IT Security Hygiene is your one stop shop to make sure you are using the best IT Security practices.
Deficient or non-existent access control to systems can lead to unauthorized access to data and information or unauthorized use of systems.
Data and information breach may result in the unauthorized disclosure of personally identifiable information, leaving the organization exposed to risks related to violations of FIPPA, PHIPA or PCI.
Access control should make use of authentication to systems that use one or more factors such as a combination of username and password to grant access to resources. Where appropriate, access to systems should require at least two-factor authentication. Two-factor authentication requires users to provide their username and password as well as one additional piece of information when authenticating to a system. The secondary piece of information may be a challenge-response to a previously configured personal question or a code from a key-fob or electronic one-time pad.
Authorization to perform actions on systems, data or information should always be granted using the principle of least privilege. The principle of least privilege ensures that users have access to the services and information that they require to do their job, and nothing more. Systems Activity Accounting is a valuable tool for monitoring access to resources. Logging successful and unsuccessful access attempts will help an administrator identify when unauthorized or inappropriate access has occurred.
Establish Control of Physical Access Where Applicable
Enable Access Control Of Local Electronic Resources (Direct)
*NOTE: Local user access attempts, successful or failed, should be logged
Enable Control Via Remote Modes (i.e. Port Access)
*Note: Remote user access attempts, successful or failed, should be logged
Enable Control Via Network Access
*Note: Network access attempts, successful or failed, should be logged
A common means of authenticating the identity of a user before authorizing access to a resource or service, passwords provide an essential layer of defense in securing McMaster University assets from unauthorized use or access. It’s the responsibility of the password creator to ensure its strength through adequate length and complexity.
Users must create and protect their passwords to prevent data breaches and losses. The following MacID password creation requirements and information will help maximize the security of your password and assets.
Passwords must include character(s) from at least three of these four-character sets:
A strong password should exclude your name or any part of it, be distinctive and memorable for you, yet challenging for others to guess. Avoid dictionary words; opt for something personally significant and unique.
Finally, passwords should never be written down or stored in a format that is human-readable. If possible, credential owners must encrypt passwords if they need to store the information, and this should only be done for backup, disaster recovery, and business continuity purposes.
Multi-Factor Authentication (MFA), also known as two-factor authentication (2FA) or two-step verification, is a way of adding an extra layer of protection to help prevent hackers from accessing your account in case it has become compromised (leaked, stolen, hacked into).
Once activated, MFA requires that users demonstrate at least two of the following in order to log in to online resources (does not apply to campus-hosted websites):
McMaster University provides the ability to enable MFA for MacID users. Click here for more information
Keep in mind that opting-in for MFA still requires users to maintain and protect their MacID password, as this will become one of the required factors in the MFA option.
Phishing is a type of online attack in which an attacker — using both technological and psychological tactics — sends one or more individuals an unsolicited email, social media post, or instant message designed to trick the recipient into revealing sensitive information or downloading malware.
Phishing attacks can be generic or customized, and can target both individuals and entire organizations. Attacks that target a specific individual or organization are commonly referred to as spear phishing attacks.
The main goal of a phishing attack is to get the individual to do something that compromises the security of their system and/or potentially their organization. To stop attackers achieving this, when you receive a suspicious email:
If you do fall victim to a phishing scam, do not be embarrassed. Report any and all suspicious email messages to is-spam@mcmaster.ca.
If you have opened any suspicious emails, links or attachments please report it to the UTS Service Desk.
Complete the McMaster UTS Phishing Course on Avenue to Learn:
Phishing messages can range from very basic to highly sophisticated. Common “red flags” or indicators include:
Adopting the following best practices can minimize the chances of falling for a phishing attack:
Software is imperfect; very often, operating systems and other applications are released for use with flaws. These flaws are known as Common Vulnerabilities and Exposures, or CVE for short. CVE can affect the can be exploited, putting the confidentiality, integrity and/or availability of a system at risk.
Every system and all software are at some time susceptible to exploitation due to the vulnerabilities and exposures in the code.
The Mitre Corporation maintains a database of common vulnerabilities and exposures (CVE). This database is updated as new vulnerabilities and exposures are discovered in existing software. In response, software manufacturers often release “patches” to repair their software. Systems without the patches installed are vulnerable to the threat defined within the CVE document.
In the past, maintaining currency of software on servers and systems was a cumbersome task. Updates and patches had to be tested extensively to ensure that they would not negatively affect another part of the system or application, as was often the case. Today, the architecture of modern operating systems and the rigour applied to testing patches before they are released have all but eliminated the risk of interference when an update is installed. There are still occasions that a patch may interfere with other applications, although these are rare.
Microsoft Windows: http://windows.microsoft.com/en-US/windows/help/windows-update
Red Hat Linux: https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Security_Guide/sect-Security_Guide-Software_Maintenance-Plan_and_Configure_Security_Updates-Adjusting_Automatic_Updates.html
Apple: http://support.apple.com/kb/HT1338
Before you embark on your international journey, ensure your digital security is top-notch. The Information Security Services team is here to help.
To report an information security incident, please visit: https://informationsecurity.mcmaster.ca/information-security-incidents/.
McMaster’s Information Security Services team can meet with you to review IT security guidance while travelling.
Travel resources and guidance for the whole community.
WEBSITE