CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
43
BEST PRACTICE GUIDELINES FOR BUSINESSES
Employ Defense-in-Depth Strategies
Emphasize multiple, overlapping, and mutually supportive
defensive systems to guard against single-point failures in
any specific technology or protection method. This should
include the deployment of regularly updated firewalls as well
as gateway antivirus, intrusion detection or protection systems
(IPS), website vulnerability with malware protection, and web
security gateway solutions throughout the network.
Monitor for Network Incursion Attempts,
Vulnerabilities, and Brand Abuse
Receive alerts for new vulnerabilities and threats across vendor
platforms for proactive remediation. Track brand abuse via
domain alerting and fictitious website reporting.
Antivirus on Endpoints Is Not Enough
On endpoints, it is important to have the latest versions of
antivirus software installed. Deploy and use a comprehensive
endpoint security product that includes additional layers of
protection, including:
TT Endpoint
intrusion prevention that protects unpatched
vulnerabilities from being exploited, protects against social
engineering attacks, and stops malware from reaching
endpoints.
TT Browser
protection for avoiding obfuscated web-based
attacks.
TT File
and web-based reputation solutions that provide a
risk-and-reputation rating of any application and website to
prevent rapidly mutating and polymorphic malware.
TT Behavioral
prevention capabilities that look at the behavior
of applications and prevent malware.
TT Application
control settings that can prevent applications
and browser plugins from downloading unauthorized
malicious content.
TT Device
control settings that prevent and limit the types of
USB devices to be used.
Secure Websites Against Attacks and Malware
Infection
Avoid compromising your trusted relationship with customers
by regularly assessing your website for vulnerabilities and
malware. Additionally, consider:
TT Choosing
SSL Certificates with Extended Validation to
display the green browser address bar to website users.
TT Displaying
recognized trust marks in highly visible
locations on your website to show customers your commitment to their security.
Protect Private Keys
Make sure to get your digital certificates from an established,
trustworthy certificate authority that demonstrates excellent
security practices. Symantec recommends that organizations:
TT Use
separate Test Signing and Release Signing infrastructures.
TT Secure
keys in secure, tamper-proof, cryptographic
hardware devices.
TT Implement
physical security to protect your assets from
theft.
Use Encryption and DLP to Protect Sensitive
Data
Implement and enforce a security policy whereby any sensitive
data is encrypted. Ensure that customer data is encrypted as
well. This not only serves to prevent data breaches, but can also
help mitigate the damage of potential data leaks from within an
organization.
Access to sensitive information should be restricted. This
should include a Data Loss Protection (DLP) solution that can
help prevent data breaches and minimize their impact.
TT Implement
a DLP solution that can discover where sensitive
data resides, monitor its use, and protect it from loss.
TT Monitor
the flow of information as it leaves the organization over the network, and monitor traffic to external
devices or websites.
TT DLP
should be configured to identify and block suspicious
copying or downloading of sensitive data.
TT DLP
should also be used to identify confidential or sensitive
data assets on network file systems and computers.