To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here

Small Business Computing
Home News & Trends Business Software Hardware & Equipment Online Marketing Web Management
Product Watch Buyer's Guide Small Business Essentials Online Forums Glossary Events

Go Back   Small Business Computing & E-commerce Forums > Small Business > Small Business Computing

Small Business Computing From security concerns to software selection, this is the place to ask your fellow small-business owners how to approach and improve your small-business computing.

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
  #1  
Old 07-18-2003, 11:46 AM
matthew purser matthew purser is offline
Member
 
Join Date: Jul 2003
Posts: 1
Security Procedures - Passwords etc

Currently running a small website which provides downloads of stationery, news info etc to our customers.

They currently can apply online for a password, and if they know their id number (4 digit number so none too hard to work out) we give them a password, which is all done automatically.

We don't do any checks really.

Now we're starting to think about putting specific content out there, management reporting, quote engines etc.

However we've run into the dilemma of how we're going to adminstrate this, our existing process has tons of holes in it. Similarly we can't 100% confirm that the existing users are who they say they are so we're going through a fairly manual process of getting them to re-apply and sign in blood so we know who they are and we give 'superuser' access to the owners of the business only.

So my question is, are there any standard security procedures one should work too. I.e is there a documented standard procedure for the provision of passwords, access rights etc anywhere?

The site will eventually become more of an extranet when it begins to interact with our backoffice systems but we need to get some more stringent policies in place first.

Fire away with questions and answers if possible!

Thanks in advance.

Matthew Purser
Reply With Quote
  #2  
Old 02-23-2004, 09:01 PM
rkissel rkissel is offline
Member
 
Join Date: Feb 2004
Location: Central Maryland
Posts: 1
Hi Matthew,
There is a considerable amount of guidance/best practices on passwords, etc on http://csrc.nist.gov/publications/
Questions? Email me.
Rich
__________________
Richard Kissel, CISSP, CISM
Information Security Analyst
Reply With Quote
  #3  
Old 03-17-2004, 11:02 PM
leeman leeman is offline
Member
 
Join Date: Mar 2004
Posts: 1
This is not so much an answer to your issue, but rather a similar question. I am having difficulty accessing the internet with my NIS enabled. I can surf freely with it disabled. I cannot seem to adjust the sensitivity of the security/privacy settings to resolve this matter. Any thoughts?
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:16 PM.







Acceptable Use Policy

internet.comMediabistrojusttechjobs.comGraphics.com

WebMediaBrands Corporate Info


Advertise | Newsletters | Feedback | Submit News

Legal Notices | Licensing | Permissions | Privacy Policy

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.