Cyber security tips for NGO's
It's not really surprising that many nonprofit organizations aren't doing everything they should to keep their computer systems secure. Technology can be quite complicated and intimidating, and even in a strong economy many nonprofit organizations can't afford the expense.
What is surprising is that the same problems exist in the business world. According to a recent survey of corporate computer security experts at more than 225 companies around the world, nearly one-third of the businesses don't have adequate plans for dealing with a cyber-terrorist attack. Although the questions weren't exactly the same, NetAction's earlier survey of computer security in nonprofit organizations found that one-third of the respondents felt their organization's security practices needed improvement.
It may be tempting to take comfort in the fact that security vulnerabilities are not unique to nonprofit organizations, but it would be a mistake. For as we noted in NetAction's survey report computers are increasingly important to the mission of many nonprofit organizations, and non-profits are much less likely to have the financial resources to recover from a cyber attack.
So to help nonprofits assess their cyber security practices, NetAction prepared the following checklist:
1) Do your work habits promote security?
Always log off when you aren't using your computer. The most basic and low-tech security practice is to lock or shut down a computer when it's not in use. If you don't do this, there's no point in password-protecting your hard drive. When users are logged off, passwords and user names are your first line of defense. Use passwords that are difficult to guess, and change them frequently. If you're worried that you'll forget your password, write it down and file it in a safe place.
2) Can your data be restored if your computer crashes?
Regular backups are a crucial component of computer security. Documents and oth
er data should be backed up daily. Backed up data can be stored on removable media (such as CDs), on a tape drive, or on a secure web site. Redundancy is the best strategy; create several backup sets so at least one is stored off site. It's also a good idea to periodically make a full backup of your hard drive so that if your hard drive crashes you won't have to reinstall each software program individually.
Many new computers include CD drives that make data backups easy and affordable. External hard drives that can be disconnected and stored off site are an affordable option for backing up a complete hard drive.
3) Is your computer safe from viruses and worms?
New computer viruses and worms are discovered all the time. Installing and regularly updating your anti-virus software is essential to maintaining the security of your computer files.
4) Is your computer safe from malicious hackers?
Every computer connected to the Internet without a fire wall is vulnerable, but the risk is greater if you are using DSL or cable broadband, or are connected to an office network. Because these types of connections are typically always on, malicious hackers can get into your computer and steal confidential information, deface your organization's web site, or use your computer as part of a distributed denial of service (DDoS) attack directed at another server. Fire wall software that can be installed on individual computers is available from many of the same developers who produce anti-virus software, such as Symantec and McAffee. In offices with networked computers, there may be a separate hard drive that serves as a fire wall for the entire network. While that may be sufficient to prevent break ins from outside the network, it's still a good idea to install software fire walls on individual computers to prevent unauthorized access from users within the network.
5) Are your mailing lists safe from spammers?
Email lists are frequent targets of spam, so mailing list security should be a high priority if you operate any mailing lists. If you are running commercial list software, such as majordomo, configure your email lists so only the list owner has access to subscribers' addresses. If you are using your email client software, such as Eudora or Outlook, avoid disclosing subscribers' addresses by putting all of your recipients' addresses in the "Bcc" field. If you are using an application service provider, such as Topica or Yahoo Groups, make sure the lists are configured to prevent the disclosure of addresses. Also, backup your subscriber list regularly. Those addresses are one of your organization's most important assets!
6) Are your confidential files safe from snoopers?
Nearly everyone stores some data on their computer that is sensitive or confidential. Use passwords and encryption to protect private data. Disable operating system features that allow files to be shared unless it's absolutely necessary, and when you do allow sharing use passwords to ensure that only authorized users have access. If you send or receive confidential data, encrypt your email messages.
7) Are you prepared for the worst?
Hard drives crash; accidents happen, natural disasters occur without warning. If you depend on computers, disaster planning is a necessity. Start by keeping an up-to-date backup of your hard drive off site, but don't stop there. Inventory your hardware, software and service providers. Ask yourself what it would take to get back online if your office was destroyed in an earthquake or fire. Write it all down and keep a copy with your off site backup. Periodically review your plan to make sure it's up-to-date.
8) Do you check "under the hood" periodically?
Although not strictly a security issue, good disk maintenance is also important,. Several software vendors sell utility tools (such as Norton System Works) that can alert you to and fix minor problems, and sometimes even retrieve lost data. Specific maintenance requirements vary, so review the User Guide that comes with the software and check your disk periodically to ensure optimal performance.
This Cyber Security Checklist is one of several checklists included in NetAction's Virtual Activist Reader. Download the complete Reader here.
-----------------------------
NetAction Notes is a free electronic newsletter, published by NetAction. NetAction is a national, nonprofit organization dedicated to promoting use of the Internet for grassroots citizen action, and
to educating the public and policy makers about technology policy issues.
To subscribe to NetAction Notes, send a message to: NetAction Notes The body of the message should state:
For more information about contributing to NetAction, contact Audrie Krause - audrie AT netaction DOT org or by phone at (415) 775-8674, or visit the NetAction Web site, or write to:
NetAction
601 Van Ness Ave.
No. 631
San Francisco, CA 94102
USA