ISSA's SoCal Security Symposium
Legacy signals
Legacy popularity: 1,801 legacy views
Great information but forgot a key security component. User Authentication.
On Wed 26th of October I attended the Information Systems Security Association (ISSA) Security Symposium in Long Beach, Califo
ia. Different security leaders discussed poignant topics like Ali Pabrai’s, CEO ecfirst.com, “Checklist for Addressing Breach Readiness” to the lighter hearted David Perry’s, Global Director Education Trend Micro, presentation “Security from the Cloud, for the Cloud, and by the Cloud”. There were also a number of vendor stations discussing a wide array of security products and services.
With so many state and federal data protection laws, and the high costs on a company after a network breach, network security is finally being discussed at the “C-Level” and by the boards of directors. The consensus among these experts is not “if” a cyber attack will occur but “when” will you finally discover that the breach? Or putting it another way there are two kinds of companies; those that have been breached and those that Just don’t know it yet.
I have written numerous articles, white papers and blog posts on the importance of network security. As physical access control systems are important for building security, authenticated access control systems are just as important to network security. Like building security is made up multiple components (door locks, alarms, fences, guards, CCTV, etc.) depending on the risk and value of the content inside the building, network security also requires many components (firewalls, anti-whatever software, abnormality monitoring, encryption, identity management, etc.). However, there was one key component I felt was missing from the show: User Authentication.
It was stated that the first line of defense of a network is the firewall. So the focus has been on having a strong, up-to-date firewall. I agree with its importance, but to me the first line of defense has to be strong user authentication. I’m not talking about user authentication to the public website but into the internal corporate network. The use of a multi-factor smart card has to be a component.
When IT companies rely on just user name and passwords they are fooling themselves that they have network security. Grabbing, sniffing, capturing and hacking passwords has become child’s play. Disgruntled employees, dishonest contractors or money-seeking visitors will do anything to everything from leaving malware infected USB drives on a desk to over-the-shoulder-surfing to get passwords. When IT come up with policies that require longer, more complex passwords that have to be changed frequently this only makes matters worse – not better. These policies drive employees to do stupid things like write passwords down on those sticky notes so cell phone cameras can capture them.
Once user authentication is established then the smartcard can be used to security pass through the firewall and into the identity management system that determines user’s rights and privileges. Strong user authentication is also a must if you have any interest in moving important data into the cloud.
In conclusion:
ISSA held a very valuable and informative symposium; many companies are addressing all different security aspects; the importance of security is finally being discussed at the top levels within a company; and the cost of a data breach can be devastating on a company. So as your IT department develop procedures to safeguard the network, don’t overlook the importance of strong user authentication before ever touching the network.
Article author
About the Author
Dovell Bonnett has been creating security solutions for computer users for over 20 years. In order to provide these solutions to consumers as directly, and quickly, as possible, he founded Access Smart. With each of his innovations, the end user — the person sitting in front of a computer — is his No. 1 customer.
This passion, as he puts it, to “empower people to manage digital information in the digital age” also led him to write the popular Online Identity Theft Protection for Dummies. Within the pervasive nature of our e-commerce and e-business community, personal information, from credit card numbers to your pet’s name, is more easily accessed, and identity theft and fraud has become an issue that touches every consumer.
Further reading
Further Reading
Article
Where to Buy Exclusive Valorant Hacks?
The makers of League of Legends, Riot Games, have a new game out called Valorant. The game has now been released from closed beta and is accessible to gamers everywhere. A strategic shooting game called Valorant has two teams of five players apiece. Valorant pits squads of five members against one another; to win rounds, each team must accomplish specific goals. Every player can join in and play online from any part of the world. Despite the fact that the game is still in its
October 30, 2022
Article
How To Protect Your Retail Business from A Robbery
Throughout the US, a recent spate of smash-and-grab robberies have been affecting many retail businesses and other smaller commercial enterprises; depriving them of the sense of security they may once have had. The financial and emotional impact this has, and continues to have on small businesses, shouldnât be underestimated, and affects not just the business owner, but the employees and other customers, too. Getting together in small gangs (although sometimes itâs upward
December 31, 2021
Article
How To Keep Your Home Safe Over the Festive Period
While the holidays are a fun and festive time for most of us, for some with criminal intentions, itâs a time of endless opportunities for theft, intrusion and generally making innocent peopleâs lives a misery. Keeping your home safe over the festive period is doubtless your priority, and here are some tips to help you achieve that: Resist posting your plans on social media You might want the world to know what fun you have planned over the holidays, but for anyone looking
December 31, 2021
Article
Protecting Your Devices from Cybercrime
Everyone can be a potential victim when it comes to a cybercrime. Many hackers want to gain access to your personal and financial information. No matter how much you think that a hacker will leave you alone and not care about you, it is always a potential hazard to leave your devices unprotected. The best thing that you can do is find the right steps to keep your devices protected from cybercrime. Some of the steps that you can use to make this work include: Use the Full-Serv
September 7, 2021