Affichage des articles dont le libellé est companies. Afficher tous les articles
Affichage des articles dont le libellé est companies. Afficher tous les articles

vendredi 9 août 2013

In 2013, what are the new threats for IT companies?

Blue Coat, computer security specialist, focuses on the impact that public attacks can have on the IT business. At first glance, they are not directly affected. Unless it happens that these attacks are launched to hide the true intention of the pirates: make diversion to aim at a specific target, a client database in an organization for example.

Opening more important of is via hundreds of points of contact to the Internet facilitate this type of practice. Especially when facing the thorny and complex of the 'devices' management, CIOS are lax and tolerate low levels of infection of machines that connect to them if.

Explosion of attacks on mobile devices

Migration gradual but sustained professional devices to tablets and smartphones course gives ideas to hackers. Symantec provides that the first massive attacks on mobile OS should appear beginning this year, affecting business fleets. It passes through the establishment of networks of botnet, as on a conventional PC, or as recently announced it Symantec by the development of "ransomware" or the "rancongiciels" that target mobile devices, like batpise Android.Fakedefender, and discovered in June.

Principle of vase communicating requires, the growth of the fleets of tablets and smartphones leave a little rest to conventional systems, says Trend Micro, another computer security specialist. To the extent that the actor believes that the most intense threats to businesses should this year come from Android apps. Trend Micro provides that there will be 1 million in 2013, or 350,000 more from late 2012.

But the attacks on PC declining

We would therefore be a turning point in computer security: If threats to mobile explode, the PC in proportion tend to be less the target of hackers.

Read more on the Blog of IT decision-makers
In 2013, what are the new threats for IT companies?

mercredi 29 mai 2013

The Anssi advises companies to accept the BYOD

The use of smartphones in business, whether they are provided by the company or provided by employees (phenomenon BYOD) necessarily induce increased risks of security and data leak.

Manufacturers and specialty publishers increasing solutions to control this trend with tools of protection or permitting separate sealed environment perso and pro in the same terminal (Good Technology, Blackberry Balance, Samsung Knox etc...).

But for ANSSI, the National Agency for the security of information systems, these solutions are insufficient. "Current security solutions are ineffective to ensure proper protection of professional data," can be read in a technical note that the Agency has released.

She therefore took the opportunity to deliver 21 recommendations for it managers.

BYOD: not a good idea

"When information systems deal with sensitive information, terminals to access must imperatively be dedicated and have been the subject of a security assessment, ideally be labeled by the ANSSI. This labelling can indeed attest to the robustness of the solution compared to the main threats a contrario those which simply consist of an application development (a "security application") which will bring, at best, partial protection of sensitive data. When the data are classified, marked as restricted or Special France, a specific regulation applies", warns the Agency.

Examples including the use of centralized management of mobile devices (RMD), the reduction of the lifetimes of passwords or the lock time of the terminal, the ban on access to the shops of applications, the functions of geolocation related applications, encryption of internet storage etc...

Finally, the ANSSI believes that the BYOD is far from being a good idea for businesses. "Because of the previous recommendations, the coexistence of private and business uses on the same terminal must be studied carefully. Compliance with the requirements of this document is wholly incompatible event of a BYOD policy within an organization. In most cases, professional terminal must be dedicated for this purpose (the user can
generally use its own terminal for personal use).

If the use of a single smartphone for both contexts cannot be avoided, depending on the sensitivity of the company data processed on the mobile, should implement solutions for effectively partitioning each environment (personal, professional) by being vigilant on various levels of security solutions of the market. A qualification by the ANSSI must be a criterion for the choice of such a solution,"said the Agency.