Human and Computer Viruses Are Both Security Risks

There is general agreement among governmental officials that the flu is going to cause major disruptions - including in the workplace, and that could present some significant security challenges. In which case there is likely to be a lot of additional employees wanting to, or needing to, work from home. Are you ready?

By Scott Bradner
Mon, August 31, 2009

Network World — The U.S. federal government is worried about the Swine Flu (official name: 2009 H1N1 influenza virus). There have been predictions by experts of two or three times the normal number of flu related deaths this coming flu season - maybe as many as 90,000 deaths in the United States - but official government forecasts say that the number is likely to be far lower. In spite of the disagreement over the number of deaths there seems to be a general agreement that millions of people in the United States will fall ill from the virus. There also is general agreement among governmental officials that the flu is going to cause major disruptions - including in the workplace, and that could present some significant security challenges.

Swine flu threat raises telework questions

In mid August the Secretaries of the US Departments of Commerce, Health and Human Services and Homeland Security announced new federal guidance from the Centers for Disease Control (CDC) for businesses in regards to the Swine Flu. They also pointed at government Web site focusing on flu related issues. The CDC guidance is quite extensive and useful as businesses work out their own flu response plans. One of the clear messages from the CDC is that a lot of employees will be staying at home, some because they get sick, some because their kids get sick and some because their kids schools closed or because a business decides to reduce the spread of the flue among their employees by telling them to work from home. In any case there is likely to be a lot of additional employees wanting to, or needing to, work from home. Are you ready?

Allowing employees to do sensitive company work at home creates a number of security issues. In order to minimize some of these issues companies need to develop and promulgate clear policies on what information employees can access from home and how it must be protected. The newly revised regulations for implementing the Mass Identity Theft Law require companies to develop "security policies for employees that take into account whether and how employees should be allowed to keep, access and transport records containing personal information outside of business premises."

This is one of the requirements that survived the recent evisceration of an earlier set of regulations designed to implement the law.

This is a good requirement. Companies should also decide if employees will be permitted to use non-company computers to work from home - you know, the computers that the kids use to run music sharing software that can open access to all files on the computer. Rules for personal use of the computers must be very clear if employees will be required to use company computers. Up to date virus protection is a must and systems need to be patched as soon as updates are issued. Methods of access should also be mandated, for example requiring the use of VPNs to access company resources can help reduce some security risks.

But it is not enough to have rules for the home-bound employees - company services must also be designed to reduce risk - for example servers that store confidential company information should not be directly accessible from the Internet. You do not want your company to be the next poster child for what happens when a corporate Web server gets hacked.

Since your company will be impacted by the swine flu you might as well use it as an opportunity to strengthen and clarify your remote access and data handling policies if you are like most businesses and have never really thought about the issue.

Disclaimer: Harvard's business is getting people to think about things and I have been working on this issue in my day job but the university has not announced a specific remote access policy (yet).

As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center