<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6654040838114505260</id><updated>2011-11-27T18:17:44.478-05:00</updated><category term='ITIL'/><title type='text'>IT Auditors</title><subtitle type='html'>Because Security Matters...</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6654040838114505260.post-8152259839310232478</id><published>2011-02-15T11:40:00.000-05:00</published><updated>2011-02-15T11:40:55.036-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ITIL'/><title type='text'>Introduction to ITIL</title><content type='html'>Glenfis proposes a set of &lt;a href="http://www.glenfis.ch/english/glenfisAcademy/eLearning/eLearning-ITILV2free.php" target="_blank"&gt;4 free e-learning tutorials&lt;/a&gt; to have a first glance at ITIL.&lt;br /&gt;The entire Web site also offers interesting links and documents on the subject in English and German.&lt;br /&gt;Don't hesitate to have a look at &lt;a href="http://www.glenfis.ch/" target="_blank"&gt;Glenfis&lt;/a&gt;!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6654040838114505260-8152259839310232478?l=itauditors.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/8152259839310232478/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6654040838114505260&amp;postID=8152259839310232478' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/8152259839310232478'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/8152259839310232478'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/2011/02/introduction-to-itil.html' title='Introduction to ITIL'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6654040838114505260.post-9037687083388774145</id><published>2010-04-14T12:23:00.002-04:00</published><updated>2010-04-14T12:35:55.519-04:00</updated><title type='text'>Auditing the billing domain</title><content type='html'>Here is a list of topics for an audit in the billing domain. The goal is to realize and end-to-end picture of the billing system, its integration with CRM and sales systems and processes:&lt;br /&gt;&lt;br /&gt;Customer management:&lt;br /&gt;- Customer risk management&lt;br /&gt;- Introduction of new customers&lt;br /&gt;- Debtors management&lt;br /&gt;- Account management and customer complaints&lt;br /&gt;&lt;br /&gt;Invoicing services:&lt;br /&gt;- Rating&lt;br /&gt;o Introduction of prices and Price models&lt;br /&gt;o Discounts&lt;br /&gt;- Billing&lt;br /&gt;o Errors&lt;br /&gt;o Corrections&lt;br /&gt;- Invoicing&lt;br /&gt;o Layout&lt;br /&gt;o Production&lt;br /&gt;&lt;br /&gt;Products:&lt;br /&gt;- Introduction of new products&lt;br /&gt;- Product structures, and processes to change product structures&lt;br /&gt;- Price manual and implementation along billing processes&lt;br /&gt;&lt;br /&gt;Controlling framework&lt;br /&gt;- ICS or SOX controls&lt;br /&gt;- Revenue assurance&lt;br /&gt;&lt;br /&gt;Architecture:&lt;br /&gt;- IT architecture of Fulfillment, Billing and production systems (incl. interface to 3rd parties)&lt;br /&gt;- Roadmap and evolution of the billing system&lt;br /&gt;- Strategy regarding future products&lt;br /&gt;- Interfaces between CRM and billing systems&lt;br /&gt;&lt;br /&gt;Compliance to regulatory requirements regarding:&lt;br /&gt;- Telecommunications law&lt;br /&gt;- Anti-trust law&lt;br /&gt;- Privacy law&lt;br /&gt;&lt;br /&gt;Data: match data between:&lt;br /&gt;- Invoices&lt;br /&gt;- Contracts: Customers – services – prices - discounts&lt;br /&gt;- Accounts receivable&lt;br /&gt;&lt;br /&gt;Invoices production:&lt;br /&gt;- Quality of produced invoices&lt;br /&gt;- Review of 3rd party certifications: ISO certifications or SAS 70 reports&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6654040838114505260-9037687083388774145?l=itauditors.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/9037687083388774145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6654040838114505260&amp;postID=9037687083388774145' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/9037687083388774145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/9037687083388774145'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/2010/04/auditing-billing-domain.html' title='Auditing the billing domain'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6654040838114505260.post-2822932001750960153</id><published>2008-09-11T16:07:00.007-04:00</published><updated>2008-09-11T16:17:26.495-04:00</updated><title type='text'>Security Policy for the use of Handheld Devices in a Corporate Environment</title><content type='html'>Available since June 2008 in the SANS Reading Room:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sans.org/reading_room/whitepapers/pda/32823.php" target="_blank"&gt;http://www.sans.org/reading_room/whitepapers/pda/32823.php&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6654040838114505260-2822932001750960153?l=itauditors.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/2822932001750960153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6654040838114505260&amp;postID=2822932001750960153' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/2822932001750960153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/2822932001750960153'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/2008/09/security-policy-for-use-of-handheld.html' title='Security Policy for the use of Handheld Devices in a Corporate Environment'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6654040838114505260.post-2904779473760706225</id><published>2008-02-17T07:03:00.003-05:00</published><updated>2008-02-17T07:30:19.569-05:00</updated><title type='text'>ISSAF: Information Systems Security Auditing Framework</title><content type='html'>&lt;div style="text-align: justify;"&gt;From the &lt;a href="http://www.oissg.org"&gt;Open Information Systems Security Group&lt;/a&gt;'s Web site:&lt;br /&gt;"&lt;a href="http://www.oissg.org/issaf/"&gt;&lt;img src="http://www.oissg.org/images/stories/thumb_issaf.gif" alt="Information Systems Security Assessment Framework" title="Information Systems Security Assessment Framework" style="margin: 0px 15px; float: left; width: 100px; height: 66px;" height="66" width="100" /&gt;&lt;/a&gt;The &lt;a href="http://www.oissg.org/issaf/"&gt;ISSAF&lt;/a&gt; is &lt;a href="http://www.oissg.org"&gt;OISSG&lt;/a&gt;'s flagship project. It is an effort to develop an end-to-end framework for security assessment. The ISSAF aims to provide a single point of reference for professionals involved in security assessment; it reflects and addresses the practical issues of security assessment. The ISSAF is an evolving framework and it will be further amended and updated."&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;After a quick look at the document, my first impression is:&lt;br /&gt;- it is a bible (1300 pages)&lt;br /&gt;- it takes into account both Methodologies and Practical Assessment procedures and use of most known tools for auditing&lt;br /&gt;- checklists and questionnaires are provided as well&lt;br /&gt;- it's FREE!&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;So, no reason not to &lt;a href="http://www.oissg.org/issaf/"&gt;download it&lt;/a&gt;!&lt;br /&gt;&lt;br /&gt;&lt;div class="dm_cat"&gt;&lt;div class="dm_description"&gt; &lt;p&gt;   &lt;/p&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6654040838114505260-2904779473760706225?l=itauditors.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/2904779473760706225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6654040838114505260&amp;postID=2904779473760706225' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/2904779473760706225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/2904779473760706225'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/2008/02/issaf-information-systems-security.html' title='ISSAF: Information Systems Security Auditing Framework'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6654040838114505260.post-1215229649999255133</id><published>2008-01-14T16:10:00.000-05:00</published><updated>2008-12-09T03:00:50.729-05:00</updated><title type='text'>L'intelligence économique, moteur de compétitivité de votre entreprise - Maîtrise et protection de l'information stratégique</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_CQaHL2lZKcU/R6jWzNlUABI/AAAAAAAAB3I/_c59f-bW3cQ/s1600-h/Conference_DST.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_CQaHL2lZKcU/R6jWzNlUABI/AAAAAAAAB3I/_c59f-bW3cQ/s400/Conference_DST.PNG" alt="" id="BLOGGER_PHOTO_ID_5163613148088107026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;i&gt;Conférence du Commandant Eric Jaillet,&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;i&gt;chargé de communication à la Direction de la Surveillance du Territoire (DST) à Lyon&lt;br /&gt;chargé de cours en Sécurité des Systèmes d’Information auprès des universités et grandes écoles.&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt; &lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;strong&gt;&lt;u&gt;&lt;span style="font-family:Comic Sans MS;"&gt;La&lt;span&gt;  &lt;/span&gt;maîtrise de l'information, enjeu de  sécurité économique&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;&lt;u&gt; &lt;/u&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Parallèlement  à de ses traditionnelles missions de contre-espionnage et de contre-terrorisme,  la Direction de la Surveillance du Territoire (DST) qui relève du Ministère de  l'Intérieur, développe une action de protection du patrimoine industriel,  commercial et scientifique.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Les  enjeux de cette mission sont la compétitivité économique et la préservation de  l'emploi .&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Dans  un contexte de globalisation et de déréglementation, les entreprises françaises  (grands comptes ou PME/PMI) peuvent compter sur la DST pour les aider à faire  face aux attaques&lt;span&gt;  &lt;/span&gt;déloyales de la  concurrence étrangère.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Mais,  dans un monde communiquant où la priorité est donnée à l'information, protéger  ce patrimoine (R&amp;amp;D, savoir-faire, stratégie commerciale, etc.) ce n'est pas  le dissimuler, le confiner, mais bien au contraire le faire fructifier par le  jeu de transactions judicieuses tout en veillant à ne jamais s'en laisser  déposséder.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Les  systèmes destinés à l'échange et au stockage de l'information se trouvent  naturellement au cœur&lt;span&gt;  &lt;/span&gt;de la  problématique et de leur maîtrise dépend étroitement le niveau de sécurité  économique de l'entreprise.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Dans  une telle dynamique où l'ouverture se doit d'être constamment vigilante, il  convient que chaque dépositaire d'une parcelle de ce patrimoine soit sensibilisé  aux risques existants :&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;1.&lt;span&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Actions  d'ingérence économique menées par des services de renseignement étrangers ;  l'espionnage industriel figurant souvent parmi leurs nouvelles missions. Or  actuellement près de 80 % du renseignement est issu de sources dites  « techniques » ou SIGINT (Signal Intelligence) qui peuvent aller  jusqu'à des agressions informatiques ciblées. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;2.&lt;span&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Actions  offensives des officines de renseignement privées dont le nombre croît  régulièrement et qui parfois n'hésitent pas à profiter des faiblesses du système  supportant l'information convoitée ou de l'imprudence du possesseur d'un PC  portable...&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;3.&lt;span&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Actions,  rarement illégales mais souvent dolosives pour qui ne contrôle pas sa  communication, des cellules d'Intelligence Economique et Stratégique qui  utilisent de plus en plus les NTAI (nouvelles technologies d'analyse de  l'information) pour capter les informations à valeur ajoutée que la concurrence  laisse filtrer imprudemment. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;       &lt;p style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;4.&lt;span&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Actions  menées par les acteurs de la « cyberdélinquance », les pirates  informatiques, dont l'essentiel du coût direct ou indirect est supporté par les  entreprises. A noter que certains pirates peu scrupuleux vont jusqu'à louer  ponctuellement leurs services à des officines de renseignement  privées.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;5.&lt;span&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Actions  liées au crime organisé, comme : vol de matériel, contrefaçon, racket,  corruption, blanchiment d'argent, etc.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Une  attention toute particulière sera portée aux secteurs stratégiques dans les  domaines des technologies de souveraineté et au-delà, à tous les secteurs  innovants et/ou particulièrement exposés à la concurrence internationale (cf. &lt;a href="http://www.tc-2010.fr/" target="_blank"&gt;www.tc-2010.fr&lt;/a&gt; ).&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Globalement,  un progrès significatif doit être réalisé en matière de sécurité des systèmes  d'information, les vulnérabilités intrinsèques de ces outils constituant une des  faiblesses majeures de l'entreprise, de plus en plus dépendante à leur  égard.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Ces  vulnérabilités résultent de la combinaison de facteurs humains et de facteurs  techniques.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Les  facteurs humains reposent essentiellement sur le comportement inadapté des  utilisateurs qui fragilisent le système d'information par leur ignorance, leur  inconscience ou leur naïveté : mauvaise gestion et divulgation des mots de  passe, défaut de vigilance vis-à-vis des PC portables, usage inapproprié de la  messagerie pour échanger « en clair » des données sensibles,  etc.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Les  facteurs techniques reposent sur une accumulation de strates fragiles :  systèmes d'exploitation présentant tous de nombreuses failles, idem concernant  les protocoles les plus courants (TCP-IP / IPV4) et les logiciels applicatifs  (bugs…), mauvaise administration des serveurs et pratiques dangereuses des  utilisateurs finaux.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;A  défaut de leur prise en compte, les risques qui pèsent sur les systèmes  d'information de l'entreprise vont atteindre un niveau incompatible avec une  bonne gestion.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Une  attention particulière doit être portée aux points suivants :&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0cm 0cm 0pt 90pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;u&gt;L'intégrité  des données&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;La  perte totale ou partielle de ses informations est une menace qui pèse au  quotidien sur l'entreprise, que cette perte soit d'origine accidentelle ou  criminelle.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Il  convient de mettre en place des procédures de sauvegarde en veillant tout  particulièrement à prendre en compte les données qui se trouvent stockées sur  les disques durs des PC portables et des postes de travail (se sont souvent les  plus pertinentes et elles échappent trop souvent au champ de la sauvegarde  institutionnelle qui ne concerne que les serveurs…).&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Attention  également à ne pas mettre « tous ses œufs dans le même panier »,  c'est-à-dire à ne pas conserver les supports de sauvegarde trop près des  originaux !&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 90pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;u&gt;La  disponibilité&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;La  disponibilité est la capacité à pouvoir accéder aux informations en temps utile.  L'optimisation des TIC pour améliorer la compétitivité de l'entreprise (travail  collaboratif, flux tendus, accélération des échanges, etc.) a considérablement  accru son niveau de dépendance et ses exigences en matière de disponibilité.  Corrélativement, dans le prolongement naturel de la qualité et de la continuité  de service, il convient d'accorder plus d'attention à la sécurité des systèmes  d'information qui concourt naturellement à garantir un haut niveau de  disponibilité.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 90pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;u&gt;L'authentification  ou non répudiation des échanges électroniques&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Les  entreprises utilisent de plus en plus fréquemment les outils de messagerie  électronique pour échanger des documents contractuels et commerciaux qui sont  susceptibles d'engager la responsabilité de l'expéditeur et parfois du  destinataire (réponse à un appel d'offres, bon de commande, bon de livraison,  facture, devis, etc.). En cas de contestation, toujours possible entre tiers  contractants, un document électronique standard n'a strictement aucune valeur  juridique et n'ouvre droit à aucun recours…&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Pour  donner force probante à un document électronique, il convient de le signer  électroniquement avec un certificat de signature électronique conforme à la loi  française qui en régit l'usage (cf. art. 1316-4 du Code  Civil).&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt; &lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 90pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;u&gt;La  confidentialité des données&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Les  données jugées confidentielles, c'est-à-dire celles qui sont de nature à être  convoitées par une tierce partie dans le contexte actuel d'hyperconcurrence,  qu'elles soient de nature scientifique, technique, stratégique, financière ou  commerciale, sont aujourd'hui pratiquement toujours numérisées, stockées sur des  mémoires et échangées en réseau. Si l'on ne renforce pas significativement les  niveaux de sécurité autour de ces données on s'expose à ce qu'elles soient  compromises…&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Il  convient de les protéger en lecture, en copie et en modification.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;La  confidentialité est à prendre en compte vis-à-vis d'une menace externe à  l'entreprise, mais aussi vis-à-vis d'une menace interne. N'oublions pas que 57%  des actes de malveillance informatique sont d'origine interne !&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Il  convient donc de cloisonner l'information et de tenir compte du « besoin  d'en connaître ».&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 90pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;u&gt;La  protection de l'image de l'entreprise&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;L'image  fait aujourd'hui partie des éléments essentiels d'un fonds de commerce et les  technologies de l'information et de la communication sont souvent mises à  contribution pour porter une image positive et moderne : site web, portail,  commerce électronique de type B to B ou B to C, etc.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Si  l'on ne sécurise pas ces outils de communication, on s'expose à des actions qui  peuvent les dégrader (modification de contenu ou blocage de site web,  divulgation de numéros de CB de la clientèle) et venir ternir l'image de leur  exploitant.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 90pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style=";font-family:Symbol;font-size:100%;"  &gt;&lt;span style="font-family:Arial;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;&lt;u&gt;Risques  juridiques&lt;/u&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Citons  pêle-mêle quelques risques de nature juridique :&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 72pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-family:Times New Roman;"&gt;–&lt;span&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Non  respect de la protection des données à caractère personnel&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 72pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-family:Times New Roman;"&gt;–&lt;span&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Utilisation  de logiciels sans licence &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt 72pt; text-indent: -18pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-family:Times New Roman;"&gt;–&lt;span&gt;          &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Diffusion  de fichiers illicites (Warez)&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0cm 0cm 0pt; text-align: center;" align="center"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Le  déficit des sociétés françaises en matière de S.S.I. étant patent et persistant,  malgré des efforts régulièrement consentis, on est en droit de s'interroger sur  le bien-fondé des mesures de sécurité adoptées.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;L'importance  stratégique de la maîtrise de l'information mérite sans doute qu'on lui accorde  plus d'attention, c'est-à-dire davantage de temps et de moyens, mais surtout que  la question soit appréhendée sous un tout autre angle.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;&lt;br /&gt;Une  accumulation d'outils dédiés à la sécurité (logiciels antivirus, pare-feu et  autres proxies), aussi indispensables soient-ils, n'a jamais constitué &lt;i&gt;&lt;u&gt;une&lt;/u&gt;&lt;/i&gt;&lt;u&gt; &lt;i&gt;politique de S.S.I.&lt;/i&gt;&lt;/u&gt;, or c'est bien  de cela qu'il s'agit.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Une  telle démarche, véritable projet transversal d'entreprise, comparable à la  qualité, ne peut trouver son origine et sa légitimité qu'au travers une volonté  bien affirmée et constante dans le temps de la Direction Générale.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Une  bonne politique de S.S.I. sera composée, pour les trois quarts, de mesures  organisationnelles (procédures, règles contractuelles, sensibilisation et  formation des utilisateurs, etc.) et, pour le quart restant, de mesures purement  techniques.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;La  réussite d'un tel projet managé rial, passe par la désignation d'un responsable  de la sécurité des systèmes d'information (R.S.S.I.), directement rattaché à la  Direction Générale et surtout, indépendant du service informatique.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0cm 0cm 0pt; text-indent: 54pt; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Arial;"&gt;Contact  DST en Rhône-Alpes : 04.78.66.67.00&lt;br /&gt;&lt;br /&gt;-----------------------------------------------&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Conférence présentée par:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.rotary-francophone.org/"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px;" src="http://www.rotary-francophone.org/charte/images/logorf.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6654040838114505260-1215229649999255133?l=itauditors.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/1215229649999255133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6654040838114505260&amp;postID=1215229649999255133' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/1215229649999255133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/1215229649999255133'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/2008/01/lintelligence-conomique-moteur-de.html' title='L&apos;intelligence économique, moteur de compétitivité de votre entreprise - Maîtrise et protection de l&apos;information stratégique'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_CQaHL2lZKcU/R6jWzNlUABI/AAAAAAAAB3I/_c59f-bW3cQ/s72-c/Conference_DST.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6654040838114505260.post-2468879632831703313</id><published>2007-11-28T10:25:00.000-05:00</published><updated>2007-11-28T11:04:42.762-05:00</updated><title type='text'>Security policy for the use of handheld devices in corporate environments</title><content type='html'>The purpose of this security policy is to establish an authorized method for using handheld devices in a corporate environment.&lt;br /&gt;&lt;br /&gt;Note that this policy does not target a defined business, and remains very general. Consequently, many points provided depend on the business environment and need to be set up according to a right balance between device and services usability, business needs and security.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;Introduction: Security Challenges &amp;amp; Threats to handheld devices&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Handhelds are subject to the same types of vulnerabilities that affect &lt;a href="http://en.wikipedia.org/wiki/Laptop" target="_blank"&gt; laptops&lt;/a&gt;. Furthermore, as handhelds are smaller and lighter, such devices are more subject to loss and theft, according to various studies from cab companies and airports; those places tend to be the preferred ones for losing devices. Hence, the most predominant weaknesses affecting handheld devices include:&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Loss or theft of the physical device&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Computer_virus" target="_blank"&gt; Viruses&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Trojan_horse_%28computing%29" target="_blank"&gt;Trojans&lt;/a&gt;, and&lt;a href="http://en.wikipedia.org/wiki/Computer_worm" target="_blank"&gt; worms&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Data_theft" target="_blank"&gt; Data theft&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Mobile_code" target="_blank"&gt; Mobile code &lt;/a&gt; exploits&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Authentication#Computer_security" target="_blank"&gt; Authentication&lt;/a&gt; theft&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Wireless_security" target="_blank"&gt; Wireless exploits&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Denial-of-service_attack" target="_blank"&gt; Denial of service attacks&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;All of these &lt;a href="http://en.wikipedia.org/wiki/Vulnerability_%28computing%29" target="_blank"&gt; vulnerability&lt;/a&gt; areas are unique and specific to the type of operating system that runs on a device, as different platforms offer different vulnerabilities that require mitigation by unique and appropriate safeguards.&lt;br /&gt;&lt;br /&gt;While handheld devices are probably more likely to be a carrier of viruses, than the actual target of a directed attack, it is possible through automated port scans for hackers to identify mobile devices that they can attack directly. Though currently the likelihood of a directed attack may not be high, as &lt;a href="http://en.wikipedia.org/wiki/Wi-Fi" target="_blank"&gt; Wi-Fi&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/W-CDMA%20wireless" target="_blank"&gt; CDMA&lt;/a&gt; (cellular) access becomes more available it can be expected that these types of attacks will increase. When used in standalone mode, and not connected to any types of networks, handheld devices have no vulnerability at all to direct attacks.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;1. General part&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;1.1. Statement of purpose&lt;br /&gt;&lt;/li&gt;&lt;li&gt;1.2. Scope&lt;br /&gt;&lt;/li&gt;&lt;li&gt;1.3. Roles &amp;amp; responsibilities&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Should the employees be kept responsible for their handheld?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Should private handheld devices access corporate networks and resources?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Unauthorized actions, such as violating the policies and their consequences.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;1.4. User awareness training&lt;br /&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Employees should sign the security policy.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Employees should get trained in order to properly use both the device and the available services.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;1.5. Policy enforcement&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Live inventory of connected devices.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Monitoring devices configuration and be able to modify it according to policies.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Authorized / Unauthorized services.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Access to corporate resources according to internal data classification.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;2. Physical security&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Ownership information should be provided, if someone tries to return the lost device back.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Procedure in case of lost device.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Call the IT department or helpdesk, possibly to a dedicated number.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Passwords policy.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Device lockout.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;SIM card pin (reduce risk of sim cloning and issues when sim is stolen).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Remote device management capabilities: block and/or wipe data on device.&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;3. Operating System security&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Firmware updating and patching.&lt;/li&gt;&lt;li&gt;Device’s operating system hardening.&lt;/li&gt;&lt;li&gt;Patches &amp;amp; updates.&lt;/li&gt;&lt;li&gt;Removing unneeded services and applications.&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/File_Transfer_Protocol" target="_blank"&gt; FTP&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Internet file-sharing.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Certificates management.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;4. Applications security&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Authorized applications to be installed&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Prohibit installation of unsigned applications.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Possibly allow installation of third-party signed applications.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Allow installation of enterprise / operator signed applications.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Antivirus policy.&lt;/li&gt;&lt;li&gt;Firewall policy.&lt;/li&gt;&lt;li&gt;Email policy&lt;/li&gt;&lt;li&gt;Email signatures.&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Email encryption.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;5. Data security &amp;amp; Access to corporate networks&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Information classification policy and its application to handheld devices&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Define what documents are allowed to be stored on the device&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Data storage&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Enabling / Disabling data encryption on device&lt;/li&gt;&lt;li&gt;Enabling / Disabling data encryption on MMC (MultiMedia Card)&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Data backup&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Backup frequency&lt;/li&gt;&lt;li&gt;Backup according to access method&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Access to corporate networks&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Allow / Refuse access to corporate networks through WLAN&lt;/li&gt;&lt;li&gt;Allow access to corporate networks only using sync software&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;6. Bluetooth security&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Enabling / disabling Bluetooth support&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Enabling / disabling Bluetooth dial-up modem support?&lt;/li&gt;&lt;li&gt;Enabling / disabling Bluetooth beam support&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Bluetooth version control&lt;/li&gt;&lt;li&gt;Enabling / disabling auto-discovery function&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Possibly using a timer?&lt;/li&gt;&lt;li&gt;Possibly using a password?&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Enforcing pairing&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Possibly with strong key / passphrase&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Enabling / Disabling Bluetooth traffic encryption?&lt;/li&gt;&lt;li&gt;Definition of unauthorized use of Bluetooth services&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;7. Over-The-Air provisioning security&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Securing OTA communications&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Push Proxy gateway filtering&lt;/li&gt;&lt;li&gt;Push messages authentication&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Service Indication / Service loading policies&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;8. Synchronization security&lt;ul&gt;&lt;li&gt;Antivirus policy&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Desktop PC antivirus up-to-date (engine and virus definitions)&lt;/li&gt;&lt;li&gt;Handheld antivirus up-to-date (engine and virus definitions)&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Run an antivirus scan before connecting to desktop PC&lt;/li&gt;&lt;li&gt;Disable WLAN support while connected to desktop PC&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;References&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Mobile_device_management" target="_blank"&gt; Mobile Device Management (Wikipedia)&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6654040838114505260-2468879632831703313?l=itauditors.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/2468879632831703313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6654040838114505260&amp;postID=2468879632831703313' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/2468879632831703313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/2468879632831703313'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/2007/11/security-policy-for-use-of-handheld.html' title='Security policy for the use of handheld devices in corporate environments'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6654040838114505260.post-2478947310574929658</id><published>2007-11-28T05:45:00.000-05:00</published><updated>2007-11-28T07:15:14.080-05:00</updated><title type='text'>Cleaning your personal computer</title><content type='html'>Here is a list of applications I use frequently to scan and remove infections:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.hijackthis.de/" target="_blank"&gt;HijackThis&lt;/a&gt;:&lt;br /&gt;This tool scans running processes, registry keys, browser helper objects (BHOs) and other stuff. You can supply your log file to the website where it can be analyzed, providing user ratings on known applications.&lt;br /&gt;&lt;a href="http://www.hijackthis.de/" target="_blank"&gt;http://www.hijackthis.de&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://siri.geekstogo.com/SmitfraudFix.php" target="_blank"&gt;SmitFraudFix:&lt;/a&gt;&lt;br /&gt;This tool removes Desktop Hijack malware.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.safer-networking.org/" target="_blank"&gt;Spybot - Search &amp;amp; Destroy&lt;/a&gt;:&lt;br /&gt;Detects and removes spyware, a kind of threat not yet covered by common anti-virus applications.&lt;br /&gt;&lt;a href="http://www.safer-networking.org/" target="_blank"&gt;http://www.safer-networking.org/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6654040838114505260-2478947310574929658?l=itauditors.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/2478947310574929658/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6654040838114505260&amp;postID=2478947310574929658' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/2478947310574929658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/2478947310574929658'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/2007/11/cleaning-your-personal-computer.html' title='Cleaning your personal computer'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6654040838114505260.post-1371212530625108345</id><published>2007-11-24T12:34:00.000-05:00</published><updated>2007-11-24T12:55:42.571-05:00</updated><title type='text'>Comodo Personal Firewall</title><content type='html'>I was looking for a good firewall for Windows computers, with a granularity up to iptable rules under Linux. I formerly used protect my computers with Sygate personal firewall. But since Sygate has been acquired by Symantec, they do not provide free personal firewall anymore.&lt;br /&gt;The result of the acquisition of Sygate by Symantec is this shitty Norton Internet Security, the most intrusive software I ever used.&lt;br /&gt;&lt;br /&gt;And then, it was there: &lt;a href="http://www.personalfirewall.comodo.com/" target="_blank"&gt;Comodo Personal Firewall&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This tool is FREE, and is far more powerful than Sygate used to.&lt;br /&gt;&lt;br /&gt;Main features (from the Web site and modified):&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Constantly monitors and defends PCs from internet attacks&lt;/li&gt;&lt;li&gt;Gain complete control over which programs are allowed internet access&lt;/li&gt;&lt;li&gt;Applications monitoring: exe, libraries, dependencies&lt;/li&gt;&lt;li&gt;Easy port mapping&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Host Intrusion Prevention System can stop malware ever being installed&lt;/li&gt;&lt;li&gt;Automatic online updates Service&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Real time traffic monitoring enables to react instantly to threats and identify bandwidth bottlenecks.&lt;/li&gt;&lt;li&gt;Easy to use interface and quick setup&lt;/li&gt;&lt;li&gt;No license fee - complete protection at no cost for networks and home users&lt;/li&gt;&lt;/ul&gt;However, default options make it intrusive: unknown or suspicious files are automatically submitted to Comodo servers for analysis. The way Comodo's engine defines suspect files is still unclear to me yet.&lt;br /&gt;&lt;br /&gt;My advice:&lt;br /&gt;- Install it if you are an experimented user&lt;br /&gt;- Take time to setup options&lt;br /&gt;- Disable unneeded services: Submitting suspicious to Comodo servers (privacy purposes!)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6654040838114505260-1371212530625108345?l=itauditors.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itauditors.blogspot.com/feeds/1371212530625108345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6654040838114505260&amp;postID=1371212530625108345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/1371212530625108345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6654040838114505260/posts/default/1371212530625108345'/><link rel='alternate' type='text/html' href='http://itauditors.blogspot.com/2007/11/comodo-personal-firewall.html' title='Comodo Personal Firewall'/><author><name>Nykoleptic</name><uri>http://www.blogger.com/profile/02422189054159320402</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
