ABOUT US

Our development agency is committed to providing you the best service.

OUR TEAM

The awesome people behind our brand ... and their life motto.

  • Neila Jovan

    Head Hunter

    I long for the raised voice, the howl of rage or love.

  • Mathew McNalis

    Marketing CEO

    Contented with little, yet wishing for much more.

  • Michael Duo

    Developer

    If anything is worth doing, it's worth overdoing.

OUR SKILLS

We pride ourselves with strong, flexible and top notch skills.

Marketing

Development 90%
Design 80%
Marketing 70%

Websites

Development 90%
Design 80%
Marketing 70%

PR

Development 90%
Design 80%
Marketing 70%

ACHIEVEMENTS

We help our clients integrate, analyze, and use their data to improve their business.

150

GREAT PROJECTS

300

HAPPY CLIENTS

650

COFFEES DRUNK

1568

FACEBOOK LIKES

STRATEGY & CREATIVITY

Phasellus iaculis dolor nec urna nullam. Vivamus mattis blandit porttitor nullam.

PORTFOLIO

We pride ourselves on bringing a fresh perspective and effective marketing to each project.

  • Top 10 Laws of Security

    By

    Aladdin T. Dandis
    Information Security Compliance Officer
    Jordan eGovernment Program


    Abstract

    It is very important to realize and understand the laws of security, by which all sectors in an enterprise or government can empower security within their perimeters. The higher understanding of this laws, the better security implementation is realized. These laws can be applied in each business field or any business environment. Such laws can be implemented in any degree of simplicity or complexity. Therefore, it is important to understand the environment deeply before reflecting such laws, in order to meet security goals aimed by the owners.

    1 Introduction

    It is proven that analysis of a system the key factor for successful management. These systems are collection of functional and non-functional components that work inherently to meet the strategic objectives of the enterprise. For that, it is important to control relations and processes among such components. Without providing an acceptable security level, all of these components are facing various risks. These risks are hard to be migrated to an acceptable level without good security management. This paper is aimed to urge the top 10 laws of security in any system. Each of which should work with collaboration of the others to gain sustainable framework and robust integration to secure the enterprise.

    2 First Law: Security is a process, not a product

    This law is the conclusion of Bruce Scheiner’s well known book “Secrets and Lies”. It is predicted result the should be taken as the first law. Most of decision makers handle with security as being a product that is more powerful and competent to use with other products. Therefore, technology is the real driver of such people, and they are following technology updates for anti-malware, IDSs, Firewalls…etc. Such idea about security minimizes the efforts of correct security implementation, causing end users to neglect their responsibility on securing their environments.

    For that, Bruce emphasizes on this law to extend our view to security to cover managerial and administrative process to take its right place to enforce and strengthen level of security in the perimeters, throwing part of the responsibility on managers and end users in security. This can be realized using Information Security Policies, Standards, Guidelines and Procedures, in addition to applying suitable and effective level of awareness to deal with information assets in a healthy way.


    3 Second Law: Security is must-to-have, not better-to-have decision

    In the past, security was not matured to be essential since the number of technology specialists was low, and easy to be known. Therefore, most applications were using minimal security measures, and sometimes optionally, to deal with the systems effectively and to keep performance high. Nowadays, technology provided us with high performance machines that can overcome such obstacle. In addition, “specialists” in security and technology are increased more and more as time goes ahead. This should raise security from “optionality” to “enforceability”. Number of hackers, whether they are white, black or gray. The more seriously management treats security, the more security level will be gained.


    4 Third Law: Security is built from the Core, not on the Edge

    As a complementary to the second law, security should be applied step by step as we build the system, from requirements to analysis to design to implementation up to termination stage. Most security vendors apply their measures in the boundaries of the system, forgetting that relations among information assets and employees their selves are more dangerous. For example, applying security measures such as firewalls on a system and giving the permission to any employee the choice and capability to bypass them or configuring them, this will compromise security within this enterprise. Therefore, separation of duties principle is important to determine the roles for each employee and the permissions that should be given to him before the system is built.


    5 Fourth Law: Understanding the business is the most crucial factor to a successful security level

    Understanding the system will simplify the way of analyzing vulnerabilities and relevant threats that have the ability to exploit these vulnerabilities. Moreover, understanding the system will simplify the way to architect security. The better understanding of the system, the better security design and implementation can be realized. However, a lot of environments now are studied by security experts in collaboration with system analysts to understand and secure these environments correctly and from higher and more points of views.


    6 Fifth Law: Security awareness is the most cost-effective security measure

    Surveys on security measures proved that security problems come from internal users. As a result, companies are reforming their views to security from being just technical to extended views such as awareness and investment in security people. Security awareness is a low cost security measure, but it is very effective for the discussions and conversations that are conducted among employees to share their experience and knowledge.

    Security awareness helps people to deal with information assets geniusly, and to increase level of security from practical point of view.


    7 Sixth Law: Without updating security periodically, security is out of date

    This law is compliant with the first law. Security level is considered “High” if security measures are maintained and increased periodically. This should be part of applied security policy in the enterprise. Most of security officers are interested in installing new security software and hardware, including IDSs, IPSs, Firewalls, anti-malware, monitoring tools…etc, without giving special care to updates and support. Moreover, security officers should update their knowledge about security measures and security attacks, including new trends and methodologies of attacks and security. This will harden the systems as security professionals remain professionals all the time. Research, training, reading, listening and attending security materials, courses, webcasts, conferences and workshops are some resources of knowledge updates. Security professionals are posting specialized blogs on the web to discuss new trends and problems in security era. Some programmers, specially in open source community, provides updates and tools to fix security problems under various platforms. This will support the level of security and enhance administrators and security officers’ capabilities to treat security problems and design suitable remedies to them.


    8 Seventh Law: Trust is a result of security

    Trust is the ultimate goal of security. Without trust, interactions and transactions are suspicious. In e-commerce and e-government contexts, trust is the main pillar of successful implementation and usage. This level of high security is provided using high security standards and policies. The more success in implementation of these policies and standards, the more security level is provided, and them more trusted transactions can be realized. Information security assurance is that part of security that emphasizes on this feature. It supports security using proactive measures to meet the level of trust aimed by the enterprise. These measures should support CIA triplet: Confidentiality, Integrity and Availability. Encryption, Business Continuity, Information Security Governance and Compliance are some examples of security projects that support trust.


    9 Eighth Law: Security is the responsibility of everyone

    Most of managers and employees believe that security is the responsibility of security officers. This is a big mistaken belief. As mentioned in the fifth law above, awareness is the most important security measure. Hence, no people urge that security is the responsibility of each employee and manager within the boundaries and perimeter of the enterprise. This fact doesn’t mean that everyone should know everything about security, but it means that security officers have their role in analyzing, architecting, implementing, testing, maintaining and managing security according to published policies and standards, where others should follow security policies and standards, and using available security controls, in addition to handling information assets with the expected level of awareness.


    10 Ninth Law: Security is not just technical issues

    Reference to the first law and eighth law, security is not a just a technical issue. Security is a mixture of political, economic, socio-cultural, managerial, legal and technical issues and factors. The right security implementation should cover these issues. Therefore, security management have to communicate roles from different departments to gain the right recommendations and feedback to security.

    Political issues should deal with external relationships with other countries and information exchange. Economic issues cover risks and revenue of security implementation. Legal issues include laws and regulations affects or can be affected by information security management and practices. Management issues include polices, standards, separation of duties and business continuity program. The last dimension is socio-cultural issues which determine factors and consequences of information security on social and cultural life of employees and other stakeholders. Finally, it is clear that technological issues are important, specially in our networked world.


    11 Tenth Law: Security, Privacy and Transparancy should be managed carefully

    Most of people are looking for security from confidentiality prospective. Security is rather about integrity and availability also. Privacy is about tracking and monitoring the identity, collecting information that is NOT confidential, but private. In information age, and under the refection of social responsibility and democracy, information should be disclosed to community as much as possible, this means that not all information are confidential or private. In this prospective, integrity and availability should be considered as well. Some managers, politicians or business owners try to hide information of public sensitivity level to take over their "kingdoms". As a result, most of those who leave their "kingdoms" lately will disclose OR enforced to diclose these information for legal accountability and investigations.

    Informatino should be kept public as much as possible, taking integrity and availability as "better to have" choice, if no privacy or confidentiality requirement is needed.


    12 Conclusions

    Security is culture. No body can claim that he is secured 100%. More efforts should be paied to protect information assets of the entity and ensure its integrity. Business is built on Trust, and no trust without security. It is important to notice the great effect of human being due care and due deligence as crucial factors to practice security awareness. It is very important to cover security issues periodically to ensure no vulnerabilities stand out their. Finally, management, employees, teachers, students, doctors, family... etc should work together under pre-defined rules and strategic security objectives to secure their communities and environments.
  • Web 2.0 , Information Security and Privacy

    Abstract
    Since Web 2.0 culture raised to the surface by its own intrensic attraction and gravity, new trends of threats appear to attack this attractive picture to meet some dangerous goals for those attackers. Most of these threats origionates on Fraud, Social Engineering, Spywares and others. This essay illustrates the most important threats for Web 2.0
    Introduction
    Most of us use internet to gather information about something, or to interact others for some commercial, educations, social, political or any other beneficial activities for us and others. This internet community was supposed to arise in a way that everybody can make advantage from and for everbody. This culture was enforced by the tools by which Web 2.0 was featured with year by year, such as Wikies, Blogs, Social Networking...etc.
    The most important problem for Web 2.0 is that everybody wants to announce hiself/herself to web community, selling and marketing ideas for others to get some advantages, wheather they are financial or reputative. This led to publish information for others for free, and gave others the opportunity to abuse these information for illegal puposes, which will be discussed below in brief.
    Social Networking
    Some survays claim that more than 250 millions of internet users have account in one or more social networking websites. In fact, this feature allowed for millions of people to get in touch again after years of being away from each other. Most of old friends met without barriers, and people are sharing their events, photos, letters in individual form or groups form. People who are interested in some events, ideas and celebrates are now able to find the groups by which they feel they can be active and interactive to be part of them.
    This is the positive and beautifull face.
    On the contrary, people are publishing their private information in the cyberspace without guaranteeing their privacy are protected. Even you applied your security measures as putting permissions for those who can access or cannot access your profile, your profile is NOT withing your pocket, and your information could be hacked by some way or another. This fact is clear for people who are aware of security, but not for others. Some studies revealed that search tools that are available within social networking websites can be used for investigative activities. This means that your information and "links" to your friends can be visulized, so your relations and social life can be viewed easily. Some police and intellegence investigators make use of these information in an attempt to capture some crimianls or spies. But attackers are very glad to find repositories provide such valuable information for free!
    As a result, some attackers use these information for fraudelent activities, using social engineering methods to collect information from victims, and use identity theft tools to overcome those victims to gain their purposes. Some studies pointed out that sexual harrasments and financial fraud crimes was done againest children and students form both genders. Some was abused for distributing terrorist activities and ideas, and others for political and economical purposes.
    Blogs
    Freedom is great, and using our rights to be free to talk, read and write is very great thing. But using technology to watch and track people and individulas what they are talking about is some kind of intelligence.
    When publishing a blog, people are sharing ideas about something. Some blogs are hot, others are weak. Some bloges appear to be Free Private Websites, whereas others seem to be forums. However, people find it interesting to publish their opinions and ideas freely, which can be studied easily by social, political and commercial institutes to find public opinion about some event, issue or product. Do you thing it is legal? Is it fair to get these information for free without greetings to those "human machines" that are constructing such blogs?
    On the other hand, what is the degree ot trust that such information belog to the human who claims to be the owner of this blog? Can you prove that "I (Aladdin Dandis)" is writing these words or I am doing some "Copy-Pasts" activity from copyrighted material?
    I think these issues should be addressed and considered before writing such blogs!
    Wikies
    Here is another problem. A lot of writers urgue about wikies to be source of information. What is criteria that should be followed to make sure that information posted in such wikies are trusted and real? Who is the writer? Is he a specislist or just a human wants to show people that he/she is writing scientifica material?
    Wikies are great source of information when restricting and qualifying the writers of them. Some rigid conditions should be followed before and after posting the wiki, to make sure that source and reviewer are eligible to enhance human knowledge in a right way. Without that, any human can post any information, and any reviewer can rate it by any good or excellent mark!
    Conclusion
    In the end, it is essential to protect our informatino and identity from being abused, since Web 2.0 opens people to a generation of open minds, and if we are not aware how to post and interacte the right people and information, then we are wasting ourselves for cloudious and dark future.
  • Enhancing National Internet Security

    Abstract
    The increasing rate of cyber terrorism and attacks in the cyber space should balance the efforts needed to adhere the acceptable level of Internet Security on the national level. These efforts should be coordinated under the information security strategy of the nation before getting to practice it using technical security measures. This strategy should include all the major stakeholders of internet in the nation, including Government, Business, Academic Institutions and the individuals. Each of those components should collaborate the national efforts to the required level of acceptance to secure Internet. For the ultimate level, these efforts should be harmonized with the international efforts considering Internet Security.

    1. Introduction

    Internet is considered now one of the most used technologies to transfer and exchange information throughout the world, and the number of internet users increases very fast day by day. The major usage of internet is to transfer and obtain information, e-commerce, email and download software and books. But as technology goes ahead, another services are now provided through internet, including VoIP, Content Delivery, Teleconferencing, TV on Demand…etc. The need for eGovernment Services pushed internet usage to new generation of eservices. But as technology goes ahead, vulnerabilities and attacks increases indeed, putting new interest for information security specialists to cover these issues, specially that internet technology and services are very attractive to users who can be exploited easily with the absence of awareness and legalizations.

    The intent of this paper is to explain the concept of Internet Security, and to address the areas by which all internet stakeholders of various sectors can collaborate their efforts to provide the acceptable level of security of this resource.

    2. Concept of Internet Security

    Internet Security is defined as "the prevention of unauthorized access and/or damage to computer systems via internet access". The most security measures used within this field involve data encryption, which is the translation of data into a form that is unintelligible without a deciphering mechanism, and Passwords, which are secret words or phrases that gives a user access to a particular program or system. (Wikipedia)

    3. Components of Internet Security

    Internet security is composed of three major components, each of which has its separate way to secure:

    1. Infrastructure: which include Communication Lines (cables or fibers), routers, DNS, DHCP, ISPs, Protocols…etc. This part usually dependent on physical matters. Internet infrastructure is usually owned by great corporates or the government itself. For ISPs, the business sector owns some ISPs.

    2. Applications: these are the web applications and e-services that are used within the umbrella of Internet. Some applications are commercial such as in e-commerce, some are for education purposes as VoIP, some related to eBanking, eGovernment….etc. Some individuals own some applications as that of FTP sites, buying and selling…etc

    3. Content: this is the core of Internet advantages, which related to information itself, including emails, photos, multimedia, e-telephony, books, articles…etc.

    For that, Internet is a mixture of physical and logical technologies, hence, internet security professionals should be fluent in the four major aspects: (Wikipedia)

    1. Penetration testing: this skill is essential in order to discover the vulnerabilities of systems connected to internet such as extranets, websites, e-commerce applications and banking systems.

    2. Intrusion Detection: which used to detect (prevent for Intrusion prevention) how attackers, hackers and any malicious activities are functioning or whether they are within the perimeter of the system. This can be done using some specialized software and tools to analyze the log of internet access on-bound or out-bound the enterprise.

    3. Incidence Response: this is the exercise of detection and handling of any incident considering information systems security, such as attacks, DoS, malicious activities, physical destruction, and disruption of systems.

    4. Legal / Audit Compliance: which is related to legalization aspects concerning information security as Cyber Crime Law and Privacy and Data Protection Act and other regulations concerning digital certificates and digital signature. In addition, compliance issues are essential in Internet Security, as Information Security Strategies, Policies, Standards, Guidelines and Procedures.

    4. Responsibility of Internet Security (Stakeholders)
    Internet security is responsibility of each party use it. The basic sectors in any society are mainly four: Government, Business, Academia and Individuals. Now it is the time to explore the role of each sector to secure the Internet.

    4.1 Government

    The main responsibility of Government is to develop and enforce suitable legalization to secure Internet environment. This includes laws, bylaws, regulations, and information security strategies and policies. Such legalization should cover: e-Transactions Law, Cyber Crime Law, Privacy and Data Protection Act, e-Signature and Certificate Authorities. This suite of laws should provide the suitable accountability methods of enforce these laws and to manage Internet access in a secure manner. ISPs should also be very well regulated to control access to Internet using the suitable security measures.

    As per, the role of Government extends further than regulating and accountability, since it should plan and implement suitable National Information Security Awareness Program to identify the weaknesses in using Internet within the borders. In addition, the Government should regulate and control the activities of Computer Emergency Response Teams CERTs to monitor, detect and handle any cyber attack or incident related to the Internet infrastructure in the country.

    4.2 Business

    The engine of regulations and legalization in any country is to serve business and human beings. The business is a strategic partner to the Government in the globe. This partnership throws charges on the business toward the country. One of these charges is Internet security. The main reason for such charge is that most of our new business uses Internet as a major tool to conduct bargains and simplify marketing. Therefore, the business should collaborate the efforts to secure Internet by the following methods:

    1. IT vendors should provide powerful security tools to be used by the Government, Business and other sectors to secure Internet, by purchasing them or developing them locally.

    2. Business should make use of these security measures and tools in the correct way, in compliance with the Governmental laws, regulations and policies. Business should conduct IT audits to make sure that their systems are secure enough when using Internet.

    3. Business should financing and supporting the efforts of non-profit organizations and research institutes regarding Internet security, which can be motivated by the Government. Such support can be done by building capacity of such organizations and institutes, providing the research and monitoring tools and security measures as supplementary efforts.

    4.3 Academic Institutions

    This is the scientific part of the story, by which advanced and specialized studies and research can be implemented and conducted to enhance Internet security and discover new types of attacks and vulnerabilities, and providing new innovative solutions to secure Internet. Such institutes can share knowledge with other research institutes in other countries, and conducting experiments on their labs by specialized personnel and researchers. Non-profit organizations regarding internet security should be included within this collaborative efforts. Finally, Academic
    institutes are acquired to develop training courses and materials and conducting for a national information security awareness program for other sectors in the country.

    4.4 Individuals

    Awareness is the most important part that should be practiced by the individuals. If the individual is well aware of Internet security then the largest part of the problem is solved. In addition, individuals are acquired to follow regulations and policies, and make use of suitable security measures when connecting to Internet. He/she should not introduce himself/herself as a hacker for any reason. Awareness is the most powerful tool for this sector.

    5. Incorporating of International Responsibility

    National efforts cannot get its full advantages without the incorporation of international efforts related to the subject of Internet Security. Such efforts varies in political signature as non-profit organizations, which could be multilateral such as IMPACT Alliance, or to be part of the regional or international organizations such as UN, or that of Academic Institutes as that of International CERT of Carnegie Mellon University. In addition, a lot of international standardization organizations have developed protocols, schemas and frameworks to enhance Internet Security, to secure infrastructure, applications and the content transmitted through Internet.

    In addition, there is a commitment between big vendors to optimize security measures when connecting their products to Internet, such as email applications. Some venders who are interested in security tools such as antiviral software and intrusion detection and prevention, provides some free services to Internet globe considering security matters, such as security operations centers, but it is not 100% free services, since they provide these services for free for some limit, not absolutely. However, big venders, usually, provide awareness and training materials and courses for the globe to enhance Internet Security.

    6. Conclusions

    Internet security is a practice not a theory. Each sector in the country should contribute its efforts to keep internet use secure to the acceptable level. Government, Business, Academic Institutes and even Individuals are acquired within these efforts. The Government will take the regulatory part, Business will take the financial part, Academic Institutes will take the scientific methodology part, and individuals will take the practice. However, if the Government is very
    well organized in its vision, regulations, legalization and policies, then other sectors will contribute in the acceptable level to implement these issues for the benefit of Internet Security in the country.
  • Search This Blog

    Powered by Blogger.

    Featured Post

    Enhancing National Internet Security

    Abstract The increasing rate of cyber terrorism and attacks in the cyber space should balance the efforts needed to adhere the acceptable le...

    WHAT WE DO

    We've been developing corporate tailored services for clients for 30 years.

    CONTACT US

    For enquiries you can contact us in several different ways. Contact details are below.

    Information Security Academy

    • Street :Road Street 00
    • Person :Person
    • Phone :+045 123 755 755
    • Country :POLAND
    • Email :contact@heaven.com

    Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

    Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation.