Thursday, September 09, 2010

Top 10 Windows Vulnerabilities

By understanding Windows based vulnerabilities, organizations can stay a step ahead and ensure information availability, integrity, and confidentiality. Listed below are the Top 10 Windows Vulnerabilities:
  1. Web Servers - misconfigurations, product bugs, default installations, and third-party products such as php can introduce vulnerabilities.
  2. Microsoft SQL Server - vulnerabilities allow remote attackers to obtain sensitive information, alter database content, and compromise SQL servers and server hosts.
  3. Passwords - user accounts may have weak, nonexistent, or unprotected passwords. The operating system or third-party applications may create accounts with weak or nonexistent passwords.
  4. Workstations - requests to access resources such as files and printers without any bounds checking can lead to vulnerabilities. Overflows can be exploited by an unauthenticated remote attacker executing code on the vulnerable device.
  5. Remote Access - users can unknowingly open their systems to hackers when they allow remote access to their systems.
  6. Browsers – accessing cloud computing services puts an organization at risk when users have unpatched browsers. Browser features such as Active X and Active Scripting can bypass security controls.
  7. File Sharing - peer to peer vulnerabilities include technical vulnerabilities, social media, and altering or masquerading content.
  8. E-mail – by opening a message a recipient can activate security threats such as viruses, spyware, Trojan horse programs, and worms.
  9. Instant Messaging - vulnerabilities typically arise from outdated ActiveX controls in MSN Messenger, Yahoo! Voice Chat, buffer overflows, and others.
  10. USB Devices - plug and play devices can create risks when they are automatically recognized and immediately accessible by Windows operating systems.
Security assessments help organizations identify, manage, and reduce their risks.

Labels: , , ,

Tuesday, March 03, 2009

Small Business Security Quiz

Take this quiz to determine your Security Quotient. Preparation is the key to protecting your company’s information assets. Take this security quiz to determine your Security Quotient.
1) We have recent off-site computer backups. Yes/No
2) We have updated anti-virus software on all computers/servers. Yes/No
3) We restrict employee access to confidential information. Yes/No
4) All of our policies are documented and in written form. Yes/No
5) We have a firewall to protect us. Yes/No
6) We encrypt confidential documents/E-mail. Yes/No
7) We have a formal electronic document archiving procedure. Yes/No
8) We monitor and restrict Internet access. Yes/No
9) We performed a security assessment of our IT systems. Yes/No
10) We can distinguish an intruder from normal Internet traffic. Yes/No

Score one point for each Yes answer.
8 or more points - You are well on your way to securing your IT systems.
6 to 7 points - keep working, you may need assistance to reduce risks.
5 or fewer points - you need to make security a priority and get assistance as soon as possible.

Network and security assessments help protect your sensitive information and provide peace of mind.

Labels: , , ,

Tuesday, February 03, 2009

Managed Security Services

Leading firms are taking a proactive approach to security and using managed security services to reduce their IT related risks. Managed security services typically provide traditional forms of security protection:
  • Network Infrastructure - Physical access to servers, system backups with off-site rotation, encrypting the backup media, and protecting wireless networks.
    Internet Connectivity - protection can include firewalls & Virtual Privacy Network (VPN), intrusion detection and prevention, and remote connectivity.
  • Management - incident response plans, patch management, and change management processes.
  • Employee Management - policies and procedures, passwords, protection against social engineering, locking down USB thumb drives, handheld PDA's, encrypting laptop hard drives, etc.
  • Document Management - protection includes access privileges, document retention and archiving, encryption, etc.
  • Electronic threats - protection from anti-virus, anti-spyware, anti-popup, etc.
  • E-mail & Communications - anti-spam, e-mail archiving, instant messaging (IM), and archiving.
  • Risk Management - risk evaluation, business continuity planning, testing, etc.
While managed security services provide the initial layers of protection against IT related threats, they should be supplemented with security assessments and audits. Assessments and audits help ensure the organization's security expenditures are properly allocated to the most important areas. In addition, assessments and audits help protect the organization's intellectual property and its image and reputation.

Labels: , ,

Tuesday, January 06, 2009

Security Assessments – A Subscription Service

A matter of priority. Not every security risk is created equal. Some risks have a greater impact than others. In addition, some threats are more likely to occur than others. Security assessments help organizations allocate their budget to the areas that reduce risks.

Security is an on-going process and leading organizations are taking a subscription approach to security assessments. With new vulnerabilities discovered on a daily basis, a system that is secure one day may be completely wide open the next. Much like regular anti-virus updates, subscribing to recurring security assessments helps your organization identify weaknesses before they can be exploited. Security assessments provide specific knowledge about your system, allowing you to more effectively allocate your security budget.

Don’t wait for an unwanted intruder to discover your network vulnerabilities. A comprehensive network security assessment helps:
  • Protect your image and reputation
  • Reduce your costs by cost effectively allocating your security budget to the most important areas

Labels: ,

Thursday, August 07, 2008

New and Emerging Threats

One way organizations manage new and emerging threats is by performing network and security assessments and audits on a periodic basis. By reviewing your systems, people, and processes, assessments helps determine the areas that create the greatest risk.

Once the assessment has identified risk areas, the organization can quantify the likelihood of the event and implement corrective action to mitigate and reduce IT related risks. This prioritized Action Plan is a risk response mechanism that addresses the risks according to the importance to the organization.

By allocating IT funds to areas that are most critical, assessments and audits add value to the organization by:
  • Helping align IT with the business
  • Prioritize security spending
  • Allocating resources to areas with the greatest impact

Labels: , , , , , ,

Tuesday, July 01, 2008

Security Assessments

The assessment difference. Many organizations wait until it is too late, either they've been hacked or they are mandated by regulations to have an outside, external security assessment. Leading organizations don't wait and are proactive, using outside security assessments to help the firm leverage its IT investment to enhance employee productivity, reduce costs, improve customer service, and achieve a competitive edge.

As organizations automate manual processes, information systems and the data they manage become a corporate asset. In addition to increasing value, these same information systems create additional risk for the organization and create a single point of failure.

Network and security assessments help organizations identify, manage, and reduce their risks. In addition to technical configurations, security assessments can also be used to review your staff, how they work, and their procedures.

Find out more information about various types of assessments that help manage firewall, user, web application, database, and compliance related risks.

Labels: , , ,

Wednesday, June 11, 2008

Overview of Security Standards

Standards help protect information. All organizations, regardless of size, need to secure their data and intellectual property. Standards provide organization management information security guidance and direction. Each standard, when applied effectively, helps an organization address security related issues. Standards represent the knowledge of a large number of experts and provide security implementation recommendations. However, by their nature, standards cannot exactly match the requirements of every organization and care must be taken when determining the appropriateness for each organization.

Various Standards
  • ITIL - Information Technology Infrastructure Library is not focused on security. Instead, it provides a foundation for managing IT infrastructure with a primary focus on service support and service delivery.
  • COBIT - Control Objectives for Information and related Technology focuses on controls that provide management with assurance that IT is operating in a controlled manner.
  • NIST - the National Institute of Science and Technology develops and issues standards, guidelines, and other publications to assist federal agencies in implementing the Federal Information Security Management Act (FISMA) of 2002 and aims to protect information and information systems.
  • ISO - the International Organization for Standardization (ISO) is the world’s largest developer of standards (over 15,000 in total), including the 27000 series focused on information security.
When combined with assessments, standards can help you identify, manage, and reduce your security risks.

Labels: , , ,

Thursday, March 06, 2008

Controls Help Mitigate and Reduce Risks

Controls are administrative, management, technical, and legal methods that are used to manage risk. Controls include policies, procedures, programs, techniques, technologies, guidelines, and organizational structures. They help an organization comply with standards by addressing information security risks, information confidentiality, integrity, and availability.

