电脑桌面
添加EHS学习资料网到电脑桌面
安装后可以在桌面快捷访问

04EACSession46.pptxVIP专享VIP免费原创优质

04EACSession46.pptx_第1页
04EACSession46.pptx_第2页
04EACSession46.pptx_第3页
InformationSecurity–CreatingAwareness,EducatingStaff,andProtectingInformationSession46ChrisAidan,CISSPInformationSecurityManagerPearsonTopicsCoveredDataPrivacySpyware&AdwareSPAM&SPIMPhishingPasswordsSocialEngineeringEmail&ChatServicesSecuringWorkstationsDataBackupsEquipmentDisposalDataRecoveryDemoDataDisposalAccessRightsPhysicalSecurityEmergingThreatsIncidentResponseCreatingAwarenessQuestionsUsefulLinksWhySecurity?LiabilityPrivacyConcernsCopyrightViolationsIdentityTheftResourceViolationsReputationProtectionMeetExpectationsLaws&RegulationsUnderstandingThreatsWhatisvaluable?Whatisvulnerable?Whatcanwedotosafeguardandmitigatethreats?Whatcanwedotoprepareourselves?MostbelievetheywillwinlotterybeforegettinghitbymaliciouscodeProtectingInformationlike:SocialSecurityNumberDriverslicensenumberInsurancenumbersPasswordsandPIN’sBankinginformationKeepSensitiveDataPrivateTerminologyHackers–whitehat–greyhat–blackhatDOS&DDOS1337(Leet)speakWarezScriptkiddiesSpyware&Adware(Scumware)Spyware-ApplicationsthatmonitoractivitywithoutexpresspermissionAdware-Applicationsthatmonitoractivitywithexpresspermission–ReadtheEULASPAM&SPIMSPAM-–JunkemailSPIM-SPAMhascometoInstantMessaging–Uncontrolledviewing(pop-upwindows)–BotgeneratedPhishingPhishingisacomputerscamthatusesSPAM,SPIM&pop-upmessagestotrickusintodisclosingprivateinformation(SocialSecurityNumber,CreditCards,bankingdata,passwords,etc)–Oftensentfromsomeonethatwe“trust”orareinsomewayassociatedwithus–Appearstobealegitimatewebsite–Embeddedinlinksemails&pop-upmessage–PhishingemailsoftencontainspywaredesignedtogiveremotecontroltoourcomputerortrackouronlineactivitiesSelectagoodone–Atleast7characters–Mixtureofupperandlowercasecharacters–Mixtureofalphaandnumericcharacters–Don’tusedictionarywordsKeeppasswordssafeChangethemoftenDon’tshareorreusepasswordsTwo-factorauthenticationPasswordsSocialEngineeringSocialEngineeringistheartofpryinginformationoutofsomeoneelsetoobtainaccessorgainimportantdetailsaboutaparticularsystemthroughtheuseofdeceptionEmail&ChatServicesEmailandchataresentincleartextovertheInternetDatacaneasilybecapturedandreadbysavvycomputerusersandsystemsadministratorsSafeguardsshouldbeputintoplacepriortousingtheseprogramsforsending/receivingsensitiveinformationlikeSocialSecurityNumbersEnhanceOurWorkAreaSecuritySecureworkstations–Lockoursystems(Ctrl-Alt-Delete)–Shutdown–Runuptodatevirusscanningsoftware–Passwordprotectfiles–Applysoftwarepatches–Installcablelocks–RunadesktopfirewallIsOurDataBeingBackedUp?TestbackupsSecurelystorebackupmedia(offsite)RestrictaccesstowhocanperformrestorationEquipmentDisposalWhathappenstooldcomputerwhentheyarereplaced?Dothosesystemscontainsensitiveinformation?SeveralprogramstosecurelyremovedatafromcomputersystemsarecommerciallyavailableDataRecoveryDEMODumpsterDivingWeneverknowwhoislookinginourtrashShredsensitivedocumentsSecureshredbarrels,andmakesurethatproperhandlingproceduresareinplaceAccessRightsOnlyallowaccessthatisabsolutelyrequiredDon’tgrantaccountsbasedonthefactthataccess“may”berequiredUseleastprivilegeaccesspoliciesthatstateaccesswillonlybegrantedifrequired,notbydefaultAreaccountsremovedandpasswordschangedwhensomeonechangesjobsoristerminated?Perf...

1、当您付费下载文档后,您只拥有了使用权限,并不意味着购买了版权,文档只能用于自身使用,不得用于其他商业用途(如 [转卖]进行直接盈利或[编辑后售卖]进行间接盈利)。
2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。
3、如文档内容存在违规,或者侵犯商业秘密、侵犯著作权等,请点击“违规举报”。

碎片内容

国企EHS+ 关注
实名认证
内容提供者

国企EHS小张,专门收集EHS资料

最新文章

    确认删除?
    企业微信
    • 微信客服
    客服QQ
    • QQ点击这里给我发消息
    人工电话
    回到顶部