Home > Ask the Security Experts > Application Security Questions & Answers > What security software should be installed on Internet café computers?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What security software should be installed on Internet café computers?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 23 December 2008
If you or a member of your staff has to use an Internet cafe or similar public access point, what programs should you check for to make sure your data isn't kept on the machine? Is the machine secure if Windows SteadyState, an antivirus product or proper firewall, is installed? Generally speaking, just how safe is it to use such a place for day-to-day business (not banking)?

>
The security provided by many Internet cafes and other similar public access points has greatly improved over the last few years. But that's no substitute for due diligence on the part of users.

To start, the computers provided in an Internet café should certainly have a desktop security suite installed. The suite should have, as a minimum, firewall, antivirus and antispyware programs. It's obviously in the interests of the Internet café to ensure its computers run safely and efficiently. However, I would still not sanction their use by members of staff for business-related work or correspondence. How do you know that the desktop security suite has the latest virus signatures? Or that the newest system and software patches are installed? The recent zero-day flaw in Internet Explorer would certainly put many Internet café browsers at risk. Although the Internet café may have a policy of blocking questionable websites, attacks can also spread from legitimate sites that have been unwittingly compromised. An unlimited number of strangers sharing an Internet café machine greatly increases the likelihood of it becoming infected.

The problem with any public access point is that it has to be treated as a hostile environment. The physical and logical security controls that are possible within your organization's buildings are not available in the outside world. It is therefore much harder to ensure that sensitive business information remains safe. Despite the presence of security programs, such as a desktop security suite, there is still the risk of shoulder surfers and security cameras observing keystrokes or the contents of your screen. You can use privacy screen guards, such as those made by 3M Corp., to prevent people sitting next to you from being able to read your screen, but I don't know how to disguise your password keystrokes!

A tool like Windows SteadyState will certainly help the café's system administrator to control what users can and can't do, such as access programs, configuration settings, removable storage devices and websites. SteadyState also makes it easy for administrators to wipe data from a computer's hard drive. It is difficult to know, however, that this erasure is always performed once a machine is vacated and reassigned to another user. You, therefore, have to assume that data and deleted files may persist on the machine's hard disk.

Finally, all organizations should have a formal policy covering the use of mobile and third-party devices in places such as Internet cafes. It should include the requirements for physical protection, access controls, encryption, backups and virus protection. It should also include rules and advice on connecting shared or mobile devices to corporate networks and guidance on their use in public places. You need to reduce the chances of an employee accidentally disclosing sensitive information such as sales figures, client data or passwords. For me, the risks are just too high when using a third-party shared computer.


BROWSE BY TAG
Application Security,   NAC and Endpoint Security Management,   Secure Remote Access,   Enterprise Network Security,   Network Access Control Basics,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Application Security
Do Facebook URL security concerns justify blocking social networks?
Is there a way to block iPhone widgets that bypass Web filters?
Should enterprises be concerned with Twitter in the workplace?
Are there still Google Desktop security problems?
Can an IP spoofing tool be used to spam SPF servers?
Will an application usage policy best control network bandwidth?
How can URL-shortening services be manipulated?
Is my security program ready for Web application firewall deployment?
How to ensure the security of a shopping cart application
When to use the service features of the Metasploit hacking tool

Secure Remote Access
Endpoint protection best practices manual: Combating issues, problems
Best Mobile Data Security Products
Perimeter defense in the era of the perimeterless network
Securing the intranet with remote access VPN security
Information security book excerpts and reviews
Diverse mobile devices changing security paradigm
Cisco warns of security appliance flaws
How to configure NAP for Windows Server 2008
Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
What are the security risks of opening all the ports on an internal router?

Network Access Control Basics
Security vendors can learn from ConSentry Networks demise
Best Network Access Control Products
Perimeter defense in the era of the perimeterless network
Network access control technology: Over-hyped or underused?
Symantec offers endpoint protection management, monitoring services
Configuring access control lists
What is the difference between a VPN and remote control?
Quiz: Endpoint security on a budget
Opinion: Gartner gets NAC wrong, again
What are the best network security books?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
authentication  (SearchSecurity.com)
RADIUS  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts