CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA 43 BEST PRACTICE GUIDELINES FOR BUSINESSES Employ Defense-in-Depth Strategies Emphasize multiple, overlapping, and mutually supportive defensive systems to guard against single-point failures in any specific technology or protection method. This should include the deployment of regularly updated firewalls as well as gateway antivirus, intrusion detection or protection systems (IPS), website vulnerability with malware protection, and web security gateway solutions throughout the network. Monitor for Network Incursion Attempts, Vulnerabilities, and Brand Abuse Receive alerts for new vulnerabilities and threats across vendor platforms for proactive remediation. Track brand abuse via domain alerting and fictitious website reporting. Antivirus on Endpoints Is Not Enough On endpoints, it is important to have the latest versions of antivirus software installed. Deploy and use a comprehensive endpoint security product that includes additional layers of protection, including: TT  Endpoint intrusion prevention that protects unpatched vulnerabilities from being exploited, protects against social engineering attacks, and stops malware from reaching endpoints. TT  Browser protection for avoiding obfuscated web-based attacks. TT  File and web-based reputation solutions that provide a risk-and-reputation rating of any application and website to prevent rapidly mutating and polymorphic malware. TT  Behavioral prevention capabilities that look at the behavior of applications and prevent malware. TT  Application control settings that can prevent applications and browser plugins from downloading unauthorized malicious content. TT  Device control settings that prevent and limit the types of USB devices to be used. Secure Websites Against Attacks and Malware Infection Avoid compromising your trusted relationship with customers by regularly assessing your website for vulnerabilities and malware. Additionally, consider: TT  Choosing SSL Certificates with Extended Validation to display the green browser address bar to website users. TT  Displaying recognized trust marks in highly visible locations on your website to show customers your commitment to their security. Protect Private Keys Make sure to get your digital certificates from an established, trustworthy certificate authority that demonstrates excellent security practices. Symantec recommends that organizations: TT  Use separate Test Signing and Release Signing infrastructures. TT  Secure keys in secure, tamper-proof, cryptographic hardware devices. TT  Implement physical security to protect your assets from theft. Use Encryption and DLP to Protect Sensitive Data Implement and enforce a security policy whereby any sensitive data is encrypted. Ensure that customer data is encrypted as well. This not only serves to prevent data breaches, but can also help mitigate the damage of potential data leaks from within an organization. Access to sensitive information should be restricted. This should include a Data Loss Protection (DLP) solution that can help prevent data breaches and minimize their impact. TT  Implement a DLP solution that can discover where sensitive data resides, monitor its use, and protect it from loss. TT  Monitor the flow of information as it leaves the organization over the network, and monitor traffic to external devices or websites. TT  DLP should be configured to identify and block suspicious copying or downloading of sensitive data. TT  DLP should also be used to identify confidential or sensitive data assets on network file systems and computers.

Select target paragraph3