C3 Security Consulting LLC
Confidentiality
Integrety
Availability
company banner
HomeSecurityServicesVistaInformationCompany
  
floating layer default test box
Security
FOREFRONT
Hardware
Networking
Patch Management
PKI
Web
Windows
Wireless
On this page:
Prevention
Best Practices
Security Policies
Security Planning
Related Links
An alternative OS for iPAQ
If you like Linux and have an iPAQ you can replace the OEM O/S with a Linux kernel.
Linux Devices
To see a range of devices that run on Linux look at www.linuxdevices.com.
Using Active Directory to Lock Down Your Network
Microsoft Active Directory provides the means to manage the identities and relationships that make up your network environment. Find webcasts, virtual labs, and other resources that show how you can use Active Directory to help establish secure administrative policies and practices.
Insecure.org
Scanners, sniffers, and many more useful tools for the security minded.
SANS Institute
SANS Institute Web site maintains articles, documents, and links on computer security and wireless technologies.

Information Technology Security

Print view

  • At C3SC we will ensure your current systems are securely configured.
  • We will create processes for maintaining that security.
  • We will train your administration staff how to keep your environment safe.
  • We will audit your existing environment and give a comprehensive report on findings and solutions.

The adage “an ounce of prevention is worth a pound of cure” is particularly true for IT security. Frequently, by the time an attack has been discovered the damage has already been done.

Many attacks come in the form of viruses, trojans, and bots. They can reside on a system for days, weeks, or even months before being discovered. During that time they can monitor your key strokes, view your data, and change or corrupt valuable information.

Intrusion detection systems have their place but remember:

prevention, prevention, prevention!

IT security must be considered in a framework of security as a whole, as it relates to your business. A great example of this is the attack on the London office of the Somitomo Mitsui Bank, where criminals were able to place key-logging devices on computers to try to steal £220M. (approx $350M).

Physical security must work with IT security to make the business secure.

Best Practices

  • Best practices apply to your plans and processes, your systems, and your staff.
  • At C3SC we will show you how to keep security alive and evolving.
  • We will also train your staff to be security conscious. By setting down specific expectations you can minimize accidental security breaches.

With any process planning it helps to define some high level goals and methodologies. Creating a working set of best practices helps align separate and potentially isolated IT programmes. A management framework is needed so everyone knows what to do (policy, internal controls and defined practices).

To be truly effective a guide for best practices should:

  • Support the regulatory requirement needs of your business - core business.
  • Avoid duplication of effort - efficiency.
  • Reduce dependency on technology experts - cost reduction.
  • Make it easier to leverage external assistance - interoperability.
  • Reduce risks and errors - cost reduction.
  • Improve quality - cost reduction/reliability/customer satisfaction.
  • Improve the ability to manage and monitor - cost reduction/efficiency.
  • Increase standardization - cost reduction.
  • Improve trust and confidence from management and partners - business reputation.

You would be amazed how many companies make significant investments in IT security only to have it be forgotten and allowed to stagnate. Unfortunately, security breaches are a growing market, both from amateur hackers and dedicated industrial espionage agents. The complexity of these attacks is also escalating so the responses must be dynamic to effectively prevent them.

Another security weakness that is frequently overlooked are your employees. Either through malice or accident, statistically your own employees will account for at least a third of all security breaches you experience.  

Effective prevention is through coherent planning and the development of best practices to prevent the “opportunities” from occurring. C3SC will provide tailored operational models for your environment that keep security processes and procedures fluid to adapt to change as needed.

A Security Policy

This is your base line. It sets out what you want to achieve and communicates it to management, employees, customers and auditors. It will define your organization's approach to security and set expectations. It differs from a plan by concentrating on strategy, whereas a plan will define the specific actions and procedures.

It is important to start with a policy. The policy will provide a framework for a coherent plan and help avoid duplication of effort and counteractive processes. A proactive approach now will reduce your exposure and the impact of security violations when, not if, they occur.

