In Depth
Safe at Home: CISOs on Security for Home PCs and Networks
CISOs are always pushing computer security policies. We asked three of them to forget the policies and show us how they handle security on their own home computer systems.
By Derek Slater
Maintenance: Runs antivirus and antispyware/ antiadware programs at least weekly. System vulnerability checker runs every three weeks or when updated or when suspicious activity is detected. Keeps Netscape and Windows patches up-to-date.
Web hygiene: Cookies filtered to the maximum extent possible. Browser set to not retain history of visited sites. Frequent cleansing of cache and other temporary log/tracking info directories is done using CyberScrub. Does not return "receipt requests" on e-mail.
Wireless: Uses AirMagnet and MiniStumbler to detect wireless vulnerabilities.
Shoppers beware: Family does lots of Internet shopping, but only with widely known and valid businesses. CISO logs in to online banking via an SSL Version 3.0 browser format, and checks bank statements online for any unusual purchase amounts.
Don't overlook: Disables the entire network when family goes on vacation.The Kid Factor"I try to keep security as transparent as possible, but I get the normal grousing about, 'Dad is always blocking me.' I sit down and show them the threats facing them and how [a security breach] can destroy their data. I find out how they use the Internet and PCs so that we can work together to build a secure format for them, showing them how to run each of the security tools and how to check their configs to see if any problems are noticed."
Other stories by Derek Slater
home pc security
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



