Information Security

Whilst information technology enables businesses to achieve more than ever before, it also brings opportunity for the unscrupulous and the malicious. Protecting your business information systems and communications infrastructure from the uninvited is a specialist discipline built into our thinking.

IT Security can be broken down into 4 areas in order of risk:

1          Employees and Users

2          Virus and Malicious Software

3          Network Intrusion

4          Eaves dropping, Line tapping and Sniffing

Employees and Users

By far the greatest cause of security compromise is behaviour, naivety and misuse of systems by users. Training and enforcement are the tools available to the business to educate staff and users to the vulnerabilities they represent to the business.

A short course to the techniques used by the unscrupulous to infiltrate the business to build awareness and good practice. These should be backed up by enforcement through contracts of employment.

It is very important for the business to be aware of some issues that might arise from their employees, workers or external contractors of the harm that can be done to their computer equipment.  Users of computers who have access to the internet or external devices have the ability to access internal information and to access external mediums that could affect your business.  Here are just a few examples:

Employees could access external websites such as social networking sites and blogging sites.  Consequently they could be posting information that is derogatory to the Company and therefore a proper email and internet policy is advisable.

Employees could access external websites and download information from them which may harm your network, for example innocently downloading a virus via an email attachment.  It is therefore important to restrict access to certain sites or to bring to the attention of the user that such access will be a disciplinary offence.  Displaying a policy on this could be kept on the desk top and regular email or memo reminders should be sent to staff.

Use of external devices such as USB memory sticks, CDs etc, must be prohibited or have restricted use.  Again, the use of such devices may mean an employee downloads information from an external device without knowing a virus is attached, or the act may be deliberate.  It is advisable to have an external device checked before it is introduced to the system or have a complete ban.

*From the outset of employment it is important to ensure that restrictions are included in their contracts of employment to prevent staff from stealing company information.  Company information may take the form of electronic data, including confidential proprietary information, supplier and customer lists. Drafting restrictive covenants is not easy, if the restrictions are too tight, then they may not be enforced, meaning you cannot rely on them.  It is advisable to take legal advice in these situations.

Furthermore use of online shopping sites during work hours should also be prohibited or restricted to say 1 hour during the lunch break.

Virus and Malicious Software

Viruses are pieces of active software code designed to modify the business system in some way; many and various. They are carried within or attached to normal legitimate software programs or media. Often they are carried by the innocent email, screen saver or game with the usual enticement of being free.

To combat these is the use and regular update of proprietary antivirus software. In addition, these should be checked and monitored regularly to ensure there good performance.

As many of these forms of attack enter the business network via email, email washing by an external supplier improves security by removing this form of attack before it enters the business network.

Network Intrusion

The business network Internet connection creates this form of vulnerability. The unscrupulous will attack the business network interface to test it defences and attempt to infiltrate and place malicious code inside the network.

The use of good quality correctly set up and maintained firewalls, reduces this risk. In addition, the software used to interact with and carry traffic through the firewall, should be proprietary, tested and approved to ensure these do not carry weaknesses creating open opportunities.

Eaves dropping, Line tapping and Sniffing

This form of security risk involves the unscrupulous listening in upon the business external network traffic and extracting data. For most business this form of security risk can almost be ignored, as most businesses do not transmit information of sufficient value to warrant this from of attack. This is the realm of the well resourced and highly trained IT engineer. However, this form of security vulnerability can be exploited from anywhere in the world.

**Where a risk is considered to exist IP tunnelling and encryption should used.

* The ICT Practice partner Vicky Edwards specialises in Employment Law and Contracts of Employment. If you wish to know more about drafting effective employment contracts please contact us.

**The ICT Practice partner Tirath Rai is accredited to NATO and has experience in testing and probing business network for data transmission vulnerabilities.

 
Accredit UK

Registration No: CON/09/182

The ICT Practice is registered with the National Computing Centre as a Quality Assured Supplier and Members of the UK Information Technology Association.


© The ICT Practice 2011

Accordion Menu
Project News
April 2010

The ICT Practice welcomes Robin Layfield

Jan. 2010 -  PHP developer Robin Layfield is to replace David Carter as head developer of the Utopia project. David who was instrumental in the early stages of our Utopia project is to concentrate upon our Health and Safety projects.

Read more...
Solutions
Partners
Peter Kemp

Senior Partner
Commercially focused IT that stands the test of time

Whether you need stable networks your business can depend on, or you’d like to know how technology can help generate new revenue streams, Peter is the person to talk to.

Read more...
 
John Griffiths

Design that improves the bottom line

John uses his design and marketing skills to build and manage eye-catching online and print communications. The well-planned websites he creates are underpinned by sound strategies and solid, creative design to develop a successful online presence for his customers.

Read more...
 
Eddie White

Streamlining technology

Integrating networks, telephony and broadband are all in a day’s work for Eddie who is also a qualified trainer running courses on using applications, PCs and the web.

Read more...
 
Stephen Welch

Creating dependable business assets

Reliability, security and savings are just some of the reasons why Stephen uses open source software to help businesses improve the way they do things, providing technical solutions that become assets rather than simply being costs.

Read more...
 
Anthony Ramm

Making life easier

Content management systems, networks and infrastructures that are easy to use are just some of the tools Anthony employs to enable people to concentrate on the parts of their jobs they enjoy the most.

Read more...
 
Steve Priest

Crisis? What crisis?

Virtual technologies, solid infrastructures and reliable security are just some of the ways Steve helps people to run their businesses effectively and there’s very little he can’t turn his hand to.

Read more...
 
Nick Irons

Microsoft Visual Basic Developer

Read more...
 
Allan Bean

Trusted, practical advice for solving problems big or small

Whether starting from scratch or facing issues with existing set ups, small to medium sized businesses and home offices turn to Allan for help with systems, networks, hosting, web design, email and various IT disasters to name but a few.

Read more...
 
Robin Layfield

Making the web work

With his background in e-commerce, an eye for design and an understanding of the many and varied ways that people use web software, Robin makes it his job to turn complex concepts into simple-to-use applications.

Read more...
 
Michael Evans

Technology that’s a pleasure to use

Michael believes that technology should work for people, rather than the other way around, allowing them to concentrate on their businesses without constraints.

Read more...
 
About Us

The Practice was formed in 2007 by members of the UK Information Technology Association. UKITA had been created 4 year previously in 2003 with grant funding from Advantage West Midlands the regional development body.  Originally WMITA, UKITA set out to encourage the development of ICT in the region and to set standards in this comparatively new and unregulated IT profession.

Read more...
Contact Us

Our contact details:

The ICT Practice
Gala House
3 Raglan Road
Edgbaston
Birmingham 
B5 7RA

Tel No: +44 (0)870 753 4020
Fax No: +44 (0)870 753 4022 Read more...

Accordion Menu