vendredi 25 janvier 2008

Security 1: keep it simple!

Security is a big issue for IT Production. Especially for some risky businesses (banks, nuclear industry, R&D, harmonica factories in Libya and the like).


There is a general trend to view IT security as a stacking of infinite layers of firewalls, secure network bubbles, DMZs, encryption protocols, secure ID tokens, RFID chips, etc etc etc…


However, no matter how modern and technologically up to date the IT security might be, it still depends on human rules and regulations, and there is always a man in the loop…


Thus, in the “real life”, most security breaches and real estate losses are caused not by hackers and IT attacks, but by physical errors, misconducts, neglects and, sometimes, seldom, premeditated crimes and massive frauds (banks, please take note).


90% of securities issues in IT production can be solved at a very modest price, with a bit of personal commitment, common sense, and logical behaviour. Never jot passwords of scraps of paper, never put some sensible data on an USB key attached to your keying, always use the paper shredder to destroy confidential documents… And above all, SHUT YOUR MOUTH when you are in public transports. Every year, I can hear sensible conversations about big contracts in the train, by the same people who advocate to invest 5 millions in the latest RFID Security Architecture to ensure “full IT Security”…

Aucun commentaire: