#1 (permalink)  
Old 06-07-2002, 10:35 AM
rudeboy's Avatar
Devil's Advocate
 
Join Date: May 2002
Location: Boston, MA
Posts: 370
Rep Power: 32
rudeboy will become famous soon enough
Physical Security

Has anyone here had data or systems compromised due to a breach in physical security (dumpsters, doors, s.e.'d guards) and what did you do as a measure of incident response because of it?

Last edited by rudeboy; 07-10-2002 at 04:06 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-10-2002, 06:12 PM
vokx's Avatar
Building the family
 
Join Date: Jun 2002
Posts: 82
Rep Power: 12
vokx is on a distinguished road
it all depends...

I had this problem at the last corporate job i had...dumpster pilfering, server room break ins, stolen laptops, etc.
Unfortunately there is no easy answer...
start with EVERYTHING being shredded on the way out to the bins. you'd be surprised what people just toss in the bins.
if you have any idea who has keys, recall them and reissue on a tighter basis. everyone doesn't need a friggin master key - if they insist, give them a bathroom key with "001" stamped on it and they probably will never even know. (best to change all the locks at this point too)
laptops may not be left in the office, they must be either removed from prem or put in a lock box - we had three boxes installed for this in small closets - something that bolts down and locks up.
video surveillance - all major entrances and sensitive areas, we used netbotz in our server room. we actually caught a VP trying to delete mail from the server.
its kinda like the racecar analogy - speed costs money, how fast do you want to go? its all proportionate to the $ you can spend.
and if you think your janitorial staff or security guards are to blame...fire everyone (be sure you have documentation of the kind of shit that has been goin on) and rehire an entirely new crew - and make sure they are bonded - also national.
change passwords regularly - that way when someone writes it down it only works for a little while - not the length of their emplyment.
don't want to bore so i'll knock off here.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-11-2002, 12:19 PM
rudeboy's Avatar
Devil's Advocate
 
Join Date: May 2002
Location: Boston, MA
Posts: 370
Rep Power: 32
rudeboy will become famous soon enough
formal measures

Thanks for the reply. We are actually not too bad on the physical security part. I have been tasked with writing some incident response procedures (forensics included) and was wondering what are good templates to use concerning IR for a physical breach. We have cameras, shredders, bonded clean crew, etc. at all sites.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Internet Security Companies sliver_fish Security 2 02-06-2004 01:43 PM
Wireless Security Book Grifter Security 5 01-13-2003 06:25 PM
Apache Security Book Grifter Security 1 11-25-2002 11:53 PM


All times are GMT -7. The time now is 11:55 PM.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43