SMEs Fall Down on IT Acceptable Use Policies

Small- and medium-sized enterprises (SMEs) are leaving themselves vulnerable to security and compliance risks by not having Internet Acceptable Use Policies (AUPs) that address the latest and most dangerous Internet-based threats, according to St. Bernard Software.

In a survey of IT administrators at 500 companies, four key IT threat areas were found to be missing in written AUPs: (1) spyware, (2) inappropriate surfing, (3) instant messaging and (4) P2P use. In addition, it was found that the majority of these organizations had no perimeter security solution to defend against these threats or manage and enforce policies. Every day, these Internet-based threats try to exploit networks and expose SMEs to the risks of security breaches, legal liability, lost productivity and the erosion of network resources.

Details of the survey data are:

• Spyware: 70 percent of organizations have not addressed this in their AUP; 68 percent have no perimeter solution.

• Inappropriate surfing: 64 percent have not addressed this in their AUP; 80 percent have no perimeter solution.

• Instant messaging: 72 percent have not addressed this in their AUP; 79 percent have no perimeter solution.

• P2P: 72 percent have not addressed this in their AUP; 78 percent have no perimeter solution.

“This survey reveals a high percentage of SMEs are leaving themselves open to abuse of corporate AUPs, either because they are ambiguous or incomplete, or that there are no IT solutions in place to make sure employees abide by policies and company rules,” said John Jones, CEO of St. Bernard Software. “By understanding what’s at risk, SMEs are better equipped to meet threats head-on. The first step should be to develop a Security Policy and an Acceptable Use Policy that support their business goals, and are detailed enough to include all the issues they might encounter.”

EVault Announces ‘Data Turkey’ Awards

EVault, Inc. are searching for candidates for the first annual Data Turkey Awards to honor business professionals who have lived through a data loss or whose actions and quick thinking have helped to avert a data disaster. The winners of these two categories, Most Spectacular Data Recovery and Most Disastrous Data Loss, will each receive a $500 American Express gift check and a free one-year subscription to EVault’s Protect online data protection solution for up to 10GB of data. EVault will also make a $500 contribution on behalf of each winner to honor a local charity of their choice.

Any small business owner, IT or business professional is eligible for the award. Applicants must go to www.evault.com/turkey to enter to win. Deadline for submissions is Dec. 2, 2005 at midnight. Winners will be notified on or around Dec. 5, 2005. Official “Data Turkey Awards” Rules can be found at www.evault.com/turkey. All submissions become the sole property of EVault and will not be publicized unless agreed upon by all parties involved. Applicants must share scenario specifics — lowlights and highlights — regarding their data recovery and data loss situation.

A Fully-Integrated E-Signature Solution

Interlink Electronics (www.interlinkelectronics.com) is introducing the ePad XL interactive signature terminal. Created to capture, bind and verify signatures, ATM card data and interactive customer information, the ePad XL terminal is designed for deployment in banks, hotels, car rental counters, cellular service offices and other customer-facing applications. In addition to capturing and encrypting personal signatures, ePad XL’s LCD touch screen displays text and graphic content for customer review and interaction.

ePad XL has a 5.7” LCD touch screen with a resolution of 320x240 dots per inch (dpi) that is pressure sensitive: Capturing signatures with a resolution of 903x1238 points per inch (ppi) and a data rate of 200 reports per second. ePad XL employs the industry’s leading secure terminal technology including secure key injection, tamper response, dedicated security processor, firmware authentication, file authentication, PIN encryption, master/session key, DUKPT, single and triple DES 64 and 128 bit keys. Signature data encryption is an option to the standard model.

The ePad VL’s card reader is a bidirectional, 3-track magnetic stripe reader that delivers a high read rate and ease-of-use. Along with secure key injection and tamper response, the card reader is equipped with a Visa PED approved dedicated security processor.

Iridian Measures to Detect Contact Lenses

Iridian Technologies has developed two new countermeasures designed to detect contact lenses imprinted with iris patterns. Iridian has experienced accelerating adoption of its technology over the past two years with installations in the Canadian CANPASS program, the US/Canada NEXUS Air program, the United Arab Emirates and other Middle Eastern countries and immigration programs in the Netherlands, the UK, Germany, Australia and Japan.

“As the breadth and depth of our deployments are increasing, the need to offer enhanced countermeasures increases,” said Frank Fitzsimmons, president and CEO of Iridian Technologies. “We designed these countermeasures specifically to address the growing number of watch list deployments.”

Iridian has implemented two approaches for printed contact lens countermeasures. The first recognizes commercially available printed contact lenses. The second is a countermeasure that evaluates the iris image and detects the presence of any generic printed contact lens based on its features. The introduction of the new printed contact lens countermeasures significantly reduces the ability of bad actors to avoid being detected if they are enrolled in the database.

Iridian countermeasures are characterized by their penetration rate and false alarm rate. The penetration rate is the rate at which a threat goes undetected by a countermeasure. The false alarm rate is the rate at which a countermeasure falsely detects a threat when none is present.

“Our countermeasures are designed to optimize the penetration rate and false alarm rate,” said Ulf Cahn von Seelen VP of Algorithms and Research. “The goal is to create a countermeasure which further enhances security while maintaining the extraordinary convenience of iris recognition.”