Companies pour time, energy, and money into products to maintain network security. Yet their network's biggest threat is frequently from the inside. An adequate Internet policy is crucial in protecting company networks where they are most vulnerable
By inadvertently allowing inappropriate e-mail, sexual in nature or otherwise offensive, to be sent within the office, companies are vulnerable to legal action.
Employees who don't know how to respond to potential security breaches, such as social engineering tactics, leave the company open to security attacks. Employees who are not properly trained or who are unhappy with their jobs are also more likely to divulge proprietary or otherwise sensitive information to unauthorised individuals, such as competitors.
The most effective Internet policies reflect the corporate culture, business objectives and the importance placed on the Internet as a business tool.
With millions of employees now potentially able to commandeer company property for personal use during the workday, companies are understandably concerned about the misuse of corporate Internet resources.
According to a 1999 joint Computer Security Institute (CSI)/FBI study, 97 percent of companies reported insider abuse of Internet resources. The average loss per company due to employee abuse - including malicious and inappropriate Web-based content - is $93 000 (R7.5 million) per year, although losses at individual companies totalled up to $3 million (R25.5 million). Kevin Isaac, regional manager of Symantec Middle East and Africa, points out that when employees use the Internet inappropriately, they could jeopardise the security and privacy of the enterprise. In addition to having basic security measures in place (such as firewalls, virus and mobile code protection, and content filtering) companies need to focus on training employees in order to reduce the impact of the human threat.
'The Net has become an essential business communications tool. It supports intra- and inter-enterprise research and collaboration, and accelerated business processes. The productivity gains that Web-enabled enterprises may enjoy, however, are tempered by new concerns.
Employees with Internet access may waste time and precious bandwidth accessing subject matter that has no bearing on business. In 1999, IDC Research reported that 30 to 40 percent of employee Internet usage is non-business related - amounting to millions of dollars per year in lost productivity. With enterprise bandwidth needs doubling every 90 to 180 days (Gartner Group, 1999), some employers are looking to limit employees' Internet usage in order to control the rising cost of connectivity.
'In addition,' says Isaac, 'certain subject matter may in fact be inappropriate for use or distribution within an enterprise, and may leave the corporation liable for a variety of lawsuits.' Company networks may also become vulnerable to infection, intrusion, and tampering via files such as cookies or other active content, which can be downloaded via the Web, often without the user's knowledge. Finally, employees may fall prey to social engineering tactics, inadvertently downloading malicious code, or disgruntled employees may intentionally try to harm the company.
According to the 1999 Computer Security Institute/FBI Computer Crime and Security Survey, 38 percent of respondents had one to five security breaches originate within their organisations, while 16 percent had six to ten. Many security breaches occurred because untrained employees were unaware of how their computer use - email or Internet - impacted on company security.
E-mail threats
Employee e-mail can cause several types of security breaches. If employees open unsolicited e-mail attachments or do not scan attached documents for viruses before opening them, companies are vulnerable to virus attacks. Also, if companies rely on employees to keep their virus definitions updated, instead of pushing out new virus definitions automatically to ensure policy enforcement, employees risk infection even if they do scan for viruses before opening attachments. By inadvertently allowing inappropriate e-mail, sexual in nature or otherwise offensive, to be sent within the office, companies are vulnerable to legal action.
Surfing dangers
Employees spending time surfing for personal use also impact network security. The most common concern is that employees are wasting time. But there are other considerations. Just as with e-mail, inappropriate Web surfing may lead to legal suits if an employee views sexually explicit or discriminatory material online. And employees who excessively download MPEG or MP3 files risk clogging or slowing down the network.
Non-work-related surfing also increases the chances that an employee will visit a site using ActiveX or Java.
These languages can be used to create malicious code that can communicate directly with the user's machine, giving hackers access to data and, potentially, the network. If employees download free software or screen savers from unknown sources, your system may be infected with a virus or Trojan horse, which may inflict damage ranging from file deletion to stealing passwords. However, experts say that larger and more popular sites that use these languages are fairly safe because the sites employ security measures.
The password challenge
Passwords are a major vulnerability in most companies. It's not unusual for people to try to save time by sharing passwords or choosing a simple password. Weak passwords make it easy for unauthorised users to gain access. A potentially weaker spot in your network security may not be the user passwords, but the users. A carefree attitude toward passwords is what social engineers are banking on. It makes it that much easier to trick an employee into giving out their password over the phone or via email.
Social engineering tactics
Employees who don't know how to respond to potential security breaches, such as social engineering tactics, leave the company open to security attacks. Employees who are not properly trained or who are unhappy with their jobs are also more likely to divulge proprietary or otherwise sensitive information to unauthorised individuals, such as competitors.
A major finding of the Information Security Survey 1999 - conducted by KPMG and BMI Tech-knowledge Group in South Africa - was that 66 percent of end users do not view information security as important. This is despite 70 percent of respondents investing in formal information security policies. This begs the question: how effectively are managers communicating their information security policies?
Internet security is becoming an essential tool for doing business in the 21st century. While earlier means of delivering harmful content - such as physical access and file sharing via diskettes - are still a concern, the primary threats to companies' network security have now shifted. According to Isaac, today the two primary sources of harmful content are Internet access and e-mail.
The thought police
Employers are turning to their IT departments to solve Internet usage issues. The assumption is that since Internet usage is a technology-based problem, it is the responsibility of the IT department. Internet usage monitoring and data gathering are often the first steps in bringing Internet security issues to heel. But, since Internet monitoring often brings employees' personal Internet use to management's attention, IT can be perceived as 'the bad guy', says Isaac.
'IT managers are in the front line of politically and emotionally charged dilemmas, including privacy and trust issues.'
'Internet monitoring solutions can help to identify inefficient use of corporate Internet resources. Unfortunately, these solutions cannot answer the philosophical questions that accompany Internet monitoring, such as who has the right to view Internet usage logs and under what circumstances are employees reprimanded?'
All above board
A formal, written Internet usage policy helps to take IT managers out of the line of fire and allows them to focus on strategic technology issues.
According to Advocate Mariette de Jongh, a labour law specialist and former part-time CCMA commissioner, e-mail can be a very damaging tool, one that needs to be properly managed and secured.
'If it isn't, it can have devastating consequences for companies and their employees,' De Jongh notes. She says that employees should be aware, however, that there is no absolute right to privacy. 'Employers have to, by law, notify employees that they are going to monitor Internet and e-mail use within the company. In fact, they should even go so far as to get written consent from employees.'
And this is where the importance of a proper Internet policy comes in.
She explains that, although employees do have the right to privacy, they are using the employer's property and therefore the contradictions have to be weighed up.
Monitoring the contents of the communication can be justified if the employer has reasonable grounds to suspect abuse, proof of which is not always easy to obtain. If an employee suspected and/or accused of improper use challenges the allegations, the employer cannot simply rely on a printout of the e-mail or verification of sites visited. In terms of the Computer Evidence Act (59 of 1983) the employer may be required to obtain an affidavit from a computer expert or the company's IT manager verifying, inter alia, that the print out is a true copy and that there was no interference in obtaining it.
Yet more dangerous ground surrounding e-mails is the concept of vicarious liability. De Jongh explains that if an employee makes certain defamatory statements within the course of his or her duties, the employer can be held liable.
'So it is essential to state in your e-mail and Internet policy that employees are prevented from making statements that could be construed as statements coming from the company.'
An Internet usage policy is everybody's business
Managing on-the-job Internet access is not just another 'IT project'. When the IT department is asked to spearhead an Internet usage policy project, it must involve the entire enterprise.
The most effective policies reflect the corporate culture, business objectives and the importance placed on the Internet as a business tool. Besides IT, other key departments within the organisation, such as legal and HR, need to be involved in policy development and enforcement. Operations, finance, accounting and others should also be asked to provide input. Opinions should be solicited from all employee levels, from entry-level sales and customer service staff to the CFO and CEO. The resulting policy will be easier to implement and enforce when everyone feels they have had a role in developing it.
The policy that is developed should be brief and easily understood. Many employees don't realise that most Websites can trace online activities back to their employer and even track which applications they are using. In other words, when a staff member surfs at work, they can compromise enterprise security. It is helpful to provide this type of context to employees in your policy.
Once a policy has been developed, it must be communicated to all employees, Isaac stresses. To be sure employees are aware of the policy, some organisations require the employee to sign a copy of the policy, which is then kept in their employment file. The consequences for not adhering to the policy should be clearly stated and communicated as well. Additional training in the proper use and management of the Internet may be necessary.
Tools for monitoring Internet usage
Managerial supervision alone cannot prevent all employee Internet abuses. It is only logical that the IT department be responsible for monitoring employees' usage and access. In order to minimise resource allocations for monitoring employee Internet usage, many enterprises are turning to policy-based Internet filtering solutions. These solutions enable IT to develop its own set of monitoring and reporting rules - based on the unique needs of their enterprise as defined in the Internet usage policy. These tools can usually be customised for certain times of day or work groups. Once the rules are defined by IT, the filtering software automatically monitors and reports Internet usage based on those parameters.
'A sound Internet usage policy, combined with an Internet content filtering solution, can help IT managers to better protect network security, protect proprietary information and reduce liability exposure,' he adds. 'IT managers can further minimise security breaches - and create an effective enterprise content security solution - by using Internet content filtering solutions in conjunction with mobile code and virus protection and email content filtering solutions.
Educate your users
The most effective, yet often neglected, method for addressing the 'human factor' is to establish a policy of regular and consistent user training, with a focus on the company's security objectives. Start by determining your policy needs and what level of training is required for each department. For example, IT security staff need to have an in-depth understanding of the security products and systems that the company uses, while non-technical staff and management can have a more general understanding of what is in place.
There are various training options available, such as hands-on learning, Web-based training, classroom, or seminar-style training. Consider what the employees need to learn, and then determine which training methods would be most effective. To emphasize a sense of company culture and reinforce the importance of maintaining confidentiality, an in-person seminar or classroom-style training is probably the most effective, say experts. If you need to instruct employees on how to use new security software, a hands-on approach may be best. Training professionals can help you to determine the most effective approach.
Enforce your policy
Determine who will administer and enforce the policy. HR departments should make all staff aware of the policy during staff orientation, get signed copies of policies from employees (acknowledging their understanding and adherence) and enforce the policy by following up with the established consequences when necessary. Consequences should be clearly stated in the policy. Generally, security system and network administrators should implement security measures, develop an incident response team to address potential breaches, and work with the HR department by reporting potential problems.
As dependence on the Internet continues, and the threats to the enterprise network continue to evolve, it's important to implement safeguard solutions, especially at the end-user level. While virus protection, firewalls, and content filtering technologies can help to monitor threats, end-user behaviour may compromise network security. Employee training is a key proactive security measure to round out your network security strategy.
8 steps to protecting your network
Avoid security breaches due to human factors with the following measures:
1. Establish an Internet usage policy. Let employees know the company's rules about personal use of e-mail and the Internet. Developing Internet usage policies will also help IT managers to configure and monitor network security solutions more efficiently.
2. Use technology that scans e-mail for inappropriate content and logs Internet activity that falls outside the parameters set by management.
3. Legal experts say that monitoring employees' e-mail and Internet use can help to protect the company in case of a lawsuit. Have a policy and a content-monitoring solution in place to show an effort to protect employees from harassment, for example.
4. Train users to know when and how to download the latest anti-virus updates, as well as how to spot a potential virus. Teach employees how to scan documents before opening them.
5. Patch known holes in software to reduce the chances of a virus entering from Web-pages or e-mail.
6. Develop a password policy, requiring frequent password changes and educating users on social engineering tactics, and reinforce that they should never give out a password. Password cracking software is available to help find weak user passwords in your network. However, the software won't protect the company against an employee's negligent behaviour. Often, educating employees is sufficient.
7. Determine each employee's need to access sensitive information, and restrict access to only what is necessary for their role in the company.
8. Warn employees of the dangers of downloading free software and screen savers.
Symantec, a world leader in Internet security technology, provides a broad range of content and network security solutions to individuals and enterprises, including virus protection, vulnerability assessment, intrusion prevention, Internet content and e-mail filtering, remote management technologies and security services to enterprises around the world. For more information call Robyn Weeda at Symantec SA on 083-296-7096 or e-mail rweeda@symantec.com

