Thursday, September 09, 2010

Top 10 Windows Vulnerabilities

By understanding Windows based vulnerabilities, organizations can stay a step ahead and ensure information availability, integrity, and confidentiality. Listed below are the Top 10 Windows Vulnerabilities:
  1. Web Servers - misconfigurations, product bugs, default installations, and third-party products such as php can introduce vulnerabilities.
  2. Microsoft SQL Server - vulnerabilities allow remote attackers to obtain sensitive information, alter database content, and compromise SQL servers and server hosts.
  3. Passwords - user accounts may have weak, nonexistent, or unprotected passwords. The operating system or third-party applications may create accounts with weak or nonexistent passwords.
  4. Workstations - requests to access resources such as files and printers without any bounds checking can lead to vulnerabilities. Overflows can be exploited by an unauthenticated remote attacker executing code on the vulnerable device.
  5. Remote Access - users can unknowingly open their systems to hackers when they allow remote access to their systems.
  6. Browsers – accessing cloud computing services puts an organization at risk when users have unpatched browsers. Browser features such as Active X and Active Scripting can bypass security controls.
  7. File Sharing - peer to peer vulnerabilities include technical vulnerabilities, social media, and altering or masquerading content.
  8. E-mail – by opening a message a recipient can activate security threats such as viruses, spyware, Trojan horse programs, and worms.
  9. Instant Messaging - vulnerabilities typically arise from outdated ActiveX controls in MSN Messenger, Yahoo! Voice Chat, buffer overflows, and others.
  10. USB Devices - plug and play devices can create risks when they are automatically recognized and immediately accessible by Windows operating systems.
Security assessments help organizations identify, manage, and reduce their risks.

Labels: , , ,

Thursday, July 01, 2010

Top 10 Wireless Network Risks

Many organizations are installing and implementing wireless networks. To help business managers make informed decisions, Altius IT provides this list of the Top 10 wireless network risks:
  1. Bandwidth Stealing – Outside intruders can connect to wireless access points. By using the Internet connection to download music, games, and other software, they reduce employee productivity.
  2. Criminal Activity - An unauthorized user can use the Internet connection for malicious purposes such as hacking or launching Denial of Service Attacks.
  3. Masquerade – By using the Internet line, an intruder “hides” under protective cover and appears to be a part of your organization.
  4. Litigation Risks – Organizations are at risk if the intruder is doing illegal activity such as distributing child pornography. If the criminal activity is discovered and investigated, the origin of the attack will be traced back to the organization.
  5. Reputation - An organization’s image and reputation is at stake if the wireless network was used as the initial access point to hack into restricted government networks.
  6. Financial risks - Most ISP's not only reveal customer information to the authorities to assist with legitimate criminal investigations, but also hold the organization responsible for any and all activities related to the Internet connection.
  7. Confidentiality – Wireless networks tend to be connected to in-house private networks. This may allow an intruder to completely bypass any hardware firewall protective devices between the private network and the broadband connection.
  8. Evil Twins - Most new laptops include the ability to connect to wireless networks. Laptop computers may accidentally connect to fake (“evil twin”) networks. Employees believe they are connected to the authentic network however they are actually connected to a fake network that steals ids, passwords, and other confidential information.
  9. Clear text – Some network information is transmitted in clear text and is not encrypted. Once inside your network, an intruder can install a network sniffer and gain access to confidential information without the victim’s knowledge.
  10. Information Sensitivity – Not all data has the same sensitivity. Due to the risks involved with wireless networks, confidential data such as client lists, trade secrets, etc. should not be stored on or accessible by wireless networks.
Security Assessments help organizations identify, manage, and reduce their wireless network risks. For more information please visit us at http://www.altiusit.com/.

Labels: , , , ,

Tuesday, June 16, 2009

Proactive Document Management

As organizations review their business processes and make them more efficient, document management solutions help automate the process of electronically capturing, storing, and securely managing business information.

Benefits of electronic document management solutions include:
  • Centralized storage of information leads to increased employee productivity
  • Enhanced levels of customer service through improved access to information
  • Reduced costs by instantly locating documents
Document management solutions do have their risks. If documents are not filed using a formal methodology, document management solutions can reduce employee productivity and increase your costs. In addition, failure to manage and secure your documents may increase your liability to lawsuits.

A proactive approach to managing electronic files protects your documents and helps meet compliance requirements. Many firms are using security audits to help them identify, manage, and reduce their document management risks.

Labels: , ,

Tuesday, February 03, 2009

Managed Security Services

Leading firms are taking a proactive approach to security and using managed security services to reduce their IT related risks. Managed security services typically provide traditional forms of security protection:
  • Network Infrastructure - Physical access to servers, system backups with off-site rotation, encrypting the backup media, and protecting wireless networks.
    Internet Connectivity - protection can include firewalls & Virtual Privacy Network (VPN), intrusion detection and prevention, and remote connectivity.
  • Management - incident response plans, patch management, and change management processes.
  • Employee Management - policies and procedures, passwords, protection against social engineering, locking down USB thumb drives, handheld PDA's, encrypting laptop hard drives, etc.
  • Document Management - protection includes access privileges, document retention and archiving, encryption, etc.
  • Electronic threats - protection from anti-virus, anti-spyware, anti-popup, etc.
  • E-mail & Communications - anti-spam, e-mail archiving, instant messaging (IM), and archiving.
  • Risk Management - risk evaluation, business continuity planning, testing, etc.
While managed security services provide the initial layers of protection against IT related threats, they should be supplemented with security assessments and audits. Assessments and audits help ensure the organization's security expenditures are properly allocated to the most important areas. In addition, assessments and audits help protect the organization's intellectual property and its image and reputation.

Labels: , ,

Thursday, December 04, 2008

Mitigating Risks

Organizations are finding that IT systems are a double edge sword. Not only do they increase employee productivity and reduce costs, they also increase risks as intellectual property and sensitive information are stored in a central location. Assessments can help organizations identify and manage risks. Once risk areas have been identified, organizations have a number of ways to mitigate or reduce their risks.

  • Risk Assumption. Accept the potential risk and continue operating the IT system or implement controls to lower the risk to an acceptable level. Administrative, physical, and technical controls help lower the organization's risks.
  • Risk Avoidance. Avoid the risk by eliminating the risk and/or consequence. For example, bypass or eliminate certain functions of a system or shut down the system when risks are identified.
  • Risk Limitation. Limit the risk by implementing controls that minimize the adverse impact of the risk. For example, implement preventive controls such as Intrusion Prevention Systems (IPS) that actively identify and restrict access to information.
  • Risk Planning. Manage risks by developing a risk mitigation plan that prioritizes, implements, and maintains controls. Implement managed services to minimize risks.
  • Risk Research. Lower the risk of loss by acknowledging the vulnerability or flaw and researching controls to correct the vulnerability.
  • Risk Transference. Compensate for the loss by transferring the risk to another party. In addition to securing systems,organizations have the option to insure against security breaches. For example, insurance can cover the cost of regulatory mandated notifications that a security breach has occurred as well as fines, fees, or penalties arising from privacy or consumer protection errors.

Labels: , , ,

Tuesday, November 11, 2008

Database Regulatory and Compliance Issues

Sarbanes-Oxley (SOX), the Health Insurance Portability and Accountability Act (HIPAA), and the Gramm-Leach-Bliley (GLB) Act were all enacted to help protect information. These acts require internal controls to protect information integrity, confidentiality, availability, and accountability. While accountants and auditors are familiar with internal controls, many IT departments lack the the knowledge and controls needed to safeguard information. Even sophisticated databases, managed by Database Administrators (DBAs), lack secure controls and and connectivity to information.

Many DBAs have complete access to all of your organization's data. While complete access helps manage and minimize downtime, it also puts your organization at risk as the DBA has access to all information and log files. Your management must determine the minimum amount of access needed to allow the DBAs to perform job duties. For example, must the DBA have access to confidential or sensitive data such as payroll, protected health information (PHI), or other types of confidential information?

Assessments help ensure your internal controls provide the appropriate reporting and procedures, detect unauthorized use of systems, and meet compliance requirements.

Labels: , ,

Thursday, August 07, 2008

New and Emerging Threats

One way organizations manage new and emerging threats is by performing network and security assessments and audits on a periodic basis. By reviewing your systems, people, and processes, assessments helps determine the areas that create the greatest risk.

Once the assessment has identified risk areas, the organization can quantify the likelihood of the event and implement corrective action to mitigate and reduce IT related risks. This prioritized Action Plan is a risk response mechanism that addresses the risks according to the importance to the organization.

By allocating IT funds to areas that are most critical, assessments and audits add value to the organization by:
  • Helping align IT with the business
  • Prioritize security spending
  • Allocating resources to areas with the greatest impact

Labels: , , , , , ,

Tuesday, July 01, 2008

Security Assessments

The assessment difference. Many organizations wait until it is too late, either they've been hacked or they are mandated by regulations to have an outside, external security assessment. Leading organizations don't wait and are proactive, using outside security assessments to help the firm leverage its IT investment to enhance employee productivity, reduce costs, improve customer service, and achieve a competitive edge.

As organizations automate manual processes, information systems and the data they manage become a corporate asset. In addition to increasing value, these same information systems create additional risk for the organization and create a single point of failure.

Network and security assessments help organizations identify, manage, and reduce their risks. In addition to technical configurations, security assessments can also be used to review your staff, how they work, and their procedures.

Find out more information about various types of assessments that help manage firewall, user, web application, database, and compliance related risks.

Labels: , , ,

Wednesday, June 11, 2008

Overview of Security Standards

Standards help protect information. All organizations, regardless of size, need to secure their data and intellectual property. Standards provide organization management information security guidance and direction. Each standard, when applied effectively, helps an organization address security related issues. Standards represent the knowledge of a large number of experts and provide security implementation recommendations. However, by their nature, standards cannot exactly match the requirements of every organization and care must be taken when determining the appropriateness for each organization.

Various Standards
  • ITIL - Information Technology Infrastructure Library is not focused on security. Instead, it provides a foundation for managing IT infrastructure with a primary focus on service support and service delivery.
  • COBIT - Control Objectives for Information and related Technology focuses on controls that provide management with assurance that IT is operating in a controlled manner.
  • NIST - the National Institute of Science and Technology develops and issues standards, guidelines, and other publications to assist federal agencies in implementing the Federal Information Security Management Act (FISMA) of 2002 and aims to protect information and information systems.
  • ISO - the International Organization for Standardization (ISO) is the world’s largest developer of standards (over 15,000 in total), including the 27000 series focused on information security.
When combined with assessments, standards can help you identify, manage, and reduce your security risks.

Labels: , , ,

Thursday, April 10, 2008

Web Application Security

Web applications are the most vulnerable element of an organization’s IT infrastructure. As your organization uses the Internet for customer, supplier, employee, and vendor interactions, Web technologies and database interfaces become more complex and require additional security. Web application and database assessments are ideal for:


  • Web sites that interface with database systems

  • Ensuring compliance (HIPAA, Sarbanes Oxley, GLB, etc.)

  • Emerging and fast growing firms Businesses concerned about security

  • Organizations in the financial and health care industries

  • Buffer overflow, SQL injections, cross site scripting, JavaScript, and other programming concerns
Web application security assessments help your firm manage a range of vulnerabilities including buffer overflow, SQL injection, cross site scripting, Google hacking, authentication risks, JavaScript, Common Gateway Interface (CGI), PHP, broken links, authentication hacking, and many other types of web related vulnerabilities.

Labels: , , ,

Thursday, October 11, 2007

Need to Manage your Risks?

Mid-size firms have growth challenges. Many are growing quickly and don't have the resources of large firms. One mid-size organization provided employment screening and background checks. The firm was growing rapidly, attracting large clients, and expected to double in size within two years. Management was concerned that the IT staff and infrastructure cannot support the organization’s rapid growth.

They contracted with a firm to provide a network assessment amd an analysis of data backups, anti-virus, e-mail, software licensing, software patching, laptops, and many other areas. In addition to the IT infrastructure, the Work Plan included interviews with IT, management, and key users to determine if there was an alignment or satisfaction issue with IT.

The analysis included a comparison of the IT department with industry benchmarks so the organization could evaluate if they were making effective use of IT spending. The assessment also reviewed written policies, business continuity plans, and related procedures and guidelines.

The assessment identified several “hidden” issues that would have caused a disruption in business operations. The prioritized Action Plan gave the firm guidance to make immediate changes to their network infrastructure and IT staff. The organization’s management had peace of mind knowing that the plan allowed the firm double in size over the next two years.

Network assessments provide management with peace of mind and help organizations achieve growth targets.

Labels: , , , , ,

Tuesday, April 17, 2007

5 Steps to Risk Management

Risk management services provide strategies, processes, and tools to identify, analyze, respond to, control, and evaluate risks. A formal five step approach to risk management helps organizations identify, manage and reduce risks.
1. Identify Risks - Assessment. Outside, independent assessments identify risks that cause downtime and business interruption. Review your technology systems, people, and processes.
2. Risk Findings - Analysis. Additional investigation and research. Analyze findings and evaluate your organization’s risk tolerance based upon information provided during the assessment.
3. Risk Response - Action Plan. Develop a prioritized action plan of recommendations, responsibilities, and related costs. The Action Plan provides the steps needed to address vulnerabilities.
4. Risk Control - Managed Services. Managed networking and security solutions protect your information assets.
5. Risk Effectiveness – Evaluate & Repeat. Evaluate the effectiveness of your organization’s risk management mechanisms. Not just a one-time event, prepare for the next assessment.

Find out more about assessments and how they can help your organization reduce its risks.

Labels: , , , ,

Tuesday, January 16, 2007

Security Tip #1 - Assessments Enhance Value

Network and security assessments and audits help determine if IT funds are effectively being used, identify and quantify IT related strengths and weaknesses, and help you focus on those areas that create the most value for your firm. Assessments are ideal for:


  • Ensuring compliance (HIPAA, Sarbanes Oxley, etc.)


  • Emerging and fast growing firms


  • IPO ready organizations


  • Organizations concerned about security


  • Businesses with geographically distributed offices


  • Organizations in the financial and health care industries


  • Firms working with the government or large institutions


  • Organizations that share and collect personal and/or proprietary data

Assessments and Business Value

While some organizations want tactical advice on the state of the IT department, others want to maximize their investment in IT by developing and implementing a formal strategy. Before an organization can develop and execute strategy, the business can use assessments to understand its IT infrastructure and related strengths and weaknesses.

Find out more about IT network and security assessments and how they can help your organization.

Labels: , , , , ,

Thursday, November 02, 2006

Security Tip #3 - Firewalls, What they Can't Do For You

Firewalls can't do everything. Firewalls are a good first step to protect you against hackers, but they do have their limitations. Like a deadbolt lock on a front door, a firewall can't tell you if you have other vulnerabilities that might allow a hacker access to your network.

Why you need formalized security protection:


  • Firewalls can’t protect against attacks that don’t go through the firewall – wireless networks, dial-up modems, and internal employees often by-pass firewall protection
  • Firewalls reflect the overall level of security of your network – a failure may expose your sensitive data

  • Firewalls stop incoming threats but you still require formalized management, destruction, and archival procedures for your electronic documents

  • Firewalls are not a replacement for a strong Security Policies and Procedures Manual

Your reputation is compromised when a firewall doesn’t encrypt confidential documents and E-mail. Your costs increase when a firewall doesn’t protect you against computer viruses. Formalized procedures and tools are needed to protect your confidential documents and electronic communications. Organizations need security vulnerability assessments to manage their risks.

Your security structure is only as strong as its weakest link. Security professionals have the experience needed to help protect your reputation. Security assessments help you identify, manage, and reduce your risks.

Labels: , , ,

Tuesday, October 03, 2006

Security Tip #4 - Hackers, What You Need to Know

Hackers know things that you don't. That's their edge. It's the reason that they can break into networks, leaving a path of destruction in their wake. Concerned about security? Your concerns may be directly related to the value of the information you are trying to protect. For example, is your data difficult to recreate? What are the implications if someone outside the company gets access to your confidential documents? You can’t always prevent hackers from breaking in, but you can make it more difficult for them to succeed.

Why you need formal security protection:


  • Hackers like the challenge of breaking into systems

  • Without proper protection, any part of your network is at risk

  • Hackers cause network downtime (downtime cost calculator)

  • Hackers seek out weaknesses in your systems
Don't assume that ad-hoc security can protect you from Internet threats. A managed approach to security provides the protection you need.

Labels: , , , , , ,

Tuesday, September 19, 2006

Security Tip #5 - Employees are your hidden threat

Internal employee threats. You have probably taken steps to secure your systems from external “hacker” threats. But what steps have you taken to protect your organization from your own employees? The Computer Security Institute estimates that between 60% and 80% of network misuse comes from within the enterprise.

Managing your employees and their access to data help you manage your risks. From the inside, employees bypass many of your controls designed to protect your data from unwanted intruders. Even if you maintain passwords on confidential documents, employees can run scripts that detect and remove passwords on files. How can you address this employee threat? Identify your vulnerabilities and integrate security solutions at the network level.

The top three reasons why you need employee network level security protection:

  • Your employees already have access to your network.

  • Employees don’t have to pass through external security checkpoints.

  • Your confidential data needs more than password protection.

Enhance and enforce security at the network level. Managing your employees and their access to data help you manage your risks. Please visit Altius IT for more information on security readiness and risk management.

Labels: , , ,

Thursday, July 06, 2006

Security Tip #7 - Passwords, what you need to know

Passwords, are you ever really secure? If you have a newer computer, you already know the experience of increased productivity you get from having state-of-the-art equipment. What you don’t know is that faster systems, when combined with high-speed Internet lines, let unwanted visitors “crack” your passwords at an alarming rate.

Many organizations forget that not all of their threats are external, internal threats must be considered as well. In addition, confidential data may be accessed from remote locations and a good password policy may be the only protection.

Without a formalized password protection policy, you risk loss of revenue due to system and network downtime. Many organizations have determined their cost of downtime, however recent surveys show that the cost to recreate data is generally greater than originally estimated. In addition to internal costs, organizations must consider the cost of customer dissatisfaction due to loss of data integrity.

Passwords are a critical component of your security readiness. Formalize your password policies and verify that they are enforced. Inconsistent password policies and procedures leave you at risk and cannot protect your valuable information assets. Managing your passwords will help you manage your risks and protect your image and reputation.

Want more information on how passwords can be part of an overall approach to securing your network? Find out how our security consulting service provides information asset protection.

Labels: , , ,

Tuesday, June 06, 2006

Security Tip #8 - Security Assessments

Subscription security assessments. It is often difficult to decide where to properly allocate your security budget. Rather than simply throwing money at the problem, leading organizations use periodic security assessments to help pinpoint network security issues.

As new vulnerabilities are discovered on a daily basis, a system that is secure one day may be completely wide open the next. Much like regular anti-virus updates, subscribing to recurring security assessments helps an organization identify network security weaknesses before they can be exploited.

In addition to protecting your IT systems, periodic security assessments help protect your organization's reputation by helping identify vulnerabilities before they are exploited by unwanted intruders. Find out more about security assessments and how they can help protect your "information assets".

Labels: , , , , ,

Saturday, September 10, 2005

Security Quiz - Find Your Security IQ

Think you are secure? Take a security quiz and find your security IQ. Protection of your network and data is one of your primary concerns. This simple Security Quiz will help you determine your Security Quotient. Score one point for each Yes answer in this simple ten question quiz.

Labels: , ,