<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Practical Issues in InfoSec &#187; Physical Security</title>
	<atom:link href="http://www.dlstrom.com/category/physical-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dlstrom.com</link>
	<description>... putting information security within reach of everyone!</description>
	<lastBuildDate>Tue, 20 Dec 2011 17:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Don&#8217;t Do This!</title>
		<link>http://www.dlstrom.com/2011/03/02/dont-do-this/</link>
		<comments>http://www.dlstrom.com/2011/03/02/dont-do-this/#comments</comments>
		<pubDate>Wed, 02 Mar 2011 17:15:50 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=366</guid>
		<description><![CDATA[As always, we can learn from example . . . A little over a month ago I used my 4GB USB flash drive to move a small executable file from one computer to another. After using it I dropped it back into my computer bag like I always do&#8230;. Or, so I thought. &#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230; Life [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2011/03/02/dont-do-this/" data-text="Don&#8217;t Do This!" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2011/03/02/dont-do-this/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>As always, we can learn from example . . .</p>
<p>A little over a month ago I used my 4GB USB flash drive to move a small executable file from one computer to another. After using it I dropped it back into my computer bag like I always do&#8230;.</p>
<p>Or, so I thought.</p>
<p>&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;</p>
<p>Life was good and I had no need for the USB drive. But then I really needed it for moving another file between computers that were not networked.</p>
<p>I rummaged through my computer bag. No luck.</p>
<p>I cleaned the extraneous stuff off my desk. Still could not find the drive.</p>
<p>I even removed all the change in the cup holders in my pickup. No joy.</p>
<p>Finally, it was found deep in the bottom of my computer bag, where it was supposed to be.</p>
<p>&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.</p>
<p>As The Professor used to say in college, &#8220;It&#8217;s intuitively obvious&#8221; that USB drives can be easily lost.</p>
<p>What should we do? Here a couple of ideas&#8230;</p>
<ul>
<li>Never store confidential information on a USB drive.</li>
<li>If you must put confidential information on a USB drive, then encrypt the USB drive, or the files on the USB drive. This is pretty easy. You can use a drive from <a href="https://www.ironkey.com/">IronKey</a>, or you can use a generic drive with <a href="http://www.truecrypt.org/">TrueCrypt</a>.</li>
</ul>
<p>So, be careful out there. Don&#8217;t lose your personal information by putting it on an unencrypted USB drive.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2011/03/02/dont-do-this/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Common Sense and Physical Security</title>
		<link>http://www.dlstrom.com/2010/01/08/common-sense-and-physical-security/</link>
		<comments>http://www.dlstrom.com/2010/01/08/common-sense-and-physical-security/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 23:00:00 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[People]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=292</guid>
		<description><![CDATA[I received a call this week from a friend who works in a small office. She had been out for a few days, and when she returned it became obvious that someone had been rummaging through the stuff on her desk. Then, she started telling me that when she turned her computer on there was [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2010/01/08/common-sense-and-physical-security/" data-text="Common Sense and Physical Security" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2010/01/08/common-sense-and-physical-security/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>I received a call this week from a friend who works in a small office. She had been out for a few days, and when she returned it became obvious that someone had been rummaging through the stuff on her desk.</p>
<p>Then, she started telling me that when she turned her computer on there was evidence that someone had been using her computer, as well.</p>
<p>Needless to say, she was pretty upset and wanted to know how she could tell who the offender was. She was hoping that there were some &#8220;tracks&#8221; somewhere that would tell here everything about who had been using her computer.</p>
<p>She wanted to confront the others in the office about accessing her computer and desk items while she was out.</p>
<p>Now, let&#8217;s look at some details from a common-sense perspective&#8230;</p>
<ul>
<li>The computer was configured so that it didn&#8217;t require a password to get into Windows. My recommendation was that she make the computer require a password to enter Windows. I suggested to her that the added security far outweighed any perceived inconvenience here.
</li>
<li>It also turns out that the computer in question is a notebook. She had just been turning the computer off at night and leaving it on her desk. Further inquiry led to the discovery that she had a locked file cabinet where she kept the important company information. My recommendation was to make it so the computer could not be accessed while she was not there. I suggested that she lock the notebook computer in the cabinet when she left the office for the day.
</li>
<li>Further questioning helped me to realize that the business has purchased this notebook computer a year ago, but there was no need for portability. So, why did they purchase a notebook? I couldn&#8217;t get a firm answer. My recommendation is that a notebook only be purchased if there is a need for portability, as portability makes theft of the computer easier.
</li>
<li>Regarding who and why someone accessed the computer without permission, there could be a variety of reasons. I suggested to her that she calmly discuss with her office-mates that it appeared someone had been looking for something while she was out. I also suggested that it is important she do this professionally, and to encourage them to call her is something is needed while she is out. These are people that she has to work with, and it is important that relationships not be antagonistic.
</li>
</ul>
<p>The conclusion is that this situation could have been averted with just a few simple actions.</p>
<p>Let&#8217;s all use common sense when approaching physical security.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/01/08/common-sense-and-physical-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec Tip: Shred Confidential Documents</title>
		<link>http://www.dlstrom.com/2009/07/03/infosec-tip-shred-confidential-documents/</link>
		<comments>http://www.dlstrom.com/2009/07/03/infosec-tip-shred-confidential-documents/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 12:00:00 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=255</guid>
		<description><![CDATA[I can remember many, many years ago when my Dad disposed of old tax documents. He just threw them in the trash. The only redeeming factor was that we lived in the country and burned all of our paper trash. But, have you ever known anyone to just toss a confidential document in the trash? [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/07/03/infosec-tip-shred-confidential-documents/" data-text="InfoSec Tip: Shred Confidential Documents" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/07/03/infosec-tip-shred-confidential-documents/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>I can remember many, many years ago when my Dad disposed of old tax documents. He just threw them in the trash.</p>
<p>The only redeeming factor was that we lived in the country and burned all of our paper trash.</p>
<p>But, have you ever known anyone to just toss a confidential document in the trash? What is considered &#8220;<strong>confidential</strong>&#8220;?</p>
<p>Here are some examples of what you should consider <strong>confidential</strong>&#8230;</p>
<ul>
<li>
Anything with your Social Security number on it</li>
<li>
Anything with a credit card number on it</li>
<li>
Anything that is a credit application</li>
<li>
Anything with user accounts and passwords</li>
<li>
Anything with bank account numbers</li>
</ul>
<p><strong>Tip: Purchase a cross-cut shredder and shred confidential documents.<br />
</strong></p>
<p>This will help to protect you from identity theft, or someone using your credit to make purchases.</p>
<p>Make you life easier. Shred those documents!</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/07/03/infosec-tip-shred-confidential-documents/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

