Home > Ask the Information Security Experts > Data protection Questions & Answers > How to protect employees' personal information and passwords
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

How to protect employees' personal information and passwords

Ken Munro EXPERT RESPONSE FROM: Ken Munro

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 26 April 2009
Even though employees are told over and over again to not give out their user names and passwords, it doesn't always work. What are the best ways to protect employees' personal information and keep social hackers from stealing passwords?

>
As complexity increases, so does the temptation to write a password down. As does the chance of a user's domain password being used elsewhere (such as on a social networking site). Reuse increases the chance of compromise; your Active Directory environment may be nice and secure, but third parties rarely look after password hashes and data in the same secure manner.

Forced password expiry is often cited as a route to increased security. I disagree! If a hacker is stealing passwords and has access to anyone's domain credentials, why would they wait 30 days to use them? Once they get hold of the credentials, they'll place a back door, and then they won't need the credentials again.

Some companies try expiring user passwords every 30 days but that is a sure-fire route to annoy your users, reduce goodwill towards your security department, and increase chances of passwords being written down.

Instead, teach your users how to create, remember and look after a strong password, and expire them far less frequently. You'll win friends in your workforce, and the training programme will help you build relationships and communicate more about security. Security is not a technical problem, it's a people problem. Therefore technical offerings are rarely the solution: advice which IT security departments would do well to take heed of!

In the end, the best way to protect employees' personal information and passwords is education. Help your staff equate the importance of their username and password with their debit card PIN number and bank account details.

Giving away your PIN with your bank card is a way to get your account emptied. Giving away your credentials to a PC that you use for online banking is just as stupid.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Data protection
How to detect if machines have been infected with Trojans, keyloggers
What are USB flash drive security best practices?
Are iPhone encryption features on the way?
What should be part of an employee termination checklist?
Are there keylogger monitors that can effectively spot malware?

User Password Security
Microsoft, security firms warn of password meltdown
Single sign-on system removes password chaos at East Kent NHS Trust
Brute force attacks target Yahoo email accounts
The consequences of poor Microsoft SharePoint security permissions policies
Unpatched vulnerability discovered in Microsoft SQL Server
Supplier's problems with passwords solved by single sign-on technology
Social networks and spear phishing attacks
How effective are password hack tools?
Gartner: How to succeed at identity and access management
Windows password security: System tools and policy

Security Policies and User Awareness
Cloud-based services require stalwart business continuity plans
Preventing phishing attacks: Enterprise best practices
CISOs take measured steps to reduce social media risks
Increasing information security awareness in the enterprise
How to develop a culture of security in the enterprise
Creating and enforcing a clear-desk policy
Physical security threats: Don't gift your data away
Cut down on calls to help desk with cybersecurity awareness training
Layoffs prompt insider threat fears, cybersecurity survey finds
How to write an information security policy

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Financial Services Authority  (SearchSecurityUK.com)
IISP (Institute of Information Security Professionals)  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Access Management: Authentication, Biometrics, Password Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts