Top tips for security staff


Insight Focus
Introduction
Passwords
Network and PC Hygiene
Mail
Printing and other media
Physical security

Passwords
  • Strong passwords make a good starting point. The idea is to come up with something that is difficult to crack by both guesswork and by brute force, but at the same time is easy for you to remember.

    Avoid using single dictionary words, names or birthdays (especially those of family members or pets). One approach is to think of a phrase you can easily remember such as a line from a song. Take the first letter from each word to form a password, and then change some letters to similarly-shaped special characters. You can use the entire phrase, but the novelty soon wears off when you're typing it in for the tenth time in a morning.


  • Australian Standard AS 17799 recommends passwords be at least eight characters and contain a mix of characters and case. Hence "Mary Mary quite contrary, how does your garden grow?" might become "MMq<,hdygg?".
  • The value of a strong password is reduced if you don't log out or at least engage a screen saver lock when you're away from your computer. Those carrying out the majority of security breaches tend to have physical access to systems.
  • Once you do come up with a memorable password, don't write it down on a Post-It note that lives under your screen or the keyboard, or anywhere else for that matter.

    Keep in mind that while social engineering attacks (such as "this is Jim from IT, we're resetting all the passwords so I need to know your password, please" or bogus surveys), while not widespread in Australia, can still pose a risk. Remember, you might not know what the questioner already knows or will later be able to find out about you.


  • Change passwords regularly. Intervals of six to 12 weeks balance the inconvenience against potential exposure to threat. Make a note in your PDA or organiser of the dates on which you should attend to this. Bear in mind that other passwords (such as voicemail) are also valuable and staff should also be making efforts to keep them secure.


  • Lastly, if you have been given a security token for two-factor authentication never let anyone else use it.


Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • Array Can the Telco Reform Act be win-win?
    In the second of our two programs looking at the Senate Inquiry into the Telecommunications Legislation Amendment Bill, we hear from shareholders, bureaucrats and industry groups.
  • Array Has New Zealand's smiling assassin delivered?
    One year into its tenure, how has the new New Zealand Government performed on issues of technology and telecommunications?
  • More blogs »

Tags

Back to top

Featured