Version: 2008

Comments on: Feds scramble to meet data breach deadline

Deadline for federal agencies' policies for dealing with data breaches approaches and it's not yet clear whether everyone will be done in time.

Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
blind and incompetent
by weegg July 19, 2007 7:16 AM PDT
The federal gov't. Enough said!
Reply to this comment
How to do network security.
by ralfthedog July 19, 2007 9:59 AM PDT
1. Do not use windows or OS-X for your servers. If you want to be secure you MUST run servers on an OSS operating system, you MUST be able to do a custom compile.

2. Figure out the smallest number of services you can run on your servers. Compile a version of the OS that only has those services.

Do not install any outside software if there is any way to avoid it. It is very important to start at 0 and add stuff, not start with stuff and remove what you don't need.

3. Test this configuration. If your client software breaks because you left something off, try to get around using the client software. Adding things back to the server should be a painful last resort.

4. Train everyone. The most likely place for a breach is not your computers, but the people who use them. Test them on policy. Make sure they know what to do, and make sure they do it.

Let people know that if they make a mistake, they are not in trouble as long as they let you know right away. Everyone makes mistakes.
Reply to this comment
Security and HDD Encryption
by Hardrada July 19, 2007 11:16 AM PDT
Simple. If you use the products from Utimaco, specifically SafeGuard easy and Lenovo laptops, (which the gov't already does) you simply use the fingerprint reader only (risky) and implement the password for the admins only. No users can login without the fingerprint reader.

Done.
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement