{"id":99,"date":"2012-01-18T22:53:12","date_gmt":"2012-01-19T04:53:12","guid":{"rendered":"http:\/\/cybersecurity.bellevue.edu\/?p=99"},"modified":"2021-08-30T13:11:33","modified_gmt":"2021-08-30T19:11:33","slug":"staying-off-of-the-suspect-list","status":"publish","type":"post","link":"https:\/\/cybersecurity.bellevue.edu\/index.php\/2012\/01\/18\/staying-off-of-the-suspect-list\/","title":{"rendered":"Staying off of the suspect list"},"content":{"rendered":"<p>Often, we\u2019re our own worst enemy.\u00a0 We do things that make us a likely target for blame.\u00a0 In other words, we\u2019re on the suspect list.\u00a0 We receive the blame when something goes wrong because of our actions or the access we maintain.<\/p>\n<p>The idea is to keep yourself and other off of that list.\u00a0 First of all, it disrupts the investigation in finding the true source of the problem.\u00a0 Second, it causes others to distrust those on the suspect list, even if their innocent.\u00a0 The best way to prove innocence is to have a clear name from the onset.<\/p>\n<p>Often security professionals and IT managers have access to many systems, applications, or facilities. They believe it\u2019s required because of their position or responsibility.\u00a0 The problem is that having access puts them on the suspect list.\u00a0 Many times I\u2019ve been accused when there were network issues.\u00a0 \u201cWere you running one of your security scans again?\u201d was a common statement aimed at me just because I had the ability to run scans, not that I did.<\/p>\n<p>Often other activities may add us to the \u201csuspect list\u201d, such as browsing the Internet, transferring documents from home to work and vice versa, clicking on links in email, or installing freeware or shareware applications on a work computer. While they\u2019re not bad in and of themselves, these actions do have potentially dangerous consequences.<\/p>\n<p>Here are five things you need to do to keep yourself off of the suspect list:<\/p>\n<ul>\n<li>Limit your access.\u00a0 This is the concept of least privilege.\u00a0 If you don\u2019t need it or don\u2019t use it every day, disable or delete your access to it.<\/li>\n<li>Only use administrator privileges when you administer the system.\u00a0 If you\u2019re always logged as an admin, then you\u2019re just asking for trouble.<\/li>\n<li>Freeware isn\u2019t always free and shareware may mean your sharing more than the program.\u00a0 Finding programs on the Internet may save money in the short run, but they occasionally contain hidden malware than can take down your system.<\/li>\n<li>Think before you click.\u00a0 Be aware of where you go on the Internet.<\/li>\n<li>Keep your secrets secret.\u00a0 If you allow others to use your login id or badge, then that person is you and you\u2019ll be on the suspect list if something goes wrong. Badges and passwords are like gum, it\u2019s not cool to share once used.\u00a0<\/li>\n<\/ul>\n<p>Security\u2019s objective is to keep people off of the suspect list.\u00a0 We know that the great majority of our work force wants to do what\u2019s right.\u00a0 We want to help you.\u00a0 Like the police, our objective isn\u2019t to get you into trouble, but to keep you out of trouble.\u00a0 Consider what you should do to keep yourself and others off the suspect list.\u00a0 It will make your life much easier.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Often, we\u2019re our own worst enemy.\u00a0 We do things that make us a likely target for blame.\u00a0 In other words, we\u2019re on the suspect list.\u00a0 We receive the blame when something goes wrong because of our actions or the access we maintain. The idea is to keep yourself and other off of that list.\u00a0 First [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[18,8],"tags":[],"class_list":["post-99","post","type-post","status-publish","format-standard","hentry","category-online-safety-tips","category-security-education"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/99","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/comments?post=99"}],"version-history":[{"count":3,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/99\/revisions"}],"predecessor-version":[{"id":994,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/99\/revisions\/994"}],"wp:attachment":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/media?parent=99"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/categories?post=99"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/tags?post=99"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}