations recovery)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Disaster recovery planning (technical aspects of recovery)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Crisis management (organization's response)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;A top down approach to business continuity planning helps an organization minimize the impact of a disruption on business operations. More than just recovering from a data center outage, continuing business operations requires the involvement of business units and upper management. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;Risk management and a Business Impact Analysis (BIA) provide management with a planned approach to managing a disruption caused by a fire, flood, earthquake, terrorism, or other natural disaster. When recovering from a disaster, the organization's image and reputation must be protected. An employee, designated as the spokesperson for the organization, allows a consistent message to be delivered to employees, customers, and the media.&lt;br /&gt;&lt;br /&gt;Business continuity plans reduce the cost of a business disruption. Many organizations use &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;risk assessments&lt;/a&gt; to help them itentify areas that can lead to disruptions in business operations.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-7772395101361493200?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7772395101361493200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7772395101361493200'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2008/01/business-continuity-more-than-just.html' title='Business Continuity - more than disaster recovery'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-4517318547568487378</id><published>2007-12-04T16:11:00.000-08:00</published><updated>2011-05-11T14:53:49.572-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='policies and procedures'/><category scheme='http://www.blogger.com/atom/ns#' term='security policy'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='information security policy'/><title type='text'>Information Security Policy</title><content type='html'>&lt;strong&gt;Security Policies&lt;/strong&gt;. Policies represent the corporate philosophy of an organization. They provide management the direction and support needed to perform their day-to-day duties. In the case of information security, an information security policy helps provide direction in accordance with business requirements, standards, laws, and regulations.&lt;br /&gt;&lt;br /&gt;Policies should be established in line with business objectives. For example, management demonstrates support for and commitment to information security through the issuance and maintenance of an information security policy.&lt;br /&gt;&lt;br /&gt;Leading organizations use an information security policy to define information security and establish the framework for setting control objectives within an organization. &lt;a href="http://www.altiusit.com/policies.htm"&gt;Policies &lt;/a&gt;help organizations ensure that preventative, detective, and corrective controls are in place and operating as desired.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-4517318547568487378?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4517318547568487378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4517318547568487378'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/12/information-security-policy.html' title='Information Security Policy'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-2186687681760802591</id><published>2007-11-09T10:32:00.000-08:00</published><updated>2007-11-09T10:40:11.122-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='it value'/><category scheme='http://www.blogger.com/atom/ns#' term='align it'/><category scheme='http://www.blogger.com/atom/ns#' term='it governance'/><title type='text'>IT Governance</title><content type='html'>&lt;strong&gt;What is IT governance and why is it important?&lt;/strong&gt; Let's first start with corporate governance. Corporate governance is a set of responsibilities and practices used by an organization’s management to provide strategic direction to the business. Governance ensures that goals are achievable, risks are properly addressed, and organizational resources are properly utilized.&lt;br /&gt;&lt;br /&gt;IT governance is an integral part of corporate governance and consists of the leadership, structures, and processes that ensure IT extends the organization’s strategy and objectives. IT governance is the responsibility of the board of directors and executive management.&lt;br /&gt;&lt;br /&gt;IT governance helps ensure the alignment of IT with business objectives. Fundamentally, IT governance is concerned with:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Value&lt;/em&gt; - IT delivers value to the business by strategic alignment of IT with the business&lt;/li&gt;&lt;li&gt;&lt;em&gt;Risks&lt;/em&gt; - IT risks are mitigated by embedding accountability into the business&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Assessments&lt;/a&gt; help ensure IT is propertly managing risks and delivering value to your organization.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-2186687681760802591?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2186687681760802591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2186687681760802591'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/11/it-governance.html' title='IT Governance'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-7921753075855151276</id><published>2007-10-11T15:55:00.000-07:00</published><updated>2007-11-09T10:41:24.937-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Need to Manage your Risks?</title><content type='html'>&lt;strong&gt;Mid-size firms have growth challenges&lt;/strong&gt;. Many are growing quickly and don't have the resources of large firms. One mid-size organization provided employment screening and background checks. The firm was growing rapidly, attracting large clients, and expected to double in size within two years. Management was concerned that the IT staff and infrastructure cannot support the organization’s rapid growth.&lt;br /&gt;&lt;br /&gt;They contracted with a firm to provide a network assessment amd an analysis of data backups, anti-virus, e-mail, software licensing, software patching, laptops, and many other areas. In addition to the IT infrastructure, the Work Plan included interviews with IT, management, and key users to determine if there was an alignment or satisfaction issue with IT.&lt;br /&gt;&lt;br /&gt;The analysis included a comparison of the IT department with industry benchmarks so the organization could evaluate if they were making effective use of IT spending. The assessment also reviewed written policies, business continuity plans, and related procedures and guidelines.&lt;br /&gt;&lt;br /&gt;The assessment identified several “hidden” issues that would have caused a disruption in business operations. The prioritized Action Plan gave the firm guidance to make immediate changes to their network infrastructure and IT staff. The organization’s management had peace of mind knowing that the plan allowed the firm double in size over the next two years.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Network assessments&lt;/a&gt; provide management with peace of mind and help organizations achieve growth targets.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-7921753075855151276?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7921753075855151276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/7921753075855151276'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/10/need-to-manage-your-risks.html' title='Need to Manage your Risks?'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-491063431932596358</id><published>2007-09-16T13:01:00.000-07:00</published><updated>2007-11-09T10:44:12.201-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='isms'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Information Security Management Systems (ISMS)</title><content type='html'>&lt;strong&gt;Securing information systems&lt;/strong&gt; is a business, not an IT issue. As more and more systems are automated, business managers are at risk to IT related disruptions. As a result, business managers now play an important role in IT related risk management.&lt;br /&gt;&lt;br /&gt;Technology has revolutionized the operations of many firms as they have moved away from mainframe computer systems to infrastructures comprised of networks, the Internet, and enterprise-wide processing. Risk management services assess the risks of an organization’s use of technology, the resulting exposure to technology risks, and the adequacy of controls to mitigate those risks.&lt;br /&gt;&lt;br /&gt;A &lt;a href="http://www.altiusit.com/assessmentsoverview.htm"&gt;variety&lt;/a&gt; of outside, independent &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;risk assessments&lt;/a&gt; are available that help firms identify, manage, and reduce their risks. In addition to providing peace of mind, risk assessments help organizations meet compliance related requirements.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-491063431932596358?