Application Software
Are our common applications configured for security?
The expanded features and increased complexity of applications
such as word processing, e-mail, and web browsing create new
vulnerabilities. It is important to apply the safeguards that
are in place and apply security updates in a timely manner.
These questions address security issues related to your suite
of applications:
- Are we applying appropriate application software updates
and security "patches" in a timely manner to all
department computers and servers?
- Have we set the macro security level to medium or high
in MS Office applications?
- If not needed for our department applications, have we
disabled the automatic execution of Visual Basic Script
(VBS) programs?
- Have faculty and staff been instructed to place online
orders only through secure web sites?
- Do our staff have the appropriate level of access to applications
based on their current responsibilities?
- Is application access promptly removed for employees who
have left the department?
An answer of "no" to any of the above questions
indicates a risk for which remedial steps should be considered.
Vulnerabilities and methods for closing them vary greatly
from one application to another. Computer users are encouraged
to frequently visit application software vendor websites for
current information on security those applications.
|