Showing posts with label safety. Show all posts
Showing posts with label safety. Show all posts

Tuesday, October 13, 2009

In-the-Cloud Approach to Cyber Security


Security breaches or other unexpected interruptions can happen anytime to anyone -- whether you are a large enterprise or a small business. Fully maintaining communication network security is a demanding responsibility -- and typically not the best use of your limited IT resources, that would be better applied to delivering incremental new business technology benefits to your organization.

Fortunately, there are alternatives to a do-it-yourself comprehensive security solution. Skilled managed service providers continue to enhance their network security offerings.

AT&T announced the availability of Security Event and Threat Analysis and Security Device Management, two new managed security services available for businesses of all sizes.

Customized to Your Unique Business Needs

The services enable you to engage AT&T security professionals selectively and simply to provide customized security support. Services range from security event analysis and threat management analysis to targeted security device management including firewalls, intrusion detection sensors and VPN servers.

These new services use AT&T’s expertise in security analysis to evaluate, correlate, and report on information from multiple devices and device types, both on your premises and embedded in the AT&T network.

AT&T Managed Service Benefits Include:
  • Prioritizing security events based on threat and risk management methodologies using AT&T and customer-defined standards.
  • Rapid notification when security events are detected and identified as critical by the AT&T Security Network Operations Center.
  • Event mitigation and security analyst counseling during critical security incidents.
  • Global Security Operation Centers and 24X7 T1-T4 Analyst Coverage with portal access through AT&T’s BusinessDirect Portal.
With Security Device Management, AT&T provides complete, customizable monitoring and management of your security hardware and software, with a range of services including managing your organization’s current security capabilities up to assessing, designing and implementing a custom security infrastructure.

Full Suite of Professional Services
These new services are a natural complement to AT&T’s existing Security Consulting services, which include independent assessments of vulnerabilities inherent in customers’ networks, as well as the policy and procedures surrounding them. Security Consulting services include Log Management, Security Policy Management, Vulnerability Analysis, Application Security, Trusted Advisor services and Payment Card Industry Solutions.

AT&T delivers a suite of security and business continuity services to help assess vulnerabilities, protect infrastructure, detect attacks, and respond to suspicious activities and events. The upcoming AT&T Cyber Security Conference is an annual day-long conference offered by the AT&T Chief Security Office.

Tuesday, March 10, 2009

Safety Concerns / Age Requirements for Blogs

A reader asks:

I am wondering if you know if there is an age requirement for students to use blogger since I am a middle school teacher?


There is no age requirement on the Blogger end of things. I don't know if your administration/district has an age requirement.

In the 'settings' tab on Blogger's dashboard, you can set up firewalls to keep search engines from finding a blog and to keep anyone from viewing the blog except whomever you choose. These safety features are easy to use and provide a level of security equal to or better than anything a school's IT department could produce themselves.

And it's free.

Friday, January 23, 2009

Managed Security with a Strategic Twist


Managed services provider Verizon Business has added an interesting twist to its security toolbox. Traditionally, managed security services are tactical: they monitor a network for potential attacks, using virus signatures and other definitions.

Earlier this month, Verizon upgraded its customers' security capabilities with what it calls its "Risk-Correlation Service," designed to add strategic insight to security.

The RCS works with vulnerability scans -- either those it does for customers or those from vendors such as McAfee, Qualys, and others -- to determine where potential vulnerabilities exist. The service also documents your system to create a map of devices and the business processes that run on them. "It marries threat information with vulnerability information," says Jonathan Nguyen-Duy, Director of Product Management for Verizon.

Calculating Risks
The result is a Web-based scorecard that shows Verizon customers not only where potential problems exist, but rank the level of relative importance of those devices. "We can tell you the likelihood of an event on a particular device, but also the business process associated with that device," says Nguyen-Duy. "Using the information from the vulnerability scan, we can tell you about the impact on availability. Is the device running real-time transactions, or is it a database server that might have less sensitive information?"

Strategically, companies can use the information presented in the online scorecard to get a sense of where to improve their online protection. Not all information is created equal, and not every database server requires the same level of protection.

The scorecard is designed to help companies prioritize their security budgets and their business continuity programs. "With limited resources, it's important to understand the relative risk of each vulnerability," he says.

Protection from Attacks
The online scorecard also works when attacks are underway. In those instances, it helps customers work with Verizon to identify where remediation is most important. "Sometimes you have to work in real-time to figure out where attacks are happening," Nguyen-Duy says. "Your ability to respond is improved when you have better information on the threat and what business process might be affected."

Being proactive about security is like flossing your teeth; you know you should do it more often, but it doesn't always happen. Applying a methodology that combines both strategic and tactical security needs is very wise. Clearly, when it comes to security, it's easier to be reactive when you've already been proactive.

Besides, the complexity of providing comprehensive network security protection, and keeping it fully up to date, is something best left to the experts. That's why managed security is one of the most utilized managed service offerings.

Tuesday, October 14, 2008

Online Security in a Global Networked Economy


Because of the expanding growth and complexity of communication networking, and the risks presented by a new breed of skillful hackers, serious security threats are an unfortunate certainty within the highly interconnected office environment of today.

These threats are very real and the results are costly to those businesses that have been affected. Apparently, the victims aren't entirely at random, which is often assumed to be the case.

According to the 2007 CSI Computer Crime and Security Survey, almost one-fifth (18 percent) of those respondents who suffered one or more kinds of security incident further said they had suffered a "targeted attack" -- defined as a malware attack aimed exclusively at their organization or at organizations within a small subset of the general population.

Beyond the Virus Threat
Moreover, financial fraud overtook virus attacks as the source of the greatest financial losses. Virus losses, which had been the leading cause of loss for seven straight years, fell to second place.

In today's global marketplace, every business needs to be vigilant in pro-actively protecting its corporate assets. Gone are the days of simply scanning for viruses. Today a comprehensive, layered approach is required to secure the network and company resources from multiple types of threats.

Small and medium-sized businesses (SMBs) are particularly vulnerable because they typically do not have expert resources on staff to ensure the network is secure, that regulatory compliance issues are being properly addressed, and that network monitoring and updates are effectively maintained 24 hours a day.

Alternative to the In-House Solution
Managed service providers can help SMBs secure their network by deploying a layered approach that uses various advanced technologies and solutions, protecting the network, and anticipating multiple types of potential security breaches -- from Trojan horse attacks and spyware, to data tampering and information theft.

Managed security services create a resilient multilayer defense:
  • Prevention -- proactively keeps the intrusions out
  • Detection -- identifies when an intrusion is occurring or has occurred
  • Response -- takes action to defeat a potential intrusion once detected
The advantage of working with a managed security provider is that services can be scaled to meet an organization's exact security requirements. This flexibility allows companies to minimize service outages and operational expenses, thereby reducing the overall financial impact.

The Challenge to Stay Current
Frankly, a large enterprise IT team can also benefit from an out-tasked network security solution, as the demands to ensure that in-house staff is staying current increases exponentially over time.

Ask a managed service provider to help you assess your security needs and design the best solution for your business. A comprehensive security audit is often the first step in this process.

By all means, be prepared for the unexpected, and keep your business safe. However, this is a complex task that's best left to the experts, while you free-up time to focus on your core business objectives.