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/491063431932596358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/491063431932596358'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/09/information-security-management-systems.html' title='Information Security Management Systems (ISMS)'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-755574734790812497</id><published>2007-08-07T15:20:00.000-07:00</published><updated>2007-11-09T10:45:34.735-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sensitive information'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='personal information'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Preventing Identity Theft</title><content type='html'>&lt;strong&gt;Personally identifiable information&lt;/strong&gt; such as your name, date of birth, social security number, and many other forms of identification present risks when this information is stored electronically. Not only can the information be easly accessible by many employees, but it can also be viewed by unwanted intruders.&lt;br /&gt;&lt;br /&gt;Information identity thefts present two different types of risks: &lt;ul&gt;&lt;li&gt;Take overs - accounts can be taken over by an imposter posing as you. The imposter can purchase goods and services using your existing accounts.&lt;/li&gt;&lt;li&gt;Application fraud - with sufficient information, an imposter can open new accounts in your name. Their goal is to get as much money and products as quickly as possible.&lt;/li&gt;&lt;/ul&gt;Five steps you can take to protect sensitive information:&lt;br /&gt;1) Request a free credit report by calling (877) 322-8228 or visiting &lt;a href="http://www.annualcreditreport.com/"&gt;http://www.annualcreditreport.com/&lt;/a&gt;.&lt;br /&gt;2) Reduce the amount of credit cards and shred unsolicited credit card applications.&lt;br /&gt;3) If a business requests a SSN, ask if another number can be substituted instead.&lt;br /&gt;4) Ask businesses to only request and keep the minimum amount of information they need to do their job.&lt;br /&gt;5) Ask if your information is shared with others and how your information is protected.&lt;br /&gt;&lt;br /&gt;Five steps businesses can take to secure sensitive information:&lt;br /&gt;1) Identify the minimum amount of information that needs to be collected and stored.&lt;br /&gt;2) Identify the minimum amount of staff that needs to access sensitive information.&lt;br /&gt;3) Educate your staff about policies and the need to keep information private.&lt;br /&gt;4) Encrypt information so it is protected even if the network is compromised.&lt;br /&gt;5) Outside independent security assessments help identify, manage and reduce risks.&lt;br /&gt;&lt;br /&gt;For more information on assessments, please visit &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Altius IT&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-755574734790812497?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/755574734790812497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/755574734790812497'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/08/preventing-identity-theft.html' title='Preventing Identity Theft'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-913014252798147474</id><published>2007-07-14T16:12:00.000-07:00</published><updated>2011-05-11T14:57:31.039-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='it outsourcing'/><category scheme='http://www.blogger.com/atom/ns#' term='outsourcing'/><category scheme='http://www.blogger.com/atom/ns#' term='it management'/><category scheme='http://www.blogger.com/atom/ns#' term='outsource it'/><title type='text'>High Connectivity Costs</title><content type='html'>&lt;strong&gt;Prevent high connectivity costs&lt;/strong&gt;. Executives are concerned about the high costs of connecting people with information. Well managed networking and security initiatives with follow-up support can prevent these high costs.&lt;br /&gt;&lt;br /&gt;Suites of networking, security, and risk management services specifically address concerns expressed by executive management:&lt;br /&gt;1. &lt;em&gt;High costs&lt;/em&gt; – Executives are finding it increasingly difficult to be in constant communication with business associates and the high cost of bringing together people and information is a major problem.&lt;br /&gt;2. &lt;em&gt;Experience&lt;/em&gt; - Very few IT personnel have the depth of experience and expertise working with executives to prevent the high costs of bringing together people and information.&lt;br /&gt;3. &lt;em&gt;Support&lt;/em&gt; – Executives are finding that efficient and effective use of their existing systems requires knowledgeable employees and support.&lt;br /&gt;&lt;br /&gt;Outsourcing can be a cost effective solution if in-house IT personnel don't have the necessary experience and support. &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Network security assessments&lt;/a&gt; help you manage your IT related risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-913014252798147474?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/913014252798147474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/913014252798147474'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/07/high-connectivity-costs.html' title='High Connectivity Costs'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-8966970496612559005</id><published>2007-06-05T16:05:00.000-07:00</published><updated>2011-05-11T14:59:29.038-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='it standards'/><category scheme='http://www.blogger.com/atom/ns#' term='policies and procedures'/><category scheme='http://www.blogger.com/atom/ns#' term='it policies'/><title type='text'>Policies Manage Your Risks</title><content type='html'>&lt;strong&gt;Policies help organizations manage risks&lt;/strong&gt;. By reviewing business requirements and anticipated future growth plans, organizations can identify and prepare policies that are aligned with the organization's goals and objectives.&lt;br /&gt;&lt;br /&gt;Policies often consist of the following:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;&lt;em&gt;Policy&lt;/em&gt; – the rules and requirements for risk management and continuing business operations.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;em&gt;Standards&lt;/em&gt; – detailed networking and security technologies for protecting information systems.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;em&gt;Guidelines&lt;/em&gt; – system or topic related recommendations and best practices.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;em&gt;Procedures&lt;/em&gt; – details to implement standards and guidelines, guides for installing software, securing facilities, documenting security breaches, etc.&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;In some instances, policies can conflict with each other. In these circumstances, a steering committee can address policy conflicts and identify appropriate compromises and alternative solutions. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;If your organization lacks policies, policy templates provide a jump start and help you manage your risks. More information on &lt;a href="http://www.altiusit.com/policies.htm"&gt;policy templates&lt;/a&gt; is available at Altius IT.&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-8966970496612559005?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8966970496612559005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/8966970496612559005'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/06/policies-manage-your-risks.html' title='Policies Manage Your Risks'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-1496568397770800644</id><published>2007-05-04T08:52:00.000-07:00</published><updated>2007-11-09T10:48:08.580-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network audit'/><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Network Assessments</title><content type='html'>&lt;strong&gt;Network assessments&lt;/strong&gt; help organizations identify, manage, and reduce their risks. While there are many forms of assessments, a typical assessment reviews the network infrastructure with the main purpose of ensuring reliability.&lt;br /&gt;&lt;br /&gt;Typical areas reviewed include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Network – servers, workstations, laptops&lt;/li&gt;&lt;li&gt;Scalability - performance, connectivity&lt;/li&gt;&lt;li&gt;Backups – including off-site rotation&lt;/li&gt;&lt;li&gt;Electronic communications - e‑mail and IM&lt;/li&gt;&lt;li&gt;Software - licensing, patch management, custom&lt;/li&gt;&lt;li&gt;Policies – procedures, change management&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;Find out more about &lt;a href="http://www.altiusit.com/assessmentsoverview.htm"&gt;network assessments&lt;/a&gt; and how they can help you enhance the reliability of your network infrastructure.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-1496568397770800644?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1496568397770800644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1496568397770800644'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/05/network-assessments.html' title='Network Assessments'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-1848494840675336128</id><published>2007-04-17T13:28:00.000-07:00</published><updated>2007-11-09T10:50:09.902-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>5 Steps to Risk Management</title><content type='html'>&lt;strong&gt;Risk management&lt;/strong&gt; services provide strategies, processes, and tools to identify, analyze, respond to, control, and evaluate risks. A formal five step approach to risk management helps organizations identify, manage and reduce risks.&lt;br /&gt;1. &lt;em&gt;Identify Risks&lt;/em&gt; - Assessment. Outside, independent assessments identify risks that cause downtime and business interruption. Review your technology systems, people, and processes.&lt;br /&gt;2. &lt;em&gt;Risk Findings&lt;/em&gt; - Analysis. Additional investigation and research. Analyze findings and evaluate your organization’s risk tolerance based upon information provided during the assessment.&lt;br /&gt;3. &lt;em&gt;Risk Response&lt;/em&gt; - Action Plan. Develop a prioritized action plan of recommendations, responsibilities, and related costs. The Action Plan provides the steps needed to address vulnerabilities.&lt;br /&gt;4. &lt;em&gt;Risk Control&lt;/em&gt; - Managed Services. Managed networking and security solutions protect your information assets.&lt;br /&gt;5. &lt;em&gt;Risk Effectiveness&lt;/em&gt; – Evaluate &amp;amp; Repeat. Evaluate the effectiveness of your organization’s risk management mechanisms. Not just a one-time event, prepare for the next assessment.&lt;br /&gt;&lt;br /&gt;Find out more about &lt;a href="http://www.altiusit.com/assessmentsoverview.htm"&gt;assessments&lt;/a&gt; and how they can help your organization reduce its risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-1848494840675336128?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1848494840675336128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/1848494840675336128'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/04/5-steps-to-risk-management.html' title='5 Steps to Risk Management'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-4102277220637724899</id><published>2007-03-22T12:45:00.000-07:00</published><updated>2011-05-11T14:55:16.644-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='portable storage device'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='usb'/><title type='text'>Data on the Move</title><content type='html'>&lt;strong&gt;Portable devices,&lt;/strong&gt; such as USB flash drives, offer employees the ability to transfer data from one device to another. Frequently used by exectives that work both in the office and at home, these devices put data "on the move".&lt;br /&gt;&lt;br /&gt;Outside the protective perimiter of the IT department, security of the data on the portable storage devices is now the responsibility of the employee. To minimize their risks, many organizations are now implmenting porttable storage device security controls:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Restricting users and their ability to store information on USBs, CD-RWs, etc.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Implementing policies that require biometric security access on the USB devices&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Requiring that data on the USB devices be encrypted (some devices permit only 10 attempts to crack the code before being permanently locked out).&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Network and security assessments&lt;/a&gt; can help organizations identify, manage, and reduce their portable store device security risks.&lt;/li&gt; &lt;br /&gt;&lt;ul&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-4102277220637724899?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4102277220637724899'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/4102277220637724899'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/03/data-on-move.html' title='Data on the Move'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-2433259269871661068</id><published>2007-02-20T09:14:00.000-08:00</published><updated>2011-05-11T15:00:39.049-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='msp'/><category scheme='http://www.blogger.com/atom/ns#' term='managed security'/><title type='text'>Security - not just a one-time event</title><content type='html'>&lt;strong&gt;Managed Security&lt;/strong&gt;. Many organizations take a "Project" vs. an "Investment" approach to securing their information assets. With "Project" security, an organization waits until a security breach occurs and then the organization takes appropriate action. For example, an organization gets hit with a virus. It then authorizes the acquistion of anti-virus software. The Project approach to security is typically ad-hoc with many as yet undiscovered vulnerabilities.&lt;br /&gt;&lt;br /&gt;An alternative approach to security involves the "Investment" approach to security. By investing in security, the organization recognizes that securing the network infrastructure is critical to the success of the organization. The "Investment" approach typically uses a managed approach to security.&lt;br /&gt;&lt;br /&gt;A managed approach to security can better balance functionality with security and typically involves the following five phases:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Security strategy&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Security alignment&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Security design and implementation&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Security monitoring&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Security audit&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;For more information on these five phases, please visit &lt;a href="http://www.altiusit.com/security.htm"&gt;Security Overview&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-2433259269871661068?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2433259269871661068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/2433259269871661068'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/02/security-not-just-one-time-event.html' title='Security - not just a one-time event'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-116899387082425476</id><published>2007-01-16T16:21:00.000-08:00</published><updated>2011-05-11T15:01:49.295-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Security Tip #1 - Assessments Enhance Value</title><content type='html'>&lt;strong&gt;Network and security assessments &lt;/strong&gt;and audits help determine if IT funds are effectively being used, identify and quantify IT related strengths and weaknesses, and help you focus on those areas that create the most value for your firm. Assessments are ideal for:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Ensuring compliance (HIPAA, Sarbanes Oxley, etc.)&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Emerging and fast growing firms&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;IPO ready organizations&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Organizations concerned about security&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Businesses with geographically distributed offices&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Organizations in the financial and health care industries&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Firms working with the government or large institutions&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Organizations that share and collect personal and/or proprietary data&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;b&gt;Assessments and Business Value&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;While some organizations want tactical advice on the state of the IT department, others want to maximize their investment in IT by developing and implementing a formal strategy. Before an organization can develop and execute strategy, the business can use assessments to understand its IT infrastructure and related strengths and weaknesses.&lt;br /&gt;&lt;br /&gt;Find out more about IT &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;network and security assessments&lt;/a&gt; and how they can help your organization.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-116899387082425476?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/116899387082425476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/116899387082425476'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2007/01/security-tip-1-assessments-enhance.html' title='Security Tip #1 - Assessments Enhance Value'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-116680949677335223</id><published>2006-12-22T09:37:00.000-08:00</published><updated>2007-11-09T10:51:11.233-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Security Tip #2 - Protecting Your Data</title><content type='html'>&lt;strong&gt;Encryption can protect your data&lt;/strong&gt;. Most organizations have sensitive information that needs to be stored on IT systems and distributed to authorized business contacts in a safe and secure manner. It is important to use secure encryption technology when conducting business and electronically exchanging information. Encryption makes information unintelligible to everyone except for your intended recipient.&lt;br /&gt;&lt;br /&gt;Confidential information is created on a daily basis. Restricting access to confidential information on your network is only part of the solution. Increase the integrity of the data by encrypting sensitive information. Your business contacts need to use encryption to help maintain the confidentiality of your data since not all of your confidential information is contained within your office. Employees frequently work out of the office and this information must be transported in a safe and secure manner.&lt;br /&gt;&lt;br /&gt;Your reputation is at risk when confidential information is compromised and increased costs are incurred when information is exposed to unauthorized personnel. Don’t wait for someone to gain access to your confidential information. Encrypt information to protect you from threats both inside and outside of your organization.&lt;br /&gt;&lt;br /&gt;Find out more about networking, &lt;a href="http://www.altiusit.com/"&gt;security&lt;/a&gt;, and risk management solutions.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-116680949677335223?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/116680949677335223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/116680949677335223'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/12/security-tip-2-protecting-your-data.html' title='Security Tip #2 - Protecting Your Data'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-116250447052233861</id><published>2006-11-02T13:49:00.000-08:00</published><updated>2011-05-11T15:03:05.052-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='firewall'/><category scheme='http://www.blogger.com/atom/ns#' term='managed security'/><category scheme='http://www.blogger.com/atom/ns#' term='penetration assessment'/><title type='text'>Security Tip #3 - Firewalls, What they Can't Do For You</title><content type='html'>&lt;strong&gt;Firewalls can't do everything&lt;/strong&gt;. Firewalls are a good first step to protect you against hackers, but they do have their limitations. Like a deadbolt lock on a front door, a firewall can't tell you if you have other vulnerabilities that might allow a hacker access to your network.&lt;br /&gt;&lt;br /&gt;Why you need formalized security protection:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Firewalls can’t protect against attacks that don’t go through the firewall – wireless networks, dial-up modems, and internal employees often by-pass firewall protection &lt;br /&gt;&lt;li&gt;Firewalls reflect the overall level of security of your network – a failure may expose your sensitive data &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Firewalls stop incoming threats but you still require formalized management, destruction, and archival procedures for your electronic documents&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Firewalls are not a replacement for a strong Security Policies and Procedures Manual&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;Your reputation is compromised when a firewall doesn’t encrypt confidential documents and E-mail. Your costs increase when a firewall doesn’t protect you against computer viruses. Formalized procedures and tools are needed to protect your confidential documents and electronic communications. Organizations need security vulnerability assessments to manage their risks.&lt;br /&gt;&lt;br /&gt;Your security structure is only as strong as its weakest link. &lt;a href="http://www.altiusit.com/security.htm"&gt;Security professionals&lt;/a&gt; have the experience needed to help protect your reputation. &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;Security assessments&lt;/a&gt; help you identify, manage, and reduce your risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-116250447052233861?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/116250447052233861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/116250447052233861'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/11/security-tip-3-firewalls-what-they.html' title='Security Tip #3 - Firewalls, What they Can&apos;t Do For You'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-115991170247051240</id><published>2006-10-03T14:41:00.000-07:00</published><updated>2011-05-11T15:04:44.189-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='hackers'/><title type='text'>Security Tip #4 - Hackers, What You Need to Know</title><content type='html'>&lt;strong&gt;Hackers know things that you don't&lt;/strong&gt;. That's their edge. It's the reason that they can break into networks, leaving a path of destruction in their wake. Concerned about security? Your concerns may be directly related to the value of the information you are trying to protect. For example, is your data difficult to recreate? What are the implications if someone outside the company gets access to your confidential documents? You can’t always prevent hackers from breaking in, but you can make it more difficult for them to succeed.&lt;br /&gt;&lt;br /&gt;Why you need formal security protection:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Hackers like the challenge of breaking into systems&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Without proper protection, any part of your network is at risk&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Hackers cause network downtime (&lt;a href="http://www.altiusit.com/downcost.htm"&gt;downtime cost calculator&lt;/a&gt;)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Hackers seek out weaknesses in your systems&lt;/li&gt;&lt;/ul&gt;Don't assume that ad-hoc security can protect you from Internet threats. A managed approach to &lt;a href="http://www.altiusit.com/security.htm"&gt;security&lt;/a&gt; provides the protection you need.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-115991170247051240?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/115991170247051240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/115991170247051240'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/10/security-tip-4-hackers-what-you-need.html' title='Security Tip #4 - Hackers, What You Need to Know'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-115868222048330088</id><published>2006-09-19T09:00:00.000-07:00</published><updated>2011-05-11T15:06:05.174-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>Security Tip #5 - Employees are your hidden threat</title><content type='html'>&lt;strong&gt;Internal employee threats.&lt;/strong&gt; You have probably taken steps to secure your systems from external “hacker” threats. But what steps have you taken to protect your organization from your own employees? The Computer Security Institute estimates that between 60% and 80% of network misuse comes from within the enterprise.&lt;br /&gt;&lt;br /&gt;Managing your employees and their access to data help you manage your risks. From the inside, employees bypass many of your controls designed to protect your data from unwanted intruders. Even if you maintain passwords on confidential documents, employees can run scripts that detect and remove passwords on files. How can you address this employee threat? Identify your vulnerabilities and integrate security solutions at the network level.&lt;br /&gt;&lt;br /&gt;The top three reasons why you need employee network level security protection: &lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Your employees already have access to your network.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Employees don’t have to pass through external security checkpoints.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Your confidential data needs more than password protection.&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;Enhance and enforce security at the network level. Managing your employees and their access to data help you manage your risks. Please visit Altius IT for more information on &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;security readiness&lt;/a&gt; and &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;risk management&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-115868222048330088?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/115868222048330088'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/115868222048330088'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/09/security-tip-5-employees-are-your.html' title='Security Tip #5 - Employees are your hidden threat'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-115462720662642069</id><published>2006-08-03T10:32:00.000-07:00</published><updated>2011-05-11T15:07:11.721-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic threats'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan horse'/><title type='text'>Security Tip #6 - Viruses are a constant threat</title><content type='html'>&lt;strong&gt;Anti-virus threats are increasing&lt;/strong&gt;. Experts believe that as many as one out of every ten e-mail messages contain a virus. Don't put your organization at risk, obtain and implement reliable anti-virus software. Consider the follwing:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Viruses destroy the integrity of your computer systems.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Manual anti-virus updates at inconsistent intervals doesn’t provide protection from viruses that spread quickly with no advance warning.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Viruses cause significant damage.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Your critical files are distributed across your network. Server and workstation files at corporate and remote locations need to be protected.&lt;/li&gt;&lt;/ul&gt;Viruses cost you money and increase IT support time. In addition, employee frustration results in employee turnover and increased management recruiting time and expenses. Your loss of data integrity results in customer dissatisfaction. Viruses compromise your image and reputation.&lt;br /&gt;&lt;br /&gt;Don’t count on inconsistent anti-virus solutions to protect your valuable information assets. Automated anti-virus systems with server and desktop protection help you manage your risks. For more information on viruses and to learn the difference between a worm and a virus, please visit &lt;a href="http://www.altiusit.com/files/articles/articlewpviruses.htm"&gt;http://www.altiusit.com/files/articles/articlewpviruses.htm&lt;/a&gt;. Call us today and find out how our &lt;a href="http://www.altiusit.com/security.htm"&gt;security&lt;/a&gt; services can help protect your information assets.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-115462720662642069?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/115462720662642069'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/115462720662642069'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/08/security-tip-6-viruses-are-constant.html' title='Security Tip #6 - Viruses are a constant threat'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-115221790340272922</id><published>2006-07-06T13:31:00.000-07:00</published><updated>2011-05-11T15:10:33.496-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='passwords'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='password test'/><title type='text'>Security Tip #7 - Passwords, what you need to know</title><content type='html'>&lt;strong&gt;Passwords, are you ever really secure?&lt;/strong&gt; If you have a newer computer, you already know the experience of increased productivity you get from having state-of-the-art equipment. What you don’t know is that faster systems, when combined with high-speed Internet lines, let unwanted visitors “crack” your passwords at an alarming rate.&lt;br /&gt;&lt;br /&gt;Many organizations forget that not all of their threats are external, internal threats must be considered as well. In addition, confidential data may be accessed from remote locations and a good password policy may be the only protection.&lt;br /&gt;&lt;br /&gt;Without a formalized password protection policy, you risk loss of revenue due to system and network downtime. Many organizations have determined their cost of downtime, however recent surveys show that the cost to recreate data is generally greater than originally estimated. In addition to internal costs, organizations must consider the cost of customer dissatisfaction due to loss of data integrity.&lt;br /&gt;&lt;br /&gt;Passwords are a critical component of your security readiness. Formalize your password policies and verify that they are enforced. Inconsistent password policies and procedures leave you at risk and cannot protect your valuable information assets. Managing your passwords will help you manage your risks and protect your image and reputation.&lt;br /&gt;&lt;br /&gt;Want more information on how passwords can be part of an overall approach to securing your network? Find out how our &lt;a href="http://www.altiusit.com/security.htm"&gt;security consulting service&lt;/a&gt; provides information asset protection.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-115221790340272922?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/115221790340272922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/115221790340272922'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/07/security-tip-7-passwords-what-you-need.html' title='Security Tip #7 - Passwords, what you need to know'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-114963568869056191</id><published>2006-06-06T15:57:00.000-07:00</published><updated>2011-05-11T15:11:20.832-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Security Tip #8 - Security Assessments</title><content type='html'>&lt;strong&gt;Subscription security assessments&lt;/strong&gt;. It is often difficult to decide where to properly allocate your security budget. Rather than simply throwing money at the problem, leading organizations use periodic security assessments to help pinpoint network security issues.&lt;br /&gt;&lt;br /&gt;As new vulnerabilities are discovered on a daily basis, a system that is secure one day may be completely wide open the next. Much like regular anti-virus updates, subscribing to recurring security assessments helps an organization identify network security weaknesses before they can be exploited.&lt;br /&gt;&lt;br /&gt;In addition to protecting your IT systems, periodic security assessments help protect your organization's reputation by helping identify vulnerabilities before they are exploited by unwanted intruders. Find out more about &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;security assessments&lt;/a&gt; and how they can help protect your "information assets".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-114963568869056191?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/114963568869056191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/114963568869056191'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/06/security-tip-8-security-assessments.html' title='Security Tip #8 - Security Assessments'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-114677730994620561</id><published>2006-05-04T14:08:00.000-07:00</published><updated>2011-05-11T15:12:23.116-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data protection'/><category scheme='http://www.blogger.com/atom/ns#' term='data backup'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Security Tip #9 - Backups Are Your Initial Defense</title><content type='html'>&lt;strong&gt;Don’t risk losing your valuable data&lt;/strong&gt;. What are your annual costs of lost data when you consider lost employee productivity, lower levels of customer service, and reduced competitiveness? Protect your IT systems with reliable backups so you don’t lose money.&lt;br /&gt;&lt;br /&gt;Why you need reliable IT system backups &lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Information can be lost at a moment’s notice&lt;/li&gt;&lt;br /&gt;&lt;li&gt;It is time consuming to recreate data&lt;/li&gt;&lt;br /&gt;&lt;li&gt;The cost of downtime is greater than your initial estimates&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Hackers and viruses aren’t your only threats, employees can accidentally delete critical files&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Data is often distributed - server and workstation files at corporate and remote locations needs to be protected&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;Your risks &lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Lost productivity results in higher employee costs &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Increased IT support costs you money&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Lower levels of customer service results in lost clients&lt;/li&gt;&lt;/ul&gt;Don't count on untested backup systems to protect your valuable information assets. Formalized backup systems with off-site rotation help you manage your risks and are your key to protecting your information assets.&lt;br /&gt;&lt;br /&gt;Call us today and find out how our &lt;a href="http://www.altiusit.com/security.htm"&gt;security consulting service &lt;/a&gt;can help protect your information assets.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-114677730994620561?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/114677730994620561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/114677730994620561'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/05/security-tip-9-backups-are-your.html' title='Security Tip #9 - Backups Are Your Initial Defense'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-114425890477928057</id><published>2006-04-05T10:32:00.000-07:00</published><updated>2011-05-11T15:13:20.532-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security policies'/><category scheme='http://www.blogger.com/atom/ns#' term='policies and procedures'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>Security Tip #10 - Don't Risk Client Trust</title><content type='html'>&lt;strong&gt;Don’t risk losing your clients’ trust in you&lt;/strong&gt;. Protect your IT systems with security policies and procedures. You'll protect your information assets and your valuable image and reputation.&lt;br /&gt;&lt;br /&gt;By not having sound policies and procedures, many organizations face the following risks:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Loss of data integrity and client trust in you&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Your clients incur lower levels of service due to untimely IT operations&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;You experience increased management accountability due to loss of adequate controls&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;You incur increased costs due to systems that are not always available&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;Security policies and procedures can help you maintain client confidentiality. By implementing effective policies and procedures, client trust is maintained even while security threats are increasing at an alarming rate.&lt;br /&gt;&lt;br /&gt;Many critical business processes and client interactions are now automated to the point where the importance of security readiness has risen exponentially. Don’t count on firewalls and passwords to protect your valuable information assets. Security policies help you manage your risks and are your key to maintaining client trust.&lt;br /&gt;&lt;br /&gt;Find out why you need a &lt;a href="http://www.altiusit.com/assessmentnetworkandsecurity.htm"&gt;managed approach to security&lt;/a&gt; instead of the ad-hoc approach that leaves many organizations vulnerable.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-114425890477928057?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/114425890477928057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/114425890477928057'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/04/security-tip-10-dont-risk-client-trust.html' title='Security Tip #10 - Don&apos;t Risk Client Trust'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-114142084387329931</id><published>2006-03-03T13:11:00.000-08:00</published><updated>2011-05-11T15:14:23.877-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='managed security'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>Does Ad-hoc Security Really Work?</title><content type='html'>&lt;strong&gt;Ad-hoc security&lt;/strong&gt; may not provide the level of security you need. Imagine installing a firewall here and a database application there. Each element may be secure, however, when all components are combined into an interrelated network, your organization may be at risk.&lt;br /&gt;&lt;br /&gt;Altius IT recommends a formalized and planned approach to security. &lt;a href="http://www.altiusit.com/security.htm"&gt;Security design&lt;/a&gt; allows top down planning and implemention of security technology. Not only does this approach offer enhanced security, it may also reduce your costs since security can be aligned with your organization's goals and objectives.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-114142084387329931?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/114142084387329931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/114142084387329931'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/03/does-ad-hoc-security-really-work.html' title='Does Ad-hoc Security Really Work?'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-113881609070197928</id><published>2006-02-01T09:47:00.000-08:00</published><updated>2007-11-09T11:08:06.035-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Single Points Of Failure</title><content type='html'>A &lt;strong&gt;Single Point of Failure&lt;/strong&gt; (SPOF) analysis analysis helps your organization manage its risks. By identifying your points of failure, you can:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Reduce your costs&lt;/em&gt;. By effectively allocating and prioritizing resources to critical areas. In addition, your internal staff can focus on your core competencies.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Enhance your image and reputation&lt;/em&gt;. By delivering on a narrow range of assigned duties, the team evaluating your single points of failure can help you eliminate downtime.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Improve your competitive position&lt;/em&gt;. By improving system availability, you'll be more competitive in your market place and better able to compete against larger organizations.&lt;/li&gt;&lt;li&gt;&lt;em&gt;Increase your levels of customer service&lt;/em&gt;. Your systems will keep you in contact with those you serve.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Find out more about managing your &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;Single Points of Failure&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-113881609070197928?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113881609070197928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113881609070197928'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/02/single-points-of-failure.html' title='Single Points Of Failure'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-113831127290692993</id><published>2006-01-26T13:34:00.000-08:00</published><updated>2007-11-09T11:01:22.178-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic threats'/><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='e-mail'/><title type='text'>Electronic Communications</title><content type='html'>&lt;strong&gt;Concerned about managing your risks?&lt;/strong&gt; Want to know how others plan to use Information Technology to manage their risks?&lt;br /&gt;&lt;br /&gt;Organizations are finding that the fast paced Information Technology (IT) industry is a double edge sword. While improving operational efficiencies, employees are exposing their businesses to even greater risks.&lt;br /&gt;&lt;br /&gt;Imagine going in to work one day and finding that you have been summoned to appear in court. You find that a lawsuit has been filed against your organization. After some research by your legal staff, you are told that one of your employee’s E-mail messages is being used against you and will appear as evidence in your upcoming trial. Imagine that when you read your employee’s E-mail message for the first time, you discover that the E-mail contains sensitive and confidential information about your organization. What can your organization do to avoid future risks?&lt;br /&gt;&lt;br /&gt;Organizations are finding that they need to change the way they handle and maintain their electronic records and communications. Many are planning to use IT to manage their risks and potential liabilities by securing and managing their electronic documents and confidential communications.&lt;br /&gt;&lt;br /&gt;Areas where IT will be used to manage business risks include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Document management&lt;/li&gt;&lt;li&gt;Confidential communications&lt;/li&gt;&lt;li&gt;Sensitive communications&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;strong&gt;Document Management&lt;/strong&gt;&lt;br /&gt;In the past, organizations maintained large volumes of paperwork in office filing cabinets and off-site warehouses. Access to information required employees to sift through files trying to locate the needed records.&lt;br /&gt;&lt;br /&gt;Many organizations improved their access to information through the use of Information Technology solutions that automated the document storage and retrieval process. Through IT solutions such as electronic mail and electronic scanning and filing, documents could be located in minutes or even seconds. No longer did it take days or weeks to find the requested information.&lt;br /&gt;&lt;br /&gt;In providing immediate access to information, a new risk emerged. While documents were accessible for internal reference purposes, they were also available to be subpoenaed. A second problem also arose. With traditional file cabinets, organizations tended to have only one version of a document on file. However, with electronic filing, an organization could have word processing documents, E-mail messages, electronic fax transmissions and other types of electronic communications available at a moment’s notice.&lt;br /&gt;&lt;br /&gt;Organizations now realize the implications of maintaining electronic communications and the need to better manage these documents through a formalized document management archival and destruction procedure.&lt;br /&gt;&lt;br /&gt;To manage risks, future document management procedures will be developed at the highest executive levels and pushed down to lower levels within the organization Enforced company wide, document management will consider information stored internally, on tape backup media, on the Internet/Intranets, as well as communications with outside business contacts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Confidential Communications&lt;/strong&gt;&lt;br /&gt;In addition to managing their documents, organizations must be especially concerned about their confidential communications. These types of communications may occur within an organization or may also include communications with outside business contacts.&lt;br /&gt;&lt;br /&gt;To mange their risks, organizations will use IT to better protect their electronic communications. Confidential documents and communications will be encrypted to protect information. While these steps are already being used by some organizations, others are finding that more extensive procedures need to be implemented.&lt;br /&gt;&lt;br /&gt;Electronic communications via E-mail will receive special attention. Employees typically have found it beneficial to store electronic versions of E-mail messages. Management tends to believe that these messages may pose more harm than good. As a result, management may dictate that this type of correspondence be removed after a period of time. While many organizations have controlled the archival and destruction of E-mail messages within their organization, most have yet to address electronic communications with outside contacts.&lt;br /&gt;&lt;br /&gt;To manage their risks, organizations will implement solutions that more fully address confidential communications and E-mail. For example, management can dictate that E-mail messages expire a pre-determined number of days after the initial transmission of the message. This provides management with the peace of mind knowing that their risks are properly managed.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Sensitive Communications&lt;/strong&gt;&lt;br /&gt;Business executives in the future will be expected to take more of a proactive role by actively controlling and monitoring electronic communications. IT systems will be configured to restrict the sending or receiving of messages that may contain questionable material.&lt;br /&gt;&lt;br /&gt;By configuring software applications to look for certain keywords or phrases, outgoing E-mail correspondence can be stopped before the message has left the sender’s desk. Questionable incoming messages may be routed to a special pending mailbox where they will be held pending a third party review.&lt;br /&gt;&lt;br /&gt;By configuring software to look for certain keywords or phrases, an organization can prevent questionable communications that may result in sexual harassment lawsuits or other types of litigation.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;br /&gt;Electronic document management and communications solutions allow organizations to control costs and improve their operational efficiencies. To manage these risks, organizations will implement solutions that address the liabilities associated with electronic records and communications.&lt;br /&gt;&lt;br /&gt;Organizations that are successful in using Information Technology to manage current and future business risks will achieve competitive advantages in their marketplaces. Please &lt;a href="http://www.altiusit.com/contactus.htm"&gt;contact us&lt;/a&gt; for more information on managing your risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-113831127290692993?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113831127290692993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113831127290692993'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2006/01/electronic-communications.html' title='Electronic Communications'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-113346045016166565</id><published>2005-12-01T10:07:00.000-08:00</published><updated>2011-05-11T15:16:39.874-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network audit'/><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='network management'/><title type='text'>Fix on Fail Network Management</title><content type='html'>&lt;strong&gt;Managing risks&lt;/strong&gt;. To reduce their total cost of ownership, industry leading organizations know that IT systems need to be properly managed and maintained. The “Fix on Fail” approach to systems management results in employee frustration, missed deadlines, increased costs, and lower levels of customer service.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altiusit.com/other.htm"&gt;Manage IT&lt;/a&gt; provides you with the peace of mind knowing that your systems are properly managed and maintained. Our network management service provides you with immediate access to our network experts who quickly respond to your questions and problems.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-113346045016166565?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113346045016166565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113346045016166565'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/12/fix-on-fail-network-management.html' title='Fix on Fail Network Management'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-113346002230474113</id><published>2005-12-01T09:57:00.000-08:00</published><updated>2011-05-11T15:18:07.619-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security policies'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><category scheme='http://www.blogger.com/atom/ns#' term='security strategy'/><title type='text'>Want to Save on Security Costs?</title><content type='html'>&lt;strong&gt;Security alignment&lt;/strong&gt;. Concerned that you aren't cost effectively allocating your security resources? Information Technology (IT) strategy and security alignment ensures cohesive goals and results throughout the enterprise. Altius IT’s &lt;a href="http://www.altiusit.com/security.htm"&gt;security services&lt;/a&gt; align IT to the organization, improve efficiencies, reduce costs, enhance customer service, and help the organization achieve a competitive edge in its market place.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-113346002230474113?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113346002230474113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113346002230474113'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/12/want-to-save-on-security-costs.html' title='Want to Save on Security Costs?'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-113095933317716778</id><published>2005-11-02T11:15:00.000-08:00</published><updated>2011-05-11T15:19:43.680-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='it outsourcing'/><category scheme='http://www.blogger.com/atom/ns#' term='outsourcing'/><category scheme='http://www.blogger.com/atom/ns#' term='it management'/><title type='text'>Focus on Core Business Functions</title><content type='html'>&lt;strong&gt;Insourced vs. Outsourced IT?&lt;/strong&gt; In this day and age, It is important to recognize the value of IT and its tie to enabling business operations. Successful solutions require skills and competencies to address networking and security issues.&lt;br /&gt;&lt;br /&gt;Outsourcing IT may help an organization achieve a competitive advantage in their marketplace. As the number and sophistication of security threats continue to increase, organizations find it difficult to justify keeping all functions in-house. The majority of organizations are already facing difficulty in finding and hiring staff with the required skills and competencies. As well, the majority of their perceived threats revolve around non-core functional areas, like patch management and viruses.&lt;br /&gt;&lt;br /&gt;By outsourcing non-strategic security functions, organizations may be in a better position to concentrate on their core business while working with their outsourced service providers to enhance their security infrastructure and support their growth initiatives.&lt;br /&gt;&lt;br /&gt;Please visit Altius IT for more information on outsourced solutions for your &lt;a href="http://www.altiusit.com/other.htm"&gt;networking&lt;/a&gt; and &lt;a href="http://www.altiusit.com/security.htm"&gt;security&lt;/a&gt; concerns.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-113095933317716778?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113095933317716778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113095933317716778'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/11/focus-on-core-business-functions.html' title='Focus on Core Business Functions'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-113095839847662747</id><published>2005-11-02T10:55:00.000-08:00</published><updated>2011-05-11T15:21:06.216-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='risk audit'/><category scheme='http://www.blogger.com/atom/ns#' term='it management'/><category scheme='http://www.blogger.com/atom/ns#' term='risk assessment'/><title type='text'>Risk Management Benefits</title><content type='html'>&lt;strong&gt;Risk management&lt;/strong&gt; tools and processes allow business managers to position their organizations to be industry leaders. By properly employing risk management processes, an organization can receive many benefits including:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Peace of mind by through enhanced network and system availability&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Enhanced image and reputation by keeping you in contact with your business associates&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Improved competitive position by helping you compete effectively in the market place&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Increased levels of customer service by keeping you in contact with those you serve&lt;/li&gt;&lt;/ul&gt;Don't let your organization get left behind. Learn more about our &lt;a href="http://www.altiusit.com/riskassessments.htm"&gt;risk assessment&lt;/a&gt; services and how they can help you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-113095839847662747?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113095839847662747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/113095839847662747'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/11/risk-management-benefits.html' title='Risk Management Benefits'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-112882635164830330</id><published>2005-10-08T19:45:00.000-07:00</published><updated>2011-05-11T15:22:07.402-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network management'/><category scheme='http://www.blogger.com/atom/ns#' term='risk management'/><category scheme='http://www.blogger.com/atom/ns#' term='managed security'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>Reduce Total Cost of Ownership</title><content type='html'>&lt;strong&gt;Reduce total cost of ownership&lt;/strong&gt;. Industry leading organizations know that IT systems need to be properly managed and maintained. The “Fix on Fail” approach to systems management results in employee frustration, missed deadlines, increased costs and lower levels of client service.&lt;br /&gt;&lt;br /&gt;Altius IT recommends the managed solutions listed below. The support schedule depends upon the importance of IT to your organization.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Daily/Weekly&lt;/em&gt; &lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Check hard drive – capacity and free space&lt;/li&gt;&lt;br /&gt;&lt;li&gt;System – scan drives for errors, defragment&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Software patches – patch management&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Review anti-virus software – auto updates&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Troubleshooting – examine log files for errors&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Check anti-spyware – updates and scans&lt;/li&gt;&lt;br /&gt;&lt;li&gt;User access – add/remove access to systems&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Applications – add/configure and troubleshoot&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Mobile devices – synchronize with desktops&lt;/li&gt;&lt;br /&gt;&lt;li&gt;User support – problem determination, assistance&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Server – application monitoring and size limits&lt;/li&gt;&lt;/ul&gt;&lt;em&gt;Monthly/Quarterly service&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;E-mail – size, user delegate permissions&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Firewall – firmware updates, subscription status&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Internet - review firewall bottlenecks and log file&lt;/li&gt;&lt;br /&gt;&lt;li&gt;System backups - test and review off-site rotation&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Security assessment – penetration test and report&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Backup e-mail – test proper operation and findings&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Public folders – access and security&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Data folders – access and security&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Document – retention procedures, archiving&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Assessment – independent review of systems&lt;/li&gt;&lt;/ul&gt;&lt;em&gt;Annual service&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Integrity – review user access to systems &amp;amp; data&lt;/li&gt;&lt;br /&gt;&lt;li&gt;IT alignment – with business goals and direction&lt;/li&gt;&lt;br /&gt;&lt;li&gt;IT planning – long range planning and updates&lt;/li&gt;&lt;br /&gt;&lt;li&gt;IT budget – maintenance and special projects&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Policies – review/update policies and procedures&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Best practices – to ensure system availability&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Business continuity – testing and plan revision&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Updates – renew annual subscriptions&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Domains – check expiration of domain names&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Archiving – year end archiving procedures&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Best practices – tools/checklists (database, e-mail)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Audit – outside independent audit of IT&lt;/li&gt;&lt;/ul&gt;For more information, please refer to Altius IT's managed &lt;a href="http://www.altiusit.com/other.htm"&gt;networking&lt;/a&gt; and &lt;a href="http://www.altiusit.com/security.htm"&gt;security&lt;/a&gt; services.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-112882635164830330?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112882635164830330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112882635164830330'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/10/reduce-total-cost-of-ownership.html' title='Reduce Total Cost of Ownership'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-112882576946089193</id><published>2005-10-08T19:38:00.000-07:00</published><updated>2011-05-11T15:23:03.565-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='outsource security'/><category scheme='http://www.blogger.com/atom/ns#' term='security outsourcing'/><category scheme='http://www.blogger.com/atom/ns#' term='outsource it'/><title type='text'>Security Outsourcing Solutions</title><content type='html'>&lt;p&gt;&lt;strong&gt;Security outsourcing&lt;/strong&gt; allows an organization’s internal staff to focus on core competencies without dealing with day-to-day distractions. Altius IT takes an extremely complex and complicated undertaking and ensures that every step is properly planned and executed.&lt;br /&gt;&lt;br /&gt;Altius IT’s five step outsourcing toolkit manages the process of migrating from insourced to outsourced &lt;a href="http://www.altiusit.com/security.htm"&gt;security&lt;/a&gt; and &lt;a href="http://www.altiusit.com/other.htm"&gt;networking&lt;/a&gt; services: &lt;/p&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Requirements – defines and establishes the roles of internal and external resources&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Service level agreement (SLA) – documents the formal blueprint of duties and procedures&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Transition – identifies the steps to be followed both before and through the transition to outsourced services&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Reporting – deliverables provided during the course of the engagement&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Management – project management and quality control to keep outsourcing on target &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-112882576946089193?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112882576946089193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112882576946089193'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/10/security-outsourcing-solutions.html' title='Security Outsourcing Solutions'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-112640164675952264</id><published>2005-09-11T18:09:00.000-07:00</published><updated>2011-05-11T15:25:16.602-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network audit'/><category scheme='http://www.blogger.com/atom/ns#' term='network assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>Freedom and Peace of Mind</title><content type='html'>&lt;strong&gt;Time…there is never enough of it.&lt;/strong&gt; Have you ever thought how nice it would be to have unlimited time where you can spend as much time as needed to secure your systems? The reality is that you wear many hats and you don't have sufficient time to spend on security.&lt;br /&gt;&lt;br /&gt;Life made easier one task at a time. The solution is IT support on demand. It helps you be every where you need to be. Outsourced IT can be your virtual IT assistant. Unique suites of services allow you to accomplish multiple tasks simultaneously without the normal time constraints.&lt;br /&gt;&lt;br /&gt;Hourly, daily, weekly, and monthly support packages are provided based upon your specific needs and requirements.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;&lt;em&gt;&lt;a href="http://www.altiusit.com/other.htm" target="_blank"&gt;Manage IT Suite&lt;/a&gt;&lt;/em&gt; provides you with the peace of mind knowing that Altius IT provides you with technical expertise so your network is well managed and maintained.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Enterprise-wide &lt;a href="http://www.altiusit.com/"&gt;security audit services&lt;/a&gt; provides a multilayered approach to advance your level of security.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;em&gt;&lt;a href="http://www.altiusit.com/riskassessments.htm" target="_blank"&gt;Risk Management services&lt;/a&gt;&lt;/em&gt; provide full service solutions to reduce your risks.&lt;/li&gt;&lt;/ul&gt;Freedom for your business and built for business. &lt;a href="http://www.altiusit.com/" target="_blank"&gt;Security&lt;/a&gt; makes your life easier one task at a time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-112640164675952264?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112640164675952264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112640164675952264'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/09/freedom-and-peace-of-mind.html' title='Freedom and Peace of Mind'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-112640405121686656</id><published>2005-09-10T18:56:00.000-07:00</published><updated>2007-11-09T10:58:12.371-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessment'/><category scheme='http://www.blogger.com/atom/ns#' term='security quiz'/><title type='text'>Security Quiz - Find Your Security IQ</title><content type='html'>&lt;strong&gt;Think you are secure?&lt;/strong&gt; Take a security quiz and find your security IQ. Protection of your network and data is one of your primary concerns. This simple &lt;a href="http://www.altiusit.com/securityquiz.htm" target="_blank"&gt;Security Quiz&lt;/a&gt; will help you determine your Security Quotient. Score one point for each Yes answer in this simple ten question quiz.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-112640405121686656?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112640405121686656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112640405121686656'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/09/security-quiz-find-your-security-iq.html' title='Security Quiz - Find Your Security IQ'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-16596253.post-112640262115901791</id><published>2005-09-10T18:24:00.000-07:00</published><updated>2011-05-11T15:28:47.212-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sensitive information'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='data security'/><category scheme='http://www.blogger.com/atom/ns#' term='network security'/><title type='text'>Security Vulnerability Flowchart</title><content type='html'>&lt;strong&gt;See how your assets may be threatened.&lt;/strong&gt; Your information systems face a variety of threats from a number of different sources. Consider the risks you face from:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Hackers scanning and probing access points to your network&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Access to your corporate data from remote locations&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Firewalls and their limitations&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;E-mail threats such as phishing and viruses&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Internal security breaches&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Business continuity and single points of failure issues&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Web site threats including Denial of Service and defacing&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Intruder detection and prevention systems&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Data protection and encryption&lt;/li&gt;&lt;/ul&gt;Our &lt;a href="http://www.altiusit.com/" target="_blank"&gt;security audit services&lt;/a&gt; provide an Executive Summary overview of how your information assets are threatened.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/16596253-112640262115901791?l=itsecurityinfo.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112640262115901791'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/16596253/posts/default/112640262115901791'/><link rel='alternate' type='text/html' href='http://itsecurityinfo.blogspot.com/2005/09/security-vulnerability-flowchart.html' title='Security Vulnerability Flowchart'/><author><name>Jim Kelton</name><uri>http://www.blogger.com/profile/14952520030502887568</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://1.bp.blogspot.com/_07jaIudoaHM/TL9Xcl0NsLI/AAAAAAAAAAw/xUux2fZQoZw/S220/jimkphoto.jpg'/></author></entry></feed>
