Thursday, February 4, 2010

Quick Security Tip


Social Engineering:

I was with a client the other day in a secure room. The client left for lunch, locking me inside the secure room. The door to the secure room contains a glass window that allows any passerby to see inside. An outside vendor comes by and knocks on the door. This immediately brought to mind a common problem.

While this vendor was almost certainly legitimate, my only interaction with this client is with this secure room and the individual who locked me in. I have no idea who this vendor is, or, even if he is the clients legitimate electrician, if he has any business being in this secure room at this particular time. I routinely see UPS/FedEx/USPS hold open doors for people to allow them access into an area in which they have no business, but the delivery person has no idea and, true to the intent of social engineering, allows the person in.

In my case, I walked up to the door and advised the external vendor that I did not have the authority to allow him access to this area. He was furious and began yelling. This reminded me that social engineering is not just walking into a building looking as if you belong. Social engineering can include being quite unpleasant.

If a person exclaims loudly enough that he belongs, perhaps someone will be more apt to open the door. It’s odd to me how people innately understand the problem of social engineering when they’re at home, but quickly forget it at work.

To put this situation in the light of a personal situation, imagine you are visiting a friend at his home. He trusts you, so when he has to run a quick errand, he leaves you at his house and locks the door. Moments later, the cable guy shows up and demands entrance to install a new cable hookup. You would almost instinctively refuse entrance, and if he became loud and obnoxious, you may even call the police. Why would you act differently at work?

-Ben.

Ben Howard is a Sr. IT Consultant with NSK Inc

NSK Inc.
75 Kneeland St., Suite 201
Boston, MA 02111
617-303-0480

Monday, February 1, 2010

IT Associate At NSK Inc Receives VMWare Certification

Boston IT consulting firm now certified in VMware vSphere 4 virtualization

Boston, MA, February 1, 2010NSK Inc. recently announced that one of their IT Associates, Justin Etling is now a VMware® Certified Personnel. VMware software allows system administrators to run multiple operating systems on one CPU and lets users create virtualized servers. Etling is certified in VMware’s vSphere™ 4, a cloud computing application designed to manage large pools of virtualized computing infrastructure including hardware and software components. According to Etling, “virtualization is the future of the IT industry.”

“Virtualization is going to be a huge project driver for small to medium businesses (SMB) in 2010,” comments Timothy Lasonde, President of NSK Inc. “As small businesses begin to realize that they can get more out of their equipment by implementing these new technologies, the demand for qualified technicians who understand SMB companies and how to correctly utilize this technology is skyrocketing. Justin is leading NSK in its virtualization efforts and his certification helps to position us appropriately.”

In order to become VMware certified, Etling completed a fifty hour training course which culminated in a certification exam. He says the course was very beneficial and that VMware is “really easy to use and implement.” Once a technician becomes a VMware Certified Professional, they are officially licensed to use, install, and configure VMware solutions. Etling claims his new credentials are a huge asset to NSK Inc. “A lot of our clients use [VMware] to save money on hardware and software costs. Our clients also use the application for disaster recovery. If a server dies, you can instantly bring it up on another server, which minimizes downtime.”

About VMware

VMware delivers solutions for business infrastructure virtualization that enable IT organizations to energize businesses of all sizes. With the industry leading virtualization platform – VMware vSphere™ – customers rely on VMware to reduce capital and operating expenses, improve agility, ensure business continuity, strengthen security and go green. With 2008 revenues of $1.9 billion, more than 150,000 customers and 22,000 partners, VMware is the leader in virtualization which consistently ranks as a top priority among CIOs. VMware is headquartered in Silicon Valley with offices throughout the world and can be found online at www.vmware.com.

VMware, VMware vSphere and VMware vCenter are registered trademarks and/or trademarks of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.

About NSK Inc.

NSK Inc is a leader in information technology consulting, with a focus on IT management for SMB companies. Headquartered in Boston, MA with an additional office in Palo Alto, CA, the company offers a wide array of IT services for business driven information challenges. They provide service and support for small and medium-sized businesses and groups working within large organizations.

NSK Inc also creates custom software products for investment banks, equity management organizations, and other specialized industry areas. For more information, please visit www.nskinc.com.

Press Contact

To schedule a press briefing, please contact:

Cathie Briggette

NSK Inc.

(p) +1 617 303-0480

(e) cathie@nskinc.com

Monday, January 25, 2010

NSK Inc. Hires New Marketing Intern



Name: Michael Lupacchino

Education: Emerson College

Position: Marketing Intern

Michael Lupacchino joined the NSK Inc Team as a Marketing Intern in January 2010. He graduated Cum Laude from Emerson College in December 2009 with a B.S. in Marketing Communications. A native of East Hartford, Connecticut, Michael’s interest in IT began when his mom purchased the family’s first computer (running Windows 95) in 1996.

A self taught technician, Michael slowly immersed himself in virus and spyware removal, registry cleaning, hardware and software instillations, audio and video editing, and wireless network set-up through the help of search engines, online forums, and owner’s manuals.

Previous to NSK Inc, Michael worked for the Emerson College IT Help Desk where he served as a Lab Assistant, Help Desk Technician, and Student Manager. A devout Windows® user, he became well versed in Mac® systems and software during his time at the Help Desk.

Michael was a member of EmComm, Emerson’s student run Integrated Marketing Communications Agency, as an account executive and as Director of Information Technology. He also worked as a freelance marketing consultant for Camp Stanleyfor the Performing Arts.

His other interests revolve around the performing arts. He restarted the Emerson Dance Company in 2007 and served as President until December 2009. He has directed and choreographed numerous showcases and has been involved with Emerson Stage. His most recent work will be shown in X-Dance 2010, debuting in February at Emerson College.

On working at NSK Inc, Michael is incredibly lucky to have found such a position. “To find an internship in both marketing and information technology seemed almost too good to be true.” He says that he is really enjoying his time with the company and is incredibly thankful for the opportunity.

Monday, January 18, 2010

NSK Inc. Hires New Sr. IT Associate

Name: Shane Martz

Education: Gibbs College

Years Active: 10

Originally from Wethersfield, CT, Shane Martz started his career in IT at the age of six when his father brought home a computer. He began working in the IT Industry professionally at eighteen. After spending time at Gibbs College, Shane became a full time employee in the IT Services sector.

Previous to NSK Inc., Shane worked for the IT Department of Skyhook Wireless, a Boston based company that specializes in wireless global positioning technology for mobile devices and smart phones.

Shane joined the NSK Inc. team in January 2010, as a Senior IT Associate. He is a Microsoft Certified Professional (MCP) and is working towards his MSCA (Microsoft Certified Systems Administrator). Shane is a cross-platform specialist, being well versed in Windows, Macintosh, and Linux systems.

On working at NSK Inc., Shane is thrilled to be here. He cites great business practices and high customer satisfaction as part of the NSK Inc. charm. According to Shane “There is nothing worse than being a provider with customers who don’t like you.” He states he really enjoys the fact that our clients like to work with us and is really excited about furthering his career at NSK Inc.

Thursday, January 14, 2010

Give in a Crisis.... But be wary who you are giving to



















There is an emerging humanitarian crisis in Haiti, currently the front page story on every major new website.

This is a quick security reminder due to the timeliness of the issue. The e-mail I received above is actually legitimate, but this is the same e-mail I would expect a scam-artist to use, just using the hyper-links and shortened URLs to point to illegitimate sites.

Quick security tip:

Be particularly wary of scam artists trying to profit from human nature. When catastrophy strikes, many people want to help and will often be too eager to send their money to bother checking where the money is actually going. Be wary of e-mails soliciting help and more wary still when the URLs are shortened. Don't be discouraged from donating, just make sure you go directly to the site to which you wish to give your time and money. If you want to donate through the Red Cross, go directly to www.redcross.org, or to the charity or benefit of your choosing.

Wednesday, November 25, 2009

Final Version of MGL 93H 201CMR 17.00 Filed

OCABR (Massachusetts Office of Consumer Affairs and Business Regulation) on October 29th, 2009 filed the "Final" version of the "Standards for the Protection of Personal Information" also know as MGL 93H 201 CMR 17.00 with the Secretary of State's office. The first issue was in September of 2008, and after more than a year of amendments to the original regulations this is the final step before the regulation takes effect on March 1, 2010. The final regulations include some further clarifications than the amendment that was released in August of this year, but are substantially similar.


The latest revisions were written in response to requests from companies and business leaders that were looking for further clarification of the regulation.


Following are the changes:


17.02 Definitions
Owns or licenses - adds the word "stores"
Service provider - adds the word "stores" and deletes the phrase provided, however that "Service provider" shall not include the U.S. Postal Service.

17.03 Duty to Protect and Standards for Protecting Personal information


Clarifies the language in section (2)(f)(2) relating to service provider contracts - A contract entered into with a third party service provider is deemed to be in compliance with this section until March 1, 2012, even if the contract does not include a requirement that the third party service provider maintain such appropriate safeguards, as long as the contract was entered into no later than March 1, 2010


"Definition of Owns or Licenses. A company owns or licenses personal information if it "receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment." The final regulations make clear for the first time that a company that "stores" the personal information of a Massachusetts resident is subject to the regulations' requirements, even if the company does not otherwise process or access such information.


Definition of Service Providers. A service provider is defined as "any person that receives, stores, maintains, processes, or otherwise is permitted access to personal information through its provision of services directly to a person that is subject to this regulation." The final regulations eliminate a previous carve-out that had stated, "‘service provider' shall not include the U.S. Postal Service." It is not clear that the OCABR intends this change to mean that a company using the U.S. Postal Service to transmit personal information must contractually require the U.S. Postal Service to implement and maintain appropriate security measures for such personal information, as it must do with other service providers. But the OCABR has stated that a company must assess the risks of using a common carrier, including the U.S. Postal Service, to transmit personal information and take steps to protect that personal information.


Amending Existing Contracts with Service Providers. The final regulations clarify prior language related to a grace period for amending existing contracts with service providers so that such contracts require the service providers to implement and maintain appropriate security measures for personal information. The regulations now make clear that a company has until March 1, 2012 to amend existing contracts with service providers to include personal information security provisions, as long as the existing contracts were entered into before March 1, 2010. As before, service-provider contracts that the company entered into after March 1, 2010, must include personal information security provisions." [1]


For a copy of the most up to date Regulation please click here.


MPICA - Massachusetts Personal Information Compliance Assessment


[1] David M. McIntosh, Lisa M. Ropple Christine Santariga - Ropes & Gray LLP Boston Office

Friday, October 16, 2009

Your Timeline for Compliance with MGL 93H 201CMR17.00

October 2009

Designate an Information Security Officer - You will need to designate at least 1 person at your place of business who will maintain the comprehensive information security program. Finding that person now will help get the rest of the items in line for when they need to be done. You can get a compliance checklist at: 201 CMR 17.00 Compliance Checklist

November
Start Assessing Your Information:

Identify the paper, electronic and other type records, including storage media, laptops and portable devices that contain personal information.**
Check all anti-virus and security patches on all computer systems and servers -- make sure they are up to date.**
a. Check that you have reasonably up-to-date versions of
system security agent software (including malware
protection)**
Identify what "personal information" moves around your business and out of your office including:**
a. healthcare/insurance information
b. benefits/401K information
c. Accounting/Tax information
d. Employment and Credit Applications
e. Checks and credit card information
Identify persons who need to see the "personal information" and those who do not.
Identify where encryption for personal information is needed.**
Identify what third-party service providers your business may use that have access to personal information.
Identify reasonably foreseeable internal and external risks to paper and electronic records containing personal information.**
Identify any systems that are connected to the internet and make sure the firewall protection for files containing personal information are up-to-date.**

December 2009

Purchase any hardware or software upgrades that are needed**
Get control of user IDS and other identifiers**
Come up with a reasonably secure method of assigning/selecting passwords for users**
Start developing your WISP (Written Information Security Program)
Make sure that your WISP is applicable to all records containing personal information about a resident of the Commonwealth of Massachusetts

Make sure that you include:

Administrative, technical and physical safeguards for Personal information protection
Any identified and reasonably foreseeable internal and external risks to paper and electronic records
Regular and ongoing employee training, and procedures for monitoring employee compliance
Disciplinary measures for violators
Policies and procedures for when and how records containing personal information should be kept, accessed or transported off your business premises
Processes for blocking terminated employees physical and electronic access to personal information, including deactivating their passwords and user names
Steps taken to verify third party service providers access
The length of time that you are storing records containing personal information.
Specifically the manner in which physical access to personal information records is to be restricted
Whether you are storing your records and data in locked facilities, storage areas or containers and the security measures taken to keep these areas secure
Actions and documenting that is taken in connection with any breach of security

January 2010

Install all hardware and software upgrades**
Test policies that have been written
Start Training Employees on new policies
Finalize WISP
December

Finish Training Employees
Send out WISP Policy to all Employees and get signatures from all that they understand and will comply

February 2010 and beyond

Continue monitoring your systems and procedures**
Continue providing training to new and existing employees
Update policies as required
Assure all computers and servers remain up-to-date with patches and anti-virus software**

** NSK Inc. can help you with any of these tasks, just let us know.