img00063-20100128-1719

This week I have been in Germany teaching a couple of my Social Networking Security classes. Thanks very much to everyone who attended. I was recently on-site and managed to take a shot of this lady cleaning an office. In my opinion this is the type of person who is perfectly placed to undertake industrial espionage. Think about it she could easily plant bugging devices, key loggers and you would not be any the wiser until it was too late.

Remember Social Engineering is not just about shoulder surfing, eavesdropping or tailgating. Social engineering is the ability to obtain as much information from you and your organization which can be used for criminal purposes. In order to protect against these types of attack you can:

  1. Conduct a Classification and Impact Analysis
  2. Identification of Baseline Controls (High, Medium & Low.
  3. Human Resources: Adopt & Follow Clear Guidelines!
  4. Ensure you adopt Security Awareness Programme & Usage Policy
  5. Access Control: Establish Clear Internal & external Guidelines
  6. Administrator Responsibilities
  7. Secure Workstations / Laptops / Software etc
  8. Network Security: Firewalls, IDS, IPS Etc
  9. Establish Clear Remote Access Guidelines
  10. Conduct Regular Backups
  11. Social Engineering: Be Aware of Dangers
  12. Establish Clear Audit Trails & Monitoring
  13. Security Implementation: Timings etc
  14. Audit…Audit & Audit!!!!