![]() |
![]() |
|
April 12, 2005Ten Tips for Corporations to Protect Customer Information from Identity TheftCyberguard sent out an interesting press release today that provides "Ten Tips for Corporations to Protect Customer Information from Identity Theft". The list is pretty self explainatory:
Comments
Interesting press release. One has to wonder about it...most of the recommendations are common sense, and things that should have been implemented a long time ago. 3. The server that contains the personal information should NOT allow direct connectivity to any user on the public Internet. You know, my first thought was, "duh"...but then, I have to remember all of the incidents that occur because this simple edict isn't followed. 10. All communication of personal data sent to/from the database across public and private networks should be permitted over encrypted channels (HTTPS / SSL SSH). Permitted? How about "required"? The most important points about security weren't made...you have to have management that requires, supports, and endorses security policies, and you have to hire people capable of doing the things required to put the technical security measures in place, and to monitor them. Without those two, the 10 items listed by Cyberguard are pointless. Finally, I'm not sure any of these would have prevented the ChoicePoint incident... H. Carvey |
![]() ![]()
My 5 Favorite Books
Writing Secure Code
Secure Programming Cookbook Security Engineering Secure Coding Principles & Practice Inside the Security Mind ![]()
My 5 Favorite Papers
Smashing the Stack
Penetration Studies Covert Channel Analysis of Trusted Systems DoD Trusted Computer System Evaluation Criteria NSA Security Recommendation Guides ![]()
Archives
December 2005
November 2005 October 2005 September 2005 August 2005 July 2005 June 2005 May 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004 August 2004 July 2004 June 2004 May 2004 April 2004 March 2004 February 2004 January 2004 December 2003 November 2003 October 2003 September 2003 August 2003 July 2003 June 2003 May 2003 April 2003 March 2003 February 2003 January 2003 December 2002 November 2002 October 2002 September 2002 August 2002 July 2002 ![]() |
|