Sour time is coming. Spy programs are stealing information more easily. The reason is weak algorithms, which provide systems safety, for example data encryption and hashing. Information security awareness training is important: spend more time to verify page security level, when using internet for transactions.
If the page is secured, it does not mean that it is safe. Almost in all secured pages are built in SSL (Secure Sockets Layer). Do you know what features are included in SSL? The most familiar are MD4, SHA-1, AES, and RC5. Maybe for ordinary user it is enough. For attacker it is more than enough!
Strong algorithms are MD5, SHA-512, and RC6. It is recommended to use strong algorithms together. Systems weakest area makes system vulnerable on attacks. So, avoid to use already cracked algorithms, for example:
* DES (cracked in 1998);
* RC4 (cracked in 2000);
* MD5 (cracked in 2004);
* SHA-1 (big cracks founded in 2005);
* RSA (cracked all versions to RSA-640. RSA-640 cracked in 2005)
Most of all web pages SSL are using MD5, RC4, RSA-256, particularly all e-banks. If these e-banks have no time for upgrading old algorithms, maybe you have time to check out yourself this.
Click in your web browser for page properties and verify security options. Do not be surprised! Some page security level is older than mentioned in this text. That is a reason, why spyware is so strong and Trojans can easy get password and credit-card numbers.
All of SSL algorithms are scientist's achievements in deep mathematics to create as strong as possible information security before 5 to 10 years.
Now almost every algorithm is cracked and if not, then will be. Hackers are fast. After few years they will summarize all already cracked algorithms together. And it means that all week and middle week e-bank systems will fall.
Certificate In Information Security
The first step in the process of implementing information security is to select a standard applicable to you; in this case it is the BS7799-3:2005. The next stage involves choice of policies after determining their content and structure. It is imperative that we do some research and satisfy that the selected policies are complete and up-to-date in all respects. The policies also must be able to meet your requirements so as to make your organization BS7799 compliant.
At the outset we need to understand how to define and create policies. Either ready made policies can be purchased off the shelf or creating them in house if sufficient talent exist in the organization. Usually the management finds it very convenient to buy readymade polices and then modify them to suit their needs. Before such purchase is done, it is advisable to read every clause, word and sentences and then put them to use. The process of buying the pre-defined policies is the path of least resistance and usually preferred do the only reason that something does not go amiss when making policies on your own. The best process is to buy the ready made policies and then make the necessary changes as per your retirement to meet your business needs keeping in mind the ultimate aim of implementing the BS7799 in your organization. Ready made set of policies is available from the some of the IS Policy Portal which are quite comprehensive, and which fully meet the requirements as set out in the BS7799 along with ISO17799 and other standards.
Just having a copy of the IS security policy in hand is simply not enough. You have to understand the contents in the context of your organizational needs and then make necessary changes before implementing them. This is very easy to speak about but very difficult to implement in real life situation. The main hurdle before the IS manager is how to go about implementing the IS security policies as implementing is the most critical part of any kind of implementing.
Both Infosecuritylab & Alex Gwen Thomson are contributors for EditorialToday. The above articles have been edited for relevancy and timeliness. All write-ups, reviews, tips and guides published by EditorialToday.com and its partners or affiliates are for informational purposes only. They should not be used for any legal or any other type of advice. We do not endorse any author, contributor, writer or article posted by our team.
Accredited Online Doctoral Degrees As technology advances, online education is becoming not so distant. Thanks to online degrees, people can get educated without buying an air ticket!