Monday, January 5, 2009

Information security - 2

Data security can be compromised by personal presence too. Let us look at 3 ways in which a person with malicious intent can try to take a peek into your sensitive information.

Shoulder surfing
Notice how your boss stands behind you at your workstation, as if to see whether you do things right. Now imagine that instead of your workstation, you are in a cyber café and instead of your boss, a stranger is standing behind you. If his intention is to grab some information from your screen or observe your keystrokes as you type your password, he is said to be shoulder-surfing.
Precaution: Always make sure no one stands behind you, observing what you do - not even the café owner/manager.

Dumpster diving
Some people are so desperate for information; they actually dive into a garbage bin and dig out paper containing data that is important from their viewpoint. It could be a draft of some report, or the printout of an as yet confidential financial statement. It may seem messy, but such people do not mind dirtying their hands to lay hold of material that could possibly make them millionaires.
Precaution: If your office has a shredder, use it to shred all waste paper as a habit or even as a rule. Or simply tear the paper into small bits if you don't have a shredder.

Piggy-backing
Most Corporates these days restrict entry to their premises to people holding electronic access cards. Have you ever observed strangers quietly sneak in behind an employee who enters swiping his access card? Who knows, that person could hang around with open eyes and ears and study the layout of your building. He could learn where your company's server room and other sensitive areas are.
Precaution: Make sure that when you swipe your access card, nobody follows you. If someone does follow, alert the security guard and get that person frisked. It's not only about bombs. Information getting leaked out can lead to potentially incalculable losses.

1 comment:

lauren said...

Very well written blog about at ways in which a person with malicious intent can try to take a peek into your sensitive information which involve Shoulder surfing,Dumpster diving andPiggy-backing plus their precautions.Good work
digital signature certificate