Home > Midmarket CIO Tips > Security for the midmarket > Security awareness training: How to educate employees about spyware
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Security awareness training: How to educate employees about spyware


Joel Dubin
09.13.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This tip originally appeared on SearchSecurity.com, a sister site of SearchSMB.com.


We all know the threats posed by spyware to enterprise networks: user ID and password theft, financial loss, productivity drain, intellectual property theft. Security practitioners have two defenses at their disposal: the human and the technical. While the technology for combating spyware is improving, antivirus vendors have only recently started adding functionality to target it. That means the best defense is the human one – employees and end users. They can help in the battle against spyware through security awareness training and information security policies.

Educating end users about spyware should be part of any comprehensive security awareness training. It should be part of at least half-day or, preferably, whole-day training required by all employees at all levels, from the executive suite down to the receptionists and security guards at the front door. Everybody uses a computer today. Training should be a condition of employment with mandatory attendance noted as part of annual performance reviews. As the number of security threats keeps growing every year, training should be updated annually and employees should be required to take it once a year.

Training conducted in groups of a few dozen at a time will not disrupt daily operations, yet it can still cover the entire staff over the course of a year. Your IT/ Information Security staff members should have the background to put together and conduct training without having to look elsewhere. But if staffing is an issue, consider professional trainers from outside the company.

Awareness training should cover the following:

  • Safe Web surfing
  • Acceptable uses for the Internet (for those allowed access)
  • Policies against downloading software to desktops
  • The type of Web sites are prohibited by policy, especially those likely to breed spyware
  • Tips on spotting potentially infected desktops
  • When to call the Help Desk

Reinforce training efforts with monthly newsletters that include security awareness tips. Focus on a new topic each month, and make spyware one of those topics. Newsletters can be designed to be colorful and eye-catching. Also, consider a "Security Awareness" award for an outstanding employee who was alert and saved the company from a spyware, or other, incident. Put the employee's picture in the newsletter. Internal publicity is a real morale booster.

Policies for preventing spyware are similar to those for protecting a network from other uninvited malware, such as viruses, worms and Trojans. The most effective policy is to prohibit employee access to the Internet altogether. But this may be unrealistic since many employees need Internet access for their work. At the very least, keep Internet access tightly controlled and be sure that those with access do, indeed, have a legitimate business need.

Spyware/malware policies include prohibiting users from downloading software from the Internet, including file-sharing software and toolbars, and prohibiting users from visiting questionable Web sites, the most obvious being pornography and gambling sites. These types of software and Web sites are notorious for harboring spyware.

Here is sample language for an end user policy:

"Employees shall not deliberately download any software from the Internet to their desktops without specific written permission from the Information Security department. Users are warned that all their Internet activity is subject to logging and monitoring at any time and that inappropriate use may subject them to disciplinary action up to and including termination."

A policy targeting spyware prevention specifically might state the following:

"Users are advised to report to the Help Desk suspicious activity on their desktops, such as excessive pop-windows opening simultaneously, unusually slow desktop performance or their Web browser being redirected to unwanted sites, such as pornographic or gambling sites. They should seek assistance from the Help Desk and advise that they suspect their desktop has been infected with spyware."

Lastly, provide users with something, such as this checklist, which can serve as constant reminder to be vigilant in the fight against spyware.

About the author
Joel Dubin is an independent computer security consultant based in Chicago. He specializes in web and application security and is the author of the recently released book
The Little Black Book of Computer Security available from Amazon.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Information security management for the midmarket
Droid does, but will IT support it?
Information security program revamp adds outsourcer oversight and more
From data breaches to risk management frameworks: Test your knowledge
The challenge of managing risk when IT budgets tighten
Why cybersecurity awareness is everyone's responsibility
Information technology management e-book downloads for midmarket CIOs
10 must-have steps for an effective SMB information security program
Your IT security budget: How to get more bang for the buck
Using key risk indicators to sell your information security program
IT security spending a bright spot in '09, with more growth predicted

Risk management for the midmarket
Information security program revamp adds outsourcer oversight and more
From data breaches to risk management frameworks: Test your knowledge
Adopting a beta tool: Risks vs. rewards for a midsized enterprise
The challenge of managing risk when IT budgets tighten
Why cybersecurity awareness is everyone's responsibility
How to decide if changing technology vendors is worth the time, risk
A guide to managing the risk assessment process
Free risk management tools and resources for the enterprise
CIOs taking risk of cutting vendor maintenance contracts to save money
10 must-have steps for an effective SMB information security program

Security tools for the midmarket
Why CIOs need to get real about identity and access management in 2010
Free risk management tools and resources for the enterprise
IT security spending a bright spot in '09, with more growth predicted
Security and risk management in the midmarket
Identity and access management planning guide for the midmarket
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Unified communications: Securing access to OCS
Unified communications security: How safe is it?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts