Archived Tips
II. Asset Management
- How do you deal with risk?
- A company should review its information security policies and procedures annually.
- Information security must be supported by executive management to be effective.
- What will make companies take information security seriously?
- Small and mid-sized companies need to do SOMETHING about their Cyber-security!
- What is Enterprise Risk Management?
- Are you protecting you company proprietary information?
- Hat #3: Ask Information Security about PCI DSS.
- What does an insider threat look like?
- What should you look for in an information security leader?
III. Physical Security
- All information is not created equal. Does your company use a data classification system?
- Company's need to inventory all computer equipment and devices (PDA's, cell phones, wireless cards, etc).
- Do you use a password on your smart phone?
- What is a critical asset?
- Does your company inform you on what you can and cannot do on company assets?
- How do you get rid of old CD's or DVD's?
- The company party in 2012 is BYOD!
IV. Human Resources Security
V. Operational Security
- What are your security procedures when you terminate an employee?
- The six most common desk security mistakes employees make everyday.
- What is data leakage?
- Who are your employee's talking to about sensitive information?
- Passwords need to change regularly and when specific incidents occur.
- Announcing an Information Security Awareness Training program for end-users.
- Bank of America suffers 10 million loss from internal fraud.
- If Microsoft called what would you do?
- What is "war texting"?
- Are you a spammer like me?
- Its Black Friday, don't you dare click on that link!
- The punch bowl may be spiked!
- Your smart phone may be telling on you!
VI. Access Control
- How does your company destroy its information systems (computers, hard drives, PDA, etc)?
- What do you do about protecting paper documents?
- Let's dissect your operations!
- Your third party provider has the same information security obligations as your company.
- An expensive case of the "separation of duties"principle.
- What framework is your company using?
- Hat #4: Ask the business about PCI DSS.
- Are you using the FREE information security tools in your environment?
- Are you betting that someone else is doing the vetting?
VII. Information Systems Maintenance
VIII. Incident Management
- What encryption standard are you using for your wireless network?
- Is Anti-Virus enough protection for your company?
- How often should your company check its operating systems and software for updates?
- If you use AT&T and T-Mobile you have a vulnerability.
- What is DLP?
- What does your name say about you?
- Did you know Facebook uses facial recognition?
- Beware: Hackers are after the snackers!
- Hat #2: Ask IT about PCI DSS.
- A "smart phone" is only as "smart" as the user.
IX. Business Continuity / Disaster Recovery
- Would you know if an employee committed a security breach?
- Does your company have a written incident response plan in place?
- How much did a data breach cost in 2010?
- Is it difficult to investigate a security breach? Yes!
- Who is Epsilon and what does their breach mean to you?
- Does your company understand targeted attacks?
- What industry is leading breaches in 2011?
X. Legal and Regulatory Compliance
- "I didn't know I had to do that" is NOT a legal defense!
- Tax prepares must comply with the Gramm-Leach-Bliley Act!
- Your social media posts can be used against you in a court of law!
- Beware when disposing of prescription pill bottles!
- What is the Red Flags Rule?
- Is a national breach notification law needed? Yes!
- Do your employees understand their confidentiality obligations?
- Hat #1 : Ask the attorney about PCI DSS.