Showing posts with label Information Systems. Show all posts
Showing posts with label Information Systems. Show all posts

Tuesday, August 12, 2014

Video Footages: ATM Skimming!

Be on the lookout for these four tricks and traps

A Handy Way to Foil ATM Skimmer Scams - Thieves continue to place hidden cameras at ATMs to surreptitiously record customers entering their PINs. This previously reported way to stop from being a victim still works against the hidden cameras.

Monday, January 13, 2014

What You May Need to Know about Your Smart TVs & Phones

Smart appliances may be too smart for our own good!

Take smart TVs, for instance. As this article illustrates, some of these new appliances are particularly vulnerable to hackers. Once compromised, the TVs allow access to account information, including login credentials (which owners may use for access to more than just their smart-TV account). Even scarier, hackers could gain access to front-facing cameras to see everything happening in the room where the TV is connected. Instead of you watching your favorite program, criminals may be watching you!   

As many people get new smartphones for holiday gifts, they will be tempted to sell their old devices. If you're one of them, keep this story, reported by a Virginia ABC affiliate, in mind.
McAfee online security expert Robert Siciliano did a little experiment; he purchased 30 different devices from craigslist, including laptops, notebooks, iPads and smartphones. "I asked every single person if they re-installed the operating system or reformatted the drive, and they all said yes," Siciliano said. "On more than half of the devices, I found enough information to steal identities or, in some cases, even get people into trouble." 
The takeaway? Be mindful that erasing your personal data from your devices requires more than a delete button.

Here's a good resource  for learning how to sufficiently wipe your smartphones, tablets, computers and more before handing them off to a stranger. 

Thursday, September 5, 2013

Successful Digital Strategy: Bridge the gap between CIO and CMO

CIO & CMO doesn't trust each other, IT doesn't provide fast turn-around!

Business is largely about competition and, even within organizations, a healthy dose of rivalry between colleagues can be a good thing. However, a survey just conducted by Accenture Interactive (see The CMO-CIO Disconnect) points to a downright unhealthy relationship in many C-Suites which can do nothing but damage to firms. 

At a time when many executives say that improving digital reach will be a significant differentiator for their companies, research shows that two of the most important digital leaders — the Chief Marketing Officer (CMO) and the Chief Information Officer (CIO) — do not trust each other, understand each other, or collaborate with each other.

That is very bad news for their businesses and, not incidentally, for their own careers. When IT and marketing departments work at cross-purposes, the results are inefficiencies and mishaps and it is customers who suffer. Potential buyers simply don't have the time or energy to do business with a company that makes things harder for them.

To begin to mend the CMO-CIO relationship, it's important to understand the source of each side's frustrations. CMOs' answers to survey questions make it clear that they view IT as an "execution and delivery" provider, instead of as a strategic partner. CMOs do not believe they are getting fast enough turnaround on projects and adequate quality from the IT departments. Because many CMOs do not believe they are getting the service they want from their IT departments, many bypass the IT department and work with outside vendors. Forty-five percent of marketing executives say they would prefer to enable marketing employees to operate data and content without IT intervention.


For their part, IT executives believe marketers make promises they can't keep and do not provide them with adequate information on business requirements. The CIOs believe the marketing teams often do not understand — or appreciate — data integration or IT standards. Nearly half (49 percent) of CIOs say marketing pulls in technologies without consideration for IT standards. Forty-seven percent say the marketing team lacks understanding of data integration.


CEOs and others in the C-suite should not turn a blind eye to this tension, hoping for it to resolve itself. It is crucial for companies to instill more collaboration and understanding across the functions.

Here are five suggestions for supporting a CMO-CIO relationship that will ultimately benefit customer experience and drive sales:

Identify the CMO as the "Chief Experience Officer."
This is more than simply a change in nomenclature It is a constant reminder to the CMO that the job doesn't end with branding and advertising. The CMO must design and drive a customer experience that is consistently first-rate, at every touch point within the company — a goal that lays more emphasis on the role of IT and the need to reach a deeper understanding.

Signal that IT is the strategic partner to marketing
The CIO cannot be viewed as only the chief technology platform provider; the role must be elevated to a strategic member of the C-suite.

Get the two leaders working from the same playbook
Already, CIOs and CMOs spend more than 30 percent of their respective budgets on technology. It is time for them to agree on key business levers for marketing and IT integration, such as access to customer data and speed to market along with security, privacy, and standardization.

Change the skill mixes
Make sure the marketing department becomes more tech savvy and the IT department better understands marketing. Again, coming together around the consumer and customers will help to breakdown internal silos and align agendas. Upgrading their skills will help both departments make better decisions about technology and understand its impact on business outcomes.

Develop trust by trusting
It is time for leaders in organizations to extend their trust to — and accept it from — business units beyond their own.

Saturday, January 26, 2013

Documentary: A Gift for the Hackers

Privacy is becoming antiquated

Increasingly devices like printers and scanners are being connected directly to the Internet. It’s all very convenient, bit is it safe?

Your mobile, your printer, your hard drive, everything is connected… but it’s like a Swiss cheese. Medical files, financial information, and trade secrets, they’re all there for the taking. It’s shocking, it should not be allowed. It’s a design flaw.

Is this vulnerability in tens of thousands of devices compromising your security and your privacy? Computer security has become a big concern for companies and individuals.

As a result it has also become a big business. The world’s number one producer of computers and printers, Hewlett – Packard (HP), has an annual turn over of 127 billion dollars.

Wednesday, January 23, 2013

Security audit finds Developer OUTSOURCED his JOB to China

Pro-active Log Review Might Be A Good Idea

A security audit of a US critical infrastructure company last year revealed that its star developer had outsourced his own job to a Chinese subcontractor and was spending all his work time playing around on the internet.

The firm's telecommunications supplier Verizon was called in after the company set up a basic VPN system with two-factor authentication so staff could work at home. The VPN traffic logs showed a regular series of logins to the company's main server from Shenyang, China, using the credentials of the firm's top programmer, "Bob".

"The company's IT personnel were sure that the issue had to do with some kind of zero day malware that was able to initiate VPN connections from Bob's desktop workstation via external proxy and then route that VPN traffic to China, only to be routed back to their concentrator," said Verizon. "Yes, it is a bit of a convoluted theory, and like most convoluted theories, an incorrect one."

After getting permission to study Bob's computer habits, Verizon investigators found that he had hired a software consultancy in Shenyang to do his programming work for him, and had FedExed them his two-factor authentication token so they could log into his account. He was paying them a fifth of his six-figure salary to do the work and spent the rest of his time on other activities.

The analysis of his workstation found hundreds of PDF invoices from the Chinese contractors and determined that Bob's typical work day consisted of: 

9:00 a.m. – Arrive and surf Reddit for a couple of hours. Watch cat videos 

11:30 a.m. – Take lunch

1:00 p.m. – Ebay time

2:00-ish p.m – Facebook updates, LinkedIn 

4:30 p.m. – End-of-day update e-mail to management 

5:00 p.m. – Go home

The scheme worked very well for Bob. In his performance assessments by the firm's human resources department, he was the firm's top coder for many quarters and was considered expert in C, C++, Perl, Java, Ruby, PHP, and Python.

Further investigation found that the enterprising Bob had actually taken jobs with other firms and had outsourced that work too, netting him hundreds of thousands of dollars in profit as well as lots of time to hang around on internet messaging boards and checking for a new Detective Mittens video.

Bob is no longer employed by the firm. ®

Source from The Register

Refer here to read further details.

Thursday, January 10, 2013

The dangers of USB drives

What makes USB drives so great at carrying malware?

Stuxnet, which was discovered in June and has since spread to millions of machines around the world, is the most sophisticated computer attack we've ever seen.

Though its true purpose is unknown—teams of experts across the globe are poring through the code in an effort to divine its intentions—the deviousness of its design has prompted many researchers to call it a "cyber-weapon," one perhaps created by the United States or Israel to disrupt Iran's nuclear program.
What's most interesting about Stuxnet isn't how smart its authors were; it's how dumb they guessed we all would be. 
How did the worm's creators expect to get it inside some of the most secure installations in the world?
After all, sensitive machines often operate behind an "air gap"—that is, their networks are physically separated from the Internet and other dangerous networks where viruses can roam freely.

Getting anything inside one of these zones requires the complicity of an employee. That's exactly what Stuxnet got, because its authors designed the worm to piggyback on the perfect delivery system—the ubiquitous, innocent-looking USB flash drive, the planet's most efficient vector of viruses, worms, and other malware.

What makes USB drives so great at carrying malware?

They're the mosquitoes of the digital world—small, portable, and everywhere, so common as to be nearly invisible

Funny story: At a conference in Australia last year, IBM handed out thumb drives that turned out to be infected by malware. It was a computer-security conference.

We know we shouldn't click on e-mail attachments from strangers, and we know we should be wary of typing our passwords into shady sites online. But the USB disk has somehow evaded our suspicion; few of us look at them and recoil at the dangers that could be lying within.

Indeed, USB sticks evoke exactly the opposite emotion—if you saw a stray one on the street or lying around your office, wouldn't you pick it up and put it in your computer to try to identify the rightful owner? If a company wants to ratchet up security, it's not as simple as banning all thumb drives.

To be extra careful, you'd have to ban iPods, cameras, and every other USB-based doohickey—all of those devices are capable of carrying Stuxnet-like viruses, too.

The only hope is education: Don't trade USB sticks, don't stick an unknown one into your machine, and don't pick one up off the street and plug it in your machine just to see what's inside.

But I don't know if we're ever going to win that battle. It's human nature. If I were a normal person and I didn't work in this bubble of security? If I found a USB drive, the first thing I would want to do is want to plug it in, too.

Saturday, January 5, 2013

Term Of The Month: "Geotagging"

Commonly used via social media applications such as Twitter, Facebook etc.

Geotagging, in general, means geographical identification has been added to various media you may have created, such as a geotagged photographs, videos, websites, SMS messages, QR Codes, or RSS feeds, just to name a few.  

Look at a recent Facebook post you made. Was your location included with it, such as shown in this example?



That is one type of geotagging.

Simply by posting a photo of a meal you have just been served or the great trick your kid performed on the playground, you are potentially broadcasting your whereabouts.

This can be very dangerous if you think someone is stalking you, so consider disabling your smartphone's and/or mobile device's GPS embedding feature.

Friday, December 14, 2012

NIST Glossary of Infosec Terms

Looking for a gift for your boss who doesn't quite understand information security lingo?

The National Institute of Standards and Technology has one you can give, and it's free. NIST has issued a draft of Interagency Report 7298 Revision 2: NIST Glossary of Key Information Security Terms.

As we are continuously refreshing our publication suite, terms included in the glossary come from our more recent publications. The NIST publications referenced are the most recent versions of those publications. It is our intention to keep the glossary current by providing updates online.

New definitions will be added to the glossary as required, and updated versions will be posted on the Computer Security Resource Center website.

The glossary includes most of the terms found in NIST publications. It also contains nearly all of the terms and definitions from CNSSI-4009, an information assurance glossary issued by the Defense Department's Committee on National Security Systems, a forum that helps set the US federal government's information assurance policy.

NIST is seeking comments and suggestions on the revised glossary, and they should be sent by Jan. 15 to secglossary@nist.gov.

Wednesday, December 5, 2012

NIST Issues Credential Revocation Guide

Revocation Model for Federated Identities

Organizations can't easily revoke authentication credentials when they employ more than one identify provider. With multiple identity providers and unique requirements for organizations to federate them, no one approach exists to manage them.

To address this dilemma, the National Institute of Standards and Technology has issued NIST Interagency Report 7817: A Credential Reliability and Revocation Model for Federated Identities.

IR 7817 describes and classifies different types of identity providers serving federations. For each classification, the document identifies perceived improvements when the credentials are used in authentication services and recommends countermeasures to eliminate some identified gaps.

With the countermeasures as the basis, the document suggests a Universal Credential Reliability and Revocation Services model that strives to improve authentication services for federations.

Here's how NIST explains the challenge:

Identity providers establish and manage their user community's digital identities. Users employ these identities, in the form of digital credentials, to authenticate service providers. The digital identity technology deployed by an identity provider for its users varies and often dictates a specific authentication solution in order for the service provider to authenticate the user.

A federated community accommodates two or more identity providers along with the specific authentication solution. With the diverse set of identity providers and the unique business requirements for organizations to federate, there is no uniform approach in the federation process. Similarly, there is no uniform method to revoke credentials or their associated attributes.

In the absence of a uniform method, IR 7817 investigates credential and attribute revocation with a particular focus on identifying missing requirements for revocation. As a by-product of the analysis and recommendations, the report suggests a model for credential reliability and revocation services that serves to address some of the missing requirements.

Wednesday, September 12, 2012

Insiders suspected in Saudi cyber attack

Biggest Security Threat? Insiders?

One or more insiders with high-level access are suspected of assisting the hackers who damaged some 30,000 computers at Saudi Arabia’s national oil company last month, sources familiar with the company’s investigation say.

The attack using a computer virus known as Shamoon against Saudi Aramco – the world’s biggest oil company – is one of the most destructive cyber strikes conducted against a single business. Shamoon spread through the company’s network and wiped computers’ hard drives clean.

Saudi Aramco says damage was limited to office computers and did not affect systems software that might hurt technical operations. The hackers’ apparent access to a mole, willing to take personal risk to help, is an extraordinary development in a country where open dissent is banned.
“It was someone who had inside knowledge and inside privileges within the company,” said a source familiar with the ongoing forensic examination. 
Hackers from a group called “The Cutting Sword of Justice” claimed responsibility for the attack. They say the computer virus gave them access to documents from Aramco’s computers, and have threatened to release secrets. No documents have so far been published.

Reports of similar attacks on other oil and gas firms in the Middle East, including in neighboring Qatar, suggest there may be similar activity elsewhere in the region, although the attacks have not been linked. - Reuters

Monday, September 3, 2012

How Critical Is To Keep Your System Upto Date?

Only 9 of 22 virus scanners block Java exploit

According to an analysis conducted by the AV-Comparatives, less than half of the 22 anti-virus programs tested protect users against the currently circulating Java exploit that targets a highly critical vulnerability in Java version 7 Update 6.

Two versions of the exploit were tested: the basic version that was largely based on the published proof of concept and started the notepad instead of the calculator, and, for the second variant, heise Security added a download routine that writes an EXE file to disk from the internet.

The test system was Windows XP that, except in the case of Avast, Microsoft and Panda, had the full versions of the security suites installed. For Avast, Microsoft and Panda, the researchers used the free versions of the products. Only 9 of the 22 tested products managed to block both variants of the exploit (Avast Free, AVG, Avira, ESET, G Data, Kaspersky, PC Tools, Sophos and Symantec).

Twelve virus scanners were found to be unsuccessful (AhnLab, Bitdefender, BullGuard, eScan, F-Secure, Fortinet, GFI-Vipre, Ikarus, McAfee, Panda Cloud Antivirus, Trend Micro and Webroot). Microsoft's free Security Essentials component at least managed to block the basic version of the exploit. It should be pointed out that these results are based on a snapshot taken on 30 August at 1pm and don't represent the overall quality of these anti-virus programs. 

The tested version of Java was current at the time, and the exploit code had been in circulation for several days. These findings demonstrate that it is unwise to base the protection of a system on a virus scanner alone. To prevent installed applications and plugins from becoming malware hideouts, these must also be kept up to date. Oracle appears to have now closed the critical Java hole with the release of Java version 7 Update 7 on Thursday evening. Those who have Java installed on their systems should update to the new version as soon as possible.

The exploit is bound to be a highly popular item in the armouries of cyber crooks for years to come because it is platform-independent and highly reliable. Just how reliable it is becomes clear when examining the statistics of an installation of the BlackHole exploit toolkit: after the integration of the exploit, the Java exploits achieved a success rate of between 75 and 99 per cent. Overall, BlackHole managed to infect every fourth computer – the usual success rate is one in ten.

Saturday, September 1, 2012

Don't post risqué photos online

Hackers Have Home-Field Advantage

Many of you reading that warning may be thinking "No kidding." But, you'd be surprised how many seemingly self-aware, intelligent, should-know-better adults continue to participate in this risky behavior. 

Even if you believe you are posting photos in a private or password-protected location, keep this in mind: If it's on the Internet, it's vulnerable. Hackers have been at this for years and know exactly how to get into "protected sites" to gain access to your information. Plus, the people to whom you've given access to your spicy photos can also copy and post them elsewhere for the world to see and to your embarrassment.

