Security Basics mailing list archives

Re: Small business IT security


From: bitshield () gmail com
Date: 14 Nov 2006 20:12:43 -0000

Hello Jonathan

First of all I would enforce these guys to use their own admin accounts, while the company maintains another one. 
Having auditing enabled on each machine could therefore provide minimal trace back abilities. Additionally I would lock 
their admin accounts so that these guys can only access the systems when explicitly requested (which will require 
someone to unlock the account).

Let them sign an NDA (non-disclosure agreement) so that they “could” be prosecuted when they reveal confidential 
information to the competitors.

Well, there is a lot more to do, but these cheap steps will provide some improvements. Sooner or later I would really 
look for an in-house staff. 80 PC together with some server may provide enough work for at least a part time 
assignement.

Regards
Joe

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence 
in Information Security. Our program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Using interactive e-Learning technology, you can earn this esteemed degree, 
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: