How best to manage the security issues social networking brings to business

08 March 2010
A social network is a communication network of social contacts and seems to have become the most popular way to stay in touch. Forrester Research stated that the number of people using the web will increase by 45% to 2.2 billion by 2013, the total global internet audience is currently 625M and two thirds of these internet users have now joined a social networking site (417M). This is a huge number of people and consequently the security risks are equally substantial. Businesses must address these risks.

It seems hard to justify the use of social networking in business as the sites are more focused on keeping in touch with friends, sharing photos, video and chatting; however businesses should not prevent employees from catching up with colleagues and talking with friends while in the office, on their tea break or having a cigarette. Staff morale is important and it would be viewed as draconian to block reasonable use of social networking sites at work. Many businesses are now embracing benefits in social networking to bring them closer to their customers and improve brand experience. The uses of social media seem endless, but what are the security issues that businesses need to consider before embarking on a new marketing campaign or allowing staff the luxury of keeping in touch with friends and family at their desks?

Social Networking brings with it an extensive variety of risks ranging from identity theft and malware infections to the potential for letting careless employees damage corporate reputation and messaging. Social networking uses diverse integrated functionality to convey information as well as feature rich functionality including web, chat, audio, video, pictures and integrated applications. As the use of these social networking tools increases in the corporate environment, so too does the inherent information security risks. Many of the applications available for download on these websites can propagate malicious code from third parties, which can include viruses or Trojans and signing up to these could involve consenting to the deployment of spyware. These also pose data leakage and malware risks to any business that allows access to social networking sites.

One of the largest security risks for businesses permitting access to social networking is the fact sites like Facebook offer thousands of integrated applications that its users can install and run. These applications include calendars that allow friends to be reminded when it's your birthday, tools to send friends online greeting cards, quizzes on myriad topics etc. Many have been designed by users and hosted externally which means that there is little regulation or standards to adhere to. In this case one primary security issue is the ability of the application in question to extract profile information which would then be stored at a third party location with obvious security implications.

Another risk for business environments involves the shortening of URLs on social networks. Shortening URLs has been born out of a characteristic of social networking type sites because users are limited to the number of characters for messages and posts. To get around this, third-party services such as tinyurl.com can encode the URL into a much shorter version but there is a clear security risk associated with this. The shortened URL does not tell the user the real destination of the link they are clicking on and they only find out once they are there, which may be too late if the site happens to contain drive-by malware.

There is no simple solution to manage these risks. Businesses can implement technical barriers to prevent any use of social networks but then the business may have lost a valuable sales and marketing tool in its effort to protect its information security and privacy. Businesses should firstly have an Acceptable Use Policy that details how social networking sites and applications can be used. The policy should also define consequences for failure to comply as this can lead to the termination of employment and legal action. It will always be difficult to restrict what employees do on their personal social networking accounts so it is important for a business to protect its information based on a worst case scenario idea that employees will download malicious code and will divulge information they shouldn’t.

It is crucial for organisations to carry out a risk assessment to establish which information is most critical to the business. They also need to evaluate how it might become vulnerable and how to protect it. Assessing current and future risk posed to the business is imperative so action can be taken and high level critical threats can be mitigated. They must also make sure their current infrastructure has the most up to date and application-aware security solutions (including both network and endpoint based solutions) to block any harmful files that may be accidently opened. Employees should receive education on the information security risks involved in their internet access and how they can guard against them - for example, only installing or running applications from trusted sources approved by the corporate IT department.

Many organisations are faced with large volumes of information when looking at their internal vulnerabilities. Pentura believes the most effective method of prioritising these vulnerabilities involves a number of key steps which Pentura has developed as a Vulnerability Risk Assessment (VRA) service. This includes: modeling and mapping the network and importing rules from multiple devices, defining the threat origins and classifying the assets based on importance to the business. This identifies the vulnerabilities presenting the greatest threat to the business, thus allowing remediation and protection of the most important assets.

Remediation may involve patching endpoint systems, changing rules on routers or firewalls to prevent the threat from entering the network, or deploying new technology to address the threats. Pentura works with organisations in developing a security strategy to gain visibility of their current security toolsets, identifies their effectiveness, provides consultancy in policy tuning and understands what additional solutions may be needed to address areas not currently covered from a security perspective. These Risk Assessments have a proven track record of success, and in many cases, remediation of the top threats has dramatically brought down the overall business risk.

Technologies have started to emerge that offer granular control of social networking functionality. Palo Alto Networks's technology allows businesses to gain user application usage visibility and affect a policy to control social networking site access from almost any aspect such as chat, email, apps and file transfer. As well as securing site access, companies that harness web 2.0 functionality for their own use should be mindful of ensuring their applications and website code is fully checked and written in a secure manner which can be validated. Last but not least, use common sense on the internet and in email, by taking an extra moment or two to think about what you've received or are about to do can mean the difference between looking at a seemingly harmless funny photo and risking critical business and personal information such as customer details, business plans, bank account details, all of which you don’t want to be in the hands of anyone other than yourself or your business.

Pentura is exhibiting at Infosecurity Europe 2010, on 27th – 29th April at Earl’s Court, London, www.infosec.co.uk

 

Latest utility and critical Industrial security articles

 Compliance with BS 8484 ensures a lone worker device service is fit for purpose

 4iSecurity's software protects Sleepmasters' headquarters

 Stolen forklift recoved in less than four hours by activating its TRACKER device

 IndigoVision's IP video security technology remotely monitors automated gas facilities in the Amazon Rain Forest

 Norbain secures exclusive agreement with Geoquip

 SALTO Systems's offline access control readers combine with Siemens' SiPass security management system

 LILIN introduces AirLive product range to provide a cost effective wireless outdoor network for IP cameras

 W32 Stuxnet-B rootkit can install itself automatically from a USB memory stick onto a fully-patched PC

 35 percent of companies believe their Intellectual Property has been handed over to competitors

 The use of wireless networks leaves information at greater risk for interception

...[view more articles on industrial & manufacturing security]...

 

Other security websites:

Industrial security links

Security guard killed at Ingles identified Security guard killed at Ingles identified

Manufacturing enters a new age Nearly 38,000 manufacturing jobs have been lost in Greater Cincinnati and Northern Kentucky over the past 10 years, but this industry is far from dying. Waves of retirements - and a high-tech shift - means workers, not jobs, will soon become scarce.

Security Guard Killed on Duty Forsyth County Sheriff Ted Paxton says a grocery store security guard is dead after being shot during a robbery. The sheriff says the shooting happened at an Ingles store on Canton Road just before midnight Sunday. Paxton says a group of robbers with their faces covered held up the store after closing time. He says it's not known whether the robbers were in the store when it closed or gained ...

Security breach in Rahul convoy at airport A major security breach and unruly scenes marked Rahul Gandhi's first political rally in Kolkata.

Social Security payback option may end Agency looks to end "do-over" strategy A little-known strategy that allows Social Security recipients to boost their income by repaying benefits received in earlier years and then claiming a bigger monthly check based on their older age may soon disappear.

Industrial agriculture puts big problems on our plates Industrial agriculture puts big problems on our plates

Security alert raised vs bandit attacks ZAMBOANGA CITY -- Security forces in Mindanao are on high alert against any retaliation from the Abu Sayyaf bandit after one of its commanders and two other members were killed in a gun battle with government troops in Sulu province on Saturday.

directory of Industrial and Manufacturing security suppliers
Search directory Register your company
Industrial and Manufacturing Security books:

SEARCH NEWS
DIRECTORY
Google