Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, January 25, 2010

Browser Mayhem: Exploring Your Options?

Ouch! Microsoft’s Internet Explorer is suffering from severe damage to its image, as both the French and German governments have recommended that people abandon the browser due to security breaches, according to the Wall Street Journal blog.

Does jumping ship at this point make sense? There is no clear consensus, as some express reservations about whether IE is actually any more vulnerable than other browsers.

The article states:

“Generally speaking, a browser switch is going to be a lot easier for an individual than it will be for corporate users, where IT policies often dictate which browser people use on their computers.

Graham Cluley, a senior technology consultant and security firm Sophos, said in
a blog post Monday that companies may cause ‘more problems than it’s worth by summarily switching browsers’ because of the potential for employee confusion and Web site compatibility problems caused by the new software.

‘My advice is to only switch from Internet Explorer if you really know what you are doing with the browser you’re swapping to,’ Mr. Cluley said. ‘Otherwise it might be a case of ‘better the devil you know.’ “

Are you advocating a switch from Internet Explorer in your organization?

Monday, November 09, 2009

Tech Pros Seek Certification

According to an article in InformationWeek, IT professionals are looking for certification in a number of areas:

“While security-related certifications topped the list of credentials IT pros are seeking, a few new areas of IT specialties also popped up among respondents' five-year career plans--including green IT (7%), healthcare IT (5%), mobile (5%), and software-as-a-service (2%) certifications.”

Healthcare seems to be the hot new niche as the result of a big fat check from the government for IT healthcare initiatives.

Are you jumping on the healthcare bandwagon, or is your eye on a tried-and-true security certificate? How much value do you feel certificates bring to the table?

Sunday, November 08, 2009

Hot Topic: Data Center Security

According to this article on eWeek.com, the majority of data centers do not have adequate defenses in place in the event of a cyber-attack. A study by AFCOM, the world's largest data center industry association, found that:

“Sixty-one percent of survey respondents said they see cyber-terrorism as a threat they need to deal with, but only a little over one-third of data center managers actually have included it in their disaster recovery plans, AFCOM said. Only 25 percent have addressed cyber-terrorism in their policies and procedures manuals, and only 60 percent have a written policies and procedures manual, AFCOM said. Only about 20 percent provide any cyber-terrorism employee training. On the other hand, 82 percent report that they perform background security checks on all potential new employees—another solid defense against cyber-terrorists, AFCOM said.”

There is an obvious gap between the perceived need for a deterrent for cyber-terrorism and what actually is actually done to prevent attacks.

Laziness? Lack of time? Lack of money? Don’t really believe it is necessary?

How do you explain this gap?

Channel Insider’s slideshow, Top Reasons SMB Security Still Sags, seems to provide some answers to this conundrum.

Thursday, November 05, 2009

10 Common Network Security Design Flaws

Brian Posey’s article on TechRepublic highlights 10 common network security design flaws. The list has clear headings, with practical advice on how to fix these flaws.

Read more about each one to get the full story, but here is the short list:
1. Set it and forget it
2. Opening more firewall ports than necessary
3. Pulling double duty
4. Ignoring network workstations
5. Failing to use SSL encryption where it counts
6. Using self-signed certificates
7. Excessive security logging
8. Randomly grouping virtual servers
9. Placing member servers in the DMZ
10. Depending on users to install updates


You don’t need to do a public mea culpa, but take a look at your network – is your company at risk as a result of any of these practices, or are these flaws so basic that only a novice would find them on his or her network?

Monday, April 20, 2009

Restrict Server Room Access to Increase Security

When staff is allowed in the data center, there is really nothing stopping them from plugging a crash cart into a Windows machine or worse, damaging or stealing equipment. By upgrading analog KVM switches with KVM IP gateways, additional security is provided by the ability to relate user names to their designated servers regardless of changes to their port configuration. Your IT staff’s access to servers and devices can be restricted, especially in branch offices where it might be harder to monitor all server room activity. If you don’t want your UNIX administrator to access Windows machines, you can make sure that does not happen.

Almost all KVM IP switches use SSL security; the same tools used by eBay and most ecommerce businesses. By using KVM IP gateways, you can manage and restrict server room access to secure your data center.

*****
Related Material:
White Paper: Remote Support using KVM IP Technology
Online Test Drive: KVM IP Access Demo of all products

Sunday, July 13, 2008

Criminal Behaviour

This report from England is of another data center being hit by thieves. Websites such as that of the Financial Times were hit and down until the back-up servers could be triggered. The snowball affect of these actions is massive. The websites go down and the hundreds of thousands who rely on these websites are in turn affected. Simply after scrap metal, these criminals have no idea about the consequences of their actions. It's not like the world is being brought to its knees like in Die Hard 4.0 but data center security is becoming an increasingly important issue.

Monday, January 14, 2008

Daylight Robbery

In the light of some data center break-ins recently, there is a change in thinking in terms of data center security. As the article says, C I Host is one of those who are altering their mind set.

Wednesday, January 02, 2008

Security

When it comes to concerns regarding data centers, security would be near the very top of the list. This article looks at how data theft hit record highs in 2007. The criminals are not stupid and realise the value of this information. Instead of trying to rob bank, jewellery stores or museums they are going after data. Will be interesting to see how this unfolds in 2008.

Monday, November 05, 2007

Hole In the Wall Gang

Times had definitely changed...
Instead of robbing banks, thieves are now breaking into data centers!!
Security is obviously a massive issue when it comes to data centers given the highly classified nature of much of the data contained on the servers. Banks, other financial institutions and government departments, especially branches of the military are at high-risk. Money is just money but the data on the stolen servers can be worth billions.
You might expect to see something like this on 24 but with this Chicago facility being hit repeatedly in the past couple of years, clearly it is real.