So far, so good - the interesting thing, however, is how some of the simplest advice is the most effective. For example, keeping your regular users from having administrative privs is rated as an "excellent" defence - and these days, is relatively easily done, as most software is well behaved with regard to needing to run as admin. Where desktop software vendors could make our lives easier though is keeping up-to-date on things like Java, Acrobat, Flash and company - Microsoft Update does a decent job... but something integrated and simple for other software might help use institute another "excellent" defence more easily.
I would imagine that this advice applies as well to other kinds of attack - this document being fairly specific to targetted phisning attacks - as they use similar vectors. Probably having up-to-date antivirus would make up a couple of notches and email whitelisting might not get an "excellent" if we were looking at a more general case. Still, it's worth a read, just to get the little grey cells working in a security type way for a few moments!
No comments:
Post a Comment