Thursday, February 03, 2011

Current Trends

We hope that you have found this blog to be useful. New postings and updates can now be found on Altius IT's Information Security and Network Security Blog.

Thank you for visiting,
Jim

Labels: , ,

Monday, December 06, 2010

IT Risk Management

IT risk management includes all of the activities that an organization carries out to manage information technology related risks. IT risk management is a formalized process and includes:

  1. Risk Assessment
  2. Risk Analysis
  3. Risk Treatment
  4. Risk Mitigation
  5. Risk Review and Evaluation
1. Risk Assessment (Identify Risks)
Risk Assessments identify possible sources of risk. They identify threats or events that could have a meaningful impact on the organization.

2. Risk Analysis (Impact)
Risk Analysis considers the probability and magnitude of each event. Risk evaluation compares the estimated risk with a set of risk criteria to determine the significance of the risk.

3. Risk Treatment (Risk Response Action Plan)
Risk Treatment identifies how each risk is to be addressed. Residual risk is the risk left over after implementing risk treatment steps that avoid the risk, transfer the risk, reduce the risk, or accept the risk.

4. Risk Mitigation (Risk Control)
Risk mitigation plans propose applicable and effective security controls that manage the risks. The plan should contain a schedule outling the tasks to be performed, individuals responsible for the actions, estimated dates, etc.

5. Risk Review and Evaluation (Risk Effectiveness)
Risk management plans change over time as the business evolves, as new threats emerge, as losses are incurred, and as management changes. Review the effectiveness of your approach and revise as necessary.

Risk assessments help organizations identify, manage, and reduce risks to acceptable levels.

Labels: , , ,

Wednesday, January 13, 2010

Information Security Tip #1: Inventory Your Assets

Understanding your information assets and access to information is essential to assessing security vulnerabilities. Whether you are an industry giant or a lean-and-mean one-person shop, here are some tips on conducting your own internal investigation:
  • Inventory. Inventory all servers, computers, flash drives, disks, and other equipment to find out where your company stores sensitive data. Also include laptops, employees’ home offices, cell phones, and e-mail. No security audit is complete until you check everywhere sensitive data might be stored.
  • Interview. Track personal information through your business by talking with your technology staff, human resources office, accounting personnel, and outside service providers. Get a complete picture of who sends your company sensitive data. Do you get it from customers? Call centers? Credit card companies? Banks or other financial institutions? What about affiliates and contractors?
  • Forms. How does sensitive data come in to your company? Via your website? E-mail? Through the mailroom? What kind of information is collected at each entry point? Customers’ credit card, debit, or checking account numbers? Do you receive sensitive health or financial data?
  • Access. Who has, or could have, access to the information? Which of your employees has permission to look at or view sensitive data? Could anyone else get a hold of it? What about vendors who supply and update software you use to process credit card transactions? Do you have contractors that run your call center, distribution, or fulfillment operations?
  • Storage. Different types of data present varying risks. Pay particular attention to how you store personally identifying information such as Social Security numbers, credit card numbers, checking account, or other financial information. Determine if the data you store can facilitate fraud or identity theft if it fell into the wrong hands.
Network security assessments help identify, manage, and reduce your IT related risks.

Labels: , , ,

Thursday, May 14, 2009

Security During Tough Economic Times

Employee risks. Although many decision makers are focused on getting through tough economic times, security experts say that management needs to be weary of employees, who fearful that their jobs could be on the cutting block, could take actions that potentially jeopardize the physical and logistical security of the company. As companies automate manual processes and adapt to the changing economic environment, merge IT departments, and cut back on controls, organizations face greater threats.

Risk assessments can help identify sensitive and proprietary information, risks to the data, and relevant state and federal compliance requirements. Everyone is concerned about security and protecting sensitive information. Once sensitive data and compliance requirements have been identified, the organization can leverage the information from the risk assessments to build in security structures that protect against IT, people, and process threats.

Network and security assessments help protect your sensitive information and provide peace of mind.

Labels: , , ,

Tuesday, March 03, 2009

Small Business Security Quiz

Take this quiz to determine your Security Quotient. Preparation is the key to protecting your company’s information assets. Take this security quiz to determine your Security Quotient.
1) We have recent off-site computer backups. Yes/No
2) We have updated anti-virus software on all computers/servers. Yes/No
3) We restrict employee access to confidential information. Yes/No
4) All of our policies are documented and in written form. Yes/No
5) We have a firewall to protect us. Yes/No
6) We encrypt confidential documents/E-mail. Yes/No
7) We have a formal electronic document archiving procedure. Yes/No
8) We monitor and restrict Internet access. Yes/No
9) We performed a security assessment of our IT systems. Yes/No
10) We can distinguish an intruder from normal Internet traffic. Yes/No

Score one point for each Yes answer.
8 or more points - You are well on your way to securing your IT systems.
6 to 7 points - keep working, you may need assistance to reduce risks.
5 or fewer points - you need to make security a priority and get assistance as soon as possible.

Network and security assessments help protect your sensitive information and provide peace of mind.

Labels: , , ,

Thursday, August 07, 2008

New and Emerging Threats

One way organizations manage new and emerging threats is by performing network and security assessments and audits on a periodic basis. By reviewing your systems, people, and processes, assessments helps determine the areas that create the greatest risk.

Once the assessment has identified risk areas, the organization can quantify the likelihood of the event and implement corrective action to mitigate and reduce IT related risks. This prioritized Action Plan is a risk response mechanism that addresses the risks according to the importance to the organization.

By allocating IT funds to areas that are most critical, assessments and audits add value to the organization by:
  • Helping align IT with the business
  • Prioritize security spending
  • Allocating resources to areas with the greatest impact

Labels: , , , , , ,

Tuesday, July 01, 2008

Security Assessments

The assessment difference. Many organizations wait until it is too late, either they've been hacked or they are mandated by regulations to have an outside, external security assessment. Leading organizations don't wait and are proactive, using outside security assessments to help the firm leverage its IT investment to enhance employee productivity, reduce costs, improve customer service, and achieve a competitive edge.

As organizations automate manual processes, information systems and the data they manage become a corporate asset. In addition to increasing value, these same information systems create additional risk for the organization and create a single point of failure.

Network and security assessments help organizations identify, manage, and reduce their risks. In addition to technical configurations, security assessments can also be used to review your staff, how they work, and their procedures.

Find out more information about various types of assessments that help manage firewall, user, web application, database, and compliance related risks.

Labels: , , ,

Tuesday, September 19, 2006

Security Tip #5 - Employees are your hidden threat

Internal employee threats. You have probably taken steps to secure your systems from external “hacker” threats. But what steps have you taken to protect your organization from your own employees? The Computer Security Institute estimates that between 60% and 80% of network misuse comes from within the enterprise.

Managing your employees and their access to data help you manage your risks. From the inside, employees bypass many of your controls designed to protect your data from unwanted intruders. Even if you maintain passwords on confidential documents, employees can run scripts that detect and remove passwords on files. How can you address this employee threat? Identify your vulnerabilities and integrate security solutions at the network level.

The top three reasons why you need employee network level security protection:

  • Your employees already have access to your network.

  • Employees don’t have to pass through external security checkpoints.

  • Your confidential data needs more than password protection.

Enhance and enforce security at the network level. Managing your employees and their access to data help you manage your risks. Please visit Altius IT for more information on security readiness and risk management.

Labels: , , ,

Wednesday, April 05, 2006

Security Tip #10 - Don't Risk Client Trust

Don’t risk losing your clients’ trust in you. Protect your IT systems with security policies and procedures. You'll protect your information assets and your valuable image and reputation.

By not having sound policies and procedures, many organizations face the following risks:


  • Loss of data integrity and client trust in you


  • Your clients incur lower levels of service due to untimely IT operations


  • You experience increased management accountability due to loss of adequate controls


  • You incur increased costs due to systems that are not always available

Security policies and procedures can help you maintain client confidentiality. By implementing effective policies and procedures, client trust is maintained even while security threats are increasing at an alarming rate.

Many critical business processes and client interactions are now automated to the point where the importance of security readiness has risen exponentially. Don’t count on firewalls and passwords to protect your valuable information assets. Security policies help you manage your risks and are your key to maintaining client trust.

Find out why you need a managed approach to security instead of the ad-hoc approach that leaves many organizations vulnerable.

Labels: , , ,

Friday, March 03, 2006

Does Ad-hoc Security Really Work?

Ad-hoc security may not provide the level of security you need. Imagine installing a firewall here and a database application there. Each element may be secure, however, when all components are combined into an interrelated network, your organization may be at risk.

Altius IT recommends a formalized and planned approach to security. Security design allows top down planning and implemention of security technology. Not only does this approach offer enhanced security, it may also reduce your costs since security can be aligned with your organization's goals and objectives.

Labels: ,

Thursday, December 01, 2005

Want to Save on Security Costs?

Security alignment. Concerned that you aren't cost effectively allocating your security resources? Information Technology (IT) strategy and security alignment ensures cohesive goals and results throughout the enterprise. Altius IT’s security services align IT to the organization, improve efficiencies, reduce costs, enhance customer service, and help the organization achieve a competitive edge in its market place.

Labels: , ,

Saturday, October 08, 2005

Reduce Total Cost of Ownership

Reduce total cost of ownership. Industry leading organizations know that IT systems need to be properly managed and maintained. The “Fix on Fail” approach to systems management results in employee frustration, missed deadlines, increased costs and lower levels of client service.

Altius IT recommends the managed solutions listed below. The support schedule depends upon the importance of IT to your organization.

Daily/Weekly

  • Check hard drive – capacity and free space

  • System – scan drives for errors, defragment

  • Software patches – patch management

  • Review anti-virus software – auto updates

  • Troubleshooting – examine log files for errors

  • Check anti-spyware – updates and scans

  • User access – add/remove access to systems

  • Applications – add/configure and troubleshoot

  • Mobile devices – synchronize with desktops

  • User support – problem determination, assistance

  • Server – application monitoring and size limits
Monthly/Quarterly service


  • E-mail – size, user delegate permissions

  • Firewall – firmware updates, subscription status

  • Internet - review firewall bottlenecks and log file

  • System backups - test and review off-site rotation

  • Security assessment – penetration test and report

  • Backup e-mail – test proper operation and findings

  • Public folders – access and security

  • Data folders – access and security

  • Document – retention procedures, archiving

  • Assessment – independent review of systems
Annual service


  • Integrity – review user access to systems & data

  • IT alignment – with business goals and direction

  • IT planning – long range planning and updates

  • IT budget – maintenance and special projects

  • Policies – review/update policies and procedures

  • Best practices – to ensure system availability

  • Business continuity – testing and plan revision

  • Updates – renew annual subscriptions

  • Domains – check expiration of domain names

  • Archiving – year end archiving procedures

  • Best practices – tools/checklists (database, e-mail)

  • Audit – outside independent audit of IT
For more information, please refer to Altius IT's managed networking and security services.

Labels: , , ,

Sunday, September 11, 2005

Freedom and Peace of Mind

Time…there is never enough of it. Have you ever thought how nice it would be to have unlimited time where you can spend as much time as needed to secure your systems? The reality is that you wear many hats and you don't have sufficient time to spend on security.

Life made easier one task at a time. The solution is IT support on demand. It helps you be every where you need to be. Outsourced IT can be your virtual IT assistant. Unique suites of services allow you to accomplish multiple tasks simultaneously without the normal time constraints.

Hourly, daily, weekly, and monthly support packages are provided based upon your specific needs and requirements.


  • Manage IT Suite provides you with the peace of mind knowing that Altius IT provides you with technical expertise so your network is well managed and maintained.

  • Enterprise-wide security audit services provides a multilayered approach to advance your level of security.

  • Risk Management services provide full service solutions to reduce your risks.
Freedom for your business and built for business. Security makes your life easier one task at a time.

Labels: , ,

Saturday, September 10, 2005

Security Vulnerability Flowchart

See how your assets may be threatened. Your information systems face a variety of threats from a number of different sources. Consider the risks you face from:


  • Hackers scanning and probing access points to your network


  • Access to your corporate data from remote locations


  • Firewalls and their limitations


  • E-mail threats such as phishing and viruses


  • Internal security breaches


  • Business continuity and single points of failure issues


  • Web site threats including Denial of Service and defacing


  • Intruder detection and prevention systems


  • Data protection and encryption
Our security audit services provide an Executive Summary overview of how your information assets are threatened.

Labels: , , ,