Showing posts with label WEEK 4. Show all posts
Showing posts with label WEEK 4. Show all posts

How to safeguard our personal and financial data?

Author: Paragons // Category:
By Si Jian

Data can be classified with labels such as public, personal, sensitive, confidential, secret, top-secret, or other categories. The more valuable or sensitive the data, the more it needs to be protected.

Example: Credit card numbers, account numbers, personnel information, Social Security numbers, tax records, network diagrams, business plans, passwords, sensitive emails, or personal medical records.

So, what precaution should we take to protect our personal and financial data?




There are 10 steps to take:



1.Use passwords to protect your access and encrypt sensitive files.


Use a strong password or pass-phrase to protect access to your data.

Passwords and other security features add layers of protection if used appropriately. By encrypting files, you ensure that unauthorized people can't view data even if they can physically access it. You may also want to consider options for full disk encryption, which prevents a thief from even starting your laptop without a passphrase. When you use encryption, it is important to remember your passwords and passphrases; if you forget or lose them, you may lose your data.


2.Follow corporate policies for handling and storing work-related information.


If you use your computer for work-related purposes, make sure to follow any corporate policies for handling and storing the information. These policies were likely established to protect proprietary information and customer data, as well as to protect you and the company from liability.


3.Install a firewall.


A firewall is a software program designed to allow good people in and keep bad people out. Most new computers come with firewalls integrated into their operating systems. Those who have a DSL or cable modem have an added layer of protection because these modems come with yet another firewall built in. If, however, you have an older computer or use dial up, you may need to buy a firewall separately and install it yourself.


4.Install and update antispyware and antivirus programs.


Microsoft and numerous application vendors offer users regular updates to existing antispyware programs, so be on the lookout. As for antivirus protection, Symantec and Norton antivirus are popular choices.


Regularly scan your computer for spyware.


Spyware or adware hidden in software programs may affect the performance of your computer and give attackers access to your data. Use a legitimate anti-spyware program to scan your computer and remove any of these files.


5.Avoid accessing financial information in public.


Resist logging on to check your bank balance when working from a coffee shop that offers wireless access. These systems are convenient, but also unknown. Casual users have no way of assessing how sturdy their firewalls are.


6.Update your browser.


Updating your browser on a regular basis can help plug up security holes, so make it a habit.


7.Look for "locks."


How can you tell if your financial site is really secure before you log on? The Web address should start with "https," instead of "http," says Weston. Also, look for small lock icon in the lower-right corner of the browser window.


8.Don't open mystery attachments.


Never open an attachment or click on a link sent to you by an unknown party. Attachments can contain viruses and links can lead unsuspecting users to dummy sites where they are asked to input financial information.


9.Restrict network or shared access.


Do not allow anyone access to sensitive/personal data unless they specifically require access. At work a web server administrator may not need access to confidential data in the backend database, a manager may not need access to the network password storage files, or a secretary may not need access to sensitive personnel files. Similarly at home, your children do not need access to your electronic tax records or bank account records. By limiting access to sensitive/confidential data to only those who really need it you can limit the risk of both accidental and malicious exposure. Additionally, by limiting access to only those requiring it, you are not only protecting the data, you are protecting your organization/family as well.


10.Dispose of sensitive information properly.


Simply deleting a file does not completely erase it. To ensure that an attacker cannot access these files, make sure that you adequately erase sensitive files.



Related links:

http://www.msisac.org/awareness/news/2007-03.cfm

http://www.us-cert.gov/cas/tips/ST06-008.html

http://finance.yahoo.com/banking-budgeting/article/103893/Six-Ways-to-Safeguard-Your-Online-Assets


The application of 3rd party certification programme in Malaysia:MSC

Author: Paragons // Category:
By Mei Hoong

Nowadays, more people are getting involved in e-commerce. Many people start to do transaction online. But still some of people deliberately limit the transactions they do online because they don’t fully trust the e-commerce process. These people simply fear for the security of personal and financial information transmitted over the Web. In order to reduce that problem, the application of third party certification programme can help organization to establish or improve customer trust by securing their Web site for business.



MSC Trustgate
MSC Trustgate.com Sdn Bhd was established in 1999 as a licensed Certification Authority (CA) operating out of the Multimedia Super Corridor in Multimedia Super Corridor in Malaysia under the Digital Signature Act 1997 (DSA). MSC Trustgate was provide security solutions and trusted services to help companies build a secure network and application infrastructure for their electronic transactions and communications over the network.


Products and services that offer by Trustgate:

1. SSL Certificate for Internet, Intranet and Server Security
An SSL Certificate is an electronic file that uniquely identifies individuals and Web sitesand enables encrypted communications. SSL Certificates serve as a kind of digitalpassport or credential. Typically, the “signer” of a SSL Certificate is a “CertificateAuthority”.

2. Managed PKI for Enterprise Trust Services
Managed Public Key Infrastructure (MPKI) service is a fully integrated enterprise platform designed to secure intranet, extranet, and Internet applications by combining maximum flexibility, performance, and scalability with high availability and security.

3. Secure Transaction with Digital ID
To ensure the confidential information remains private in transit, need to use Digital ID to sign and encrypt the transactions. Digital ID from MSC Trustgate.com is governed by the Digital Signature Act 1997. Without a legitimate Digital ID in your electronic transaction, your contract is not admissible in court in the case of dispute.


4. MyKad PKI (MyKey)
Malaysian government has put in place a smart National Identity Card (MyKad) for every citizen. MyKad with PKI capability allows its holder to conduct online transaction with government agencies and private sectors.

5. SSL VPN for Remote Access Services
MSC Trustgate offers simple and cost effective remote access solutions for mobile workers, branch offices, partners and others you want to give access to your network resources, without affecting the security of your enterprise.

6. Managed Security Services
Information security of an organization does not end by plugging in some anti-virus and spam filtering software, firewall, or IDS to your network. MSC Trustgate.com will study your business requirements, then plan and recommend relevant product and solutions to your organization.

Conclusion
MSC Trustgate enable organizations to conduct their business securely over the Internet, as much as what they have been enjoying in the physical world. Their commitment in delivering high quality services has brought us recognitions with the enterprises, government, and many leading e-commerce sites, and service providers' digital certification services, including digital certificates, cryptographic products, and software development both locally and internationally.


Related links:
http://ecomworld.wordpress.com/2008/06/25/the-application-of-3rd-party-certification-programme-in-malaysia-2/
http://wordpress.com/tag/3rd-party-certification-programme/

The threat of online security: How safe is our data?

Author: Paragons // Category:
By: Chee Yan

Access to information and entertainment, credit and financial services, products from every corner of the world even to your work is greater than ever. Thanks to the Internet, you can play a friendly game with an opponent across the ocean; review and rate videos, songs, or clothes; get expert advice in an instant; or collaborate with far-flung co-workers in a "virtual" office.

But the Internet and the anonymity it affords also can give online scammers, hackers, and identity thieves access to your computer, personal information, finances, and more.

With awareness as your safety net, you can minimize the chance of an Internet mishap. To be safer and more secure online, make these six practices part of your online routine.

Protect your personal information. It’s valuable.

To an identity thief, your personal information can provide instant access to your financial accounts, your credit record, and other assets.

Know who you are dealing with.

You can't judge an online operator's trustworthiness with a gut-affirming look in the eye.

Use security software that updates automatically.

Keep your security software active and current: at a minimum, your computer should have anti-virus and anti-spyware software, and a firewall.

Keep your operating software and web browser up-to-date, and learn about their security features.

Hackers also take advantage of Web browsers and operating system software that don't have the latest security updates.

Keep your passwords safe, secure, and strong.

Don't share them on the Internet, over email, or on the phone.

Backup important files.

If you have important files stored on your computer, copy them onto a removable disc or an external hard drive, and store it in a safe place.



Email Scams:

Some email users have lost money to bogus offers that arrived as spam in their in-box. Con artists are very cunning; they know how to make their claims seem legitimate. Some spam messages ask for your business, others invite you to a website with a detailed pitch. Either way, these tips can help you avoid spam scams:


Protect your personal information. Share credit card or other personal information only when you're buying from a company you know and trust.

Know who you're dealing with. Don't do business with any company that won't provide its name, street address, and telephone number.

Take your time. Resist any urge to "act now" despite the offer and the terms. Once you turn over your money, you may never get it back.

Read the small print. Get all promises in writing and review them carefully before you make a payment or sign a contract.

Never pay for a "free" gift. Disregard any offer that asks you to pay for a gift or prize. If it's free or a gift, you shouldn't have to pay for it. Free means free.





Malware:

Malware, short for "malicious software," includes viruses and spyware to steal personal information, send spam, and commit fraud. Criminals create appealing websites, desirable downloads, and compelling stories to lure you to links that will download malware, especially on computers that don't use adequate security software. But you can minimize the havoc that malware can wreak and reclaim your computer and electronic information.




Phishing:

Phishing is a scam where Internet fraudsters send spam or pop-up messages to lure personal and financial information from unsuspecting victims. To avoid getting hooked:


Don't reply to email or pop-up messages that ask for personal or financial information, and don't click on links in the message. Phishers can make links look like they go one place, but that actually send you to a different site.

If you need to reach an organization you do business with, call the number on your financial statements or on the back of your credit card.

Some scammers send an email that appears to be from a legitimate business and ask you to call a phone number to update your account or access a "refund."

Use anti-virus and anti-spyware software, as well as a firewall, and update them all regularly.

Don't email personal or financial information.

Review credit card and bank account statements as soon as you receive them to check for unauthorized charges.

Be cautious about opening any attachment or downloading any files from emails you received, regardless of who sent them.




Related Links:

http://www.readwriteweb.com/archives/top_online_security_threats_for_2009.php

http://www.onguardonline.gov/topics/overview.aspx