This is particularly evident with the emergence of a recent hacker trend called "fusking." Fuskers hack their way into secure sites with the sole intention of finding nude and other compromising images. And doing unthinkable and unsavory things with them.

Keep in mind the young people in your life may lack the common sense or the perspective necessary to understand just how vulnerable images like these can be, nor what kind of an impact their publication could have on their lives. Frequent reminders and modeling appropriate online behavior are the best ways to prevent your children and others from a potentially life-changing bad move online.

Saturday, August 25, 2012

Effectively Assessing Information Risks within the Enterprise

3 Lines of Cyberdefence

By combining responsible management, risk management and compliance functions and internal audits, organizations will go far in securing their data and systems. 

To succeed, internal auditors and business systems owners, including chief information security officers, must collaborate more closely to assure the security of their organizations' data systems. 

A new report from PwC, Fortifying Your Defenses: The Role of Internal Audit in Assuring Data Security and Privacy, which identifies three lines of cyberdefense:  

Management: Companies that are good at managing information security risks typically assign responsibility for their security regimes at the highest levels of the organization. Management has ownership, responsibility and accountability for assessing, controlling and mitigating risks. Risk management and 

Compliance Functions: Risk management functions facilitate and monitor the implementation of effective risk management practices by management, and help risk owners in reporting adequate risk-related information up and down the enterprise.

Internal Audit: The internal audit function provides objective assurance to the board and executive management on how effectively the organization assesses and manages its risks, including the manner in which the first and second lines of defense operate.

It's vital that internal audits be at least as strong as the management and risk management and compliance functions for critical risk areas. Without internal audits that provide proficient and objective assurance, organisations risk having their information privacy practices becoming inadequate or outmoded. 

This is a role that internal audit is uniquely positioned to fill, but, it must have the support and the resources to match to do so.

Refer here to download the report.

Tuesday, August 21, 2012

SAP Audit Guide for Expenditure

Download the Ultimate Guide to Auditing and Securing Procure-to-Pay Controls in SAP

The third installment of Layer Seven Security’s SAP Audit Guide was released today and can be downloaded at http://bit.ly/SvG956. The series has proven to be a popular resource for audit and security professionals with over 10,000 downloads to date.

The latest Guide focuses upon expenditure-related controls in areas such as vendor master data, purchasing, invoice processing and payment processing. Forthcoming volumes of the Guide will deal with areas related to inventory, human resource management and Basis.

Although the Guide was originally intended to the cover ERP-related modules most commonly implemented by SAP clients, Layer Seven Security will develop and issue similar guides for components such as Customer Relationship Management (CRM), Supplier Relationship Management (SRM) and the Enterprise Portal (EP).

Thursday, July 26, 2012

The Department of Defense Cloud Computing Strategy

Goals presented “consolidate and share commodity IT functions resulting in a more efficient use of resources.”


The Department of Defense needs to accomplish its critical global missions despite a decreasing budget and rising cybersecurity threat. To that end, the Chief Information Officer of the DoD, Teri Takai, released its Cloud Computing Strategy, which outlines its goals to accelerate the adoption of cloud computing throughout the department.


In the strategy, the Office of the CIO explains why it wants to move to the cloud, its goals, the challenges that stand in its way and methods to mitigate them, and the coming steps the Defense Department plans to take to get there. The strategy uses the National Institute of Standards and Technology’s definition of cloud computing for their strategy.


NIST defines cloud computing as: “A model for enabling ubiquitous, convenient, on‐demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.”


DoD likes this definition because it includes Software as a Service, Platform as a Service, and Infrastructure as a Service. According to the CIO, the DoD currently has a “duplicative, cumbersome, and costly set of application silos” that can benefit from more cloud computing. The goals presented in the Cloud Computing Strategy is to “consolidate and share commodity IT functions resulting in a more efficient use of resources.”


The DoD hopes to provide device and location independent on-demand secure global access to mission data and enterprise services. They also hope to enable rapid application development and reuse of applications by other organizations. This means both sharing and adopting the most secure commercially available cloud services.


The Cloud Computing Strategy also lays out four steps for implementing the Department of Defense Cloud Environment. The first will be to “Foster Adoption of Cloud Computing” by establishing a joint governance structure to drive the transition and an Enterprise First approach while reforming DoD IT finance, acquisition, and contracting and increasing cloud outreach and awareness.


The next step is to “Optimize Data Center Consolidation” by consolidating and virtualizing legacy applications and data. The third step is to “Establish the DoD Enterprise Cloud Infrastructure” so that it’s agile, consolidated, and secure.


The last step will be to “Deliver Cloud Services” using existing DoD cloud services and external providers. The CIO will provide oversight for component implementation of these steps.


Please refer here to download the strategy.

Sunday, July 22, 2012

ENISA Report: Ten Smart Grid Security Recommendations

Smart Grids need protection from cyber attacks


The EU Agency ENISA has launched a new report on how to make smart grids and their roll out a success, in particular by making sure that IT security aspects are properly taken into account from the beginning.


A smart grid is an upgraded electricity network with two-way digital communication between supplier and consumer. The adoption of smart grids will dramatically change the distribution and control of energy for solar panels, small wind turbines, electric vehicles, etc.


By making energy distribution more efficient, smart grids give clear benefits to users, electricity suppliers, grid operators, and society as a whole. At the same time, their dependency on computer networks and Internet makes our society more vulnerable to cyber-attacks, with potentially devastating results. 


Therefore, to prepare for a successful roll-out of smart grids, this study proposes 10 security recommendations for the public and private sector out of almost 100 findings.


Some key report recommendations include:


  • The European Commission (EC) and the competent authorities of the Member States (MS) need to provide a clear regulatory and policy framework on smart grid cyber security at the national and EU level, as this presently is missing.
  • The EC, in collaboration with ENISA, the MS, and the private sector, should develop a minimum set of security measures based on existing standards and guidelines.
  • Both the EC and the MS authorities should promote security certification schemes for the entire value chain of smart grids components, including organisational security.
  • The MS authorities should involve Computer Emergency Response Teams to play an advisory role in power grids’ cyber security.


Cyber security aspects of smart grids Smart grids give rise to new information security challenges for electricity networks. Information systems’ vulnerabilities may be exploited for financial or political motivation in cyber-attacks to shut off power plants.


This study makes 10 recommendations to the public and private sector involved in the definition and implementation of smart grids. These recommendations intend to provide useful and practical advice aimed at improving current initiatives, enhancing co-operation, raising awareness, developing new measures and good practices, and reducing barriers to information sharing.


The top 10 recommendations, aimed at various European Union and member-state organizations, are: 

  1. Improve the regulatory and policy framework on smart-grid cybersecurity at both the national and EU level.
  2. Create a public-private partnership to coordinate cybersecurity initiatives. 
  3. Promote initiatives to raise awareness of cybersecurity threats and conduct training.
  4. Foster knowledge-sharing initiatives.
  5. Develop minimum security measures based on existing standards and guidelines.
  6. Develop security certifications for components, products and organizational security.
  7. Create test beds and security assessments.
  8. Develop and refine joint strategies to counter large-scale cyberattacks on power grids.
  9. Involve computer security incident response teams in an advisory role.
  10. Promote academic and R&D research into smart-grid cybersecurity, including through existing research programs.

The full ENISA smart grid report can be downloaded here.

Friday, July 6, 2012

Why Business Continuity is Critical For Your Business?

4 Tips to Gain Upper Management Attention


Companies often make many strategic decisions such as outsourcing, off-shoring and long supply chains without full consideration of the consequence of business interruption.


They primarily focus in adding short-term value to the bottom-line, but when these strategies fail to deliver, reputation and brand image are compromised. Short-term financial losses might be containable, but long-term loss of market share is often much more damaging.


By implementing effective business continuity plans, businesses can increase their recovery capabilities dramatically. And that means they can make the right decisions quickly, cut downtime and minimize financial losses. So, getting buy-in at the top is crucial. It requires professionals to have better understanding of the concerns of top management and an ability to communicate risk issues in a common language.


Here are a few ways business continuity practitioners can seek upper management attention.


Emphasize business consequences: Many leaders were shaken by the corporate impact that the Gulf of Mexico oil spill incident had on the finances, share-price and reputation of British Petroleum.


Business continuity managers need to bring these real-life cases in their presentation to management and further use their skills to identify their own organization's potential high consequence events. 


Implement innovative tests and exercises: A traditional difficulty is that BCM practitioners do not report at a high enough level to affect decisions. Although often true, they are not without influence, and one way to use it is in developing an innovative testing and exercising program.


In the past, too many exercises have concentrated on evacuation, safety and emergency response. Although these are required, top management employs specific specialists to handle safety and security on their behalf. 


What BC practitioners need to do is choose scenarios and techniques in their exercises that really interest the leadership team. Using scenarios that highlight fundamental business threats and challenging top management to respond can be scary, but it also can raise the profile of BCM rapidly.


Techniques such as war games, stress testing, scenario planning and horizon scanning are becoming important to business continuity tests. These are areas in which the BCM professional could and (in the future) really should take a leading role.


Be more assertive: BCM professionals can get top level attention by taking a more assertive position to organizational change. Clearly, there are limits to which individuals can become involved in strategic decisions, but by producing a well considered analysis of the consequences of change, they can often get senior management interest.


Decisions can be reviewed or modified if consequential risks are better articulated. BCM professionals can do this through a risk management organizational framework and can make their voice heard.


Communicate BCM benefits: Practitioners must concentrate on finding value and benefits for BCM and promoting them.


For example, if having proper BCM in place helps the organization get on the approved supplier list for a major customer, it's the BC professional's job to ensure that everyone knows about it. If it were a key deciding factor that actually won a big contract, make sure that sales, marketing and finance recognize and publicize that fact.


If BCM helps procurement eliminate high-risk suppliers, again getting that message out through whatever communication vehicles is key.

Monday, July 2, 2012

Don't Get Burned by Twitter Updated-Privacy Policy

Twitter Carries a Torch for Privacy


In mid-May, Twitter published an updated privacy policy, which every Twitter user should read - and other social media sites would be smart to emulate. The policy includes a clearer explanation of the situations in which Twitter will share user information with others.


Most notably, the policy provides better clarifications about how your personal information is used than most other social media sites. The updates include a new section on how Twitter tailors content. It makes clear that Twitter can use users' contact information to help third-party services, client applications and others find Twitter accounts.


While that particular practice is not new, it is much more clearly stated today. The policy also indicates how users can opt-out of several data-sharing practices, which is incredibly important to privacy-minded individuals.


You may find Twitter very helpful to use for sharing information, learning of breaking news and doing research. It's a good option; just make sure you set your privacy settings appropriately.

Saturday, June 30, 2012

Law firms are a prime target for hackers

Mobile devices and apps provide multiple avenues for hackers to access confidential information


Laptops, cell phones and mobile apps for devices such as iPhones and Androids keep us constantly connected to friends, family and colleagues. Unfortunately, they also may be connecting lawyers to predatory hackers, according to an article in the Wall Street Journal.


Law firms are a prime target for hackers seeking to access valuable confidential information, such as documents related to upcoming mergers and acquisitions or litigation. Over the past few years, several Canadian and U.S. law firms have been targeted by hackers linked to Chinese computers, according to the article. In 2010, lawyers at Gipson Hoffman & Pancione received emails—ostensibly from members of the firm—that were designed to steal data from their computers.


At the time, the firm was representing a software company in a $2.2 billion lawsuit against the Chinese government and computer manufacturers. Emails are just one way for hackers to retrieve sensitive information. Popular cloud storage applications such as Dropbox, for instance, afford lawyers the convenience of accessing their files on multiple devices.


But these applications potentially leave information vulnerable to third parties—Dropbox reserves the right to turn over files in response to legal or regulatory requests.


To protect data security, many firms are advising attorneys to take increased security measures, such as encrypting messages, avoiding free Wi-Fi connections, password protecting their devices and deleting suspicious emails or text messages.


Read the full story at the Wall Street Journal.

Tuesday, June 12, 2012

Password-Strength Checker

Check your password—is it strong?


Learn how to use the Password Strength Calculator to test the strength of your password security. Online password strength checker for secure passwords from Microsoft.


What is a strong password?


The strength of a password depends on the different types of characters that you use, the overall length of the password, and whether the password can be found in a dictionary. It should be 8 or more characters long.


For tips about how to create passwords that are easy for you to remember but difficult for others to guess, read Create strong passwords.


Refer here.