May 13, 2001
Hit Me Baby One More Time Part II
One user's bad experience
In April 1999, I fell victim to the (dreaded) WinCIH virus. However, I was up and running a day later beacuse frequent backups had ensured that only my programs were affected. In June 2000, a company-wide CIH attack caused the dotcom project I was then working on to be delayed by 60 days! In both cases, there was no information security (infosec) policy. I have since developed my own which consists of 5 Rules:
- Choose an antivirus that includes a POP mail scanner
- Buy and install the product
- Keep it updated; possibly in real-time (auto update)
- Ensure that every developer-recommended update/security patch is downloaded and installed
- Install any third-party tools that provide additional security (like MicroEye ZipOut)
- Periodically use an Web-based scanner like Housecall for a double-check
- Disable Windows Scripting Host
- Don't preview email or open any attachments; use an online drive to exchange files
- Stay aware ALWAYS
- Stay abreast with viral and infosec happenings (the Web is a data goldmine)
Post a Comment