<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Awareness Training</title>
	<atom:link href="http://www.security-awareness-training.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.security-awareness-training.com</link>
	<description>Thoughts from the intersection of education and information security</description>
	<lastBuildDate>Tue, 09 Feb 2010 18:03:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>5 Reasons Why Security Awareness Training Programs Fail</title>
		<link>http://www.security-awareness-training.com/2010/02/5-reasons-why-security-awareness-training-programs-fail/</link>
		<comments>http://www.security-awareness-training.com/2010/02/5-reasons-why-security-awareness-training-programs-fail/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 18:03:03 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=802</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2010/02/5-reasons-why-security-awareness-training-programs-fail/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2010/02/frustration.jpg" class="alignleft wp-post-image tfe" alt="" title="frustration" /></a>All too often, I hear about security awareness training programs that fail. Here are some of the reasons that I hear: 

&#160;

The information that they contain is inappropriate for the audience (usually far too complex).
The presentation of the information is dull or dry.
The program is too expensive to run on an ongoing basis.
Students don&#8217;t have [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.security-awareness-training.com/wp-content/uploads/2010/02/frustration.jpg"><img src="http://www.security-awareness-training.com/wp-content/uploads/2010/02/frustration.jpg" alt="" title="frustration" width="150" height="150" class="alignleft size-full wp-image-807" /></a>All too often, I hear about security awareness training programs that fail. Here are some of the reasons that I hear: </p>
<p><br clear="all"></p>
<p>&nbsp;</p>
<ol>
<li>The information that they contain is inappropriate for the audience (usually far too complex).
<li>The presentation of the information is dull or dry.
<li>The program is too expensive to run on an ongoing basis.
<li>Students don&#8217;t have enough time to take the training.
<li>The program doesn&#8217;t fit with other training initiatives in the organization.
</ol>
<p>I&#8217;m not going to try to rank these in any kind of order. But, over my next few posts, I&#8217;m going to look at each of these in turn, try to identify the pitfalls, and give you some suggestions that may help you avoid them.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2010/02/5-reasons-why-security-awareness-training-programs-fail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Awareness Training for Call Center Reps</title>
		<link>http://www.security-awareness-training.com/2010/01/security-awareness-training-for-call-center-reps/</link>
		<comments>http://www.security-awareness-training.com/2010/01/security-awareness-training-for-call-center-reps/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 02:10:34 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=784</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2010/01/security-awareness-training-for-call-center-reps/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2010/01/callcenter150.jpg" class="alignleft wp-post-image tfe" alt="" title="callcenter150" /></a>
Call centers often handle highly sensitive information for customers including financial data such as credit card details, Social Security numbers, and bank account details; and, in some cases, health information. This means that they need to comply with an increasing number of regulations such as PCI DSS and HIPAA which require security awareness training for [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.security-awareness-training.com/wp-content/uploads/2010/01/callcenter150.jpg"><img src="http://www.security-awareness-training.com/wp-content/uploads/2010/01/callcenter150.jpg" alt="" title="callcenter150" width="150" height="150" class="alignleft size-full wp-image-788" /></a>
<p>Call centers often handle highly sensitive information for customers including financial data such as credit card details, Social Security numbers, and bank account details; and, in some cases, health information. This means that they need to comply with an increasing number of regulations such as PCI DSS and HIPAA which require security awareness training for all staff including full-time, part-time, temporary, and seasonal reps.</p>
<p>But security awareness training for the reps in a call center provides some challenges. In particular:</p>
<ol>
<li>Staff (rep) turnover rate can be high, and the average length of employment short.
<li>Staff often don&#8217;t have (company) email accounts.
</ol>
<p>Let&#8217;s look at each of these factors in turn.</p>
<p><b>High Staff Turnover</b></p>
<p>There&#8217;s really no such thing as a typical staff turnover rate for a call center &#8211; figures vary widely. For instance, a survey by Purdue University&#8217;s Center for Customer Driven Quality (CDQ), quoted in &#8220;<a href="http://www.auerbach-publications.com/dynamic_data/2752_1624_Call%20Center%20Management.htm" target="_blank">Call Center Management: People Versus Technology</a>&#8221; by Drew Robb, shows a very wide range.</p>
<p><a href="http://www.security-awareness-training.com/wp-content/uploads/2010/01/callcenterFig1.gif"><img src="http://www.security-awareness-training.com/wp-content/uploads/2010/01/callcenterFig1.gif" alt="" title="callcenterFig1" width="455" height="323" class="aligncenter size-full wp-image-794" /></a></p>
<p>
<center><br />
<table cellpadding=5 cellspacing=0 border=1>
<tr>
<td valign=top align=right>&nbsp;</td>
<td valign=top align=right><b>Median</b></td>
<td valign=top align=right><b>Average</b></td>
<td valign=top align=right><b>Highest</b></td>
</tr>
<tr>
<td valign=top align=right>Part-time Inbound</td>
<td valign=top align=right>20 %</td>
<td valign=top align=right>33.6 %</td>
<td valign=top align=right>300 %</td>
</tr>
<tr>
<td valign=top align=right>Full-time Inbound</td>
<td valign=top align=right>19 %</td>
<td valign=top align=right>26.0 %</td>
<td valign=top align=right>252 %</td>
</tr>
<tr>
<td valign=top align=right>Part-time Outbound</td>
<td valign=top align=right>15 %</td>
<td valign=top align=right>35.5 %</td>
<td valign=top align=right>480 %</td>
</tr>
<tr>
<td valign=top align=right>Full-time Outbound</td>
<td valign=top align=right>10 %</td>
<td valign=top align=right>21.3 %</td>
<td valign=top align=right>210 %</td>
</tr>
</table>
<p></center></p>
<p>And a survey conducted by International Customer Management Institute (ICMI) in 2000 reported on <a href="http://www.icmi.com/KnowledgeCenter/Queuetips/viewQuestion.aspx?id=1850" target="_blank">the ICMI website</a> showed the following data for average full-time staff retention periods:</p>
<p><a href="http://www.security-awareness-training.com/wp-content/uploads/2010/01/callcenterFig2.gif"><img src="http://www.security-awareness-training.com/wp-content/uploads/2010/01/callcenterFig2.gif" alt="" title="callcenterFig2" width="469" height="292" class="aligncenter size-full wp-image-797" /></a></p>
<p>Although not presented, one would expect the average retention period for part-time staff (such as seasonal staff employed during holiday seasons) to be much shorter. Overall, it would be fair to say that the turnover rates are generally a lot higher than in many other types of organization.</p>
<p>So what does this mean for security awareness training?</p>
<ol>
<li>Continuous recruitment throughout the year means that it can be difficult to schedule classroom training sessions. So training should be &#8220;on demand&#8221; which, these days, typically means web-based training.<br />&nbsp;
<li>Because of the relatively short retention periods &#8211; especially when recruiting reps for seasonal vacancies &#8211; the learning curve needs to be as short as possible. Therefore, extended training classes aren&#8217;t going to be practical, and a highly condensed and customized course/class is advisable.<br />&nbsp;
<li>The administrative effort in setting up and managing student accounts and tracking training must be minimized. Therefore automation is critical which, once again, typically means web-based training.<br />&nbsp;
</ol>
<p><b>Emails</b></p>
<p>Many web-based training systems rely on email for login identification, and for other communications with students. But not all call center reps have company email accounts, or access to email at work. So you may not be able to rely on this. If you&#8217;re looking at a web-based training system, make sure that it doesn&#8217;t depend on your students having email accounts.</p>
<p><b>Course Content and Presentation</b></p>
<p>As noted above, the time available to train your reps is going to be very limited, so you&#8217;re probably going to want to have a highly condensed and customized course/class that covers the specific business processes that your staff will be dealing with. For example, if you don&#8217;t have company email for reps (see above), you won&#8217;t need to deal with email security, and if you don&#8217;t deal with information on paper, you won&#8217;t need to cover document retention and destruction in the same way as you would if your reps deal with paper orders and invoices.</p>
<p>If you&#8217;re not going to develop the course/class yourself (and I&#8217;d recommend that you don&#8217;t), you can probably find a number of providers who will be able to work with you to develop the content you want. Look for a couple of things:</p>
<ul>
<li>A provider with a library of existing content that can be used as the basis for your training so that you&#8217;re not re-inventing the wheel.<br />&nbsp;
<li>A provider who stresses simplicity in their approach to presenting the information so that the course is succinct and focused rather than presenting the students with numerous external links, games, exercises, pop-quizzes &#8230;<br />&nbsp;
</ul>
<p>And a final note &#8211; since call centers, by their very nature, involve audio communications (telephone calls), it might be tempting to make heavy use of audio in your training courses. Don&#8217;t. As <a href="http://www.security-awareness-training.com/2009/08/using-audio-in-courses/" target="_blank">this blog post</a> talks about, excessive use of audio can:</p>
<ul>
<li>Increase course development and maintenance costs.<br />&nbsp;
<li>Use additional network bandwidth which might cause operational problems. <br />&nbsp;
<li>Slow down the learning process.<br />&nbsp;
</ul>
<p>Use audio sparingly &#8211; perhaps including some sample rep-client conversations. But don&#8217;t narrate every slide since it will slow the learners down considerably.</p>
<p><b>Other Considerations</b></p>
<p>Here are some other things you should think about when looking for a security awareness training solution for your reps.</p>
<ul>
<li>Regulations such as PCI DSS and HIPAA don&#8217;t just require staff to receive training &#8211; they require staff to read and acknowledge security policies. Doing this on paper could quickly become overwhelming for your administrators &#8211; especially when auditors come in and start asking for reports &#8211; so look for a training system that will also handle policy signatures and reporting online.<br />&nbsp;
<li>Security isn&#8217;t the only area which requires staff training and policy affirmation, so ask around your organization to see if there are other areas that could share the system (and cost!).<br />&nbsp;
<li>Managers, supervisors and IT staff are probably going to need to receive additional training. This isn&#8217;t (generally) subject to the same constraints as the training you need to provide to reps, but they should take the same basic training regardless and then receive additional courses/classes as required.<br />&nbsp;
</ul>
<p><b>Summary</b></p>
<p>Here are the key things that (I think) you should do when developing or purchasing a security awareness training solution for your call center reps:</p>
<ol style="list-style-type: upper-alpha;">
<li>Use web-based training. The system that you need should:
<ol style="list-style-type: lower-alpha;">
<li>Automate student management processes as much as possible.
<li>Incorporate policy signature management within the same system as the training.
<li>Allow use by reps who don&#8217;t have company email accounts.
<li>Be extensible to other training and/or policy signature needs within your organization.
	</ol>
<p>&nbsp;</p>
<li>Provide reps with a highly condensed course/class customized to your organization&#8217;s specific needs. Base this on existing materials wherever possible, and don&#8217;t get too fancy with the presentation &#8211; training time is of the essence.
</ol>
<div xmlns:cc="http://creativecommons.org/ns#" about="http://www.flickr.com/photos/elifayse/55173782/"><i>Call center photo from Flickr: <a rel="cc:attributionURL" href="http://www.flickr.com/photos/elifayse/">http://www.flickr.com/photos/elifayse/</a> / <a rel="license" href="http://creativecommons.org/licenses/by/2.0/">CC BY 2.0</a></i></div>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2010/01/security-awareness-training-for-call-center-reps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>H1N1 and Snowstorms &#8211; Training for Teleworkers</title>
		<link>http://www.security-awareness-training.com/2009/12/h1n1-and-snowstorms-training-for-teleworkers/</link>
		<comments>http://www.security-awareness-training.com/2009/12/h1n1-and-snowstorms-training-for-teleworkers/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 18:15:50 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=769</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2009/12/h1n1-and-snowstorms-training-for-teleworkers/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2009/12/wbt.gif" class="alignleft wp-post-image tfe" alt="" title="wbt" /></a>In a blog posting entitled &#8220;H1N1 and telework,&#8221; Akamai&#8217;s Senior Director of Information Security and Chief Security Architect, Andy Ellis, writes that:

[H1N1] affects us in the workplace. If an employee has a small child and they don&#8217;t have a stay-at-home caregiver, expect that they&#8217;re going to miss more time than in prior years &#8230; Also, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.security-awareness-training.com/wp-content/uploads/2009/12/wbt.gif"><img src="http://www.security-awareness-training.com/wp-content/uploads/2009/12/wbt.gif" alt="" title="wbt" width="150" height="150" class="alignleft size-full wp-image-776" /></a>In a blog posting entitled &#8220;<a href="http://www.csoandy.com/2009/11/h1n1_and_telework.html" target="_blank">H1N1 and telework</a>,&#8221; Akamai&#8217;s Senior Director of Information Security and Chief Security Architect, Andy Ellis, writes that:</p>
<p><br clear="all"></p>
<blockquote><p>[H1N1] affects us in the workplace. If an employee has a small child and they don&#8217;t have a stay-at-home caregiver, expect that they&#8217;re going to miss more time than in prior years &#8230; Also, you may want to suggest that employees with sick children stay at home even if they aren&#8217;t the primary caregiver, just to minimize workplace infections.</p></blockquote>
<p>Andy then goes on to talk about the components of a telework plan that could be used to minimize the disruption.</p>
<p>An interesting post and, with the recent weather-related travel problems on the East Coast, even more timely. There are going to be times when you need staff to work from home, and sometimes this may not be pre-planned. So, in addition to the components that Andy outlines in his blog, you might want to think about some of the training aspect of this. In particular:</p>
<ol>
<li>If an employee working at home is going to be:
<ul>
<li>accessing your IT systems remotely; and/or
<li>making work-related phone calls from home; and/or
<li>taking a work laptop computer home; and/or
<li>doing work on a home computer; and/or
<li>taking work-related documents home
	</ul>
<p>	you must make sure that he/she understands the additional security issues that result from working outside your organization&#8217;s perimeter. In particular, you&#8217;re going to want to caution them about ensuring the physical security of sensitive data (documents and computer resources) and, if appropriate, show them how to remotely access your network securely.<br />&nbsp;</p>
<li>The training that you provide needs to be &#8220;on-demand&#8221; because you&#8217;re unlikely to know exactly when it&#8217;s going to be needed, and it should be provided as close to the time that it&#8217;s needed as possible i.e. not a year ahead of time.<br />&nbsp;
<li>The training needs to be accessible remotely, typically through the Internet. Ideally, the training won&#8217;t require the employee to access your network remotely, but will be hosted on a server that has a web-interface.<br />&nbsp;
<li>A policy and procedure(s) need to put in place to deal with this contingency, and all line managers who might have staff working remotely should be made aware of this. The policy and procedure(s) are going to cover more than just security (see Andy&#8217;s blog post for more suggestions about what they should cover) and may well be related to your business continuity plans.<br />&nbsp;
</ol>
<p>If there ever was a topic that&#8217;s perfect for web-based training (remotely-accessible and on-demand) this is it!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2009/12/h1n1-and-snowstorms-training-for-teleworkers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Problems with Acrobat and PDF Files</title>
		<link>http://www.security-awareness-training.com/2009/12/security-problems-with-acrobat-and-pdf-files/</link>
		<comments>http://www.security-awareness-training.com/2009/12/security-problems-with-acrobat-and-pdf-files/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 19:41:51 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=758</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2009/12/security-problems-with-acrobat-and-pdf-files/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2009/12/adobe.jpg" class="alignleft wp-post-image tfe" alt="adobe" title="adobe" /></a>PDF documents are no longer the security panacea we thought they were. And security awareness training needs to catch up with this.
For years, IT and security professionals have been advising people to distribute documents in PDF format rather than as Word .doc files. In part, this prevents the average user from making changes to the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.security-awareness-training.com/wp-content/uploads/2009/12/adobe.jpg" alt="adobe" title="adobe" width="150" height="150" class="alignleft size-full wp-image-765" />PDF documents are no longer the security panacea we thought they were. And security awareness training needs to catch up with this.</p>
<p>For years, IT and security professionals have been advising people to distribute documents in PDF format rather than as Word .doc files. In part, this prevents the average user from making changes to the document, but it was also perceived as being more secure since Word files were known to contain macro viruses.</p>
<p>Sadly, the security advantages are no longer so clear-cut. It&#8217;s been known for a while that Acrobat Reader &#8211; the software that&#8217;s installed on the majority of business and home PCs &#8211; has some security problems (but, to be fair, it&#8217;s hard to find a piece of software that doesn&#8217;t). Now, csoonline.com has <a href="http://blogs.csoonline.com/adobe_warns_of_reader_acrobat_attack_in_the_wild" target="_blank">posted a warning</a> that hackers are taking advantage of a vulnerability in Acrobat Reader. And here&#8217;s <a href="http://blogs.adobe.com/psirt/2009/12/new_adobe_reader_and_acrobat_v.html" target="_blank">the official post from Adobe</a> on December 14 which says:</p>
<blockquote><p>This afternoon, Adobe received reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions being exploited in the wild.</p></blockquote>
<p>So, we have to make sure that our security awareness training includes the following advice to end-users:</p>
<ol>
<li>All applications &#8211; including Acrobat Reader &#8211; must be kept up-to-date with security patches. This is not limited to Microsoft products and the Windows operating system.<br />&nbsp;
<li>Since hackers may try to attack before security patches are available for applications, we should be <b>extremely</b> careful with documents from unknown and/or untrusted sources.<br />&nbsp;
<li>Although today&#8217;s antivirus software is very good, we can&#8217;t rely on it 100% because it takes time for updated signature files to be distributed and installed during which time we might be vulnerable to attack.<br />&nbsp;
</ol>
<p>I don&#8217;t think there&#8217;s anything really new here &#8211; just a reason to check that our awareness training is accurate, and to remind staff of the threats that are out there. And perhaps to think about whether we really need fancy formatting, or whether plain text would do just as well!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2009/12/security-problems-with-acrobat-and-pdf-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Engineering Using Facebook</title>
		<link>http://www.security-awareness-training.com/2009/12/social-engineering-using-facebook/</link>
		<comments>http://www.security-awareness-training.com/2009/12/social-engineering-using-facebook/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 17:08:44 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=749</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2009/12/social-engineering-using-facebook/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2009/09/facebook.gif" class="alignleft wp-post-image tfe" alt="facebook" title="facebook" /></a>Banning social network use DOESN&#8217;T prevent it being used for social engineering attacks.
An excellent article in Dark Reading describes how a security consulting company carried out an (authorized) social engineering attack on a client using information gleaned from Facebook. The client&#8217;s staff had posted information about what they did for the client (job titles, phone [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.security-awareness-training.com/wp-content/uploads/2009/09/facebook.gif" alt="facebook" title="facebook" width="150" height="150" class="alignleft size-full wp-image-475" />Banning social network use DOESN&#8217;T prevent it being used for social engineering attacks.</p>
<p>An <a href="http://www.darkreading.com/blog/archives/2009/12/using_facebook.html" target="_blank">excellent article in Dark Reading</a> describes how a <a href="http://www.securenetworkinc.com/" target="_blank">security consulting company</a> carried out an (authorized) social engineering attack on a client using information gleaned from Facebook. The client&#8217;s staff had posted information about what they did for the client (job titles, phone numbers, and email addresses) and personal data (appearance, height, weight, family background) &#8211; enough information for the consultant to create a bogus business card and then bluff his way into the client&#8217;s offices. In fact, as the article says:</p>
<p>
<blockquote>On the day we intended to breach the facility, our guy was dressed with a shirt embroidered with our client&#8217;s logo, and armed him with business cards, a fake company badge, and his laptop. Upon entering the building, he was immediately greeted by reception. Our man quickly displayed his fake credentials and immediately began ranting about the perils of his journey and how important it was for him to get a place to check his email and use a restroom. Within in seconds, he was provided a place to sit, connection to the Internet, and a 24&#215;7 card access key to the building. </p>
<p>After reaching the goal of accessing the network, he departed at the end of the business day. Later that evening, he returned to the empty office building to conduct a late-night hacking session. As usual, numerous credentials and passwords were obtained from insider sources. Within a short period of time, he had accessed the company&#8217;s sensitive secrets.</p></blockquote>
<p>Scary stuff. However (and I&#8217;m going to write this in bold because it&#8217;s so important) &#8230;</p>
<p><b>Banning social network use in the workplace would not have prevented this attack from being successful!</b></p>
<p>The important point to note about this (excellent) article is that banning social network use in the client&#8217;s workplace would probably have made very little difference since many of their employees &#8211; especially those expressing disaffection &#8211; would probably have continued to post the same information to Facebook from home.</p>
<p>Far better, surely, to engage the workforce and explain to them the dangers of social networks &#8211; whether used from a company system, or from home.</p>
<p>And one additional thing &#8211; if you&#8217;re responsible for an organization&#8217;s security, you really should be monitoring the social networking space at all times to detect:</p>
<ol>
<li>Inappropriate posting of information relating to your organization by your organization&#8217;s staff
<li>The fraudulent use of your organization&#8217;s name/identity
<li>Bogus accounts set up in the name of your organization&#8217;s staff
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2009/12/social-engineering-using-facebook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>URL Shortening as a Security Threat?</title>
		<link>http://www.security-awareness-training.com/2009/12/url-shortening-as-a-security-threat/</link>
		<comments>http://www.security-awareness-training.com/2009/12/url-shortening-as-a-security-threat/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 20:24:39 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=727</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2009/12/url-shortening-as-a-security-threat/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2009/12/http.gif" class="alignleft wp-post-image tfe" alt="http" title="http" /></a>Most of us are familiar with URL shortening websites such as bit.ly, tinyurl.com, and is.gd. It&#8217;s one of the technologies that&#8217;s fuelling the explosive growth of social networks such as Twitter &#8211; after all, 140 characters isn&#8217;t a lot of space to fit a message if most of it is taken up with a URL!
But [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.security-awareness-training.com/wp-content/uploads/2009/12/http.gif" alt="http" title="http" width="150" height="150" class="alignleft size-full wp-image-743" />Most of us are familiar with URL shortening websites such as <a href="http://bit.ly" target="_blank">bit.ly</a>, <a href="http://tinyurl.com" target="_blank">tinyurl.com</a>, and <a href="http://is.gd" target="_blank">is.gd</a>. It&#8217;s one of the technologies that&#8217;s fuelling the explosive growth of social networks such as Twitter &#8211; after all, 140 characters isn&#8217;t a lot of space to fit a message if most of it is taken up with a URL!</p>
<p>But the use of URL shortening can be a major headache since a shortened URL could obscure the real target address and, as a result, it could be used to redirect the viewer to an unexpected site such as a phishing website, or a website infected with malware.</p>
<p>So what should we teach our students about shortened URLs? I have to confess that I&#8217;m at a bit of a loss here. The only things that I can suggest are:</p>
<ol>
<li>Links provided by people who are known to you are &#8211; generally &#8211; going to be safer than those provided by strangers. However, Twitter and Facebook accounts have been hacked and used to send out malicious links, so knowing the sender isn&#8217;t 100% safe.<br />&nbsp;
<li>Links that have &#8216;context&#8217; are likely to be safer than links that don&#8217;t. For example, if a tweeter (is that the right term?) has been writing about learning management systems for a while, and then includes a link in a tweet that claims to be the URL for a website about e-learning, it&#8217;s probably going to be OK. If that same person suddenly posted a link with the text &#8216;Find out more about weight loss supplements&#8217;, it would be out-of-context and you should be VERY wary.<br />&nbsp;
<li>Keep all of your software up-to-date in case you&#8217;re directed to an infected website.<br />&nbsp;
</ol>
<p>Beyond that, I don&#8217;t know what to say. I know that Twitter and some of the URL shortening services have started to address the problem &#8211; Twitter by checking the destination of links entered into tweets, and URL shortening services by providing a preview service &#8211; but neither of these approaches seems to have solved the problem right now.</p>
<p>Anybody have any other advice?</p>
<p><b>Some Further Reading</b></p>
<ul>
<li><a href="http://www.infosecurity-us.com/view/3053/twitter-quietly-checks-tweeted-urls-draws-criticism/" target="_blank">Twitter quietly checks tweeted URLs &#8211; draws criticism</a> (Infosecurity Magazine)
<li><a href="http://en.wikipedia.org/wiki/URL_shortening#Criticism" target="_blank">Wikipedia &#8211; URL Shortening &#8211; Criticism</a>
<li><a href="http://www.google.com/search?q=url+shortening+security+threat" target="_blank">Google search for &#8220;URL shortening security threat&#8221;</a>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2009/12/url-shortening-as-a-security-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shopping Tips from the FBI</title>
		<link>http://www.security-awareness-training.com/2009/11/shopping-tips-from-the-fbi/</link>
		<comments>http://www.security-awareness-training.com/2009/11/shopping-tips-from-the-fbi/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 19:19:17 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=734</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2009/11/shopping-tips-from-the-fbi/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2009/11/holiday2009.gif" class="alignleft wp-post-image tfe" alt="holiday2009" title="holiday2009" /></a>Following my post about McAfee&#8217;s 12 Scams of Christmas, here&#8217;s some safe shopping advice from the FBI. Good source material for a seasonal security awareness message to your staff.
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.security-awareness-training.com/wp-content/uploads/2009/11/holiday2009.gif" alt="holiday2009" title="holiday2009" width="150" height="150" class="alignleft size-full wp-image-683" />Following my post about McAfee&#8217;s <a href="/2009/11/the-12-scams-of-christmas/">12 Scams of Christmas</a>, here&#8217;s some <a href="http://www.ic3.gov/media/2009/091130.aspx" target="_blank">safe shopping advice from the FBI</a>. Good source material for a seasonal security awareness message to your staff.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2009/11/shopping-tips-from-the-fbi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scanners and Shared Drives</title>
		<link>http://www.security-awareness-training.com/2009/11/scanners-and-shared-drives/</link>
		<comments>http://www.security-awareness-training.com/2009/11/scanners-and-shared-drives/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 17:34:37 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=718</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2009/11/scanners-and-shared-drives/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2009/11/scanner2.jpg" class="alignleft wp-post-image tfe" alt="scanner2" title="scanner2" /></a>Along the same lines as my recent post on photocopiers and information security, a friend of mine tells me that, in his organization:
&#8230; we have a major issue with people leaving scanned expenses on a shared drive. It&#8217;s great technology, but easy to forget the obvious.
Again, we have messages for two audiences:

For All Staff &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.security-awareness-training.com/wp-content/uploads/2009/11/scanner2.jpg" alt="scanner2" title="scanner2" width="150" height="150" class="alignleft size-full wp-image-724" />Along the same lines as my recent post on <a href="/2009/11/photocopiers-and-information-security/" target="_blank">photocopiers and information security</a>, a friend of mine tells me that, in his organization:</p>
<blockquote><p>&#8230; we have a major issue with people leaving scanned expenses on a shared drive. It&#8217;s great technology, but easy to forget the obvious.</p></blockquote>
<p>Again, we have messages for two audiences:</p>
<ol>
<li><b>For All Staff</b> &#8211; Be aware that scanners attached to PCs may well store copies of scanned documents on a local or networked hard drive, and those copies may be accessible to other people using the same computer. This is especially important to remember if you ever use a scanner outside your organization&#8217;s office e.g. at a Fedex/Kinkos, at a client site, at home, in a library &#8230;<br />&nbsp;</li>
<li><b>For IT Staff</b> &#8211; As far as possible, try to ensure that copies of scanned documents aren&#8217;t stored in public disk space. If that&#8217;s not possible and you handle sensitive documents, designate certain PCs+scanners as acceptable for sensitive documents and restrict access to those PCs.<br />&nbsp;</li>
</ol>
<p>As my friend says, the obvious is easy to forget.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2009/11/scanners-and-shared-drives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sometimes the Medium Can Be the Message</title>
		<link>http://www.security-awareness-training.com/2009/11/sometimes-the-medium-can-be-the-message/</link>
		<comments>http://www.security-awareness-training.com/2009/11/sometimes-the-medium-can-be-the-message/#comments</comments>
		<pubDate>Sat, 28 Nov 2009 21:34:07 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=706</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2009/11/sometimes-the-medium-can-be-the-message/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2009/11/bw.jpg" class="alignleft wp-post-image tfe" alt="bw" title="bw" /></a>An article in a recent issue of Business Week highlighted security issues with software produced by Adobe &#8211; especially Adobe Reader which is widely used in small and large organizations. The article quotes Kapersky researcher Roel Schouwenberg saying &#8220;Adobe at the moment, is the main target.&#8221; And the article goes on to suggest that &#8220;Adobe&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.security-awareness-training.com/wp-content/uploads/2009/11/bw.jpg" alt="bw" title="bw" width="150" height="150" class="alignleft size-full wp-image-711" />An article in a recent issue of <a href="http://www.businessweek.com/magazine/content/09_48/b4157032795489.htm" target="_blank">Business Week</a> highlighted security issues with software produced by Adobe &#8211; especially Adobe Reader which is widely used in small and large organizations. The article quotes <a href="http://www.kaspersky.com/" target="_blank">Kapersky</a> researcher Roel Schouwenberg saying &#8220;Adobe at the moment, is the main target.&#8221; And the article goes on to suggest that &#8220;Adobe&#8221; (presumably meaning Acrobat Reader) has replaced &#8220;Microsoft&#8221; (presumably meaning Windows) as the primary attack vector for hackers.</p>
<p>Attacks on vulnerabilities in application software rather than in the underlying operating system are hardly new. Anyone in the information security world can probably reel off a list of similar cases without too much difficulty. And all information security awareness training should remind students that applications must be kept up-to-date just as much as the operating system and antivirus software.</p>
<p>But this article also provides you with an opportunity to bring security to the attention of business managers. Often, attempts to educate managers on security issues use links and references to IT websites, or to information security blogs. And, all too often, managers ignore these sources because they have no real feel for whether the information is valid, or whether it&#8217;s just hype. But a well-written article in a reputable business journal &#8211; one that they might well subscribe to &#8211; is likely to be read and accepted far more readily. </p>
<p>Try sending a copy of this (or a similar article) to your business managers combined with an appropriate call-to-action (for example, &#8220;I&#8217;d like to use this opportunity to talk about security at our next staff meeting&#8221;), or ask to have it included in the next company newsletter. The weight carried by the journal will make it much easier for your message to be accepted. </p>
<p>Using an article or report from a well-regarded business source &#8211; the medium &#8211; conveys the message that this really is an important business issue &#8211; not just IT hype.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2009/11/sometimes-the-medium-can-be-the-message/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FBI Warning &#8211; Hackers Targeting Law Firms and PR Companies</title>
		<link>http://www.security-awareness-training.com/2009/11/fbi-warning-hackers-targeting-law-firms-and-pr-companies/</link>
		<comments>http://www.security-awareness-training.com/2009/11/fbi-warning-hackers-targeting-law-firms-and-pr-companies/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 18:18:59 +0000</pubDate>
		<dc:creator>Steve Addison</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://www.security-awareness-training.com/?p=696</guid>
		<description><![CDATA[<a href="http://www.security-awareness-training.com/2009/11/fbi-warning-hackers-targeting-law-firms-and-pr-companies/"><img align="left" hspace="5" width="150" src="http://www.security-awareness-training.com/wp-content/uploads/2009/11/email2.gif" class="alignleft wp-post-image tfe" alt="email2" title="email2" /></a>The Washington Post talks about a recent FBI warning that hackers are increasingly attacking law firms and PR companies using spear-phishing emails. These emails &#8211; previously used against military and defense targets &#8211; contain hyperlinks or file attachments which launch a malicious payload that can allow hackers to access the target&#8217;s network. Once they&#8217;re in, [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.security-awareness-training.com/wp-content/uploads/2009/11/email2.gif" alt="email2" title="email2" width="150" height="150" class="alignleft size-full wp-image-699" />The Washington Post talks about <a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/11/17/AR2009111701074.html" target="_blank">a recent FBI warning</a> that hackers are increasingly attacking law firms and PR companies using spear-phishing emails. These emails &#8211; previously used against military and defense targets &#8211; contain hyperlinks or file attachments which launch a malicious payload that can allow hackers to access the target&#8217;s network. Once they&#8217;re in, the hackers look for sensitive data &#8211; often linked to large corporate clients doing business overseas.</p>
<p>Sometimes, we focus so much on security issues relating to personal information (Social Security numbers, health information, addresses), financial transactions (credit card numbers, bank account details) and state security (military and defense secrets) that we forget other information can be extremely valuable to criminals.</p>
<p>You can find further news and warnings on the <a href="http://www.fbi.gov/cyberinvest/escams.htm" target="_blank">FBI Cyber Investigations Program website</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.security-awareness-training.com/2009/11/fbi-warning-hackers-targeting-law-firms-and-pr-companies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
