IT security best practices

 Cybersecurity : IT security best practices




Safeguards are needed to prevent cyberattacks and prepare to respond to them. Among the many measures that can be implemented, some are common to all individuals and organizations.


  Examples of essential measures for individuals  



    1- Use strong passwords:

For access to a phone or computer by choosing long and complex passwords (at least 12 characters), while avoiding dictionary words, dates of birth, and other easy-to-guess information.


Whenever possible, use a trusted password manager and as soon as possible implement additional security to access the accounts (emails, social networks) such as "two-factor authentication" (involving two consecutive verifications before allowing access to a service), in order to prevent an unauthorized person from accessing it.



     2- Use only official and up-to-date software:

(e.g. from official mobile application libraries) and update this software (computer operating system, office software, mobile applications), in order to prevent vulnerabilities in obsolete software from being used to carry out an attack and penetrate an information system.

 



3- Make regular backups:

systems and data, if possible on other devices (e.g. a hard drive, a server) disconnected, in order to be able to recover them, in the event that they are destroyed or made inaccessible, 

in the event of a ransomware attack, for example.

 

4- Use secure networks: 

especially Wi-Fi, avoiding passwordless networks and secure the wifi access of a home or a business.

 




5- Being as careful with a smartphone and tablet as with a computer is fine. separate personal and professional uses.

 




6- Take care of your personal and professional information, your digital identity:

In particular, think about encrypting data – most computers allow you to encrypt the hard drive – i.e. making it unreadable to people who would have access to it but could not "decrypt" it.

 

  Resources  

For individuals, see the recommended:

CISA(Cybersecurity and Infrastructure Security Agency)

FBI (Federal Bureau of Investigation)

NSA (National Security Agency)

 

For small and medium-sized enterprises (VSEs/SMEs) see the IT best practices guide: 

NIST Quick Start Guides

CIS Controls

ISO/IEC 27001


For more information, see The Computer Hygiene Guide

Digital Guardian Cyber HygieneOverview





 

 

 

 











Next Post Previous Post
No Comment
Add Comment
comment url