Presentation is loading. Please wait.

Presentation is loading. Please wait.

Technical Study Group April 2011. Agenda  Risks to websites and PC files  Components of password management policy  Password management systems  Password.

Similar presentations


Presentation on theme: "Technical Study Group April 2011. Agenda  Risks to websites and PC files  Components of password management policy  Password management systems  Password."— Presentation transcript:

1 Technical Study Group April 2011

2 Agenda  Risks to websites and PC files  Components of password management policy  Password management systems  Password management software - criteria  Determinants of password management policy  Assessing exposure levels  Proposed password management policies  Password management software - examples Steve Pearce - Betaplus Club April 2011

3 Risks to Websites & PC files  PC file not password protected or encrypted  PC file or Website password forgotten  PC or Web password found/broken by hacker From home PC if stolen From laptop if lost or stolen From mobile device if lost or stolen From infected public computer From website of service provider (bank, retailer etc) Steve Pearce - Betaplus Club April 2011

4 Steve Pearce - Betaplus Club October 2010 Screen clipping taken: 06/04/2011 03:31

5 Components of Password Mgt Policy  Choice of passwords Strong, memorable, duplicated, when changed?  Choice of password management system  Choice of access points for critical websites Home PC, laptop, mobile, public PC?  Choice of location for critical PC files  Credit/Debit Card policy Steve Pearce - Betaplus Club April 2011

6 Password Management Systems  Hard copy – notebook, Post-It notes etc  Internet browser password memorisation  Protected data file on PC or Cloud  Personal code for password generation  Password management software PC based Cloud based Mobile device based Steve Pearce - Betaplus Club April 2011

7 Password Mgt Software - Criteria  Feature set Password generation Automatic password entry Portability (laptop, mobile device, web access)  Ease of use / Help and support  Security Unbreakable master login Encryption Backup capability  Integrity of Supplier Steve Pearce - Betaplus Club April 2011

8 Steve Pearce - Betaplus Club October 2010

9 Establishing Password Mgt Policy Depends on combination of:  Exposure level of file or website  Required locations for PC files Home PC, laptop, mobile device PC?  Required access points for websites Home PC, laptop, mobile, public PC?  Sophistication of your PW mgt system Steve Pearce - Betaplus Club April 2011

10 Assessing Exposure Levels Website TypeFinancial risk (5)Identity loss (5)Loss of benefit (5)Overall risk High Risk Sites Bank account55515 Credit card account55515 Website that retains CC details55515 Utility website (gas, elec etc)55515 Password repository35513 Document repository55313 Remote access service (Logmein etc)55313 Medium Risk Sites Social networking site (Facebook etc)55111 Genealogy service (Ancestry etc)35311 Insurance company15511 ISP15511 Magazine / news subscription1539 Software support service1539 Retail website (no stored CC details)1359 Online backup service3339 Low Risk Sites GP surgery1337 Webmail / contacts / diary service1337 online music / ebook store1337 Reference data (govt / health etc)1315

11 Proposed PW Mgt Policies Steve Pearce - Betaplus Club April 2011

12 Password Mgt Software - examples  Passwords Plus http://www.dataviz.com/products/passwordsplus/pwp_feat ures.html http://www.dataviz.com/products/passwordsplus/pwp_feat ures.html  Roboform http://www.roboform.com/  Password Safe (Android) https://market.android.com/details?id=uk.co.kuffs.free.pas swordsafe&feature=search_result https://market.android.com/details?id=uk.co.kuffs.free.pas swordsafe&feature=search_result Steve Pearce - Betaplus Club April 2011


Download ppt "Technical Study Group April 2011. Agenda  Risks to websites and PC files  Components of password management policy  Password management systems  Password."

Similar presentations


Ads by Google