Home > Domino Tips > Spam and Security > Security awareness training: How to educate employees about spyware
Domino Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SPAM AND SECURITY

Security awareness training: How to educate employees about spyware


Joel Dublin
09.15.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


We all know the threats posed by spyware to enterprise networks: user ID and password theft, financial loss, productivity drain, intellectual property theft. Security practitioners have two defenses at their disposal: the human and the technical. While the technology for combating spyware is improving, antivirus vendors have only recently started adding functionality to target it. That means the best defense is the human one – employees and end users. They can help in the battle against spyware through security awareness training and information security policies.

Educating end users about spyware should be part of any comprehensive security awareness training. It should be part of at least half-day or, preferably, whole-day training required by all employees at all levels, from the executive suite down to the receptionists and security guards at the front door. Everybody uses a computer today. Training should be a condition of employment with mandatory attendance noted as part of annual performance reviews. As the number of security threats keeps growing every year, training should be updated annually and employees should be required to take it once a year.

Training conducted in groups of a few dozen at a time will not disrupt daily operations, yet it can still cover the entire staff over the course of a year. Your IT/ Information Security staff members should have the background to put together and conduct training without having to look elsewhere. But if staffing is an issue, consider professional trainers from outside the company.

More information

Give your users a spyware prevention checklist

Attend on-demand webcasts and read more expert insights on fighting spyware in the enterprise

Take our quiz to find out if spyware is getting the best of you

Awareness training should cover the following:

  • Safe Web surfing
  • Acceptable uses for the Internet (for those allowed access)
  • Policies against downloading software to desktops
  • The type of Web sites are prohibited by policy, especially those likely to breed spyware
  • Tips on spotting potentially infected desktops
  • When to call the Help Desk

Reinforce training efforts with monthly newsletters that include security awareness tips. Focus on a new topic each month, and make spyware one of those topics. Newsletters can be designed to be colorful and eye-catching. Also, consider a "Security Awareness" award for an outstanding employee who was alert and saved the company from a spyware, or other, incident. Put the employee's picture in the newsletter. Internal publicity is a real morale booster.

Policies for preventing spyware are similar to those for protecting a network from other uninvited malware, such as viruses, worms and Trojans. The most effective policy is to prohibit employee access to the Internet altogether. But this may be unrealistic since many employees need Internet access for their work. At the very least, keep Internet access tightly controlled and be sure that those with access do, indeed, have a legitimate business need.

Spyware/malware policies include prohibiting users from downloading software from the Internet, including file-sharing software and toolbars, and prohibiting users from visiting questionable Web sites, the most obvious being pornography and gambling sites. These types of software and Web sites are notorious for harboring spyware.

Here is sample language for an end user policy:

"Employees shall not deliberately download any software from the Internet to their desktops without specific written permission from the Information Security department. Users are warned that all their Internet activity is subject to logging and monitoring at any time and that inappropriate use may subject them to disciplinary action up to and including termination."

A policy targeting spyware prevention specifically might state the following:

"Users are advised to report to the Help Desk suspicious activity on their desktops, such as excessive pop-windows opening simultaneously, unusually slow desktop performance or their Web browser being redirected to unwanted sites, such as pornographic or gambling sites. They should seek assistance from the Help Desk and advise that they suspect their desktop has been infected with spyware."

Lastly, provide users with something, such as this checklist, which can serve as constant reminder to be vigilant in the fight against spyware.

About the author
Joel Dubin is an independent computer security consultant based in Chicago. He specializes in web and application security and is the author of the recently released book
The Little Black Book of Computer Security available from Amazon.

This tip originally appeared on SearchSecurity.com


Do you have comments on this tip? Let us know.

Rate this Tip
To rate tips, you must be a member of SearchDomino.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Spam and Security
Securely connect Lotus Domino servers on different domains
Protect Lotus Notes from malicious code with the Domino ECL
How to correct Lotus Notes public key mismatches in four easy steps
A recipe for secure IM success
Telecommuter security kit
Spear phishing: Don't be a target
FAQ: Lotus Notes Domino password issues
Seven tips to strengthen your Domino e-mail security
Admin2005 preview: Tips, techniques, and a look at Notes/Domino Rel. 7
Notes/Domino Security, An Administrator's Guide: book review

E-mail
Secure Lotus Notes/Domino 8.x from mail to unknown recipients
Domino server setting and email policy tricks admins must know
Top 10 Lotus Notes/Domino administration tips of 2008
Can Lotus Notes/Domino and Microsoft SharePoint play nice together?
Using Formula language code to sort Lotus Notes messages by subject
LotusScript action button manages Lotus Notes mail files
Exploring Lotus Notes Domino 8.0.1 and beyond
LotusScript agent moves tagged spam email to junk mail folder
Send SMS text messages between Lotus Notes 7 and mobile devices
Update to Exchange Server 2003 Connector for Lotus Notes

Lotus Notes Domino Security
How to correct Lotus Notes public key mismatches in four easy steps
Cracked users' HTTP passwords still a threat on many Lotus Notes R6 and R7 domains
Top 10 Notes/Domino administration tips of 2006
Unsecured devices worry IT professionals
Online crime as ugly as ever
McAfee sued for patent infringement
Mobile security starts with policy
Antivirus researcher Gullotto leaves Symantec for Microsoft
Symantec: Searching for a strategy?
Symantec says enterprises failing to secure instant messaging

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Domino & Lotus Notes Security Solutions: Authentication, Antispam, Encryption and Antivirus
HomeTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersDomino IT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts