Taylor & Francis makes every effort to ensure the accuracy of all the information (the “Content”) contained in the publications on our platform. However, Taylor & Francis, our agents, and our licensors make no representations or warranties whatsoever as to the accuracy, completeness, or suitability for any purpose of the Content. Any opinions and views expressed in this publication are the opinions and views of the authors, and are not the views of or endorsed by Taylor & Francis. The accuracy of the Content should not be relied upon and should be independently verified with primary sources of information. Taylor and Francis shall not be liable for any losses, actions, claims, proceedings, demands, costs, expenses, damages, and other liabilities whatsoever or howsoever caused arising directly or indirectly in connection with, in relation to or arising out of the use of the Content.
Click to increase image sizeClick to decrease image size Additional informationNotes on contributorsMichael I. Sobol MICHAEL I. SOBOL, CISA, is the president of MIS Training Institute, Framingham MA, a leading training firm in the areas of EDP audit, internal audit, and information security. In addition, he is the publisher of Infosecurity News.
Free solutions recommended for personal use Several free anti-virus solutions are available for use on personal machines. The ITSO recommends the following: Windows Defender [2] for use on Windows 10 Avast [3] or Bitdefender [4] for use on macOS, Linux, and earlier versions of Windows NOTE: These solutions are for Duke faculty, staff and students to use on personally owned machines. Anti-virus software on Duke-owned computers should be managed by departmental IT staff.
Those of us in the business of ensuring the integrity of information are increasingly concerned about the amount of sensitive business information that is at the fingertips of more and more users of computer systems. The storage and transmission of this information represents an important risk that must be dealt with. Many encryption products are currently on the market that help secure information when stored on disk and during transmission. Because of space limitations, however, we could not review all of them.
During the 1970s and early 1980s, a handful of companies were promoting disaster recovery services ranging from skeletal disaster plans, cold sites, and consulting services to full-blown hot-site recovery services. For the most part, these companies were selling on the basis of scare tactics. They told us that not only could disasters happen, they could damage and destroy data centers, computer systems, and information. Few organizations heeded their warnings, however, even though those of us in the computer security business knew the threats were real. The big challenge back then was to sell the idea of disaster recovery planning to management. Now the 1990s are upon us. Our reliance on computers has increased; millions of computers are now used in various business environments. Awareness of disasters has increased as well; there are now many examples of disasters to back up our arguments when we are trying to convince senior management of the need for disaster recovery planning.
Telephone fraud is one of the fastest growing areas of white collar crime. Last year alone, AT&T reported that this type of fraud cost US business over $2 billion. Telephone companies and private vendors have begun marketing products designed to control this type of telephone abuse. Below is a selected list of products designed to reduce this risk as well as information about how the big three telephone carriers, AT&T, MCI, and Sprint, are addressing fraud issues. In addition, specific organizations taking an active part in telephone fraud control are listed.
Access control, virus prevention, and data integrity have always been concerns for management and information security personnel. Until recently, most of the efforts in this area have been devoted to the IBM PC and compatible equipment. During the past year or so, however, Apple Computer and its Macintosh line of microcomputers have become increasingly popular in business environments. Because of this emerging interest in the Mac and because of the ongoing concern for information protection and data integrity, several vendors are now marketing security products for the Macintosh line of microcomputers. This column reviews several of those products.
This column will highlight some of the most significant events taking place in the world of new products directly geared to users of computer systems. As the publisher of ISPNews—INFOSecurity Product News, I have the opportunity to learn about the latest products having an impact on the information systems community. In this regular column, I will select a category of products and report on their distinguishing features. In addition, I will discuss areas of high risk that should be reviewed by those with responsibility for information security and asset protection. In this inaugural column, I review several of the latest products designed to protect microcomputers, local area networks, and mainframes from unauthorized access through dialin communications lines. These products have not been tested and the author does not claim that they actually perform as the vendor indicates.
Click to increase image sizeClick to decrease image size Additional informationNotes on contributorsMichael I. SobolMichael I. Sobol is President of the MIS Training Institute located in Framingham, Massachusetts. He was formerly EDP audit manager for North American operations at The Gillette Company. Mr. Sobol is also associate editor of Computer Security. A CISA, he has spoken at numerous conferences, has conducted many seminars, and has had articles published in professional journals.