Home > Security News > Secure your remote users in 2010
Security News:
EMAIL THIS
COLUMN

Secure your remote users in 2010

By Eric Ogren
16 Nov 2009 | SearchSecurity.com


Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Economic conditions are forcing IT to postpone new projects and delay infrastructure upgrades, but studies have found that the sales force is usually the first to rebound in high-tech companies looking for a direct path to revenue.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

Now is the time for security teams to start planning and budgeting on new approaches to secure the corporation's digital assets as the dynamics of the workforce shrinks or grows with the economy in 2010. Security teams in high-tech organizations can plan for increases in the number of remote sales users before the company adds new office workers and upgrades facilities.

There are a few technologies that security should be investigating for gradual deployments in the coming year to help mitigate the heightened risk of business disruption and data loss from a larger workforce of remote and mobile users in 2010.

Plan to ride the investments in new employee laptops to put Microsoft Windows 7 to the test. The shift from Windows XP to Windows 7 is inevitable for IT, so the organization may as well enlist the support of remote users to gain experience with Windows 7 security features. Windows 7 appears to provide a significantly stronger platform for applications than XP that may result in reducing the security burden. Understand the security features of Windows 7, trial secure configurations with remote workers and be prepared to use the knowledge gained to transition the rest of the workforce off XP when economic conditions allow.
Eric Ogren's weekly security columns:
How to use Internet security threat reports: Security threat reports help drive security vendor business, but they can also provide some useful information for IT security pros.

Two-factor authentication, vigilance foil password theft
:Password stealing Trojans, keyloggers and other malware are reaping account credentials by the thousands forcing some to rethink password policies and develop new defenses.

Chip and PIN adoption serves lesson for U.S. payment industry: As payment processors offer plans for end-to-end encryption, the UK is finding success with chip and pin deployments. The U.S. payment industry should take notice, expert says.

Remote user virtual workspaces will protect browsers and VPN agents from malware on home computers and less secure public networks, such as those found in hotels and cafes. The sharp uptick in recognized attack volume reported in threat reports is significantly driven by malware disguised in browser active code, browser plug-ins and browser toolbar plug-ins. The best protection against these attacks is to isolate the business access software from the underlying operating system and applications. Enhancing the security of remote connectivity software should yield fewer calls to the IT service desk and fewer chances to lose regulated data. A compromise solution would be to re-examine Microsoft IE 8, which has some nice security enhancements for remote users.

Unified communications and collaboration (UCC) technology over the Web can keep a distributed team in touch while also shaving travel and telephone bill expenses. Security capabilities exist to assure that UCC communications are held with strongly authenticated users, conducted over secure sessions, and audited for compliance with security policies. Showing the corporation how UCC can be secured can lead to cost savings and improved responsiveness to remote users.

The demands on corporate security are going to increase as businesses come out of the economic doldrums, and the demands will start with remote users. Strong authentication, transparent data encryption and secure communications to corporate applications are the basics of securing a distributed workforce. Security teams should also be using this planning time to prepare for Windows 7 migrations and also perhaps enhance operations for remote users with virtual workspaces and UCC capability.


Eric Ogren is founder and principal analyst of the Ogren Group, which provides industry analyst services for vendors focusing on virtualization and security. Prior to founding the Ogren Group, Eric served as a security industry analyst for the Yankee Group and ESG. Ogren has also served as vice president of marketing at security startups Okena, Sequation and Tizor. He can be reached by sending an email to eric@ogrengroup.com.

Tags: Security Awareness Training and Internal ThreatsBusiness Management: Security Support and Executive CommunicationsHandheld and Mobile Device Security Best PracticesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Security Awareness Training and Internal Threats
Information security book excerpts and reviews
Schneier-Ranum face-off, part 2: Social networking
Health Net breach failure of security policy, technology
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
Creating a HIPAA employee training program
Successful rogue antivirus hinges on social engineering
External attacks start with unintentional mistakes, survey finds

Business Management: Security Support and Executive Communications
Schneier-Ranum face-off, part 3: Compliance and security
Cost of security, IT management add up at healthcare facilities, study finds
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
Aligning network security with business priorities
IT business justification to limit network access
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Risk management must include physical-logical security convergence
New partnerships, creative thinking help security bust recession

Handheld and Mobile Device Security Best Practices
Protecting enterprise networks from new mobile application downloads
Screencast: Find rogue wireless access points with Vistumbler
Researchers find thousands of flawed embedded devices
Best Mobile Data Security Products
Should Windows Mobile updates come from Microsoft?
MMS messaging spoof hack could have global ramifications
How to prevent mobile phone spying
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
How secure are iPhone App Store mobile applications?
Handheld and Mobile Device Security Best Practices Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
dumpster diving  (SearchSecurity.com)
Honeynet Project  (SearchSecurity.com)
insider threat  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
pretexting  (SearchCIO.com)
shoulder surfing  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
social engineering  (SearchSecurity.com)
Total Information Awareness  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts