Top 10 Headaches for Information Security Officers and Managers
If you are responsible for some aspect of information security and want to reduce your stress levels, start by changing any of the following that exist in your organization:
- Servers where ordinary users have privileged accounts.
- Users who modify their own desktops, especially by installing their own software.
- No mechanism for scanning the network for vulnerabilities.
- A single server running everything.
- No logging of firewalled traffic, no summaries or periodic traffic analysis, and no one looking at denied or rejected packets.
- Lack of an intrusion detection system.
- "Temporary" holes made in firewalls to accommodate specific requests.
- Passwords kept on default settings with no password aging in force.
- Employees relying upon vendors to tell them of vulnerabilities found in their products rather than using a third-party bug-tracker.
- An operations team that is not paranoid enough.
|
|
|