MaxStocker.com   MaxStocker.com    
   
Home About Blog Stuff Contact
 
   
 

July 2008

Time for ISP responsibility
Posted : Fri July 25th

Keep a lid on it
Posted : Tue July 22nd

4 minutes till doomsday
Posted : Tue July 15th

It's your name, you should own it
Posted : Mon July 14th

Scum sucking weasels
Posted : Fri July 11th

The weakest link
Posted : Thu July 10th

Whoo-hoo
Posted : Sat July 5th

Google paranoia... again
Posted : Wed July 2nd

Updated word game
Posted : Thu June 26th

Another deep thought
Posted : Sun June 22nd

Fun stuff update
Posted : Thu June 19th

Deep thought for the week
Posted : Sat June 14th

How to compare hosting packages
Posted : Mon June 9th

When things go wrong
Posted : Sat June 7th

Recent Comments

Max in Whose blog is it anyway?
on Mon May 10th

Rob in Whose blog is it anyway?
on Fri May 7th

Anonymous in SEO and the magic beans
on Thu April 8th

Max in SEO and the magic beans
on Thu April 8th

n.o. in SEO and the magic beans
on Thu April 8th

silky in Right way, wrong way
on Fri February 19th

Categories

Technical
69 Entries

Security
18 Entries

Java
23 Entries

Privacy
6 Entries

Database
11 Entries

Internet
58 Entries

Business
31 Entries

Site Updates
19 Entries

Personal
86 Entries

RSS Feed RSS Feed

Tag Cloud

The weakest link
Posted : Thursday July 10th, 2008

As they say, a chain is only as long as its weakest link. So how strong is your security chain?

The reality is that the weakest link for most secure systems is not the systems themselves but the users. User education and training form a fundamental part of establishing a truly secure system.

We all know the stories. Users who keep their passwords on sticky notes attached to the monitor. Users who rotate through the same three or four passwords year after year. Users who use obvious passwords.

But there's even more to it. If a person, purporting to be an IT person contacted an employee could they get their username and password from them? Do your employees know how to judge the credentials of people who contact them? Do your employees know that they should never be giving out usernames and passwords to anyone, for any reason, ever?

It's worth keeping in mind whether you are auditing an existing system or planning for a new one, if you can't make the investment in your people there is no point in investing in expensive hardware or software. At the end of the day if a system fails because people don't understand it, or understand what is important then the system might as well not exist in the first place.

Tags

links  security  thinking  weak 

Categories

Security 

Comments

silky - Jul 11th 2008 8:54 PM
 
I must say, in my opinion educating users is not the answer to security problems. It'll never work. (it never does). The system needs to be designed to accomodate idiots. mho.


Max - Jul 14th 2008 8:55 PM
 
I totally disagree with the above and I find that kind of shortsighted thinking to be one of the problems in this field to be honest with you.

If you read the second paragraph above I specifically noted that users are a part of your security system in fact they are part of _every_ security system. If you just go with, "The users are stupid", you have failed before you started.


 
   
  Follow me on Twitter   My Facebook Profile   My LinkedIn Profile   RSS feed of my blog Home   |   About   |   Blog   |   Stuff   |   Contact   |   Privacy Policy  
   
  © 2008 Max Stocker