Home
BYTE Newsletter
Keep up with all the BYTE News and Reviews

Subscribe
Keith Ferrell

Keith Ferrell



Six Security Tips For The Holidays

Comments | Keith Ferrell, InformationWeek | November 19, 2010 12:06 PM


Employee vacations, workplace celebrations, unexpected visitors and hours and hours of online shopping loom. Time to take a pre-holiday look at your seasonal security preparations.The approaching holidays, and the joy, delights and especially the distractions that accompany them should prompt a quick review of those aspects of your security posture most likely to be affected by the holiday effect.

  • Absent Employees: before the holiday travel and time-off season gets into full swing, take a look at who's going to be gone when, whether they will be accessing your systems remotely, and if not, whether their accounts and log-ons should be suspended for the duration of their vacation. Don't forget to check the employee's workspace for potential security vulnerabilities, including password and other sensitive material that's written down, USB and other easily removable devices that could contain confidential information, accounts with automated password and log-in fills (which shouldn't be permitted in the first place, frankly) left active.
  • Absent-Minded Employees: As the holiday season moves into higher gear, the prospect for employee distraction grows apace. Pass the word that while seasonal cheer is a good thing, letting that cheer get in the way of standard security procedures and policies isn't. Some key reminders: don't leave computers and other devices running when away; shut all systems down, if possible, during holiday parties and gatherings; remind employees to be extra vigilant about spam and other suspect communications and Web sites, especially holiday-themed come-ons.
  • Unexpected Visitors: Both unscheduled drop-ins and invited guests can pose security risks. If you're having a open house, for instance, make sure that monitors aren't showing sensitive information while guest are circulating; not a bad idea, in fact, to shut down all public are systems while guests are present, if practical. Be wary as well of visitors -- and for that matter employees -- bearing digital devices containing seasonal music or other digital diversions. Strongly suggest that such devices not be plugged into your business systems.
  • Don't Let Employees Shop If Their Guard Is Dropped: Online shopping from the workplace is a fact of holiday life, and should be addressed with a) a policy that makes clear the times, if any, that online shopping is permitted via company equipment and connections, b) a triple-check of your systems' up-to-date defenses against drive-by and other malware attacks aimed at shopper, sand c) a refresher course in online shopping security for your employees. Not a bad idea to remind them that shopping by phone requires the same security vigilance as shopping from the desktop.
  • Physical Security For Digital Assets: Brick and mortar thieves are out in fore during the holiday season, so it's important that you check your workplace's physical security, especially if the workplace is going to be completely closed during part or all of the holidays.
  • Patches and Updates Don't Get Time Off For The Holidays: Many of the tips offered here are applicable throughout the year, not just during the holiday season. The same goes for your day-to-day security practices and policies. Patches will still need to be installed, virus definitions updated. Make sure you know who's responsible for the daily maintenance of your security posture, and have plans in place should they be away for the holidays.

A bit of preparation and reinforcement now will make your workplace -- and your employees -- more secure when the holiday season ramps up.



Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events