The Ten Commandments of Security
1. If you don’t know, ask.
If I suspect a cyber attack, receive a suspicious email or my computer is behaving strangely, I should contact user support to discuss what to do next. I should follow their instructions.
2. You will authenticate and authorize yourself.
The computer itself does not recognize me, so I have to prove my identity to it, for example by knowing the password to the user account (authentication). In applications, programs and information systems, I often do not have authorization for all activities. Therefore, authentication is followed by authorization, which determines what I can and cannot do.
3. Be careful where you enter your password.
I only enter my login details into a website that is encrypted, i.e. its address starts with https:// and has a lock icon at the beginning. It is important that the page address is entered exactly; even fraudulent sites can use encryption.
4. Be suspicious of incoming email.
Electronic mail is often misused to send spam, hoaxes, phishing or bulk messages. I should be wary of suspicious emails, especially those that contain attachments or links to websites. The attachment may contain malicious code and the linked website may be fraudulent.
5. You should not believe everything that is written on the Internet.
Anyone can publish information on the Internet, even an ignorant or intentionally manipulative person. Therefore, I should always verify the credibility of the information I receive. In the work environment, I have to handle information carefully; not all data is intended for everyone.
6. You will encrypt confidential information.
Data encryption ensures that the information cannot be read by anyone who obtains it, but only by someone who knows the decryption key. An electronic signature confirms that the signer is the author or that he/she agrees with the content. It also confirms that the content of an electronically signed document has not been changed after signing.
7. You are not anonymous on the Internet.
I leave behind a lot of traces by browsing websites and using services on the Internet. Other traces are created by voluntarily publishing information about myself, especially on social media. All of these activities reduce my anonymity and it is a good habit to behave as if anyone could identify me.
8. You should protect your computers and back up your data.
No one unauthorized should use someone else’s personal property, such as a computer. I must protect such a device by locking my office and using a screen lock. I must make sure that its software is up to date or entrust the management of the device to experts. I should regularly back up important data.
9. Mobile devices are also computers.
A mobile device, today most often a smartphone, is a small computer and I should treat it and the data on it in the same way as a computer. I also need be aware of the risks of carrying the device or having it with me at all times.
10. You should follow the rules and respect the law.
The same legislation applies on the Internet as in the real world, but with some additional specific legal rules. In addition to this state-required legislation, I should also follow the internal rules of organizations or the rules governing the use of specific services.