Precautions that must be taken in order to secure computer files

eia 24

a.   Backing up files: The
first basic precaution a user should take is to back up important files. This
will not prevent a security incident or hardware failure, but it may reduce the
impact if a user is involved in such an incident. On a different level,
remember that data stored on your computer would probably be lost if the
machine was stolen or destroyed.

b.   Anti-virus Scanning: Virus
scanning software should be used to check any software downloaded from the
Internet or obtained from any questionable source. Attachments received by
email should be treated with caution. This means
do not open email attachments from strangers no matter how interesting they
may be. Be equally suspicious about any unexpected email attachment from
somebody you do know — it might have been sent
without that persons knowledge from an infected machine.

c.   Password Security: Unlike
backing up files, this action may prevent a security incident. One of the more
common methods to gain unauthorized access in a network is referred to as a
“brute force” attack. Brute force attacks occur when a hacker makes
repeated, continuous attempts to guess a user’s password, perhaps using a
special cracking program that makes use of commonly available word lists –
including lists of the most commonly used passwords

d.   File Permissions: Another
basic precaution that all users should take is to ensure that permissions on
files that can be accessed by others are set properly. If a user does not want
other users to read his files, then the permissions for each file must be set
to prevent this.

e.   Protecting Data in Transit: This
should be of little concern to most Internet users because most of the packets
traveling on the Internet contain data that is not sensitive from the user’s
viewpoint, and is of no interest to Internet attackers.

f.     Network Sniffing: The first type of sensitive
information traveling across the Internet is user name, password, and IP
address combinations. These data are the primary targets of sniffer programs
operated by Internet attackers. These are read by the sniffer program and
typically recorded in a file intended to be retrieved later by the attacker.
These combinations can then be used to break into the user’s account and from
there the attacker can compromise the entire system. A solution to this problem
is to have these data sent across the Internet in a secure manner, such as by
encrypting them first.

g.   File and Email Encryption: Other
types of information traveling across the Internet are sensitive user
identifications, and files whose content is sensitive to the user. Users should
take one of two precautions, either encrypt the information or don’t send it
across the Internet. Examples of sensitive user identifications are address,
phone number, personal data, and perhaps most sensitive of all, credit card
numbers.

h.   Maintain Current Software and Updates: Use a
secure, supported operating system; Keep your software updated by applying the
latest service packs and patches.

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
0
Would love your thoughts, please comment.x
()
x