Security policies and control objectives express management’s commitment to the implementation, maintenance, and improvement of its information security management system. Leading organizations use best-practice information security control measures to satisfy the stated control objectives. Standards frequently do not mandate specific controls, but leave it to the users to select and implement controls that suit them, using a risk-assessment process to identify the most appropriate controls for their specific requirements. Organizations are typically free to select controls as long as their control objectives are satisfied.

Leading organizations follow a Plan, Do, Check, and Act process:


  • Plan – planning

  • Do – implement, operate, and maintain

  • Check - monitor, audit, and review

  • Act – continual improvement
An example of a control standard is ISO/IEC 27002:2005 Information technology -- Security techniques -- Code of Practice for Information Security Management. Network and security assessments are part of the "Check" process and help ensure you have the proper controls in place and they are functioning as desired.

Labels: , , ,

Thursday, October 11, 2007

Need to Manage your Risks?

Mid-size firms have growth challenges. Many are growing quickly and don't have the resources of large firms. One mid-size organization provided employment screening and background checks. The firm was growing rapidly, attracting large clients, and expected to double in size within two years. Management was concerned that the IT staff and infrastructure cannot support the organization’s rapid growth.

They contracted with a firm to provide a network assessment amd an analysis of data backups, anti-virus, e-mail, software licensing, software patching, laptops, and many other areas. In addition to the IT infrastructure, the Work Plan included interviews with IT, management, and key users to determine if there was an alignment or satisfaction issue with IT.

The analysis included a comparison of the IT department with industry benchmarks so the organization could evaluate if they were making effective use of IT spending. The assessment also reviewed written policies, business continuity plans, and related procedures and guidelines.

The assessment identified several “hidden” issues that would have caused a disruption in business operations. The prioritized Action Plan gave the firm guidance to make immediate changes to their network infrastructure and IT staff. The organization’s management had peace of mind knowing that the plan allowed the firm double in size over the next two years.

Network assessments provide management with peace of mind and help organizations achieve growth targets.

Labels: , , , , ,

Tuesday, April 17, 2007

5 Steps to Risk Management

Risk management services provide strategies, processes, and tools to identify, analyze, respond to, control, and evaluate risks. A formal five step approach to risk management helps organizations identify, manage and reduce risks.
1. Identify Risks - Assessment. Outside, independent assessments identify risks that cause downtime and business interruption. Review your technology systems, people, and processes.
2. Risk Findings - Analysis. Additional investigation and research. Analyze findings and evaluate your organization’s risk tolerance based upon information provided during the assessment.
3. Risk Response - Action Plan. Develop a prioritized action plan of recommendations, responsibilities, and related costs. The Action Plan provides the steps needed to address vulnerabilities.
4. Risk Control - Managed Services. Managed networking and security solutions protect your information assets.
5. Risk Effectiveness – Evaluate & Repeat. Evaluate the effectiveness of your organization’s risk management mechanisms. Not just a one-time event, prepare for the next assessment.

Find out more about assessments and how they can help your organization reduce its risks.

Labels: , , , ,

Tuesday, January 16, 2007

Security Tip #1 - Assessments Enhance Value

Network and security assessments and audits help determine if IT funds are effectively being used, identify and quantify IT related strengths and weaknesses, and help you focus on those areas that create the most value for your firm. Assessments are ideal for:


  • Ensuring compliance (HIPAA, Sarbanes Oxley, etc.)


  • Emerging and fast growing firms


  • IPO ready organizations


  • Organizations concerned about security


  • Businesses with geographically distributed offices


  • Organizations in the financial and health care industries


  • Firms working with the government or large institutions


  • Organizations that share and collect personal and/or proprietary data

Assessments and Business Value

While some organizations want tactical advice on the state of the IT department, others want to maximize their investment in IT by developing and implementing a formal strategy. Before an organization can develop and execute strategy, the business can use assessments to understand its IT infrastructure and related strengths and weaknesses.

Find out more about IT network and security assessments and how they can help your organization.

Labels: , , , , ,

Tuesday, October 03, 2006

Security Tip #4 - Hackers, What You Need to Know

Hackers know things that you don't. That's their edge. It's the reason that they can break into networks, leaving a path of destruction in their wake. Concerned about security? Your concerns may be directly related to the value of the information you are trying to protect. For example, is your data difficult to recreate? What are the implications if someone outside the company gets access to your confidential documents? You can’t always prevent hackers from breaking in, but you can make it more difficult for them to succeed.

Why you need formal security protection:


  • Hackers like the challenge of breaking into systems

  • Without proper protection, any part of your network is at risk

  • Hackers cause network downtime (downtime cost calculator)

  • Hackers seek out weaknesses in your systems
Don't assume that ad-hoc security can protect you from Internet threats. A managed approach to security provides the protection you need.

Labels: , , , , , ,

Tuesday, September 19, 2006

Security Tip #5 - Employees are your hidden threat

Internal employee threats. You have probably taken steps to secure your systems from external “hacker” threats. But what steps have you taken to protect your organization from your own employees? The Computer Security Institute estimates that between 60% and 80% of network misuse comes from within the enterprise.

Managing your employees and their access to data help you manage your risks. From the inside, employees bypass many of your controls designed to protect your data from unwanted intruders. Even if you maintain passwords on confidential documents, employees can run scripts that detect and remove passwords on files. How can you address this employee threat? Identify your vulnerabilities and integrate security solutions at the network level.

The top three reasons why you need employee network level security protection:

  • Your employees already have access to your network.

  • Employees don’t have to pass through external security checkpoints.

  • Your confidential data needs more than password protection.

Enhance and enforce security at the network level. Managing your employees and their access to data help you manage your risks. Please visit Altius IT for more information on security readiness and risk management.

Labels: , , ,

Thursday, July 06, 2006

Security Tip #7 - Passwords, what you need to know

Passwords, are you ever really secure? If you have a newer computer, you already know the experience of increased productivity you get from having state-of-the-art equipment. What you don’t know is that faster systems, when combined with high-speed Internet lines, let unwanted visitors “crack” your passwords at an alarming rate.

Many organizations forget that not all of their threats are external, internal threats must be considered as well. In addition, confidential data may be accessed from remote locations and a good password policy may be the only protection.

Without a formalized password protection policy, you risk loss of revenue due to system and network downtime. Many organizations have determined their cost of downtime, however recent surveys show that the cost to recreate data is generally greater than originally estimated. In addition to internal costs, organizations must consider the cost of customer dissatisfaction due to loss of data integrity.

Passwords are a critical component of your security readiness. Formalize your password policies and verify that they are enforced. Inconsistent password policies and procedures leave you at risk and cannot protect your valuable information assets. Managing your passwords will help you manage your risks and protect your image and reputation.

Want more information on how passwords can be part of an overall approach to securing your network? Find out how our security consulting service provides information asset protection.

Labels: , , ,

Tuesday, June 06, 2006

Security Tip #8 - Security Assessments

Subscription security assessments. It is often difficult to decide where to properly allocate your security budget. Rather than simply throwing money at the problem, leading organizations use periodic security assessments to help pinpoint network security issues.

As new vulnerabilities are discovered on a daily basis, a system that is secure one day may be completely wide open the next. Much like regular anti-virus updates, subscribing to recurring security assessments helps an organization identify network security weaknesses before they can be exploited.

In addition to protecting your IT systems, periodic security assessments help protect your organization's reputation by helping identify vulnerabilities before they are exploited by unwanted intruders. Find out more about security assessments and how they can help protect your "information assets".

Labels: , , , , ,

Saturday, September 10, 2005

Security Quiz - Find Your Security IQ

Think you are secure? Take a security quiz and find your security IQ. Protection of your network and data is one of your primary concerns. This simple Security Quiz will help you determine your Security Quotient. Score one point for each Yes answer in this simple ten question quiz.

Labels: , ,