quarta-feira, 26 de outubro de 2011

UNIVERSITY - SECURITY AND QUALITY

The quality of the IT environment provide our customers for their education institution is sufficient to serve its students, teachers and contractors?

Institutions of Higher Education,  have been driven to invest in IT. Many higher education institutions provide Internet access to students in order to research, training and application in items related to the courses offered. But this availability is rampant and constantly dangerous when it comes to information security related to it.

Advances in IT investments to Universities when there are significant administrative integration coupled with the awareness of managers of the institution in terms of improving the IT environment, making structural changes, cultural and work processes and improve information security.

In academics, Racing teaching, research and extension has been observed with respect to investment shy Information Security, leaving a large gap in this area in their applications.

Make changes are needed to put them in a satisfactory level of safety.

A proper diagnosis can suggest the best use of Universities their environment and provide them a broad view of what is and what is needed to meet current demand. The item quality, as a rule, with the implementation of ISO9000 can respond and improve many existing procedures and other important form also needed. Then leave for Information Security standards with other allies, today there are flaws that can be controlled or even cease to exist.

In fact, many do not care about security on the Web Just because something is important to us, does not mean he is (or should be) important for all others.

I have examined some sites in consultancy work and the thing is really ugly when it comes to safety on the web. On the development side, it does what it can count up to code analyzer and when we see the security perimeter is also possible to assess how quickly businesses are going in the opposite direction of safety. There raises the question: when will the time is right to spend money on security?

As with any capital investment or operating expenses, application security is a choice;

Like an internal policy of access to their respective punishments can coerce a more secure access, combine preventive, reactive and proactive to form an item of comprehensive security information elsewhere in the Universities is extremely important;

The quest for quality assurance in education is quite unique.

The misunderstanding of ISO9000 among academics is very clear and often have a mistaken view about the standard of quality. The pursuit of accreditation standards of education, shows the intention of strengthening the reputation of the Universities

"Teaching is a creative art, it is emotion and commitment. As one could reduce it to a set of

Standards and procedures? "

To meet the requirement the standard must be presented so that there is flexibility for the Academic and persuasion.

The ISO9000 in Universities should be seen as a matter of organizational culture and attitude.

Therefore, ISO 9000 can become a viable alternative, a means of building procedures to develop a better education. Think about it!.

terça-feira, 18 de outubro de 2011

SECURITY OFFICER - THIS IS THE GUY......


Do not think that managing an area of ​​Information Security is an irrelevant fact and conditional. Unlike what many think, the poor suffer SI Manager in relation to other areas trying to do their best work in research and audit. Yes, SI has also audits. The manager lives in this area pointing out the problems and trying to solve them as best as possible. Unfortunately, and especially the IT department forces him to wake up (agreements) to meet them promptly and quickly. The fact is that cater to IT means to reconcile the conflicting non-participation, ie, a conflict of interest can cause a bad image to the security area if our Information Manager itself does not take into account their political image. Sounds complicated, is not ... No .... The ability of the right manager in this area leads to the highest level of the organization, leading him to be respected by other areas.
This guy is tired of seeing situations where the word "stopgap" in the dictionary of IT and therefore it does not exist in the dictionary of the SI.
For this and other reasons that the area, in my humble opinion, should be isolated from the IT and in many cases responding to another Board. Cases in which the SI is under the jurisdiction of the final conflict ends in IT Management disturbing this area as well as the work related to it.
I have seen cases in which sparks between the IS and Management Boards were instrumental in the relationship between the areas. An Information Security Manager in addition to very patient must have a hip enough to get rid of these troublesome conflicts of interest and the power to know that your area is so great that even though Manager will be considered as "the Almighty". Do not make this phrase your motto in the Corporation, because then you'll be overpowering other areas and other managers. Humility and knowledge will be your weapons against the existing conflicts. Politically act with determination, because they know that their ability and understanding of all the parties will do better.
The world of Information Security Management in racing is to know without being hit forcing achieve improvements in processes and consequently better results Corporation.
Thinking about yourself is not thinking about YOU. When this occurs the corporation will lose. Hitting others with harsh words also will not make the winner between areas. Be tough with someone who was hard on you will do the same to the Manager which caused it.
The Information Security Manager will always be the guy that makes for its area, other areas and the corporation. The word "Envy" maybe here is very strong but have a sure thing my dear reader tiespecialistas;
"Do or Do Not, There Is No Try" for an Information Security Manager

terça-feira, 23 de agosto de 2011

CRACKER X HACKER - original in http://www.tiespecialistas.com.br/2011/08/cracker-x-hacker/


In my last article I explained to you what I mean about hackers and crackers, different as they are in good and bad. Some people questioned me about the two words here and spend a little history and comments.
"CRACKER ... wafer is not and has no taste, an invasion occurs only when there is that we learn of what tastes.
The bitter taste of all that building was destroyed. "
In the Wikipedia definition is as follows:
Cracker is a term used to describe someone who practices the breaking (or cracking) of a security system, illegally or unethically. This term was coined in 1985 by hackers against journalistic use of the term hacker. Use of this reflects the strong revolt against theft and vandalism committed by cracking.
In other words.
He who does the security breach on a system.
In the Wiki also talk about the controversy of the term, but it follows a bit of opinion. Using both neologisms reflects a strong revulsion against the theft and vandalism on the net. 'The neologism "cracker" in this sense may have been influenced by the slang term "cracker," which in Shakespearean English meant an unpleasant person and in modern colloquial American English survives as a synonym for evil delicate called "white trash."
While it is expected that any real hacker has done some raids, with undeniable skill of their techniques, the term "cracker" falls into oblivion and raises "HACKER" the position of the dark side of the Force.
Thus, there is far less overlap between hacker and cracker than regular reader misled by sensationalistic journalism might expect. Crackers tend to gather in small groups, very close and secret but well known in the media due to its disclosure. Though crackers often like to describe themselves as hackers. An easy way to distinguish and detect the difference between hackers and crackers is that crackers use names that hide their identities. Hackers never do this because they rarely use noms de guerre in everything they do, and when they do is to show rather than conceal.
Changing the subject a bit, has anyone thought to ask if the attacks are one more reason to hasten the DIGITAL LAW OF CRIMES IN BRAZIL??
In fact the very attackers know it or ever think about that.
"Hacker" is the malicious security cracker.
It is good just for a story as interesting as this. We would be forever writing it is extremely culture and history is something we can call "NO MATTER THE END BUT THE ACTS"
Whether for the WELL ... Are in the history of information security,
Whether for BAD ... Are in the history of information security,
They are nothing more than history and leverage the IT upgrades in its entirety.

Below the names of some hackers / crackers famous, only to remember .. click to see links

terça-feira, 9 de agosto de 2011

hacker attacks in Brazil




There are about two to three years I was with Mr Julio Semeghini and Dr Renato  Opice Blum in a debate on computer crime law by Decision Report.

In this debate were also Cristine Hoepers CERT.BR the other guests, follows a link to verify a portion of the transmission; http://www.youtube.com/watch?v=wjXF50ZWKcM&feature=player_embedded

Even then, in 2009, the project was of long standing waiting for approvals, (PL 84/99) seems to have no right and no end date.

With so many rodeos to put it into practice, once approved as amended and the "strikethrough" PLS 84 attacks and that more attacks will happen and these digital crimes even if they identified their attackers can not be punished because they still do not have a law that defines this type of crime.

I'm no lawyer, but I believe there is no fitness for Computer Crime still in Brazil. It seems that only the Decree Law 2.848/40 has something to define but not all of the offense. The fact is that the short memory of Brazilian politicians do not remember the attack in January 2011 complaining about the government Dilma, whose group Fatal Error Crew took the incident and claiming that the attack in June with the same group allied with Brazil Lulzsec

Other interesting dates were 2005 and 2007, when strange blackouts left more than 4 million people in the dark. Dates were also possible causes Hacker ...

And so we left behind even in Laws, as countries such as Chile and Argentina already have a Digital Law.

Forming groups and foundations such as the hackers hacking group Lulzsec Brazil, Anonymous, etc ... will be greater and greater number attacks committed;

There will always be attackers and defenders. When new holes are conquered, sites and more sites have attempted intrusions and / or invasion.

Governmental units are apparent when attacked, but what happens to the sites of small and medium enterprises?.

These are in constant attacks but not much media for this, only when a large bank or a large company is the target, then yes ....

For hackers, train invasion is easy when you have such sites to test, approve

and put into production in just over one hour.

The same tools used for safety and good of an organization, is also used by hackers, and most of the time, with greater dexterity.

It is worth mentioning here that several hackers memorable names such as Kevin Mitinik, but I believe his record as a hunter was the best hacker in his time and his name is Tsutomu Shimomura whose side was good. There is a word that hacker turned to bad programming. Hacker has always been and always will be the subject of raids, but at other times, this word was deemed knowledgeable in the improvement of our environment and that in this new era fading to the dark side of the Force Word Cracker better define an invasion but this is a topic for another story here in the IT specialists (www.tiespecialistas.com.br).

quarta-feira, 3 de agosto de 2011

A TRUE STORY



Alarming results were announced after a recent survey by the Ponemon Institute Research and Juniper Networks. The result is related to what we have seen in the media recently, hackers are almost always successful in their efforts to invade a site, and stop them is no easy task. The news shows that 90% of companies suffered some type of attack in the last 12 months. Over 77% who had actually suffered attacks internal problems due to the success of hackers in the raid. Respondents reported a very low trust in their ability to prevent attacks. Many believe that simply are not prepared. 53% believe they will also face some sort of attack in the next 12 months. Attacks on websites are often using classic vulnerabilities as "SQL Injection and Cross Site Scripting (XSS). " What are the biggest barriers to implementing an effective security strategy?
Almost half (48%) of companies surveyed said they found the security procedures too complex to implement. Another 48% mentioned the lack of resources. Companies are looking at the costs of security procedures and practices and complex, analyzing them as expensive to implement. Thus check the possibilities are cheaper. Vulnerability scanners are becoming an ever more effective in detecting faults and take corrective measures at a reduced cost. As for the consequences of these attacks, companies are seeing that the data theft and business interruption losses are more severe. With so much money being lost in breaches, companies need to invest more money in more preventative security measures even at reduced cost. "What you see is that in today's environment, systems" hacked "is almost a statistical certainty."
A fact
He warned that there would be an invasion of the sites of the corporation, but no one took action.
For several times the analyst said the SI had vulnerabilities in the IT development of corporate web sites. He analyzed, identified, reported and noted that should be considered for settlement, but was not granted.
Months passed and patch updates were installed, new devices were placed to improve perimeter security, however the application had not a single line of code updated for protection, only lines to improve customer service and streamline the business.
How many of you have heard this story?
When this occurs, the IT loses itself, along with the corporation, she takes the blame for failing to observe safety guidelines and parameters in its internal development.
A notification of security is proactive rather than an invasion and subsequent tagging of the site developed, whether outsourced or internal development, the role of SI is also possible to analyze vulnerabilities and liabilities.
An important example of success occurred on one occasion, when an analysis done on a Brazilian website in the U.S.. The analysis demonstrated vulnerabilities in the site more than holes in Swiss cheese. A notice sent to holders of the site in the country warned that the problem for biggest surprise was resolved in just over two weeks. Impressive concern and better for the Corporation as the situation was resolved in a timely manner.
The same situation occurred in the enterprise with a site available only in Brazil did not have the same attention and resolution of vulnerabilities. Guess what happened with this site?
La graffiti was a Brazilian to traditional modes of common invaders.

segunda-feira, 1 de agosto de 2011

Segurança em T,I.

Assegurar que seus dados estejam protegidos é mais que necessário nos dias de hoje. Validar informações, monitorar e adequar a niveis de segurança aceitaveis é nosso papel em ajuda-los.

domingo, 31 de julho de 2011

UMA HISTORIA REAL

Resultados alarmantes foram anunciadas depois de uma recente pesquisa realizada pelo Ponemon Institute Research  e Juniper Networks. O resultado tem relação com o que temos visto na mídia recentemente; hackers são quase sempre bem sucedidos em seus esforços para invadir um site, e pará-los não é tarefa fácil.
A noticia mostra que 90% das empresas sofreram algum tipo de ataque nos últimos 12 meses. Mais de 77% que sofreram ataques tiveram realmente problemas internos devido ao sucesso dos hackers na invasão.
Os entrevistados relataram ter uma confiança muito baixa na sua capacidade em evitar ataques. Muitos acreditam que simplesmente não estão preparados.
53% também acreditam que vão enfrentar algum tipo de ataque nos próximos 12 meses.
Ataques a sites são muitas vezes utilizando vulnerabilidades clássicas como  “SQL Injection e Cross Site Scripting (XSS). “
Quais são as maiores barreiras à implementação de uma estratégia de segurança eficaz?

Quase metade (48%) das empresas pesquisadas disseram que encontraram os procedimentos de segurança muito complexo de implementar. Outros 48% também mencionaram a falta de recursos. As empresas estão observando os custos de procedimentos de segurança e práticas complexas  e, analisando-os como caros de implementar.
Desta forma passam a verificar possibilidades mais baratas.
Scanners de vulnerabilidade estão se tornando uma forma cada vez mais eficazes em  detectar falhas e tomar medidas corretivas com custo reduzido.
Quanto às conseqüências destes ataques, as empresas estão vendo que o roubo de informação e interrupções de negócios são as perdas mais graves. Com tanto dinheiro sendo perdido em violações, as empresas precisam investir mais dinheiro em mais medidas de segurança preventiva mesmo com custo reduzido.
“O que se vê, é que no ambiente de hoje, sistemas “hackeados” é quase uma certeza estatística”.

Um fato real

Ele avisou que haveria uma invasão nos sites da corporação, mas ninguém tomou atitude.

Por varias vezes o analista de SI informou a TI que havia vulnerabilidades nos desenvolvimentos de web sites da corporação. Ele analisou, identificou, reportou e apontou que deveriam ser levados em consideração para acerto, no entanto não foi atendido.

Meses se passaram e atualizações de patches foram instaladas, novos dispositivos foram colocados para melhorar a segurança do perímetro, no entanto a aplicação não havia uma única linha de código atualizada para proteção, somente linhas para melhorar o atendimento ao cliente e agilizar o negócio.

Quantos de vocês já ouviram esta história?

Quando isto ocorre, a própria TI perde, junto com a corporação, ela leva a culpa por não observar diretrizes e parâmetros de segurança em seu desenvolvimento interno.

Uma notificação de segurança em pró-atividade é melhor que uma invasão e conseqüente pichação do site desenvolvido, Seja ele terceirizado ou de desenvolvimento interno, o papel da SI tambem é analisar vulnerabilidades possíveis e passiveis.

Um exemplo digno de acerto ocorreu em certa ocasião, quando uma analise feita em um  site brasileiro nos EUA. A analise demonstrou mais vulnerabilidades no site do que buracos em um queijo suíço. Uma notificação enviada aos detentores do site neste país alertou o problema que para maior surpresa, foi resolvida em pouco mais de duas semanas. Impressionante a preocupação e melhor para a Corporação como a situação foi resolvida em tempo hábil.

A mesma situação ocorrida na corporação com um site disponível somente no Brasil não teve a mesma atenção e resolução de suas vulnerabilidades. Adivinha o que aconteceu com este site?

Estava La uma pichação brasileira aos modos tradicionais dos usuais invasores.

sexta-feira, 1 de julho de 2011

INVEST IN INFORMATION SECURITY

One of the most problematic areas in IT Information Security when it comes to IT-related area. In fact there are complications when the SI has to monitor and restrict the area of ​​IT activity in favor of a clean and without detours. The fact is that there is no conflict of interest in terms of databases and tied with strong passwords, the corporation can be said that information security is well with life and IT.
But this only occurs in companies that value the security posture of information and counts on his fingers which ones are. Take the example of a corporation where control of access is not tied to a Single Sign On, or even the control profiles. This corporation brings with it problems of hacking and fraud consequently indisputable. All this is due to the simple fact of investments in the SI and the control of the CIO. Investments of this size for tasks should be directed to the area to protect the corporation itself. In fact what is being proposed to ensure better control how users today in many companies is to invest in the correct timing.
Some companies spend time on investments that should have run. A project this takes about 1 ½ years to close, if indeed there are many stones on the road. Most stone will be one in which the database must contain a connector where it manages some tables whose owner will not want to use it ...
It seems a little problem, which will make a big problem.
The Project Management must determine all the guidelines of the deployment process before someone gets up in the middle of the road trying to block or add items not postulates. Yes, there are always new features to include, but should evaluate the cost-benefit, align deadlines in areas and complete a project as successful.
The various players in the market is becoming increasingly upgraded this type of project designing the new Information Security and quick control methods to prevent certain actions excuses apply after termination of contract is a third-party provider or employee.
In the digital world is connected to the SI is to understand how to support, protect and add context information which turns as a demand to the corporation where mandatory audits based on international, national and internal are fully in compliance with business goals.
It is not easy to adjust these items to IT to be completely linked with the SI, but without specific criteria aligned with the best design concepts using appropriate tools and completing a good relationship between all areas of clouds problems become solutions.
It is necessary to review the relationships between areas, so that all work on the basis of one mind;
Helping the company to grow and grow as a result the corporation.
The interest in the project, providing services to the premises of the IS and the functional relationships should be aligned to a single goal;
Ensure business to win other business.

INVESTIR EM SI

Agora como articulista tambem em www.tiespecialistas.com.br

SKIMLINKS