My WebLink
|
Help
|
About
|
Sign Out
Browse
Search
AgdaPkt 2020-12-21 Amended Joint SA PFA
RedwoodCity
>
City Clerk
>
Agenda Packets
>
2020-2029
>
2020
>
AgdaPkt 2020-12-21 Amended Joint SA PFA
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
1/5/2021 12:51:59 PM
Creation date
12/18/2020 5:45:35 PM
Metadata
Fields
Template:
CC Index
CC Index - Document Type
Agenda Packet
Meeting Type
Joint
Agency Type
City Council and Successor Agency and Public Financing Authority
Date
12/21/2020
Jump to thumbnail
< previous set
next set >
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
1000
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
Show annotations
View images
View plain text
6.D. - Page 17 of 33 <br />Cybersecurity training is a well-established industry — providing a focused set of classes and <br />materials designed to reduce users' clicks on harmful links and attachments. Security training, <br />awareness, and assessment should be a routine part of the Cybersecurity strategy in government. <br />Deploying such a program covers the education, training and testing of employees to recognize, <br />delete and report attempted attacks. Studies show these programs reduce but do not eliminate <br />user error. <br />Government Technology magazine captured it best in their cover story entitled "In the quest to <br />guard against cyberthreats, can we solve the people problem? The Weakest Link.1138 The article <br />concluded that even with the best training programs and defenses, the human element may never <br />be completely overcome.39 This is precisely why recurring training and user testing is <br />encouraged by best practices. <br />Handling Incoming Emails — Phishing Defenses <br />In a worldwide survey of Managed IT Service Providers (MSP's) in 2019, "67% of Ransomware <br />attacks originated from a phishing or spam email ... the easiest method of delivery and man does <br />it pay off.1140 The greatest threats take advantage of users "within" the network, i.e., users who <br />click on malicious links or open email attachments that contain viruses or make other mistakes <br />that allow hackers to gain access to the entity's system or network. Trend Micro estimates that <br />the vast majority of all attacks occur when a user clicks on something they should not 41 <br />There are different ways to help the user community recognize and protect against a phishing <br />attack. Most network environments utilize spam filters to automatically filter incoming <br />messages. Spam filters are used to detect unsolicited, unwanted, and virus -infested email and <br />stop it from getting into email inboxes.42 "Additionally, malware detection software can also be <br />highly successful in reducing the risk of Ransomware but the anti-malware definitions (a <br />database of known infectious code) need to be constantly updated... which takes effort and time <br />but represents the single most effective defensive strategy.1143 <br />Message rules can be used to flag external emails and thereby decrease the probability that a user <br />clicks on bad content. An administrator can set up message rules on a users' client or the email <br />server. An example of a message rule might be if the sending organization includes <br />@smithco.com in the sender's address, the message is automatically moved the incoming <br />message into a personal folder called "Smith Company." A better example would be a rule that <br />flags all external emails (not from the host's domain) and warns about the threats of clicking on <br />attachments or weblinks. An example of this visual potential threat message rule is displayed in <br />Appendix C. <br />38 Government Technology Magazine, Adam Stone, The Weakest Link, Oct/Nov 2018 <br />39 Ibid <br />40 VadeSecure — Predictive Email Defense, Ransomware Attacks: Why Email is still the #1 Delivery Method", <br />January 16, 2020 <br />41 https://blo,>�ndmicro.comlonIine-phishi_n,-how-to-stay-out-of-the-hackers-nets/ <br />42 https://%v�vw.niailcliannels.com/what-is-sponi-filtering! <br />43 Epicor, Protecting Yourselffrom Ransomware ", January 2020 <br />2019-2020 San Mateo County Civil Grand Jury 9 <br />138 <br />
The URL can be used to link to this page
Your browser does not support the video tag.