Subscribe by Email


Showing posts with label Compliance. Show all posts
Showing posts with label Compliance. Show all posts

Saturday, April 6, 2013

What are the risks and liabilities with instant messaging?


There are a number of risks and liabilities associated with Instant Messaging. Till today several attempts have been done in order to create a unified IM standard. 
Few have been mentioned below:
  1. Session initiation protocol or SIP of IETF.
  2. SIP for instant messaging and presence leveraging extensions or SIMPLE.
  3. APEX or application exchange.
  4. IMPP or instant messaging and presence protocol.
  5. XMPP or open XML – based extensible messaging and presence protocol.
  6. Instant messaging and presence service of open mobile alliance (this one was developed exclusively for the mobiles.)
Although a number of benefits are given by instant message, there are also many risks and liabilities associated with it. This happens particularly when one uses IM at his/ her workplace. 
Associated risks and liabilities are:
  1. Security risks
  2. Inappropriate use
  3. Compliance risks
  4. Trade secret leakage

About Security Risks

- Security risks involve infecting the systems with viruses, worms, spyware and Trojans etc.
- Hackers and crackers make use of IM vectors for making phishing attempts, introducing the file attachments laden with virus and poisoned URLs. 
- Two main methods are used by the hackers for delivering the malicious code via instant messaging:
  1. Delivering viruses, spyware or Trojan horses through an infected file.
  2. Using the socially engineered text that has a web address enticing the recipient to go to an URL that in turn connects him/ her to a malicious website.
- The first kind of means i.e., the Trojans, worms and viruses propagate themselves by infecting the whole contact list of the user. 
- An attack done through means of a poisoned URL may infect 1000s of user’s system in a very short duration i.e., just when each of the person in the user’s contact list receives a message that appears to be from a trusted source. 
- Thus, when the recipients click on the web address, the whole cycle repeats. - Such infections might be for some criminal or a nuisance reasons. 
- These attacks are getting more sophisticated with time. 
- The connections in the instant messaging are usually in plain text. 
- This is what that makes them vulnerable to threats such as eavesdropping. 
Also, with instant messaging, the UDP ports are left exposed to the world inviting many potential security vulnerabilities and raising many security issues.

About Inappropriate Use

 
- All the organizations, be of any type need protection against the liability of the inappropriate use of the IM service by the employees. 
- The nature of the IM, be it immediate, informal or anonymous marks it as an abuse of the workplace. 
- In a number of nations, a legal responsibility has been set up by the corporations in order to make sure that the working environment is free of any harassment for the employees. 
- Instant messaging is now included as an integral part of the policies of the companies regarding the appropriate use of services such as e – mail and world wide web and some other corporate assets.

About Compliance Risks

- Using the IM services at workplace also induces a risk concerning the non – compliance to laws and regulations that govern the use of electric communications. 
- The need for the production of the archived business communications that would satisfy the judicial requests is what to which most of the common regulations is related to. 
- There are a number of IM communications falling under the category of business communications and are retrievable. 


Saturday, December 10, 2011

What are different characteristics of Compliance testing?

Compliance testing perhaps sounds a very rare kind of testing, less often heard about. It can be defined as the audit of a software system or application which is carried out against well known criteria.

There are many kinds of compliance testing and some are even developed as per the requests of the customers or the clients. Basically the compliance tests are of the following types:

Systems in Development
It refers to the compliance testing in which the verification of the fact that the intended software system or application under development meets the lock down standards, configurations and specifications as requested by the client or the customer is done.

Operating systems and applications
- It refers to the compliance testing in which the verification of the fact that an operating system and software system or applications have been configured and designed appropriately and properly as per the requirements, specifications and lock down standards given by the clients and the customers is done.

- Thus, this kind of compliance testing provides robust, adequate and efficient controls to ensure the availability, integrity and confidentiality of the software system or application is not affected during its normal usage and is maintained throughout the whole working process.

Management of IT and enterprise architecture
- It refers to the compliance testing in which the verification of the fact that the all the in-place IT management infrastructure aspects of the software system or the application have been put in their appropriate place is done.

- This is generally done to ensure that the audit, change in controls, security procedures and business continuity have been documented, formulated and put in their proper place and remain effective.

Inter- connection Policy
It refers to the compliance testing in which the verification of fact that the business continuity controls and adequate security measures that govern the connection of the software system with other systems like the systems for tele- communication, extranets, intranets, internet and so on, have been put in their appropriate place, have been cross checked with the specifications and requirements stated by the clients and the customers and have been fully documented is carried out.

These were some standard compliance tests.
Apart from these there are some normal compliance tests which encompass either a few or all of the compliance tests mentioned above.
- Some lockdown policies are applied to the underlying applications or software systems and operating systems.
- Some of these policies are passed by the clients or the customers and some by the concerned parties.
- These policies can be referred and can be used as a guidelines as and when required by the customers or clients when the software testers or developers have already performed a compliance test.
- They can also be referred after the penetration testing and vulnerability assessment of the software system or application so that more security measures can be applied to the system’s enterprise in order to improve its security.

The national security agency or NSA as it is often abbreviated has provided a number of lock down policies and guidelines to increase the awareness of the security affairs that are affecting our operating systems, software systems and applications etc.
The policies cover the following:

- Database servers
(a) oracle 10g
(b) oracle 9i
(c) Microsoft SQL server

- Operating systems
(a) Apple server operating systems
(b) Apple Mac OS
(c) Microsoft Windows NT
(d) Microsoft windows XP
(e) Microsoft windows 2000
(f) Sun Solaris 8
(g) Sun Solaris 9
(h) Microsoft windows server 2003


- Routers
- Switches
- Web servers and browsers
- IP and VoIP telephony
- SQL Server 2000
- BIND
- Novell eDirectory


Facebook activity