Social Media Security (Cybersecurity Month Tip #10)

Social media is a vastly popular use of the Internet today, and a source for a huge interchange of data. This ability to upload and download many forms of data can make social media a conduit for illegitimate information flow in and out of an organization. Social media can also allow malicious individuals to seek out and connect with people by name or by interest. Foreign intelligence services and cyber criminals have been known to create fake profiles, sometimes based on those of real people, in order to connect with and gather information on persons in an area or field of interest.

Key tips for security on social media include:
  • Use two-factor authentication; most social networks have this option.

  • Be careful who you accept "friend" requests or connections from. Check who they are already connected with, especially, to see if their connection make sense in light of what you know of this person. Avoid connecting with people you don’t know well.

  • Use care in sharing personal information, particularly work-related information and location information. 

  • Examine the privacy options and settings for the social network(s) you’re using and give careful consideration to what settings will protect your privacy and enhance the security of your information.

  • Use the same caution with links on social media that you would use with emails. Be especially cautious regarding apps that install on a social network and that ask for permission to use your account on their own (e.g. apps that want to “post on your behalf,” etc.)
Facebook recently started a program of warning users whose accounts it believed might be at risk of compromise from national intelligence services:

http://www.csoonline.com/article/2994494/cyber-attacks-espionage/facebook-warns-users-of-potential-state-sponsored-attacks.html



In honor of National Cyber Security Awareness Month, for October we will be posting short tips for users on improving their information security awareness and practices every Monday, Wednesday, and Friday all month long.

Comments

Popular posts from this blog

Weekly Infosec News Brief: 14-20 March

Weekly Infosec News Brief 20-26 July

Critical Vulnerability Discovered in IIS 6.0 Web Services