The ISACA has stated "The consistent enforcement of information security policies and standards...are critical elements in the success of a security system".

At C3SC we have skills and experience to create a policy specific to your organization. No matter what size of business we will focus on your business needs and deliver based on your requirements.

Examples of typical elements included in a comprehensive policy:

  • A Code of Ethics
  • Acceptable use
  • Responsibility
  • Due care
  • Privacy
  • Business unit specifics
  • Consequences of violations
  • Summary statement of approach and objectives
  • Support regulatory requirements

For more information, if you want to create a policy for yourselves, go to the information section for examples and suggested components.

  • C3SC has experience in developing effective security policies and we understand their value.
  • We will work with you to develop a constructive security policy, specific to your environment.
  • After developing a comprehensive security policy, we will follow through with a communication plan to ensure your message reaches the intended recipients.

Security Planning

This is where it should all come together.

The policies and vision need to be combined with industry best practices, focused on your environment to create a total security plan.

In addition to the specifics of security, it must also comprise:

  • Risk mitigation and avoidance
  • Analysis of current capacity and practices
  • Implementation plan
  • Communications plan
  • Maintenance plan
  • Future development plan

The security plan should address initial tasks, ongoing procedures, and assessment matrices. It is only by creating a living, evolving security plan that you will achieve security today and stay safe tomorrow.

Although initially daunting, these components should naturally flow from one into the next, seamlessly. The final product being a realistic and achievable secure business environment.

  • Depending on the size of your organization, security does not have to be an uncontrollable juggernaut of effort. At C3SC we recognize plans and practices that are too much work will be quickly forgotten. We create realistic solutions based on the needs of your environment.
  • We will assess
    • Physical security for IT systems
    • Topology
    • SLAs
    • Software testing and management
    • Short/long term actions
    • Measurement

  • C3SC will provide an integrated result to efficiently harden your security environment.

Vision & Policy

C3SC will perform initial evaluations, interviews, assess scope, requirements, and create a policy for your environment.

It will be:

  • practical
  • understandable
  • adaptable
  • comprehensive
  • aligned with your business strategy and goals
  • relevant to your business partners
  • designed to improve the quality of your IT systems
  • a statement of the business purpose and benefits of a policy

Plan & Implement

C3SC will work with you to develop objectives. We will create an implementation plan, mindful of resource availability and existing technology infrastructure. We will ensure it is supportable by existing resources. It can be executed by your own staff, a third party vendor, or by C3SC staff, with or without C3SC providing implementation management services.

It will be:

  • designed to fit your business needs
  • a natural extension of the policy statement
  • low impact on your business performance and ensure continuity of business functions

We will produce supporting project and operational documentation. We will train any project and operational staff necessary.

Measure & Evaluate

C3SC will provide a measurement matrix by which you can assess the performance of the implementation.We will provide processes and supporting documentation for ongoing performance measurement.We will automate wherever possible.We will produce operational service level agreements.It will support decision making and will integrate with the existing business policies and procedures.
▲Top of page
Did you know?
Email is a hackers gateway to your network.
Make sure you have adequately trained your employees in good email hygiene to reduce virus attacks.
Scrolling system messages.
To view Linux system log messages in real-time, open a terminal window, su to root, and type tail –f /var/log/messages. You will see the system messages scroll up the screen as they occur.
Folder views.
If you want all your files and folders to be listed the same way in Explorer, display the format you want in the right pane, e.g. details view, sorted by file type. Then Tools>Folder Options and the Views tab. Hit the Apply to All Folders button and the next time you traverse to a folder it will be in your "standard " display format.
Wireless networks are more vulnerable to hackers - so they need additional protection.
Encryption technologies such as Wi-Fi Protected Access can help. Although there are weaknesses with WEP, some legacy systems do not support more modern protocols like WPA, and so WEP is still better than nothing and will deter most casual eavesdropping.
Spam problems?
Microsoft filters out over three billion spam messages a day.