misasia logo
Take steps to reduce the risk of spam, viruses and back-door ‘agents’ that can hijack corporate data, says governance body By Jack Loo
01 Dec 2008

SINGAPORE, 1 DECEMBER 2008 - With the holiday season approaching, computer networks of Hong Kong companies are at risk from external attacks as employees start to spend more time shopping online, according to a survey by governance and security organisation ISACA (Information Systems Audit and Control Association).

The study, titled Shopping on the Job: Online Holiday Shopping and Workplace Internet Safety, 42 per cent of Hong Kong employees are likely to spend two or more hours shopping online using a work computer between November and December.

However, more than half (54 per cent) of the respondents’ companies indicate that they do not educate their employees about the risks that online shopping poses.

While approximately 60 per cent of the companies said they have no security measures in place to prevent employees from shopping online at work, more than 55 per cent of these companies think their employees do not fully understand the risks to which they are exposing their companies with shopping online from their workplace computer.

ISACA recommends that employees and IT departments take the following steps to reduce the risk of spam, viruses and inadvertent downloading of back-door ‘agents’ that can highjack corporate data.

For online shoppers:

•    Make sure Web sites you connect to have SSL encryption while you are entering personal information.

•    Do not allow sites to save your username or password. Avoid providing your work e-mail address as your contact information.

•    Delete cookies from your computer after you are finished shopping.

•    Use separate browser sessions for your holiday shopping versus your work-related browsing.

•    If it looks too good to be true, it probably is. Do not download free games, ringtones, wallpapers or animation onto your work computer.

For the IT department:

•    Train employees on safe computing just prior to the holiday shopping season and follow up with periodic reminders.

•    Tailor education programmes to match the various demographics, attitudes and technology know-how of groups within the workplace.

•    Conduct formal risk and threat assessments and update your Acceptable Use Policy and security measures appropriately.

•    Make sure that patches are deployed, security functions are enabled, and firewall rules, intrusion detection system (IDS) signatures, and spam filters are updated regularly.

•    Monitor networks for high-volume or suspicious traffic and respond immediately to threats. Remind employees to sound the alarm if suspicious events occur.

Comments (1)

Rose says...
e-commerce is getting more and more popular. this creates the need of having good tools to help shoppers make right decisions while buying online. reizit.com is a place where shoppers can recommend or bury a product, share experience and discuss shopping deals.
28 Jan 2009 1:34pm

Post your comment

  • Please use English to post and reply to comments
  • Please do not use offensive language in the form of racial or ethnic slurs, abuse or personal insults
  • We welcome opinion and debate geared towards finding solutions
  • Please keep comments relevant to the topic
  • All comments are moderated
** Mandatory Field

Name
    **

Email
    **

Country


Comments
Maximum characters allowed: 2000
Disclaimer: All the content posted in this category comes independently from readers of Fairfax Business Media (FBM) Asia publications, unless specified otherwise. Fairfax Business Media (FBM) is not responsible for the opinions of its readers and the content posted by them does not represent the views and opinions of FBM.

Also of Interest

John Chambers, Cisco

Networking

Chambers unfazed at disrupted speech

By Stephen Lawson
Sony Walkman

Consumer Electronics

Happy birthday! The Walkman turns 30

By Martyn Williams
Hong Kong Pavilion

Government

Hong Kong awards Shanghai Expo contract

By Ross O. Storey

Feature

Axel Winter

IT3.0 – From Lean to Outsourcing

An internal ‘banking cloud’

Application of a multi-sourcing strategy
By Axel Winter | 25 May 2009
Computerworld Singapore Readers Choice Awards 2008Computerworld Malaysia Readers Choice Awards 2008

RSS Feeds

Add this section to your favourite feed reader.