IT security best practices
Cybersecurity : IT security best practices
Safeguards
are needed to prevent cyberattacks and prepare to respond to them. Among the
many measures that can be implemented, some are common to all individuals and
organizations.
Examples of essential measures for individuals
1- Use strong passwords:
For access to a phone or
computer by choosing long and complex passwords (at least 12 characters), while
avoiding dictionary words, dates of birth, and other easy-to-guess information.
Whenever possible, use a
trusted password manager and as soon as possible implement additional security
to access the accounts (emails, social networks) such as "two-factor
authentication" (involving two consecutive verifications before allowing
access to a service), in order to prevent an unauthorized person from accessing
it.
2- Use only official and up-to-date software:
(e.g. from official
mobile application libraries) and update this software (computer operating
system, office software, mobile applications), in order to prevent
vulnerabilities in obsolete software from being used to carry out an attack and
penetrate an information system.
3- Make regular backups:
systems and data, if possible on other devices (e.g. a hard drive, a server) disconnected, in order to be able to recover them, in the event that they are destroyed or made inaccessible,
in the event of a ransomware attack, for example.
4- Use secure networks:
especially Wi-Fi,
avoiding passwordless networks and secure the wifi access of a home or a
business.
5- Being as
careful with a smartphone and tablet as with a computer is fine. separate
personal and professional uses.
6- Take care of your
personal and professional information, your digital identity:
In particular, think
about encrypting data – most computers allow you to encrypt the hard drive –
i.e. making it unreadable to people who would have access to it but could not
"decrypt" it.
Resources
For individuals, see the recommended:
CISA(Cybersecurity and Infrastructure Security Agency)
FBI (Federal Bureau of Investigation)
NSA (National Security Agency)
For small and medium-sized enterprises (VSEs/SMEs) see the IT best practices guide:
For more information, see The Computer Hygiene Guide
Digital Guardian Cyber HygieneOverview