在这个不断变化的环境中,越来越多的雇主更喜欢他们的员工在家工作(work from home)。雇主和雇员都需要采取一些预防措施。这篇文章讨论了一些安全提示,以在远程工作时保护数据。
远程(Remote)工作——安全(– Safety)和安保提示
您需要确保始终更新您的操作系统和安装的软件。卸载(Uninstall)不需要的软件。在远程工作时,您还需要注意一些其他方面的安全性:
- 使用 VPN
- 教育你的员工
- 使用好的安全软件
- 强密码
- 使用某种形式的数据加密
- 使用安全的视频会议工具。
1]使用VPN
通过家庭或其他 Wi-Fi 连接到公司 Intranet 时,第一个安全提示是使用虚拟专用网络 (VPN)(Virtual Private Network (VPN))。Intranet 是使用Internet创建的专用网络。
家中的Wi-Fi可能不是 100% 安全的,因为人们倾向于在路由器中使用默认密码或弱密码。公共免费 Wi-Fi 热点(Public free Wi-Fi hotspots)也需要大量预防措施,因为有人可能会监听您的流量以侵入您的计算机。公共Wi-Fi(Wi-Fi)热点也推荐使用VPN 软件。(VPN software)在阅读不同的品牌评论并征求队友和朋友的建议后,选择一个好的 VPN 。
为不安全的 Wi-Fi(Wi-Fi)热点和家庭Wi-Fi最终确定(Wi-Fi)VPN的最佳方法是来自公司 IT 人员的反馈。公司可以购买一些付费VPN的企业版,安装在所有员工的电脑上。这应该保护雇主的数据。
2] 教育你的员工
联系(Contact)您的所有员工并教育他们:
- 社会工程学如何运作,
- 所有关于网络钓鱼(all about phishing),
- 黑客如何攻击计算机并访问它们,以及
- 如何在连接到互联网时保持安全并确保雇主的数据更安全(Internet)
- 和类似的事情,可以避免任何可能损害雇主内部网的事情
3]防火墙和安全软件(3] Firewall and Security software)
更新(Update)员工计算机上加载的所有软件或要求您的员工安装最新版本。用于工作的安全软件(security software)应经常更新,以免损害任何员工的计算机,从而污染办公室LAN或Intranet。软件列表包括防病毒和防火墙。如果使用VPN,请确保它是最新版本。
4]强密码
检查贵公司使用的密码强度。查看您的员工使用的密码强度如何。为他们提供像 Lastpass 这样的优秀密码管理器,并告诉他们如何创建和使用强密码。但只添加员工可以在员工设备上访问/使用的网站和表格。在不同级别工作的不同人员需要访问不同类型的网站。例如,工作计算机很少有Facebook或Twitter,除非它们是与员工个人资料相关的业务流程的一部分。
5]使用某种形式的数据加密
(Data)即使您的一台计算机受到威胁,数据加密也会保护您的数据。确保(Make)加密密钥在某处是安全的。一次加密整个磁盘是一种更好的做法。查看我们在Windows Club中介绍的一些(Windows Club)优秀的加密软件(good encryption software)。
6]使用(Use)安全的视频会议工具
您可能会使用视频会议工具(video conferencing tool)。你需要一个很好的安全的,因为这些原因,你可以使用Microsoft Teams或Skype Meet。Zoom很受欢迎,如果你想使用它,你需要采取一些安全预防措施(some security precautions)。
(Security)员工远程工作时的安全提示
- 确保(Make)您的公司计算机具有良好的VPN。使用Internet时(Internet)始终(Always)保持VPN开启。
- 避免(Avoid)同时或多任务处理公司和个人工作。在公司工作和个人工作之间移动可能会泄露您浏览器的内容。它也可能导致Tabnabbing。请注意在公司 Intranet 上进行个人工作的风险。
- 始终保持磁盘加密并仅解密您用于办公室工作的那些文件。这也意味着公司应该在整个磁盘加密软件上使用文件加密软件,以保护数据。(file encryption software)整个磁盘加密软件的问题在于它们一次解密整个磁盘。
- 在工作计算机上仅使用(Use)公司提供的服务:电子邮件、即时消息、会议软件和浏览器。
- 不要使用代理(Proxies)访问在您的工作计算机上被禁止访问的站点。这听起来可能更安全,但代理可能会记录您在Internet和其他方面所做的事情。
我们是否(Did)错过了这篇文章中的任何远程工作安全提示?在下面的评论部分与我们分享您自己的提示和经验。
Remote working - Safety and security tips to protect data
In this continuously changing environment, more and more employers prefer their employеes to work from home. There are some precautions to be taken by both, the employers and employees. This post talks about some safety and security tips to protect data when working remotely.
Remote working – Safety and security tips
You need to make sure that your OS and installed software is always updated. Uninstall software you do not need. There are some other areas you need to take a look at to be safe and secure when working remotely:
- Use a VPN
- Educate your employees
- Use a good Security software
- Strong Passwords
- Use some form of data encryption
- Use a secure video conferencing tool.
1] Use a VPN
The first security tip when connecting to the company intranet over the home or some other Wi-Fi is to use a Virtual Private Network (VPN). An intranet is a private network created using the Internet.
The Wi-Fi at home may not be 100 percent safe as people tend to use default or weak passwords in their routers. Public free Wi-Fi hotspots also need plenty of precautions because someone might be listening to your traffic to hack into your computer. VPN software is recommended for public Wi-Fi hotspots too. Pick a good VPN after reading different brand reviews and asking suggestions from your teammates and friends.
The best method in finalizing the VPN for insecure Wi-Fi hotspots and home Wi-Fi is the feedback from the IT people of your company. The company can go for some paid VPN’s enterprise edition and install it on all employees’ computers. That should protect the employers’ data.
2] Educate your employees
Contact all your employees and educate them concerning:
- how social engineering works,
- all about phishing,
- how hackers attack computers and access them, and
- how to stay safe and keep the employers’ data safer when connected to the Internet
- and similar things that would avoid anything that may compromise the employers’ intranet
3] Firewall and Security software
Update all software loaded on employees’ computers or ask your employees to install the latest version. The security software used for work should be always updated so that it doesn’t compromise any employees’ computer and thereby contaminate the office LAN or Intranet. The software list includes anti-virus and firewall. If using a VPN, make sure it is the latest version.
4] Strong Passwords
Check the strength of passwords in use in your company. See how strong passwords your employees are using. Provide them with a good password manager like Lastpass and tell them how to create and use strong passwords. But add only the websites and forms the employees can visit/use on the employee device. Different people working at different levels need access to different types of websites. For example, a work computer would seldom have Facebook or Twitter unless they are part of the business processes related to the employee’s profile.
5] Use some form of data encryption
Data encryption will protect your data even if one of your computers is compromised. Make sure the encryption key is secure somewhere. It is a better practice to encrypt the entire disk at a go. Check out some good encryption software that we covered at The Windows Club.
6] Use a secure video conferencing tool
The chance are that you will be making use of a video conferencing tool. You ned a good secure one and foe those reasons, you could use Microsoft Teams or Skype Meet. Zoom is popular and if you wish to use it, you need to take some security precautions.
Security tips for employees when working remotely
- Make sure your company computer has a good VPN. Always keep the VPN turned on while using the Internet.
- Avoid doing corporate and personal work at the same time or by multi-tasking. Moving between company work and personal work may leak the contents of your browser. It may also lead to Tabnabbing. Be aware of the risks of doing personal work on the corporate intranet.
- Always keep the disk encrypted and decrypt only those files that you are using for office work. This also means that the company should use file encryption software over entire disk encryption software so that the data is protected. The problem with entire disk encryption software is that they decrypt the whole disk at a time.
- Use only company provided services on the work computer: email, instant messaging, conferencing software, and browsers.
- Do NOT use Proxies to access sites that have been disallowed on your work computer. This may sound safer, but the proxy may be making notes of what you are doing on the Internet and otherwise.
Did we miss any remote working safety and security tip in this post? Share with us, your own tips and experiences in the comments section below.