(#10) Security Policies Tip: Executable e-mail attachments -- Educate the end user

Article

(#10) Security Policies Tip: Executable e-mail attachments -- Educate the end user



This tip, submitted by searchSecurity member Rick Pierides, received a rating of 4.5. Do you have a tip on educating users? Submit it to searchSecurity.

I work with a lot of clients who cannot

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

afford the luxury of expensive filtering software for their e-mail. So when I make my visits I often take a little bit of extra, gratis time to educate end users on types of executables, how Windows parses the extensions from attachment filenames and how the bad guys attempt to hide the real extension. I like to hand out small post up-sized stickers with a listing of the more common executable extensions as a reminder. Along with current virus signatures and disabling Windows Scripting Host, this has gone a long way toward a much safer and more aware environment for my clients and their employees.

Read the rest of this tip.


For more information on this topic, visit these other searchSecurity resources:
Chat Transcript: E-mail security
Executive Security Briefing: E-mail security: Defending the server
Best Web Links: Security messaging