Home > Windows Security Tips > Vulnerability/Authentication tips for Windows > Guard against internal hackers
Windows Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

VULNERABILITY/AUTHENTICATION TIPS FOR WINDOWS

Guard against internal hackers


Tony Bradley
05.05.2005
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In the first of this two-part series, below, Tony Bradley identifies three internal controls you must have in place to prevent internal hacking. In part two, he'll offer step-by-step advice on how to configure Windows file and folder security.


A tremendous amount of attention is paid to hackers who launch Windows attacks from outside the network. The dark and elusive hacker evokes images of both horror and fascination as vast sums of time and money are spent securing the network from such evildoers. But what will those resources do to address the fact that up to 80% of attacks and data compromises occur inside the network?

External attackers present a very real concern to your network security, demanding company time, money and equipment. But internal security processes and controls rarely protect sensitive or confidential data from your company's casual snoops or dedicated attackers, whose security breaches are far more common than those launched by external hackers. You must be sure internal employees are unable to access files or resources they should not have access to.

Here are three ways to guard against internal hacking threats. You'll also find several checklists below to help you put some of these controls in place.

1. Clearly define policies
Before you can effectively enforce restrictions on employees who access data they should not be, you need to clearly explain the rules and expectations. Make sure they know which resources they are allowed to access and which ones they are not, and clearly define and enforce the consequences of violating that policy.

2. Employ file and folder security
It would be ideal for all employees to simply follow the security policies and procedures in place -- but that's a fantasy for most Windows administrators. You must guard against mischievous curiosity or blatant disregard for the rules. Make sure file and folder security is properly configured, and only authorized users or groups are able to access system resources.
Watch for Tony's upcoming tip on how to properly configure file and folder security in Windows.

3. Monitor high-risk roles
High-risk assets, or those with a greater impact on network security or company revenue, should always receive greater protection. In determining which resources get enhanced security, you must assess all internal employee roles and responsibilities, then determine which roles need closer monitoring for internal security breaches; some users will have access to more sensitive information than others. Audit your security to make sure users with greater privileges only access the appropriate files and no suspicious activity goes on.

Click for part two on how to protect desktop files and folders from internal attacks.

About the author: Tony Bradley is a consultant and writer with a focus on network security, antivirus and incident response. He compiles the About.com Guide for Internet/Network Security, providing a broad range of information security tips, advice, reviews and information. Tony also contributes frequently to other industry publications. For a complete list of his freelance contributions you can visit Essential Computer Security.


More information from SearchWindowsSecurity.com

  • Checklist: Restrict access to prevent insider hacks
  • Checklist: Lock down Joe User's administrator rights
  • Checklist: How to configure the audit policy


  • Rate this Tip
    To rate tips, you must be a member of SearchWindowsSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Intrusion Prevention Systems
    Buffer overflows can be prevented by GS cookies
    Malware prevention and detection webcast series
    Preventing malware with tools, patches and education
    Can an antivirus program stop phishing attacks?
    Wireless network security testing
    Step 3: Application-level filters
    The bot invasion in Windows
    Comparing rootkit detection tools
    Checklist: 11 things to do after a hack
    Social engineering tactics for Windows users

    Defining Policy
    What's hot in Microsoft Windows security
    Here's how three IT shops manage passwords
    Insider security threats: Watch out for the quiet ones
    Troubleshooting your Windows-based VPN
    Telecommuter security kit
    Finding lost or forgotten passwords
    Ethical hacking
    Checklist: 11 things to do after a hack
    Build secure computer password policies
    Password hardening
    Defining Policy Research

    Auditing
    Critical systems to focus on during security testing
    Troubleshooting security settings
    Security tips for dealing with a rogue user
    Security tips for dealing with a rogue user, Part 2
    NTFS permissions
    Verifying file integrity with MD5 checksums
    Effective Group Policy
    DumpEvt, a free tool for exporting Windows event logs
    Enabling auditing on a File&Print server
    Audit event log to increase system security
    Auditing Research

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts