<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.officience.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Duc</id>
	<title>Officience - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.officience.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Duc"/>
	<link rel="alternate" type="text/html" href="https://wiki.officience.com/Special:Contributions/Duc"/>
	<updated>2026-08-01T03:01:39Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.1</generator>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Security&amp;diff=988</id>
		<title>Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Security&amp;diff=988"/>
		<updated>2019-07-24T18:43:23Z</updated>

		<summary type="html">&lt;p&gt;Duc: /* See also */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Edmund Hillary &amp;amp; Tenzing Norgay 1933.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Who is responsible for computer security? ==&lt;br /&gt;
&#039;&#039;&#039;Every member of Officience is responsible.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Offies are expected to act responsibly and ethically when accessing Officience’s electronic data and technology resources.&lt;br /&gt;
* The security of a system is only as good as its weakest link. If even one person does not pay attention to security, the security of the whole system is compromised. Read example on [[Thalès Security]]. &lt;br /&gt;
&lt;br /&gt;
Good Security Standards follow the &amp;quot;90/10&amp;quot; Rule :&lt;br /&gt;
&lt;br /&gt;
* 10% of security safeguards are technical.&lt;br /&gt;
* 90% of security safeguards rely on the computer user (YOU) to adhere to good computing practices.&lt;br /&gt;
&lt;br /&gt;
== Security Topics ==&lt;br /&gt;
=== Best security practices for Offies===&lt;br /&gt;
* Data protection - classification level of information&lt;br /&gt;
* Working Area&lt;br /&gt;
* Desktop/Laptop Security&lt;br /&gt;
* Laptop security while on traveling or remote work&lt;br /&gt;
* Mobile device security&lt;br /&gt;
* Password usage&lt;br /&gt;
* Internet Usage&lt;br /&gt;
* Email usage&lt;br /&gt;
* Data Backup &amp;amp; storage&lt;br /&gt;
* Use of Encryption&lt;br /&gt;
* Media Destruction&lt;br /&gt;
&lt;br /&gt;
=== Protection from viruses, trojan horses, malicious codes ===&lt;br /&gt;
* Potential threats&lt;br /&gt;
* Malicious software&lt;br /&gt;
* Signs of malware &amp;amp; example&lt;br /&gt;
* How to protect against malware&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* P2P file sharing&lt;br /&gt;
* Identity theft&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Email phishing&lt;br /&gt;
* Avoid being a victim&lt;br /&gt;
* Reporting security breaches&lt;br /&gt;
&lt;br /&gt;
== Data protection : Classification level of information==&lt;br /&gt;
&lt;br /&gt;
== NDA (Non-disclosure agreement)==&lt;br /&gt;
See [[Non-Disclosure Agreement]]&lt;br /&gt;
&lt;br /&gt;
== Protecting data at work ==&lt;br /&gt;
&#039;&#039;&#039;The best way to secure your system is to use a managed workstation. &#039;&#039;&#039;&lt;br /&gt;
IT Support automatically updates anti-virus and patches on managed systems. &lt;br /&gt;
Here are some additional tips to protect your data.&lt;br /&gt;
* Use strong passwords&lt;br /&gt;
* Pay attention to your computer&#039;s security&lt;br /&gt;
* Use email safely&lt;br /&gt;
* Use the Internet responsibly and securely&lt;br /&gt;
* Dispose of media properly&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Pay attention to your computer&#039;s security&#039;&#039;&#039;&lt;br /&gt;
* Lock your computer with a password-protected screen saver before leaving your desk unattended.  &lt;br /&gt;
* Before you go home, log off the network. &lt;br /&gt;
* Manage your data in a manner that reflects its sensitivity.&lt;br /&gt;
&lt;br /&gt;
== Protecting data at home ==&lt;br /&gt;
If you use your home computer to access applications at Offy and your home computer is not properly protected, you can put Offy’s systems at risk.&lt;br /&gt;
* Use unprivileged account for normal use&lt;br /&gt;
* Always use anti-virus software&lt;br /&gt;
* Use VPN to connect if possible&lt;br /&gt;
* Apply patches regularly&lt;br /&gt;
* Perform regular backups&lt;br /&gt;
* Shutdown your computer when not in use&lt;br /&gt;
* Work securely from home &lt;br /&gt;
* Protect against Malware&lt;br /&gt;
* Make wireless networks secure&lt;br /&gt;
&lt;br /&gt;
IT Helpdesk does not provide support for home computers. If you need additional assistance with your home computer, please contact to us at: itsupportATofficience.com&lt;br /&gt;
&lt;br /&gt;
== Working Area ==&lt;br /&gt;
* &#039;&#039;&#039;Clear your desk at the end of day.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; leave sensitive information (paper, cd/dvd,...) on your desk without protection.&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; try to plug any other devices into Officience network without approvals from ITS&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; use personal devices (laptop,...) without approvals from direct manager &amp;amp; ITS&lt;br /&gt;
&lt;br /&gt;
== Desktop/Laptop Security ==&lt;br /&gt;
* &#039;&#039;&#039;Lock screen as soon as leaving your seat&#039;&#039;&#039;&lt;br /&gt;
* Set password-enabled screen saver with inactive timeout, recommend 15 minutes&lt;br /&gt;
* Antivirus &amp;amp; firewall must be installed and enabled in the desktop&lt;br /&gt;
* Enable &amp;amp; install Windows, Linux &amp;amp; third party updates if available&lt;br /&gt;
* Don’t install software without ITS involvement&lt;br /&gt;
&lt;br /&gt;
== Laptop Security on traveling, remote work ==&lt;br /&gt;
* Apply best security practices for desktop, laptop above&lt;br /&gt;
* Keep only necessary documents on your laptop&lt;br /&gt;
* &#039;&#039;&#039;Set password for confidential documents&#039;&#039;&#039;&lt;br /&gt;
* Encrypt the storage for confidential information&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Use only VPN to connect to Officience information systems&lt;br /&gt;
&lt;br /&gt;
== Mobile devices Security ==&lt;br /&gt;
* Never leave a smartphone unattended. Make it a personal habit to keep the phone closed at all time&lt;br /&gt;
* Keep only necessary documents on your phones&lt;br /&gt;
* Set password for confidential documents&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Don&#039;t send private, personal information without vpn or ssl protection&lt;br /&gt;
&lt;br /&gt;
== Password Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use strong passwords :&#039;&#039;&#039;&lt;br /&gt;
* Minimum of 8 characters in length&lt;br /&gt;
* Not a dictionary word or proper name&lt;br /&gt;
* Not the same as your user ID&lt;br /&gt;
* Change within a maximum of 90 days&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Memorize It – Don’t write it down!&#039;&#039;&#039;&lt;br /&gt;
Password Exchange : &lt;br /&gt;
* No password sharing &lt;br /&gt;
* Don’t send user &amp;amp; password in the same email without encryption&lt;br /&gt;
&lt;br /&gt;
Best practice are:&lt;br /&gt;
&lt;br /&gt;
* User id in 1 email &amp;amp; password in another email&lt;br /&gt;
* User id in email &amp;amp; password provided face-to-face, phone call, hangout&lt;br /&gt;
&amp;lt;sup&amp;gt;Superscript text&amp;lt;/sup&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Keep Your Computer Safe ==&lt;br /&gt;
&lt;br /&gt;
== Internet Safety ==&lt;br /&gt;
&lt;br /&gt;
== Internet Usage ==&lt;br /&gt;
Internet is for professional use.&lt;br /&gt;
&lt;br /&gt;
Use the Internet responsibly and securely :&lt;br /&gt;
* Don&#039;t post sensitive company information or company-related comments on message boards, in chat rooms or anywhere else on the Internet. &lt;br /&gt;
* Don&#039;t visit inappropriate Internet sites. &lt;br /&gt;
&lt;br /&gt;
== Email Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use email safely :&#039;&#039;&#039;&lt;br /&gt;
* Never open suspicious or unsolicited attachments&lt;br /&gt;
* Avoid responding to spam&lt;br /&gt;
* never provide credit card numbers, passwords or personal information in response to email messages&lt;br /&gt;
* install anti-virus software and update frequently&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Double check the recipients before sending emails&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Do not use corporate email for illegal actions&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Data Backup &amp;amp; Storage ==&lt;br /&gt;
&lt;br /&gt;
* Store your data in network drives to keep prevent data loss. All network drives are backuped &lt;br /&gt;
* Backup retention period is 1 week i.e your oldest data can be recovered is 1 week&lt;br /&gt;
* Data ⇒ Backup to Google Cloud (using Offy account)&lt;br /&gt;
* Data ⇒ Backup to Customer or Offy  SharePoint&lt;br /&gt;
&lt;br /&gt;
== Use of Encryption ==&lt;br /&gt;
* Confidential information must be stored on the secure network with restricted access.&lt;br /&gt;
* Whenever it is requested by the information owner to store on any devices other than the secure network server, it must be encrypted.&lt;br /&gt;
* All confidential information transmitted to an email outside domain officience.com must be encrypted.&lt;br /&gt;
&lt;br /&gt;
== Media Destruction ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Dispose of media properly :&#039;&#039;&#039;&lt;br /&gt;
Before electronic media is disposed of, appropriate care must be taken to ensure that no unauthorized person can access data by ordinary means. Electronic media such as floppy disks, rewritable CD-ROMS, zip disks, videotapes, and audiotapes should be erased if the media type allows it or destroyed if erasure is not possible.&lt;br /&gt;
&lt;br /&gt;
== Protection from viruses, trojan horses, malicious codes ==&lt;br /&gt;
=== Potential threats ===&lt;br /&gt;
* Malicious Software (viruses, trojans, worms, spyware, or other)&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* Peer-to-Peer File Sharing&lt;br /&gt;
* Identity Theft&lt;br /&gt;
* Social Engineering&lt;br /&gt;
* Some applications such as Instant Messaging (IM), Peer-to-Peer (P2P) file sharing, pose serious security risks.  You should consider anything typed into IM or transferred through P2P to be visible to the entire internet.&lt;br /&gt;
* When used in conjunction with Internet sites outside of Offy, they can cause undesirable and damaging consequences. For example, you are most likely to encounter malware browsing an external website. &#039;&#039;&#039;When accessing external websites&#039;&#039;&#039;, members of Offy must be especially cautious&lt;br /&gt;
&lt;br /&gt;
== Malicious software ==&lt;br /&gt;
Malicious software (malware) is a serious threat. These are programs that can &amp;quot;infect&amp;quot; other programs, damage hard drives, erase critical information, take critical systems off-line, and forward your data to external sites without your knowledge.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware includes:&#039;&#039;&#039;&lt;br /&gt;
* Viruses&lt;br /&gt;
* Worms&lt;br /&gt;
* Trojan Horse programs&lt;br /&gt;
* Spyware&lt;br /&gt;
* Programs which accidentally harm any system or data&lt;br /&gt;
&lt;br /&gt;
=== Malware (cont) ===&lt;br /&gt;
&lt;br /&gt;
=== Malware Example ===&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware ===&lt;br /&gt;
* Slowdown&lt;br /&gt;
* Pop-Ups&lt;br /&gt;
* Crashes&lt;br /&gt;
* Suspicious hard drive activity&lt;br /&gt;
* Running out of hard drive space&lt;br /&gt;
* Unusually high network activity&lt;br /&gt;
* New browser homepage, new toolbars and/or unwanted websites accessed without your input&lt;br /&gt;
* Unusual messages or programs that start automatically&lt;br /&gt;
* Your security solution is disabled&lt;br /&gt;
* Your friends tell you that they are getting strange messages from you&lt;br /&gt;
* New, unfamiliar icons on desktop + battery life drains quickly&lt;br /&gt;
* You see unusual error messages&lt;br /&gt;
* You are unable to access the Control Panel, Task Manager, Registry Editor or Command Prompt&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware: Example ===&lt;br /&gt;
&lt;br /&gt;
=== What to do if your PC infected with malware ===&lt;br /&gt;
&lt;br /&gt;
Anti-virus software running on Offy’s managed workstations protects against most malware.  &lt;br /&gt;
&lt;br /&gt;
Should you suspect that your computer is infected, take immediate action:&lt;br /&gt;
* Unplug the computer from the network&lt;br /&gt;
* Read the notice carefully…Is it from your real antivirus program? &lt;br /&gt;
* What does the notice say your AV program did with the infected file?&lt;br /&gt;
* SCAN the hard drive to see if the malware has been dealt with&lt;br /&gt;
* Shutdown your system&lt;br /&gt;
* Contact the IT Helpdesk for help.&lt;br /&gt;
&lt;br /&gt;
== Instant Messaging ==&lt;br /&gt;
&lt;br /&gt;
Instant messaging is the popular method of typing online conversations in real time.&lt;br /&gt;
Risks of Externally Hosted Instant Messaging:&lt;br /&gt;
* No virus protection&lt;br /&gt;
* A separate &amp;quot;exit&amp;quot; action is needed to stop it&lt;br /&gt;
* Hijacking and impersonation&lt;br /&gt;
* Malicious code&lt;br /&gt;
* Unauthorized access&lt;br /&gt;
* Poor password security&lt;br /&gt;
* Broadcasts the computer&#039;s presence online even if the interface is closed&lt;br /&gt;
* The data is sent to an external host before going to the intended recipient&lt;br /&gt;
&lt;br /&gt;
On our Skype network, someone in your contact list send you a file, it’s has icon similar to a PDF or DOC file, but, in fact it’s an execute file. If you receive and open the file, your PC will infected with virus/trojan.&lt;br /&gt;
&lt;br /&gt;
== P2P file sharing ==&lt;br /&gt;
P2P (Peer-to-Peer) means file sharing between users on the Internet.  Examples are Gnutella, KaZaA, Napster, Morpheus, eDonkey, BitTorrent and BearShare.&lt;br /&gt;
&lt;br /&gt;
P2P file sharing is inherently insecure and lives on the fringes of legality. Badly-coded clients, viruses and Trojan Horses and potential lawsuits are just some of the many threats that users must face when they venture into the untamed wilderness of the P2P world.  Some threats are:&lt;br /&gt;
* Some P2P programs share everything on your computer with anyone by default. &lt;br /&gt;
* Some P2P programs themselves contain &amp;quot;spyware&amp;quot;.&lt;br /&gt;
* Much of the P2P activity is automatic, and its use is unmonitored. &lt;br /&gt;
* Creating multiple copies of a copyrighted work, music or videos and sharing them is illegal.&lt;br /&gt;
* Computers running P2P programs can be used to spread malware, share private documents, or use your file server for store-and-forward. &lt;br /&gt;
* Various types of illegal files can be downloaded and re-shared over these P2P networks by mistake.&lt;br /&gt;
&lt;br /&gt;
== Identity theft ==&lt;br /&gt;
&lt;br /&gt;
identity theft is the unauthorized collection and use of your personal information for criminal purposes. This information can be used to open credit card and bank accounts, redirect mail, establish cellular phone service...If this happens, you could be left with the bills, charges, bad checks, and taxes.&lt;br /&gt;
&lt;br /&gt;
== Social engineering ==&lt;br /&gt;
&lt;br /&gt;
Social engineering is the practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or Internet to trick people into revealing sensitive information or getting them to do something that is against typical policies.&lt;br /&gt;
&lt;br /&gt;
== Some example about phishing mail ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Fishing (fake email)&#039;&#039;&#039; : Phishing” is the act of sending an email pretending to be from someone “official” with the intention of gaining personal information.&lt;br /&gt;
&lt;br /&gt;
== Avoid being a victim ==&lt;br /&gt;
&lt;br /&gt;
Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information.&lt;br /&gt;
If an unknown individual claims to be from a legitimate organization, try to verify his or her identity directly with the company. &lt;br /&gt;
* Do not provide personal information or information about your organization unless you are certain of a person&#039;s authority to have the information. &lt;br /&gt;
* Do not reveal personal or financial information in email, and do not respond to email solicitations for this information. This includes following links sent in email. &lt;br /&gt;
If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a web site connected to the request.&lt;br /&gt;
&lt;br /&gt;
== Reporting security breaches ==&lt;br /&gt;
&lt;br /&gt;
=== What is a security incident? ===&lt;br /&gt;
&lt;br /&gt;
Anytime you suspect a Offy computer has been compromised, whether that involves theft, hacking, a vicious virus, unauthorized use of IT technology or you witness an inappropriate or offensive use of email or the Web, you should report the incident, or seek help and advice from IT Support. &lt;br /&gt;
&lt;br /&gt;
=== Why should I report a security incident ? ===&lt;br /&gt;
&lt;br /&gt;
If your system has been infected or any data has been lost, IT Support resources can help you clean up your system. Furthermore, as a user of the network, you should be aware of your rights and responsibilities. &lt;br /&gt;
How do I report a security incident?&lt;br /&gt;
Report security violations and computing problems to the IT Help Desk at:&lt;br /&gt;
* itsupportATofficience.com&lt;br /&gt;
* securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== DEVICE USE ==&lt;br /&gt;
Guidelines for usage include:&lt;br /&gt;
* Storage and access of sexually explicit, racist, and hate oriented materials is prohibited.&lt;br /&gt;
* Illegal and/or fraudulent practices are prohibited.&lt;br /&gt;
* Installation of devices and software for non-business related activities is prohibited.  This includes, but is not limited to, gaming devices/software, instant messaging software, wallpaper and screensavers not installed by IT.&lt;br /&gt;
* Attachment of devices and/or software to allow external access to the Offy network not explicitly approved by IT is prohibited.&lt;br /&gt;
* Installation of software not properly licensed, if required, is prohibited.&lt;br /&gt;
* Deactivation of support tools, including antivirus software, systems security, and monitoring tools.&lt;br /&gt;
&lt;br /&gt;
== Useful Email &amp;amp; Websites ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Websites&#039;&#039;&#039;&lt;br /&gt;
* Corporate website: www.officience.com&lt;br /&gt;
* HRMS: hr4you.officience.com&lt;br /&gt;
* Corporate webmail: mail.officience.com&lt;br /&gt;
* Intranet: offyspace.com&lt;br /&gt;
* Helpdesk request: http://offyspace.com/sc/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Emails:&#039;&#039;&#039;&lt;br /&gt;
* IT Support: itsupportATofficience.com&lt;br /&gt;
* HR support: hrATofficience.com&lt;br /&gt;
* security alert: securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
*[https://wiki.officience.com/Security_Policy Security policy framework] following ISO/IEC 27001:2013&lt;br /&gt;
* [[Security team]]&lt;br /&gt;
* [[Thalès Security]]&lt;br /&gt;
&lt;br /&gt;
== Reference ==&lt;br /&gt;
* [https://docs.google.com/presentation/d/1snClXs8nCWRoOe5Mw-WfVTxgnEQVGat6b5gAMR2ZChg Security Training] (by Hoai Linh NGO, 2017)&lt;br /&gt;
&lt;br /&gt;
*[https://wiki.officience.com/Security_Appendix Security appendices]&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Security&amp;diff=987</id>
		<title>Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Security&amp;diff=987"/>
		<updated>2019-07-24T18:39:57Z</updated>

		<summary type="html">&lt;p&gt;Duc: /* See also */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Edmund Hillary &amp;amp; Tenzing Norgay 1933.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Who is responsible for computer security? ==&lt;br /&gt;
&#039;&#039;&#039;Every member of Officience is responsible.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Offies are expected to act responsibly and ethically when accessing Officience’s electronic data and technology resources.&lt;br /&gt;
* The security of a system is only as good as its weakest link. If even one person does not pay attention to security, the security of the whole system is compromised. Read example on [[Thalès Security]]. &lt;br /&gt;
&lt;br /&gt;
Good Security Standards follow the &amp;quot;90/10&amp;quot; Rule :&lt;br /&gt;
&lt;br /&gt;
* 10% of security safeguards are technical.&lt;br /&gt;
* 90% of security safeguards rely on the computer user (YOU) to adhere to good computing practices.&lt;br /&gt;
&lt;br /&gt;
== Security Topics ==&lt;br /&gt;
=== Best security practices for Offies===&lt;br /&gt;
* Data protection - classification level of information&lt;br /&gt;
* Working Area&lt;br /&gt;
* Desktop/Laptop Security&lt;br /&gt;
* Laptop security while on traveling or remote work&lt;br /&gt;
* Mobile device security&lt;br /&gt;
* Password usage&lt;br /&gt;
* Internet Usage&lt;br /&gt;
* Email usage&lt;br /&gt;
* Data Backup &amp;amp; storage&lt;br /&gt;
* Use of Encryption&lt;br /&gt;
* Media Destruction&lt;br /&gt;
&lt;br /&gt;
=== Protection from viruses, trojan horses, malicious codes ===&lt;br /&gt;
* Potential threats&lt;br /&gt;
* Malicious software&lt;br /&gt;
* Signs of malware &amp;amp; example&lt;br /&gt;
* How to protect against malware&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* P2P file sharing&lt;br /&gt;
* Identity theft&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Email phishing&lt;br /&gt;
* Avoid being a victim&lt;br /&gt;
* Reporting security breaches&lt;br /&gt;
&lt;br /&gt;
== Data protection : Classification level of information==&lt;br /&gt;
&lt;br /&gt;
== NDA (Non-disclosure agreement)==&lt;br /&gt;
See [[Non-Disclosure Agreement]]&lt;br /&gt;
&lt;br /&gt;
== Protecting data at work ==&lt;br /&gt;
&#039;&#039;&#039;The best way to secure your system is to use a managed workstation. &#039;&#039;&#039;&lt;br /&gt;
IT Support automatically updates anti-virus and patches on managed systems. &lt;br /&gt;
Here are some additional tips to protect your data.&lt;br /&gt;
* Use strong passwords&lt;br /&gt;
* Pay attention to your computer&#039;s security&lt;br /&gt;
* Use email safely&lt;br /&gt;
* Use the Internet responsibly and securely&lt;br /&gt;
* Dispose of media properly&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Pay attention to your computer&#039;s security&#039;&#039;&#039;&lt;br /&gt;
* Lock your computer with a password-protected screen saver before leaving your desk unattended.  &lt;br /&gt;
* Before you go home, log off the network. &lt;br /&gt;
* Manage your data in a manner that reflects its sensitivity.&lt;br /&gt;
&lt;br /&gt;
== Protecting data at home ==&lt;br /&gt;
If you use your home computer to access applications at Offy and your home computer is not properly protected, you can put Offy’s systems at risk.&lt;br /&gt;
* Use unprivileged account for normal use&lt;br /&gt;
* Always use anti-virus software&lt;br /&gt;
* Use VPN to connect if possible&lt;br /&gt;
* Apply patches regularly&lt;br /&gt;
* Perform regular backups&lt;br /&gt;
* Shutdown your computer when not in use&lt;br /&gt;
* Work securely from home &lt;br /&gt;
* Protect against Malware&lt;br /&gt;
* Make wireless networks secure&lt;br /&gt;
&lt;br /&gt;
IT Helpdesk does not provide support for home computers. If you need additional assistance with your home computer, please contact to us at: itsupportATofficience.com&lt;br /&gt;
&lt;br /&gt;
== Working Area ==&lt;br /&gt;
* &#039;&#039;&#039;Clear your desk at the end of day.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; leave sensitive information (paper, cd/dvd,...) on your desk without protection.&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; try to plug any other devices into Officience network without approvals from ITS&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; use personal devices (laptop,...) without approvals from direct manager &amp;amp; ITS&lt;br /&gt;
&lt;br /&gt;
== Desktop/Laptop Security ==&lt;br /&gt;
* &#039;&#039;&#039;Lock screen as soon as leaving your seat&#039;&#039;&#039;&lt;br /&gt;
* Set password-enabled screen saver with inactive timeout, recommend 15 minutes&lt;br /&gt;
* Antivirus &amp;amp; firewall must be installed and enabled in the desktop&lt;br /&gt;
* Enable &amp;amp; install Windows, Linux &amp;amp; third party updates if available&lt;br /&gt;
* Don’t install software without ITS involvement&lt;br /&gt;
&lt;br /&gt;
== Laptop Security on traveling, remote work ==&lt;br /&gt;
* Apply best security practices for desktop, laptop above&lt;br /&gt;
* Keep only necessary documents on your laptop&lt;br /&gt;
* &#039;&#039;&#039;Set password for confidential documents&#039;&#039;&#039;&lt;br /&gt;
* Encrypt the storage for confidential information&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Use only VPN to connect to Officience information systems&lt;br /&gt;
&lt;br /&gt;
== Mobile devices Security ==&lt;br /&gt;
* Never leave a smartphone unattended. Make it a personal habit to keep the phone closed at all time&lt;br /&gt;
* Keep only necessary documents on your phones&lt;br /&gt;
* Set password for confidential documents&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Don&#039;t send private, personal information without vpn or ssl protection&lt;br /&gt;
&lt;br /&gt;
== Password Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use strong passwords :&#039;&#039;&#039;&lt;br /&gt;
* Minimum of 8 characters in length&lt;br /&gt;
* Not a dictionary word or proper name&lt;br /&gt;
* Not the same as your user ID&lt;br /&gt;
* Change within a maximum of 90 days&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Memorize It – Don’t write it down!&#039;&#039;&#039;&lt;br /&gt;
Password Exchange : &lt;br /&gt;
* No password sharing &lt;br /&gt;
* Don’t send user &amp;amp; password in the same email without encryption&lt;br /&gt;
&lt;br /&gt;
Best practice are:&lt;br /&gt;
&lt;br /&gt;
* User id in 1 email &amp;amp; password in another email&lt;br /&gt;
* User id in email &amp;amp; password provided face-to-face, phone call, hangout&lt;br /&gt;
&amp;lt;sup&amp;gt;Superscript text&amp;lt;/sup&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Keep Your Computer Safe ==&lt;br /&gt;
&lt;br /&gt;
== Internet Safety ==&lt;br /&gt;
&lt;br /&gt;
== Internet Usage ==&lt;br /&gt;
Internet is for professional use.&lt;br /&gt;
&lt;br /&gt;
Use the Internet responsibly and securely :&lt;br /&gt;
* Don&#039;t post sensitive company information or company-related comments on message boards, in chat rooms or anywhere else on the Internet. &lt;br /&gt;
* Don&#039;t visit inappropriate Internet sites. &lt;br /&gt;
&lt;br /&gt;
== Email Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use email safely :&#039;&#039;&#039;&lt;br /&gt;
* Never open suspicious or unsolicited attachments&lt;br /&gt;
* Avoid responding to spam&lt;br /&gt;
* never provide credit card numbers, passwords or personal information in response to email messages&lt;br /&gt;
* install anti-virus software and update frequently&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Double check the recipients before sending emails&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Do not use corporate email for illegal actions&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Data Backup &amp;amp; Storage ==&lt;br /&gt;
&lt;br /&gt;
* Store your data in network drives to keep prevent data loss. All network drives are backuped &lt;br /&gt;
* Backup retention period is 1 week i.e your oldest data can be recovered is 1 week&lt;br /&gt;
* Data ⇒ Backup to Google Cloud (using Offy account)&lt;br /&gt;
* Data ⇒ Backup to Customer or Offy  SharePoint&lt;br /&gt;
&lt;br /&gt;
== Use of Encryption ==&lt;br /&gt;
* Confidential information must be stored on the secure network with restricted access.&lt;br /&gt;
* Whenever it is requested by the information owner to store on any devices other than the secure network server, it must be encrypted.&lt;br /&gt;
* All confidential information transmitted to an email outside domain officience.com must be encrypted.&lt;br /&gt;
&lt;br /&gt;
== Media Destruction ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Dispose of media properly :&#039;&#039;&#039;&lt;br /&gt;
Before electronic media is disposed of, appropriate care must be taken to ensure that no unauthorized person can access data by ordinary means. Electronic media such as floppy disks, rewritable CD-ROMS, zip disks, videotapes, and audiotapes should be erased if the media type allows it or destroyed if erasure is not possible.&lt;br /&gt;
&lt;br /&gt;
== Protection from viruses, trojan horses, malicious codes ==&lt;br /&gt;
=== Potential threats ===&lt;br /&gt;
* Malicious Software (viruses, trojans, worms, spyware, or other)&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* Peer-to-Peer File Sharing&lt;br /&gt;
* Identity Theft&lt;br /&gt;
* Social Engineering&lt;br /&gt;
* Some applications such as Instant Messaging (IM), Peer-to-Peer (P2P) file sharing, pose serious security risks.  You should consider anything typed into IM or transferred through P2P to be visible to the entire internet.&lt;br /&gt;
* When used in conjunction with Internet sites outside of Offy, they can cause undesirable and damaging consequences. For example, you are most likely to encounter malware browsing an external website. &#039;&#039;&#039;When accessing external websites&#039;&#039;&#039;, members of Offy must be especially cautious&lt;br /&gt;
&lt;br /&gt;
== Malicious software ==&lt;br /&gt;
Malicious software (malware) is a serious threat. These are programs that can &amp;quot;infect&amp;quot; other programs, damage hard drives, erase critical information, take critical systems off-line, and forward your data to external sites without your knowledge.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware includes:&#039;&#039;&#039;&lt;br /&gt;
* Viruses&lt;br /&gt;
* Worms&lt;br /&gt;
* Trojan Horse programs&lt;br /&gt;
* Spyware&lt;br /&gt;
* Programs which accidentally harm any system or data&lt;br /&gt;
&lt;br /&gt;
=== Malware (cont) ===&lt;br /&gt;
&lt;br /&gt;
=== Malware Example ===&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware ===&lt;br /&gt;
* Slowdown&lt;br /&gt;
* Pop-Ups&lt;br /&gt;
* Crashes&lt;br /&gt;
* Suspicious hard drive activity&lt;br /&gt;
* Running out of hard drive space&lt;br /&gt;
* Unusually high network activity&lt;br /&gt;
* New browser homepage, new toolbars and/or unwanted websites accessed without your input&lt;br /&gt;
* Unusual messages or programs that start automatically&lt;br /&gt;
* Your security solution is disabled&lt;br /&gt;
* Your friends tell you that they are getting strange messages from you&lt;br /&gt;
* New, unfamiliar icons on desktop + battery life drains quickly&lt;br /&gt;
* You see unusual error messages&lt;br /&gt;
* You are unable to access the Control Panel, Task Manager, Registry Editor or Command Prompt&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware: Example ===&lt;br /&gt;
&lt;br /&gt;
=== What to do if your PC infected with malware ===&lt;br /&gt;
&lt;br /&gt;
Anti-virus software running on Offy’s managed workstations protects against most malware.  &lt;br /&gt;
&lt;br /&gt;
Should you suspect that your computer is infected, take immediate action:&lt;br /&gt;
* Unplug the computer from the network&lt;br /&gt;
* Read the notice carefully…Is it from your real antivirus program? &lt;br /&gt;
* What does the notice say your AV program did with the infected file?&lt;br /&gt;
* SCAN the hard drive to see if the malware has been dealt with&lt;br /&gt;
* Shutdown your system&lt;br /&gt;
* Contact the IT Helpdesk for help.&lt;br /&gt;
&lt;br /&gt;
== Instant Messaging ==&lt;br /&gt;
&lt;br /&gt;
Instant messaging is the popular method of typing online conversations in real time.&lt;br /&gt;
Risks of Externally Hosted Instant Messaging:&lt;br /&gt;
* No virus protection&lt;br /&gt;
* A separate &amp;quot;exit&amp;quot; action is needed to stop it&lt;br /&gt;
* Hijacking and impersonation&lt;br /&gt;
* Malicious code&lt;br /&gt;
* Unauthorized access&lt;br /&gt;
* Poor password security&lt;br /&gt;
* Broadcasts the computer&#039;s presence online even if the interface is closed&lt;br /&gt;
* The data is sent to an external host before going to the intended recipient&lt;br /&gt;
&lt;br /&gt;
On our Skype network, someone in your contact list send you a file, it’s has icon similar to a PDF or DOC file, but, in fact it’s an execute file. If you receive and open the file, your PC will infected with virus/trojan.&lt;br /&gt;
&lt;br /&gt;
== P2P file sharing ==&lt;br /&gt;
P2P (Peer-to-Peer) means file sharing between users on the Internet.  Examples are Gnutella, KaZaA, Napster, Morpheus, eDonkey, BitTorrent and BearShare.&lt;br /&gt;
&lt;br /&gt;
P2P file sharing is inherently insecure and lives on the fringes of legality. Badly-coded clients, viruses and Trojan Horses and potential lawsuits are just some of the many threats that users must face when they venture into the untamed wilderness of the P2P world.  Some threats are:&lt;br /&gt;
* Some P2P programs share everything on your computer with anyone by default. &lt;br /&gt;
* Some P2P programs themselves contain &amp;quot;spyware&amp;quot;.&lt;br /&gt;
* Much of the P2P activity is automatic, and its use is unmonitored. &lt;br /&gt;
* Creating multiple copies of a copyrighted work, music or videos and sharing them is illegal.&lt;br /&gt;
* Computers running P2P programs can be used to spread malware, share private documents, or use your file server for store-and-forward. &lt;br /&gt;
* Various types of illegal files can be downloaded and re-shared over these P2P networks by mistake.&lt;br /&gt;
&lt;br /&gt;
== Identity theft ==&lt;br /&gt;
&lt;br /&gt;
identity theft is the unauthorized collection and use of your personal information for criminal purposes. This information can be used to open credit card and bank accounts, redirect mail, establish cellular phone service...If this happens, you could be left with the bills, charges, bad checks, and taxes.&lt;br /&gt;
&lt;br /&gt;
== Social engineering ==&lt;br /&gt;
&lt;br /&gt;
Social engineering is the practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or Internet to trick people into revealing sensitive information or getting them to do something that is against typical policies.&lt;br /&gt;
&lt;br /&gt;
== Some example about phishing mail ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Fishing (fake email)&#039;&#039;&#039; : Phishing” is the act of sending an email pretending to be from someone “official” with the intention of gaining personal information.&lt;br /&gt;
&lt;br /&gt;
== Avoid being a victim ==&lt;br /&gt;
&lt;br /&gt;
Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information.&lt;br /&gt;
If an unknown individual claims to be from a legitimate organization, try to verify his or her identity directly with the company. &lt;br /&gt;
* Do not provide personal information or information about your organization unless you are certain of a person&#039;s authority to have the information. &lt;br /&gt;
* Do not reveal personal or financial information in email, and do not respond to email solicitations for this information. This includes following links sent in email. &lt;br /&gt;
If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a web site connected to the request.&lt;br /&gt;
&lt;br /&gt;
== Reporting security breaches ==&lt;br /&gt;
&lt;br /&gt;
=== What is a security incident? ===&lt;br /&gt;
&lt;br /&gt;
Anytime you suspect a Offy computer has been compromised, whether that involves theft, hacking, a vicious virus, unauthorized use of IT technology or you witness an inappropriate or offensive use of email or the Web, you should report the incident, or seek help and advice from IT Support. &lt;br /&gt;
&lt;br /&gt;
=== Why should I report a security incident ? ===&lt;br /&gt;
&lt;br /&gt;
If your system has been infected or any data has been lost, IT Support resources can help you clean up your system. Furthermore, as a user of the network, you should be aware of your rights and responsibilities. &lt;br /&gt;
How do I report a security incident?&lt;br /&gt;
Report security violations and computing problems to the IT Help Desk at:&lt;br /&gt;
* itsupportATofficience.com&lt;br /&gt;
* securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== DEVICE USE ==&lt;br /&gt;
Guidelines for usage include:&lt;br /&gt;
* Storage and access of sexually explicit, racist, and hate oriented materials is prohibited.&lt;br /&gt;
* Illegal and/or fraudulent practices are prohibited.&lt;br /&gt;
* Installation of devices and software for non-business related activities is prohibited.  This includes, but is not limited to, gaming devices/software, instant messaging software, wallpaper and screensavers not installed by IT.&lt;br /&gt;
* Attachment of devices and/or software to allow external access to the Offy network not explicitly approved by IT is prohibited.&lt;br /&gt;
* Installation of software not properly licensed, if required, is prohibited.&lt;br /&gt;
* Deactivation of support tools, including antivirus software, systems security, and monitoring tools.&lt;br /&gt;
&lt;br /&gt;
== Useful Email &amp;amp; Websites ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Websites&#039;&#039;&#039;&lt;br /&gt;
* Corporate website: www.officience.com&lt;br /&gt;
* HRMS: hr4you.officience.com&lt;br /&gt;
* Corporate webmail: mail.officience.com&lt;br /&gt;
* Intranet: offyspace.com&lt;br /&gt;
* Helpdesk request: http://offyspace.com/sc/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Emails:&#039;&#039;&#039;&lt;br /&gt;
* IT Support: itsupportATofficience.com&lt;br /&gt;
* HR support: hrATofficience.com&lt;br /&gt;
* security alert: securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
*[https://wiki.officience.com/Security_Policy Security policy details] following ISO/IEC 27001:2013 &lt;br /&gt;
* [[Security team]]&lt;br /&gt;
* [[Thalès Security]]&lt;br /&gt;
&lt;br /&gt;
== Reference ==&lt;br /&gt;
* [https://docs.google.com/presentation/d/1snClXs8nCWRoOe5Mw-WfVTxgnEQVGat6b5gAMR2ZChg Security Training] (by Hoai Linh NGO, 2017)&lt;br /&gt;
&lt;br /&gt;
*[https://wiki.officience.com/Security_Appendix Security appendices]&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Security&amp;diff=986</id>
		<title>Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Security&amp;diff=986"/>
		<updated>2019-07-24T18:38:59Z</updated>

		<summary type="html">&lt;p&gt;Duc: /* See also */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Edmund Hillary &amp;amp; Tenzing Norgay 1933.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Who is responsible for computer security? ==&lt;br /&gt;
&#039;&#039;&#039;Every member of Officience is responsible.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Offies are expected to act responsibly and ethically when accessing Officience’s electronic data and technology resources.&lt;br /&gt;
* The security of a system is only as good as its weakest link. If even one person does not pay attention to security, the security of the whole system is compromised. Read example on [[Thalès Security]]. &lt;br /&gt;
&lt;br /&gt;
Good Security Standards follow the &amp;quot;90/10&amp;quot; Rule :&lt;br /&gt;
&lt;br /&gt;
* 10% of security safeguards are technical.&lt;br /&gt;
* 90% of security safeguards rely on the computer user (YOU) to adhere to good computing practices.&lt;br /&gt;
&lt;br /&gt;
== Security Topics ==&lt;br /&gt;
=== Best security practices for Offies===&lt;br /&gt;
* Data protection - classification level of information&lt;br /&gt;
* Working Area&lt;br /&gt;
* Desktop/Laptop Security&lt;br /&gt;
* Laptop security while on traveling or remote work&lt;br /&gt;
* Mobile device security&lt;br /&gt;
* Password usage&lt;br /&gt;
* Internet Usage&lt;br /&gt;
* Email usage&lt;br /&gt;
* Data Backup &amp;amp; storage&lt;br /&gt;
* Use of Encryption&lt;br /&gt;
* Media Destruction&lt;br /&gt;
&lt;br /&gt;
=== Protection from viruses, trojan horses, malicious codes ===&lt;br /&gt;
* Potential threats&lt;br /&gt;
* Malicious software&lt;br /&gt;
* Signs of malware &amp;amp; example&lt;br /&gt;
* How to protect against malware&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* P2P file sharing&lt;br /&gt;
* Identity theft&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Email phishing&lt;br /&gt;
* Avoid being a victim&lt;br /&gt;
* Reporting security breaches&lt;br /&gt;
&lt;br /&gt;
== Data protection : Classification level of information==&lt;br /&gt;
&lt;br /&gt;
== NDA (Non-disclosure agreement)==&lt;br /&gt;
See [[Non-Disclosure Agreement]]&lt;br /&gt;
&lt;br /&gt;
== Protecting data at work ==&lt;br /&gt;
&#039;&#039;&#039;The best way to secure your system is to use a managed workstation. &#039;&#039;&#039;&lt;br /&gt;
IT Support automatically updates anti-virus and patches on managed systems. &lt;br /&gt;
Here are some additional tips to protect your data.&lt;br /&gt;
* Use strong passwords&lt;br /&gt;
* Pay attention to your computer&#039;s security&lt;br /&gt;
* Use email safely&lt;br /&gt;
* Use the Internet responsibly and securely&lt;br /&gt;
* Dispose of media properly&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Pay attention to your computer&#039;s security&#039;&#039;&#039;&lt;br /&gt;
* Lock your computer with a password-protected screen saver before leaving your desk unattended.  &lt;br /&gt;
* Before you go home, log off the network. &lt;br /&gt;
* Manage your data in a manner that reflects its sensitivity.&lt;br /&gt;
&lt;br /&gt;
== Protecting data at home ==&lt;br /&gt;
If you use your home computer to access applications at Offy and your home computer is not properly protected, you can put Offy’s systems at risk.&lt;br /&gt;
* Use unprivileged account for normal use&lt;br /&gt;
* Always use anti-virus software&lt;br /&gt;
* Use VPN to connect if possible&lt;br /&gt;
* Apply patches regularly&lt;br /&gt;
* Perform regular backups&lt;br /&gt;
* Shutdown your computer when not in use&lt;br /&gt;
* Work securely from home &lt;br /&gt;
* Protect against Malware&lt;br /&gt;
* Make wireless networks secure&lt;br /&gt;
&lt;br /&gt;
IT Helpdesk does not provide support for home computers. If you need additional assistance with your home computer, please contact to us at: itsupportATofficience.com&lt;br /&gt;
&lt;br /&gt;
== Working Area ==&lt;br /&gt;
* &#039;&#039;&#039;Clear your desk at the end of day.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; leave sensitive information (paper, cd/dvd,...) on your desk without protection.&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; try to plug any other devices into Officience network without approvals from ITS&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; use personal devices (laptop,...) without approvals from direct manager &amp;amp; ITS&lt;br /&gt;
&lt;br /&gt;
== Desktop/Laptop Security ==&lt;br /&gt;
* &#039;&#039;&#039;Lock screen as soon as leaving your seat&#039;&#039;&#039;&lt;br /&gt;
* Set password-enabled screen saver with inactive timeout, recommend 15 minutes&lt;br /&gt;
* Antivirus &amp;amp; firewall must be installed and enabled in the desktop&lt;br /&gt;
* Enable &amp;amp; install Windows, Linux &amp;amp; third party updates if available&lt;br /&gt;
* Don’t install software without ITS involvement&lt;br /&gt;
&lt;br /&gt;
== Laptop Security on traveling, remote work ==&lt;br /&gt;
* Apply best security practices for desktop, laptop above&lt;br /&gt;
* Keep only necessary documents on your laptop&lt;br /&gt;
* &#039;&#039;&#039;Set password for confidential documents&#039;&#039;&#039;&lt;br /&gt;
* Encrypt the storage for confidential information&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Use only VPN to connect to Officience information systems&lt;br /&gt;
&lt;br /&gt;
== Mobile devices Security ==&lt;br /&gt;
* Never leave a smartphone unattended. Make it a personal habit to keep the phone closed at all time&lt;br /&gt;
* Keep only necessary documents on your phones&lt;br /&gt;
* Set password for confidential documents&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Don&#039;t send private, personal information without vpn or ssl protection&lt;br /&gt;
&lt;br /&gt;
== Password Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use strong passwords :&#039;&#039;&#039;&lt;br /&gt;
* Minimum of 8 characters in length&lt;br /&gt;
* Not a dictionary word or proper name&lt;br /&gt;
* Not the same as your user ID&lt;br /&gt;
* Change within a maximum of 90 days&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Memorize It – Don’t write it down!&#039;&#039;&#039;&lt;br /&gt;
Password Exchange : &lt;br /&gt;
* No password sharing &lt;br /&gt;
* Don’t send user &amp;amp; password in the same email without encryption&lt;br /&gt;
&lt;br /&gt;
Best practice are:&lt;br /&gt;
&lt;br /&gt;
* User id in 1 email &amp;amp; password in another email&lt;br /&gt;
* User id in email &amp;amp; password provided face-to-face, phone call, hangout&lt;br /&gt;
&amp;lt;sup&amp;gt;Superscript text&amp;lt;/sup&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Keep Your Computer Safe ==&lt;br /&gt;
&lt;br /&gt;
== Internet Safety ==&lt;br /&gt;
&lt;br /&gt;
== Internet Usage ==&lt;br /&gt;
Internet is for professional use.&lt;br /&gt;
&lt;br /&gt;
Use the Internet responsibly and securely :&lt;br /&gt;
* Don&#039;t post sensitive company information or company-related comments on message boards, in chat rooms or anywhere else on the Internet. &lt;br /&gt;
* Don&#039;t visit inappropriate Internet sites. &lt;br /&gt;
&lt;br /&gt;
== Email Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use email safely :&#039;&#039;&#039;&lt;br /&gt;
* Never open suspicious or unsolicited attachments&lt;br /&gt;
* Avoid responding to spam&lt;br /&gt;
* never provide credit card numbers, passwords or personal information in response to email messages&lt;br /&gt;
* install anti-virus software and update frequently&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Double check the recipients before sending emails&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Do not use corporate email for illegal actions&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Data Backup &amp;amp; Storage ==&lt;br /&gt;
&lt;br /&gt;
* Store your data in network drives to keep prevent data loss. All network drives are backuped &lt;br /&gt;
* Backup retention period is 1 week i.e your oldest data can be recovered is 1 week&lt;br /&gt;
* Data ⇒ Backup to Google Cloud (using Offy account)&lt;br /&gt;
* Data ⇒ Backup to Customer or Offy  SharePoint&lt;br /&gt;
&lt;br /&gt;
== Use of Encryption ==&lt;br /&gt;
* Confidential information must be stored on the secure network with restricted access.&lt;br /&gt;
* Whenever it is requested by the information owner to store on any devices other than the secure network server, it must be encrypted.&lt;br /&gt;
* All confidential information transmitted to an email outside domain officience.com must be encrypted.&lt;br /&gt;
&lt;br /&gt;
== Media Destruction ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Dispose of media properly :&#039;&#039;&#039;&lt;br /&gt;
Before electronic media is disposed of, appropriate care must be taken to ensure that no unauthorized person can access data by ordinary means. Electronic media such as floppy disks, rewritable CD-ROMS, zip disks, videotapes, and audiotapes should be erased if the media type allows it or destroyed if erasure is not possible.&lt;br /&gt;
&lt;br /&gt;
== Protection from viruses, trojan horses, malicious codes ==&lt;br /&gt;
=== Potential threats ===&lt;br /&gt;
* Malicious Software (viruses, trojans, worms, spyware, or other)&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* Peer-to-Peer File Sharing&lt;br /&gt;
* Identity Theft&lt;br /&gt;
* Social Engineering&lt;br /&gt;
* Some applications such as Instant Messaging (IM), Peer-to-Peer (P2P) file sharing, pose serious security risks.  You should consider anything typed into IM or transferred through P2P to be visible to the entire internet.&lt;br /&gt;
* When used in conjunction with Internet sites outside of Offy, they can cause undesirable and damaging consequences. For example, you are most likely to encounter malware browsing an external website. &#039;&#039;&#039;When accessing external websites&#039;&#039;&#039;, members of Offy must be especially cautious&lt;br /&gt;
&lt;br /&gt;
== Malicious software ==&lt;br /&gt;
Malicious software (malware) is a serious threat. These are programs that can &amp;quot;infect&amp;quot; other programs, damage hard drives, erase critical information, take critical systems off-line, and forward your data to external sites without your knowledge.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware includes:&#039;&#039;&#039;&lt;br /&gt;
* Viruses&lt;br /&gt;
* Worms&lt;br /&gt;
* Trojan Horse programs&lt;br /&gt;
* Spyware&lt;br /&gt;
* Programs which accidentally harm any system or data&lt;br /&gt;
&lt;br /&gt;
=== Malware (cont) ===&lt;br /&gt;
&lt;br /&gt;
=== Malware Example ===&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware ===&lt;br /&gt;
* Slowdown&lt;br /&gt;
* Pop-Ups&lt;br /&gt;
* Crashes&lt;br /&gt;
* Suspicious hard drive activity&lt;br /&gt;
* Running out of hard drive space&lt;br /&gt;
* Unusually high network activity&lt;br /&gt;
* New browser homepage, new toolbars and/or unwanted websites accessed without your input&lt;br /&gt;
* Unusual messages or programs that start automatically&lt;br /&gt;
* Your security solution is disabled&lt;br /&gt;
* Your friends tell you that they are getting strange messages from you&lt;br /&gt;
* New, unfamiliar icons on desktop + battery life drains quickly&lt;br /&gt;
* You see unusual error messages&lt;br /&gt;
* You are unable to access the Control Panel, Task Manager, Registry Editor or Command Prompt&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware: Example ===&lt;br /&gt;
&lt;br /&gt;
=== What to do if your PC infected with malware ===&lt;br /&gt;
&lt;br /&gt;
Anti-virus software running on Offy’s managed workstations protects against most malware.  &lt;br /&gt;
&lt;br /&gt;
Should you suspect that your computer is infected, take immediate action:&lt;br /&gt;
* Unplug the computer from the network&lt;br /&gt;
* Read the notice carefully…Is it from your real antivirus program? &lt;br /&gt;
* What does the notice say your AV program did with the infected file?&lt;br /&gt;
* SCAN the hard drive to see if the malware has been dealt with&lt;br /&gt;
* Shutdown your system&lt;br /&gt;
* Contact the IT Helpdesk for help.&lt;br /&gt;
&lt;br /&gt;
== Instant Messaging ==&lt;br /&gt;
&lt;br /&gt;
Instant messaging is the popular method of typing online conversations in real time.&lt;br /&gt;
Risks of Externally Hosted Instant Messaging:&lt;br /&gt;
* No virus protection&lt;br /&gt;
* A separate &amp;quot;exit&amp;quot; action is needed to stop it&lt;br /&gt;
* Hijacking and impersonation&lt;br /&gt;
* Malicious code&lt;br /&gt;
* Unauthorized access&lt;br /&gt;
* Poor password security&lt;br /&gt;
* Broadcasts the computer&#039;s presence online even if the interface is closed&lt;br /&gt;
* The data is sent to an external host before going to the intended recipient&lt;br /&gt;
&lt;br /&gt;
On our Skype network, someone in your contact list send you a file, it’s has icon similar to a PDF or DOC file, but, in fact it’s an execute file. If you receive and open the file, your PC will infected with virus/trojan.&lt;br /&gt;
&lt;br /&gt;
== P2P file sharing ==&lt;br /&gt;
P2P (Peer-to-Peer) means file sharing between users on the Internet.  Examples are Gnutella, KaZaA, Napster, Morpheus, eDonkey, BitTorrent and BearShare.&lt;br /&gt;
&lt;br /&gt;
P2P file sharing is inherently insecure and lives on the fringes of legality. Badly-coded clients, viruses and Trojan Horses and potential lawsuits are just some of the many threats that users must face when they venture into the untamed wilderness of the P2P world.  Some threats are:&lt;br /&gt;
* Some P2P programs share everything on your computer with anyone by default. &lt;br /&gt;
* Some P2P programs themselves contain &amp;quot;spyware&amp;quot;.&lt;br /&gt;
* Much of the P2P activity is automatic, and its use is unmonitored. &lt;br /&gt;
* Creating multiple copies of a copyrighted work, music or videos and sharing them is illegal.&lt;br /&gt;
* Computers running P2P programs can be used to spread malware, share private documents, or use your file server for store-and-forward. &lt;br /&gt;
* Various types of illegal files can be downloaded and re-shared over these P2P networks by mistake.&lt;br /&gt;
&lt;br /&gt;
== Identity theft ==&lt;br /&gt;
&lt;br /&gt;
identity theft is the unauthorized collection and use of your personal information for criminal purposes. This information can be used to open credit card and bank accounts, redirect mail, establish cellular phone service...If this happens, you could be left with the bills, charges, bad checks, and taxes.&lt;br /&gt;
&lt;br /&gt;
== Social engineering ==&lt;br /&gt;
&lt;br /&gt;
Social engineering is the practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or Internet to trick people into revealing sensitive information or getting them to do something that is against typical policies.&lt;br /&gt;
&lt;br /&gt;
== Some example about phishing mail ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Fishing (fake email)&#039;&#039;&#039; : Phishing” is the act of sending an email pretending to be from someone “official” with the intention of gaining personal information.&lt;br /&gt;
&lt;br /&gt;
== Avoid being a victim ==&lt;br /&gt;
&lt;br /&gt;
Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information.&lt;br /&gt;
If an unknown individual claims to be from a legitimate organization, try to verify his or her identity directly with the company. &lt;br /&gt;
* Do not provide personal information or information about your organization unless you are certain of a person&#039;s authority to have the information. &lt;br /&gt;
* Do not reveal personal or financial information in email, and do not respond to email solicitations for this information. This includes following links sent in email. &lt;br /&gt;
If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a web site connected to the request.&lt;br /&gt;
&lt;br /&gt;
== Reporting security breaches ==&lt;br /&gt;
&lt;br /&gt;
=== What is a security incident? ===&lt;br /&gt;
&lt;br /&gt;
Anytime you suspect a Offy computer has been compromised, whether that involves theft, hacking, a vicious virus, unauthorized use of IT technology or you witness an inappropriate or offensive use of email or the Web, you should report the incident, or seek help and advice from IT Support. &lt;br /&gt;
&lt;br /&gt;
=== Why should I report a security incident ? ===&lt;br /&gt;
&lt;br /&gt;
If your system has been infected or any data has been lost, IT Support resources can help you clean up your system. Furthermore, as a user of the network, you should be aware of your rights and responsibilities. &lt;br /&gt;
How do I report a security incident?&lt;br /&gt;
Report security violations and computing problems to the IT Help Desk at:&lt;br /&gt;
* itsupportATofficience.com&lt;br /&gt;
* securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== DEVICE USE ==&lt;br /&gt;
Guidelines for usage include:&lt;br /&gt;
* Storage and access of sexually explicit, racist, and hate oriented materials is prohibited.&lt;br /&gt;
* Illegal and/or fraudulent practices are prohibited.&lt;br /&gt;
* Installation of devices and software for non-business related activities is prohibited.  This includes, but is not limited to, gaming devices/software, instant messaging software, wallpaper and screensavers not installed by IT.&lt;br /&gt;
* Attachment of devices and/or software to allow external access to the Offy network not explicitly approved by IT is prohibited.&lt;br /&gt;
* Installation of software not properly licensed, if required, is prohibited.&lt;br /&gt;
* Deactivation of support tools, including antivirus software, systems security, and monitoring tools.&lt;br /&gt;
&lt;br /&gt;
== Useful Email &amp;amp; Websites ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Websites&#039;&#039;&#039;&lt;br /&gt;
* Corporate website: www.officience.com&lt;br /&gt;
* HRMS: hr4you.officience.com&lt;br /&gt;
* Corporate webmail: mail.officience.com&lt;br /&gt;
* Intranet: offyspace.com&lt;br /&gt;
* Helpdesk request: http://offyspace.com/sc/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Emails:&#039;&#039;&#039;&lt;br /&gt;
* IT Support: itsupportATofficience.com&lt;br /&gt;
* HR support: hrATofficience.com&lt;br /&gt;
* security alert: securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
*[https://wiki.officience.com/Security_Policy Security policy details] &lt;br /&gt;
* [[Security team]]&lt;br /&gt;
* [[Thalès Security]]&lt;br /&gt;
&lt;br /&gt;
== Reference ==&lt;br /&gt;
* [https://docs.google.com/presentation/d/1snClXs8nCWRoOe5Mw-WfVTxgnEQVGat6b5gAMR2ZChg Security Training] (by Hoai Linh NGO, 2017)&lt;br /&gt;
&lt;br /&gt;
*[https://wiki.officience.com/Security_Appendix Security appendices]&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Security&amp;diff=985</id>
		<title>Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Security&amp;diff=985"/>
		<updated>2019-07-24T18:38:16Z</updated>

		<summary type="html">&lt;p&gt;Duc: /* Reference */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Edmund Hillary &amp;amp; Tenzing Norgay 1933.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Who is responsible for computer security? ==&lt;br /&gt;
&#039;&#039;&#039;Every member of Officience is responsible.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Offies are expected to act responsibly and ethically when accessing Officience’s electronic data and technology resources.&lt;br /&gt;
* The security of a system is only as good as its weakest link. If even one person does not pay attention to security, the security of the whole system is compromised. Read example on [[Thalès Security]]. &lt;br /&gt;
&lt;br /&gt;
Good Security Standards follow the &amp;quot;90/10&amp;quot; Rule :&lt;br /&gt;
&lt;br /&gt;
* 10% of security safeguards are technical.&lt;br /&gt;
* 90% of security safeguards rely on the computer user (YOU) to adhere to good computing practices.&lt;br /&gt;
&lt;br /&gt;
== Security Topics ==&lt;br /&gt;
=== Best security practices for Offies===&lt;br /&gt;
* Data protection - classification level of information&lt;br /&gt;
* Working Area&lt;br /&gt;
* Desktop/Laptop Security&lt;br /&gt;
* Laptop security while on traveling or remote work&lt;br /&gt;
* Mobile device security&lt;br /&gt;
* Password usage&lt;br /&gt;
* Internet Usage&lt;br /&gt;
* Email usage&lt;br /&gt;
* Data Backup &amp;amp; storage&lt;br /&gt;
* Use of Encryption&lt;br /&gt;
* Media Destruction&lt;br /&gt;
&lt;br /&gt;
=== Protection from viruses, trojan horses, malicious codes ===&lt;br /&gt;
* Potential threats&lt;br /&gt;
* Malicious software&lt;br /&gt;
* Signs of malware &amp;amp; example&lt;br /&gt;
* How to protect against malware&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* P2P file sharing&lt;br /&gt;
* Identity theft&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Email phishing&lt;br /&gt;
* Avoid being a victim&lt;br /&gt;
* Reporting security breaches&lt;br /&gt;
&lt;br /&gt;
== Data protection : Classification level of information==&lt;br /&gt;
&lt;br /&gt;
== NDA (Non-disclosure agreement)==&lt;br /&gt;
See [[Non-Disclosure Agreement]]&lt;br /&gt;
&lt;br /&gt;
== Protecting data at work ==&lt;br /&gt;
&#039;&#039;&#039;The best way to secure your system is to use a managed workstation. &#039;&#039;&#039;&lt;br /&gt;
IT Support automatically updates anti-virus and patches on managed systems. &lt;br /&gt;
Here are some additional tips to protect your data.&lt;br /&gt;
* Use strong passwords&lt;br /&gt;
* Pay attention to your computer&#039;s security&lt;br /&gt;
* Use email safely&lt;br /&gt;
* Use the Internet responsibly and securely&lt;br /&gt;
* Dispose of media properly&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Pay attention to your computer&#039;s security&#039;&#039;&#039;&lt;br /&gt;
* Lock your computer with a password-protected screen saver before leaving your desk unattended.  &lt;br /&gt;
* Before you go home, log off the network. &lt;br /&gt;
* Manage your data in a manner that reflects its sensitivity.&lt;br /&gt;
&lt;br /&gt;
== Protecting data at home ==&lt;br /&gt;
If you use your home computer to access applications at Offy and your home computer is not properly protected, you can put Offy’s systems at risk.&lt;br /&gt;
* Use unprivileged account for normal use&lt;br /&gt;
* Always use anti-virus software&lt;br /&gt;
* Use VPN to connect if possible&lt;br /&gt;
* Apply patches regularly&lt;br /&gt;
* Perform regular backups&lt;br /&gt;
* Shutdown your computer when not in use&lt;br /&gt;
* Work securely from home &lt;br /&gt;
* Protect against Malware&lt;br /&gt;
* Make wireless networks secure&lt;br /&gt;
&lt;br /&gt;
IT Helpdesk does not provide support for home computers. If you need additional assistance with your home computer, please contact to us at: itsupportATofficience.com&lt;br /&gt;
&lt;br /&gt;
== Working Area ==&lt;br /&gt;
* &#039;&#039;&#039;Clear your desk at the end of day.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; leave sensitive information (paper, cd/dvd,...) on your desk without protection.&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; try to plug any other devices into Officience network without approvals from ITS&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; use personal devices (laptop,...) without approvals from direct manager &amp;amp; ITS&lt;br /&gt;
&lt;br /&gt;
== Desktop/Laptop Security ==&lt;br /&gt;
* &#039;&#039;&#039;Lock screen as soon as leaving your seat&#039;&#039;&#039;&lt;br /&gt;
* Set password-enabled screen saver with inactive timeout, recommend 15 minutes&lt;br /&gt;
* Antivirus &amp;amp; firewall must be installed and enabled in the desktop&lt;br /&gt;
* Enable &amp;amp; install Windows, Linux &amp;amp; third party updates if available&lt;br /&gt;
* Don’t install software without ITS involvement&lt;br /&gt;
&lt;br /&gt;
== Laptop Security on traveling, remote work ==&lt;br /&gt;
* Apply best security practices for desktop, laptop above&lt;br /&gt;
* Keep only necessary documents on your laptop&lt;br /&gt;
* &#039;&#039;&#039;Set password for confidential documents&#039;&#039;&#039;&lt;br /&gt;
* Encrypt the storage for confidential information&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Use only VPN to connect to Officience information systems&lt;br /&gt;
&lt;br /&gt;
== Mobile devices Security ==&lt;br /&gt;
* Never leave a smartphone unattended. Make it a personal habit to keep the phone closed at all time&lt;br /&gt;
* Keep only necessary documents on your phones&lt;br /&gt;
* Set password for confidential documents&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Don&#039;t send private, personal information without vpn or ssl protection&lt;br /&gt;
&lt;br /&gt;
== Password Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use strong passwords :&#039;&#039;&#039;&lt;br /&gt;
* Minimum of 8 characters in length&lt;br /&gt;
* Not a dictionary word or proper name&lt;br /&gt;
* Not the same as your user ID&lt;br /&gt;
* Change within a maximum of 90 days&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Memorize It – Don’t write it down!&#039;&#039;&#039;&lt;br /&gt;
Password Exchange : &lt;br /&gt;
* No password sharing &lt;br /&gt;
* Don’t send user &amp;amp; password in the same email without encryption&lt;br /&gt;
&lt;br /&gt;
Best practice are:&lt;br /&gt;
&lt;br /&gt;
* User id in 1 email &amp;amp; password in another email&lt;br /&gt;
* User id in email &amp;amp; password provided face-to-face, phone call, hangout&lt;br /&gt;
&amp;lt;sup&amp;gt;Superscript text&amp;lt;/sup&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Keep Your Computer Safe ==&lt;br /&gt;
&lt;br /&gt;
== Internet Safety ==&lt;br /&gt;
&lt;br /&gt;
== Internet Usage ==&lt;br /&gt;
Internet is for professional use.&lt;br /&gt;
&lt;br /&gt;
Use the Internet responsibly and securely :&lt;br /&gt;
* Don&#039;t post sensitive company information or company-related comments on message boards, in chat rooms or anywhere else on the Internet. &lt;br /&gt;
* Don&#039;t visit inappropriate Internet sites. &lt;br /&gt;
&lt;br /&gt;
== Email Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use email safely :&#039;&#039;&#039;&lt;br /&gt;
* Never open suspicious or unsolicited attachments&lt;br /&gt;
* Avoid responding to spam&lt;br /&gt;
* never provide credit card numbers, passwords or personal information in response to email messages&lt;br /&gt;
* install anti-virus software and update frequently&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Double check the recipients before sending emails&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Do not use corporate email for illegal actions&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Data Backup &amp;amp; Storage ==&lt;br /&gt;
&lt;br /&gt;
* Store your data in network drives to keep prevent data loss. All network drives are backuped &lt;br /&gt;
* Backup retention period is 1 week i.e your oldest data can be recovered is 1 week&lt;br /&gt;
* Data ⇒ Backup to Google Cloud (using Offy account)&lt;br /&gt;
* Data ⇒ Backup to Customer or Offy  SharePoint&lt;br /&gt;
&lt;br /&gt;
== Use of Encryption ==&lt;br /&gt;
* Confidential information must be stored on the secure network with restricted access.&lt;br /&gt;
* Whenever it is requested by the information owner to store on any devices other than the secure network server, it must be encrypted.&lt;br /&gt;
* All confidential information transmitted to an email outside domain officience.com must be encrypted.&lt;br /&gt;
&lt;br /&gt;
== Media Destruction ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Dispose of media properly :&#039;&#039;&#039;&lt;br /&gt;
Before electronic media is disposed of, appropriate care must be taken to ensure that no unauthorized person can access data by ordinary means. Electronic media such as floppy disks, rewritable CD-ROMS, zip disks, videotapes, and audiotapes should be erased if the media type allows it or destroyed if erasure is not possible.&lt;br /&gt;
&lt;br /&gt;
== Protection from viruses, trojan horses, malicious codes ==&lt;br /&gt;
=== Potential threats ===&lt;br /&gt;
* Malicious Software (viruses, trojans, worms, spyware, or other)&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* Peer-to-Peer File Sharing&lt;br /&gt;
* Identity Theft&lt;br /&gt;
* Social Engineering&lt;br /&gt;
* Some applications such as Instant Messaging (IM), Peer-to-Peer (P2P) file sharing, pose serious security risks.  You should consider anything typed into IM or transferred through P2P to be visible to the entire internet.&lt;br /&gt;
* When used in conjunction with Internet sites outside of Offy, they can cause undesirable and damaging consequences. For example, you are most likely to encounter malware browsing an external website. &#039;&#039;&#039;When accessing external websites&#039;&#039;&#039;, members of Offy must be especially cautious&lt;br /&gt;
&lt;br /&gt;
== Malicious software ==&lt;br /&gt;
Malicious software (malware) is a serious threat. These are programs that can &amp;quot;infect&amp;quot; other programs, damage hard drives, erase critical information, take critical systems off-line, and forward your data to external sites without your knowledge.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware includes:&#039;&#039;&#039;&lt;br /&gt;
* Viruses&lt;br /&gt;
* Worms&lt;br /&gt;
* Trojan Horse programs&lt;br /&gt;
* Spyware&lt;br /&gt;
* Programs which accidentally harm any system or data&lt;br /&gt;
&lt;br /&gt;
=== Malware (cont) ===&lt;br /&gt;
&lt;br /&gt;
=== Malware Example ===&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware ===&lt;br /&gt;
* Slowdown&lt;br /&gt;
* Pop-Ups&lt;br /&gt;
* Crashes&lt;br /&gt;
* Suspicious hard drive activity&lt;br /&gt;
* Running out of hard drive space&lt;br /&gt;
* Unusually high network activity&lt;br /&gt;
* New browser homepage, new toolbars and/or unwanted websites accessed without your input&lt;br /&gt;
* Unusual messages or programs that start automatically&lt;br /&gt;
* Your security solution is disabled&lt;br /&gt;
* Your friends tell you that they are getting strange messages from you&lt;br /&gt;
* New, unfamiliar icons on desktop + battery life drains quickly&lt;br /&gt;
* You see unusual error messages&lt;br /&gt;
* You are unable to access the Control Panel, Task Manager, Registry Editor or Command Prompt&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware: Example ===&lt;br /&gt;
&lt;br /&gt;
=== What to do if your PC infected with malware ===&lt;br /&gt;
&lt;br /&gt;
Anti-virus software running on Offy’s managed workstations protects against most malware.  &lt;br /&gt;
&lt;br /&gt;
Should you suspect that your computer is infected, take immediate action:&lt;br /&gt;
* Unplug the computer from the network&lt;br /&gt;
* Read the notice carefully…Is it from your real antivirus program? &lt;br /&gt;
* What does the notice say your AV program did with the infected file?&lt;br /&gt;
* SCAN the hard drive to see if the malware has been dealt with&lt;br /&gt;
* Shutdown your system&lt;br /&gt;
* Contact the IT Helpdesk for help.&lt;br /&gt;
&lt;br /&gt;
== Instant Messaging ==&lt;br /&gt;
&lt;br /&gt;
Instant messaging is the popular method of typing online conversations in real time.&lt;br /&gt;
Risks of Externally Hosted Instant Messaging:&lt;br /&gt;
* No virus protection&lt;br /&gt;
* A separate &amp;quot;exit&amp;quot; action is needed to stop it&lt;br /&gt;
* Hijacking and impersonation&lt;br /&gt;
* Malicious code&lt;br /&gt;
* Unauthorized access&lt;br /&gt;
* Poor password security&lt;br /&gt;
* Broadcasts the computer&#039;s presence online even if the interface is closed&lt;br /&gt;
* The data is sent to an external host before going to the intended recipient&lt;br /&gt;
&lt;br /&gt;
On our Skype network, someone in your contact list send you a file, it’s has icon similar to a PDF or DOC file, but, in fact it’s an execute file. If you receive and open the file, your PC will infected with virus/trojan.&lt;br /&gt;
&lt;br /&gt;
== P2P file sharing ==&lt;br /&gt;
P2P (Peer-to-Peer) means file sharing between users on the Internet.  Examples are Gnutella, KaZaA, Napster, Morpheus, eDonkey, BitTorrent and BearShare.&lt;br /&gt;
&lt;br /&gt;
P2P file sharing is inherently insecure and lives on the fringes of legality. Badly-coded clients, viruses and Trojan Horses and potential lawsuits are just some of the many threats that users must face when they venture into the untamed wilderness of the P2P world.  Some threats are:&lt;br /&gt;
* Some P2P programs share everything on your computer with anyone by default. &lt;br /&gt;
* Some P2P programs themselves contain &amp;quot;spyware&amp;quot;.&lt;br /&gt;
* Much of the P2P activity is automatic, and its use is unmonitored. &lt;br /&gt;
* Creating multiple copies of a copyrighted work, music or videos and sharing them is illegal.&lt;br /&gt;
* Computers running P2P programs can be used to spread malware, share private documents, or use your file server for store-and-forward. &lt;br /&gt;
* Various types of illegal files can be downloaded and re-shared over these P2P networks by mistake.&lt;br /&gt;
&lt;br /&gt;
== Identity theft ==&lt;br /&gt;
&lt;br /&gt;
identity theft is the unauthorized collection and use of your personal information for criminal purposes. This information can be used to open credit card and bank accounts, redirect mail, establish cellular phone service...If this happens, you could be left with the bills, charges, bad checks, and taxes.&lt;br /&gt;
&lt;br /&gt;
== Social engineering ==&lt;br /&gt;
&lt;br /&gt;
Social engineering is the practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or Internet to trick people into revealing sensitive information or getting them to do something that is against typical policies.&lt;br /&gt;
&lt;br /&gt;
== Some example about phishing mail ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Fishing (fake email)&#039;&#039;&#039; : Phishing” is the act of sending an email pretending to be from someone “official” with the intention of gaining personal information.&lt;br /&gt;
&lt;br /&gt;
== Avoid being a victim ==&lt;br /&gt;
&lt;br /&gt;
Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information.&lt;br /&gt;
If an unknown individual claims to be from a legitimate organization, try to verify his or her identity directly with the company. &lt;br /&gt;
* Do not provide personal information or information about your organization unless you are certain of a person&#039;s authority to have the information. &lt;br /&gt;
* Do not reveal personal or financial information in email, and do not respond to email solicitations for this information. This includes following links sent in email. &lt;br /&gt;
If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a web site connected to the request.&lt;br /&gt;
&lt;br /&gt;
== Reporting security breaches ==&lt;br /&gt;
&lt;br /&gt;
=== What is a security incident? ===&lt;br /&gt;
&lt;br /&gt;
Anytime you suspect a Offy computer has been compromised, whether that involves theft, hacking, a vicious virus, unauthorized use of IT technology or you witness an inappropriate or offensive use of email or the Web, you should report the incident, or seek help and advice from IT Support. &lt;br /&gt;
&lt;br /&gt;
=== Why should I report a security incident ? ===&lt;br /&gt;
&lt;br /&gt;
If your system has been infected or any data has been lost, IT Support resources can help you clean up your system. Furthermore, as a user of the network, you should be aware of your rights and responsibilities. &lt;br /&gt;
How do I report a security incident?&lt;br /&gt;
Report security violations and computing problems to the IT Help Desk at:&lt;br /&gt;
* itsupportATofficience.com&lt;br /&gt;
* securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== DEVICE USE ==&lt;br /&gt;
Guidelines for usage include:&lt;br /&gt;
* Storage and access of sexually explicit, racist, and hate oriented materials is prohibited.&lt;br /&gt;
* Illegal and/or fraudulent practices are prohibited.&lt;br /&gt;
* Installation of devices and software for non-business related activities is prohibited.  This includes, but is not limited to, gaming devices/software, instant messaging software, wallpaper and screensavers not installed by IT.&lt;br /&gt;
* Attachment of devices and/or software to allow external access to the Offy network not explicitly approved by IT is prohibited.&lt;br /&gt;
* Installation of software not properly licensed, if required, is prohibited.&lt;br /&gt;
* Deactivation of support tools, including antivirus software, systems security, and monitoring tools.&lt;br /&gt;
&lt;br /&gt;
== Useful Email &amp;amp; Websites ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Websites&#039;&#039;&#039;&lt;br /&gt;
* Corporate website: www.officience.com&lt;br /&gt;
* HRMS: hr4you.officience.com&lt;br /&gt;
* Corporate webmail: mail.officience.com&lt;br /&gt;
* Intranet: offyspace.com&lt;br /&gt;
* Helpdesk request: http://offyspace.com/sc/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Emails:&#039;&#039;&#039;&lt;br /&gt;
* IT Support: itsupportATofficience.com&lt;br /&gt;
* HR support: hrATofficience.com&lt;br /&gt;
* security alert: securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[Security team]]&lt;br /&gt;
* [[Thalès Security]]&lt;br /&gt;
&lt;br /&gt;
== Reference ==&lt;br /&gt;
* [https://docs.google.com/presentation/d/1snClXs8nCWRoOe5Mw-WfVTxgnEQVGat6b5gAMR2ZChg Security Training] (by Hoai Linh NGO, 2017)&lt;br /&gt;
&lt;br /&gt;
*[https://wiki.officience.com/Security_Appendix Security appendices]&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Security&amp;diff=984</id>
		<title>Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Security&amp;diff=984"/>
		<updated>2019-07-24T18:37:15Z</updated>

		<summary type="html">&lt;p&gt;Duc: /* Reference */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Edmund Hillary &amp;amp; Tenzing Norgay 1933.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Who is responsible for computer security? ==&lt;br /&gt;
&#039;&#039;&#039;Every member of Officience is responsible.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Offies are expected to act responsibly and ethically when accessing Officience’s electronic data and technology resources.&lt;br /&gt;
* The security of a system is only as good as its weakest link. If even one person does not pay attention to security, the security of the whole system is compromised. Read example on [[Thalès Security]]. &lt;br /&gt;
&lt;br /&gt;
Good Security Standards follow the &amp;quot;90/10&amp;quot; Rule :&lt;br /&gt;
&lt;br /&gt;
* 10% of security safeguards are technical.&lt;br /&gt;
* 90% of security safeguards rely on the computer user (YOU) to adhere to good computing practices.&lt;br /&gt;
&lt;br /&gt;
== Security Topics ==&lt;br /&gt;
=== Best security practices for Offies===&lt;br /&gt;
* Data protection - classification level of information&lt;br /&gt;
* Working Area&lt;br /&gt;
* Desktop/Laptop Security&lt;br /&gt;
* Laptop security while on traveling or remote work&lt;br /&gt;
* Mobile device security&lt;br /&gt;
* Password usage&lt;br /&gt;
* Internet Usage&lt;br /&gt;
* Email usage&lt;br /&gt;
* Data Backup &amp;amp; storage&lt;br /&gt;
* Use of Encryption&lt;br /&gt;
* Media Destruction&lt;br /&gt;
&lt;br /&gt;
=== Protection from viruses, trojan horses, malicious codes ===&lt;br /&gt;
* Potential threats&lt;br /&gt;
* Malicious software&lt;br /&gt;
* Signs of malware &amp;amp; example&lt;br /&gt;
* How to protect against malware&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* P2P file sharing&lt;br /&gt;
* Identity theft&lt;br /&gt;
* Social engineering&lt;br /&gt;
* Email phishing&lt;br /&gt;
* Avoid being a victim&lt;br /&gt;
* Reporting security breaches&lt;br /&gt;
&lt;br /&gt;
== Data protection : Classification level of information==&lt;br /&gt;
&lt;br /&gt;
== NDA (Non-disclosure agreement)==&lt;br /&gt;
See [[Non-Disclosure Agreement]]&lt;br /&gt;
&lt;br /&gt;
== Protecting data at work ==&lt;br /&gt;
&#039;&#039;&#039;The best way to secure your system is to use a managed workstation. &#039;&#039;&#039;&lt;br /&gt;
IT Support automatically updates anti-virus and patches on managed systems. &lt;br /&gt;
Here are some additional tips to protect your data.&lt;br /&gt;
* Use strong passwords&lt;br /&gt;
* Pay attention to your computer&#039;s security&lt;br /&gt;
* Use email safely&lt;br /&gt;
* Use the Internet responsibly and securely&lt;br /&gt;
* Dispose of media properly&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Pay attention to your computer&#039;s security&#039;&#039;&#039;&lt;br /&gt;
* Lock your computer with a password-protected screen saver before leaving your desk unattended.  &lt;br /&gt;
* Before you go home, log off the network. &lt;br /&gt;
* Manage your data in a manner that reflects its sensitivity.&lt;br /&gt;
&lt;br /&gt;
== Protecting data at home ==&lt;br /&gt;
If you use your home computer to access applications at Offy and your home computer is not properly protected, you can put Offy’s systems at risk.&lt;br /&gt;
* Use unprivileged account for normal use&lt;br /&gt;
* Always use anti-virus software&lt;br /&gt;
* Use VPN to connect if possible&lt;br /&gt;
* Apply patches regularly&lt;br /&gt;
* Perform regular backups&lt;br /&gt;
* Shutdown your computer when not in use&lt;br /&gt;
* Work securely from home &lt;br /&gt;
* Protect against Malware&lt;br /&gt;
* Make wireless networks secure&lt;br /&gt;
&lt;br /&gt;
IT Helpdesk does not provide support for home computers. If you need additional assistance with your home computer, please contact to us at: itsupportATofficience.com&lt;br /&gt;
&lt;br /&gt;
== Working Area ==&lt;br /&gt;
* &#039;&#039;&#039;Clear your desk at the end of day.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; leave sensitive information (paper, cd/dvd,...) on your desk without protection.&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; try to plug any other devices into Officience network without approvals from ITS&lt;br /&gt;
* &#039;&#039;&#039;Don&#039;t&#039;&#039;&#039; use personal devices (laptop,...) without approvals from direct manager &amp;amp; ITS&lt;br /&gt;
&lt;br /&gt;
== Desktop/Laptop Security ==&lt;br /&gt;
* &#039;&#039;&#039;Lock screen as soon as leaving your seat&#039;&#039;&#039;&lt;br /&gt;
* Set password-enabled screen saver with inactive timeout, recommend 15 minutes&lt;br /&gt;
* Antivirus &amp;amp; firewall must be installed and enabled in the desktop&lt;br /&gt;
* Enable &amp;amp; install Windows, Linux &amp;amp; third party updates if available&lt;br /&gt;
* Don’t install software without ITS involvement&lt;br /&gt;
&lt;br /&gt;
== Laptop Security on traveling, remote work ==&lt;br /&gt;
* Apply best security practices for desktop, laptop above&lt;br /&gt;
* Keep only necessary documents on your laptop&lt;br /&gt;
* &#039;&#039;&#039;Set password for confidential documents&#039;&#039;&#039;&lt;br /&gt;
* Encrypt the storage for confidential information&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Use only VPN to connect to Officience information systems&lt;br /&gt;
&lt;br /&gt;
== Mobile devices Security ==&lt;br /&gt;
* Never leave a smartphone unattended. Make it a personal habit to keep the phone closed at all time&lt;br /&gt;
* Keep only necessary documents on your phones&lt;br /&gt;
* Set password for confidential documents&lt;br /&gt;
* Use open public wireless carefully. &lt;br /&gt;
* Don&#039;t send private, personal information without vpn or ssl protection&lt;br /&gt;
&lt;br /&gt;
== Password Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use strong passwords :&#039;&#039;&#039;&lt;br /&gt;
* Minimum of 8 characters in length&lt;br /&gt;
* Not a dictionary word or proper name&lt;br /&gt;
* Not the same as your user ID&lt;br /&gt;
* Change within a maximum of 90 days&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Memorize It – Don’t write it down!&#039;&#039;&#039;&lt;br /&gt;
Password Exchange : &lt;br /&gt;
* No password sharing &lt;br /&gt;
* Don’t send user &amp;amp; password in the same email without encryption&lt;br /&gt;
&lt;br /&gt;
Best practice are:&lt;br /&gt;
&lt;br /&gt;
* User id in 1 email &amp;amp; password in another email&lt;br /&gt;
* User id in email &amp;amp; password provided face-to-face, phone call, hangout&lt;br /&gt;
&amp;lt;sup&amp;gt;Superscript text&amp;lt;/sup&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Keep Your Computer Safe ==&lt;br /&gt;
&lt;br /&gt;
== Internet Safety ==&lt;br /&gt;
&lt;br /&gt;
== Internet Usage ==&lt;br /&gt;
Internet is for professional use.&lt;br /&gt;
&lt;br /&gt;
Use the Internet responsibly and securely :&lt;br /&gt;
* Don&#039;t post sensitive company information or company-related comments on message boards, in chat rooms or anywhere else on the Internet. &lt;br /&gt;
* Don&#039;t visit inappropriate Internet sites. &lt;br /&gt;
&lt;br /&gt;
== Email Usage ==&lt;br /&gt;
&#039;&#039;&#039;Use email safely :&#039;&#039;&#039;&lt;br /&gt;
* Never open suspicious or unsolicited attachments&lt;br /&gt;
* Avoid responding to spam&lt;br /&gt;
* never provide credit card numbers, passwords or personal information in response to email messages&lt;br /&gt;
* install anti-virus software and update frequently&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Double check the recipients before sending emails&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Do not use corporate email for illegal actions&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Data Backup &amp;amp; Storage ==&lt;br /&gt;
&lt;br /&gt;
* Store your data in network drives to keep prevent data loss. All network drives are backuped &lt;br /&gt;
* Backup retention period is 1 week i.e your oldest data can be recovered is 1 week&lt;br /&gt;
* Data ⇒ Backup to Google Cloud (using Offy account)&lt;br /&gt;
* Data ⇒ Backup to Customer or Offy  SharePoint&lt;br /&gt;
&lt;br /&gt;
== Use of Encryption ==&lt;br /&gt;
* Confidential information must be stored on the secure network with restricted access.&lt;br /&gt;
* Whenever it is requested by the information owner to store on any devices other than the secure network server, it must be encrypted.&lt;br /&gt;
* All confidential information transmitted to an email outside domain officience.com must be encrypted.&lt;br /&gt;
&lt;br /&gt;
== Media Destruction ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Dispose of media properly :&#039;&#039;&#039;&lt;br /&gt;
Before electronic media is disposed of, appropriate care must be taken to ensure that no unauthorized person can access data by ordinary means. Electronic media such as floppy disks, rewritable CD-ROMS, zip disks, videotapes, and audiotapes should be erased if the media type allows it or destroyed if erasure is not possible.&lt;br /&gt;
&lt;br /&gt;
== Protection from viruses, trojan horses, malicious codes ==&lt;br /&gt;
=== Potential threats ===&lt;br /&gt;
* Malicious Software (viruses, trojans, worms, spyware, or other)&lt;br /&gt;
* Instant Messaging&lt;br /&gt;
* Peer-to-Peer File Sharing&lt;br /&gt;
* Identity Theft&lt;br /&gt;
* Social Engineering&lt;br /&gt;
* Some applications such as Instant Messaging (IM), Peer-to-Peer (P2P) file sharing, pose serious security risks.  You should consider anything typed into IM or transferred through P2P to be visible to the entire internet.&lt;br /&gt;
* When used in conjunction with Internet sites outside of Offy, they can cause undesirable and damaging consequences. For example, you are most likely to encounter malware browsing an external website. &#039;&#039;&#039;When accessing external websites&#039;&#039;&#039;, members of Offy must be especially cautious&lt;br /&gt;
&lt;br /&gt;
== Malicious software ==&lt;br /&gt;
Malicious software (malware) is a serious threat. These are programs that can &amp;quot;infect&amp;quot; other programs, damage hard drives, erase critical information, take critical systems off-line, and forward your data to external sites without your knowledge.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Malware includes:&#039;&#039;&#039;&lt;br /&gt;
* Viruses&lt;br /&gt;
* Worms&lt;br /&gt;
* Trojan Horse programs&lt;br /&gt;
* Spyware&lt;br /&gt;
* Programs which accidentally harm any system or data&lt;br /&gt;
&lt;br /&gt;
=== Malware (cont) ===&lt;br /&gt;
&lt;br /&gt;
=== Malware Example ===&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware ===&lt;br /&gt;
* Slowdown&lt;br /&gt;
* Pop-Ups&lt;br /&gt;
* Crashes&lt;br /&gt;
* Suspicious hard drive activity&lt;br /&gt;
* Running out of hard drive space&lt;br /&gt;
* Unusually high network activity&lt;br /&gt;
* New browser homepage, new toolbars and/or unwanted websites accessed without your input&lt;br /&gt;
* Unusual messages or programs that start automatically&lt;br /&gt;
* Your security solution is disabled&lt;br /&gt;
* Your friends tell you that they are getting strange messages from you&lt;br /&gt;
* New, unfamiliar icons on desktop + battery life drains quickly&lt;br /&gt;
* You see unusual error messages&lt;br /&gt;
* You are unable to access the Control Panel, Task Manager, Registry Editor or Command Prompt&lt;br /&gt;
&lt;br /&gt;
=== Signs of malware: Example ===&lt;br /&gt;
&lt;br /&gt;
=== What to do if your PC infected with malware ===&lt;br /&gt;
&lt;br /&gt;
Anti-virus software running on Offy’s managed workstations protects against most malware.  &lt;br /&gt;
&lt;br /&gt;
Should you suspect that your computer is infected, take immediate action:&lt;br /&gt;
* Unplug the computer from the network&lt;br /&gt;
* Read the notice carefully…Is it from your real antivirus program? &lt;br /&gt;
* What does the notice say your AV program did with the infected file?&lt;br /&gt;
* SCAN the hard drive to see if the malware has been dealt with&lt;br /&gt;
* Shutdown your system&lt;br /&gt;
* Contact the IT Helpdesk for help.&lt;br /&gt;
&lt;br /&gt;
== Instant Messaging ==&lt;br /&gt;
&lt;br /&gt;
Instant messaging is the popular method of typing online conversations in real time.&lt;br /&gt;
Risks of Externally Hosted Instant Messaging:&lt;br /&gt;
* No virus protection&lt;br /&gt;
* A separate &amp;quot;exit&amp;quot; action is needed to stop it&lt;br /&gt;
* Hijacking and impersonation&lt;br /&gt;
* Malicious code&lt;br /&gt;
* Unauthorized access&lt;br /&gt;
* Poor password security&lt;br /&gt;
* Broadcasts the computer&#039;s presence online even if the interface is closed&lt;br /&gt;
* The data is sent to an external host before going to the intended recipient&lt;br /&gt;
&lt;br /&gt;
On our Skype network, someone in your contact list send you a file, it’s has icon similar to a PDF or DOC file, but, in fact it’s an execute file. If you receive and open the file, your PC will infected with virus/trojan.&lt;br /&gt;
&lt;br /&gt;
== P2P file sharing ==&lt;br /&gt;
P2P (Peer-to-Peer) means file sharing between users on the Internet.  Examples are Gnutella, KaZaA, Napster, Morpheus, eDonkey, BitTorrent and BearShare.&lt;br /&gt;
&lt;br /&gt;
P2P file sharing is inherently insecure and lives on the fringes of legality. Badly-coded clients, viruses and Trojan Horses and potential lawsuits are just some of the many threats that users must face when they venture into the untamed wilderness of the P2P world.  Some threats are:&lt;br /&gt;
* Some P2P programs share everything on your computer with anyone by default. &lt;br /&gt;
* Some P2P programs themselves contain &amp;quot;spyware&amp;quot;.&lt;br /&gt;
* Much of the P2P activity is automatic, and its use is unmonitored. &lt;br /&gt;
* Creating multiple copies of a copyrighted work, music or videos and sharing them is illegal.&lt;br /&gt;
* Computers running P2P programs can be used to spread malware, share private documents, or use your file server for store-and-forward. &lt;br /&gt;
* Various types of illegal files can be downloaded and re-shared over these P2P networks by mistake.&lt;br /&gt;
&lt;br /&gt;
== Identity theft ==&lt;br /&gt;
&lt;br /&gt;
identity theft is the unauthorized collection and use of your personal information for criminal purposes. This information can be used to open credit card and bank accounts, redirect mail, establish cellular phone service...If this happens, you could be left with the bills, charges, bad checks, and taxes.&lt;br /&gt;
&lt;br /&gt;
== Social engineering ==&lt;br /&gt;
&lt;br /&gt;
Social engineering is the practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or Internet to trick people into revealing sensitive information or getting them to do something that is against typical policies.&lt;br /&gt;
&lt;br /&gt;
== Some example about phishing mail ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Fishing (fake email)&#039;&#039;&#039; : Phishing” is the act of sending an email pretending to be from someone “official” with the intention of gaining personal information.&lt;br /&gt;
&lt;br /&gt;
== Avoid being a victim ==&lt;br /&gt;
&lt;br /&gt;
Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information.&lt;br /&gt;
If an unknown individual claims to be from a legitimate organization, try to verify his or her identity directly with the company. &lt;br /&gt;
* Do not provide personal information or information about your organization unless you are certain of a person&#039;s authority to have the information. &lt;br /&gt;
* Do not reveal personal or financial information in email, and do not respond to email solicitations for this information. This includes following links sent in email. &lt;br /&gt;
If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a web site connected to the request.&lt;br /&gt;
&lt;br /&gt;
== Reporting security breaches ==&lt;br /&gt;
&lt;br /&gt;
=== What is a security incident? ===&lt;br /&gt;
&lt;br /&gt;
Anytime you suspect a Offy computer has been compromised, whether that involves theft, hacking, a vicious virus, unauthorized use of IT technology or you witness an inappropriate or offensive use of email or the Web, you should report the incident, or seek help and advice from IT Support. &lt;br /&gt;
&lt;br /&gt;
=== Why should I report a security incident ? ===&lt;br /&gt;
&lt;br /&gt;
If your system has been infected or any data has been lost, IT Support resources can help you clean up your system. Furthermore, as a user of the network, you should be aware of your rights and responsibilities. &lt;br /&gt;
How do I report a security incident?&lt;br /&gt;
Report security violations and computing problems to the IT Help Desk at:&lt;br /&gt;
* itsupportATofficience.com&lt;br /&gt;
* securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== DEVICE USE ==&lt;br /&gt;
Guidelines for usage include:&lt;br /&gt;
* Storage and access of sexually explicit, racist, and hate oriented materials is prohibited.&lt;br /&gt;
* Illegal and/or fraudulent practices are prohibited.&lt;br /&gt;
* Installation of devices and software for non-business related activities is prohibited.  This includes, but is not limited to, gaming devices/software, instant messaging software, wallpaper and screensavers not installed by IT.&lt;br /&gt;
* Attachment of devices and/or software to allow external access to the Offy network not explicitly approved by IT is prohibited.&lt;br /&gt;
* Installation of software not properly licensed, if required, is prohibited.&lt;br /&gt;
* Deactivation of support tools, including antivirus software, systems security, and monitoring tools.&lt;br /&gt;
&lt;br /&gt;
== Useful Email &amp;amp; Websites ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Websites&#039;&#039;&#039;&lt;br /&gt;
* Corporate website: www.officience.com&lt;br /&gt;
* HRMS: hr4you.officience.com&lt;br /&gt;
* Corporate webmail: mail.officience.com&lt;br /&gt;
* Intranet: offyspace.com&lt;br /&gt;
* Helpdesk request: http://offyspace.com/sc/&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Emails:&#039;&#039;&#039;&lt;br /&gt;
* IT Support: itsupportATofficience.com&lt;br /&gt;
* HR support: hrATofficience.com&lt;br /&gt;
* security alert: securityATofficience.com&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[Security team]]&lt;br /&gt;
* [[Thalès Security]]&lt;br /&gt;
&lt;br /&gt;
== Reference ==&lt;br /&gt;
* [https://docs.google.com/presentation/d/1snClXs8nCWRoOe5Mw-WfVTxgnEQVGat6b5gAMR2ZChg Security Training] (by Hoai Linh NGO, 2017)&lt;br /&gt;
&lt;br /&gt;
*[https://wiki.officience.com/Security_Appendix Security appencices]&lt;br /&gt;
&lt;br /&gt;
*[https://wiki.officience.com/Security_Policy Security policy details]&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=How_do_I_know_what_events_are_happening_at_OffyPlex&amp;diff=921</id>
		<title>How do I know what events are happening at OffyPlex</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=How_do_I_know_what_events_are_happening_at_OffyPlex&amp;diff=921"/>
		<updated>2018-09-23T22:11:22Z</updated>

		<summary type="html">&lt;p&gt;Duc: How to sync Offyplex events on your own agenda&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Wow, this place is so lively, I&#039;m getting lost with all these events at Offyplex ! &amp;lt;br /&amp;gt;&lt;br /&gt;
How can I conveniently stay aware about what is happening in OffyPlex?&amp;lt;br /&amp;gt;&lt;br /&gt;
I dream that I could automatically have all these events showing up in my phone&#039;s calendar app automagically, without having to move a finger ... &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Well, dream no more ! And let me show you how to do that with 3 very simple steps:&amp;lt;br /&amp;gt;&lt;br /&gt;
# Go to [http://calendar.google.com calendar.google.com] and login with our tribe’s account&lt;br /&gt;
# Search for &amp;quot;Officience Events&amp;quot; in the left box&lt;br /&gt;
# Choose one of the two emails: events@officience.com or offyevents@officience.com&lt;br /&gt;
&lt;br /&gt;
Congratulations ! The events will now be displayed in your calendar with a special color and synchronized automatically.&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Product_Presentation&amp;diff=510</id>
		<title>Product Presentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Product_Presentation&amp;diff=510"/>
		<updated>2017-11-21T10:04:19Z</updated>

		<summary type="html">&lt;p&gt;Duc: /* Main guidance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Audience ==&lt;br /&gt;
You&#039;re so proud of what we have done for client X, and now you want to make a product presentation to sell it to other clients ? Here are a few advices on how to make your product presentation appealing.&lt;br /&gt;
&lt;br /&gt;
== General guidance ==&lt;br /&gt;
For PowerPoint, here is my Bible, is very short to read, it&#039;s from my marketing guru Seth Godin (I&#039;ve read ALL his books !). It&#039;s called &amp;quot;[https://drive.google.com/a/officience.com/file/d/0Bzj0QwcgvarebmpzNUE0VTNjZjQ/view Really BAD powerpoint, and how to avoid it]&amp;quot;. Read it !&lt;br /&gt;
&lt;br /&gt;
The basic idea : for each side you should decide which &#039;&#039;&#039;emotion you want people to feel&#039;&#039;&#039;. And you start from that emotion to decide what you put in the slide. That will constraint you a lot in terms of idea. You&#039;ll have to put only one idea per slide. The role of the emotion is to make the idea sticky, by associating the two together. From one slide to another, the emotions will vary and that will form a story that drags your audience along.&lt;br /&gt;
&lt;br /&gt;
Next, you need &#039;&#039;&#039;a thesis&#039;&#039;&#039; You don&#039;t make slides to explain, you make slides to convince, to sell something. So you need to focus sharp on that thing you sell and which makes you &#039;&#039;&#039;unique&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Example :&lt;br /&gt;
&amp;quot;outsource your testing&amp;quot; : so many other people say that, why listen to you specifically ? :-(&lt;br /&gt;
&amp;quot;Vietnam is the best country for outsourcing testing&amp;quot; : wow, I&#039;m curious to hear how you can prove that ! :-)&lt;br /&gt;
&lt;br /&gt;
Now, unique does not mean selfish ! Here is another example :&lt;br /&gt;
&amp;quot;Officience is the best company for outsourcing testing&amp;quot; : Meh, this is just advertising. I won&#039;t believe a single word of it. :-(&lt;br /&gt;
&lt;br /&gt;
And the challenge is of course that you can&#039;t lie. So you need to find the right angle to tell your story. An angle that will make you friends, and where you are legitimate to be speaking about it. Note that I am specifically referring to &#039;&#039;&#039;you making friends&#039;&#039;&#039;, as an individual, because since Offi is a people-centric environment, the objective is not to convince customers to work with Officience, but to convince human beings to make projects with other human beings that is you. You don&#039;t need to sell Officience brand, sell your personal brand instead&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The side benefit is that you will get to work with people who appreciate you, life will be more fun :-) !&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Typical outline ==&lt;br /&gt;
&lt;br /&gt;
=== Intro about Officience ===&lt;br /&gt;
Started long time ago (2006), lots of employees (250), to reassure people. Some context about Vietnam and its booming economy is cool too.&lt;br /&gt;
&lt;br /&gt;
=== The service we offer ===&lt;br /&gt;
Here you can use the jargon of your industry to help people understand very quickly the service by using standardized terms. At this stage the customer know what we want to do for him.&lt;br /&gt;
&lt;br /&gt;
=== Our strengths ===&lt;br /&gt;
The idea here is to make it look neutral. Like : in which circumstances is it a good idea to work with us ? It should look like it&#039;s not always 100% a good idea.&lt;br /&gt;
&lt;br /&gt;
=== A few technical details ===&lt;br /&gt;
Aim is to show it&#039;s real we have experience and we know what we&#039;re talkign about&lt;br /&gt;
* process design&lt;br /&gt;
* Logos of the technologies we prefer.&lt;br /&gt;
&lt;br /&gt;
=== Success Story ===&lt;br /&gt;
To reassure the customer, give an example of a past project that worked so well as case study :&lt;br /&gt;
* Context and objectives&lt;br /&gt;
* The solutions we deployed&lt;br /&gt;
* The &amp;quot;extra mile&amp;quot; what we delivered extra the the custoemr didn&#039;t expect :-)&lt;br /&gt;
&lt;br /&gt;
=== The team ===&lt;br /&gt;
Last but not least, highlight of the key engagement people surrounding this product, show they human face, make them feel we already know each other, and share things in common.&lt;br /&gt;
&lt;br /&gt;
== Where to get inspired ? ==&lt;br /&gt;
&lt;br /&gt;
[[marketing.officience.com]] is our Google Site where you can find all the presentations we&#039;ve done in the past. In particular the &amp;quot;Corporate Brochure&amp;quot; presentation has general statements about Offi that you may want to embed or link in your presentation.&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Product_Presentation&amp;diff=509</id>
		<title>Product Presentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Product_Presentation&amp;diff=509"/>
		<updated>2017-11-21T10:03:44Z</updated>

		<summary type="html">&lt;p&gt;Duc: /* Typical outline */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Audience ==&lt;br /&gt;
You&#039;re so proud of what we have done for client X, and now you want to make a product presentation to sell it to other clients ? Here are a few advices on how to make your product presentation appealing.&lt;br /&gt;
&lt;br /&gt;
== Main guidance ==&lt;br /&gt;
For PowerPoint, here is my Bible, is very short to read, it&#039;s from my marketing guru Seth Godin (I&#039;ve read ALL his books !). It&#039;s called &amp;quot;[https://drive.google.com/a/officience.com/file/d/0Bzj0QwcgvarebmpzNUE0VTNjZjQ/view Really BAD powerpoint, and how to avoid it]&amp;quot;. Read it !&lt;br /&gt;
&lt;br /&gt;
The basic idea : for each side you should decide which &#039;&#039;&#039;emotion you want people to feel&#039;&#039;&#039;. And you start from that emotion to decide what you put in the slide. That will constraint you a lot in terms of idea. You&#039;ll have to put only one idea per slide. The role of the emotion is to make the idea sticky, by associating the two together. From one slide to another, the emotions will vary and that will form a story that drags your audience along.&lt;br /&gt;
&lt;br /&gt;
Next, you need &#039;&#039;&#039;a thesis&#039;&#039;&#039; You don&#039;t make slides to explain, you make slides to convince, to sell something. So you need to focus sharp on that thing you sell and which makes you &#039;&#039;&#039;unique&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Example :&lt;br /&gt;
&amp;quot;outsource your testing&amp;quot; : so many other people say that, why listen to you specifically ? :-(&lt;br /&gt;
&amp;quot;Vietnam is the best country for outsourcing testing&amp;quot; : wow, I&#039;m curious to hear how you can prove that ! :-)&lt;br /&gt;
&lt;br /&gt;
Now, unique does not mean selfish ! Here is another example :&lt;br /&gt;
&amp;quot;Officience is the best company for outsourcing testing&amp;quot; : Meh, this is just advertising. I won&#039;t believe a single word of it. :-(&lt;br /&gt;
&lt;br /&gt;
And the challenge is of course that you can&#039;t lie. So you need to find the right angle to tell your story. An angle that will make you friends, and where you are legitimate to be speaking about it. Note that I am specifically referring to &#039;&#039;&#039;you making friends&#039;&#039;&#039;, as an individual, because since Offi is a people-centric environment, the objective is not to convince customers to work with Officience, but to convince human beings to make projects with other human beings that is you. You don&#039;t need to sell Officience brand, sell your personal brand instead&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The side benefit is that you will get to work with people who appreciate you, life will be more fun :-) !&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Typical outline ==&lt;br /&gt;
&lt;br /&gt;
=== Intro about Officience ===&lt;br /&gt;
Started long time ago (2006), lots of employees (250), to reassure people. Some context about Vietnam and its booming economy is cool too.&lt;br /&gt;
&lt;br /&gt;
=== The service we offer ===&lt;br /&gt;
Here you can use the jargon of your industry to help people understand very quickly the service by using standardized terms. At this stage the customer know what we want to do for him.&lt;br /&gt;
&lt;br /&gt;
=== Our strengths ===&lt;br /&gt;
The idea here is to make it look neutral. Like : in which circumstances is it a good idea to work with us ? It should look like it&#039;s not always 100% a good idea.&lt;br /&gt;
&lt;br /&gt;
=== A few technical details ===&lt;br /&gt;
Aim is to show it&#039;s real we have experience and we know what we&#039;re talkign about&lt;br /&gt;
* process design&lt;br /&gt;
* Logos of the technologies we prefer.&lt;br /&gt;
&lt;br /&gt;
=== Success Story ===&lt;br /&gt;
To reassure the customer, give an example of a past project that worked so well as case study :&lt;br /&gt;
* Context and objectives&lt;br /&gt;
* The solutions we deployed&lt;br /&gt;
* The &amp;quot;extra mile&amp;quot; what we delivered extra the the custoemr didn&#039;t expect :-)&lt;br /&gt;
&lt;br /&gt;
=== The team ===&lt;br /&gt;
Last but not least, highlight of the key engagement people surrounding this product, show they human face, make them feel we already know each other, and share things in common.&lt;br /&gt;
&lt;br /&gt;
== Where to get inspired ? ==&lt;br /&gt;
&lt;br /&gt;
[[marketing.officience.com]] is our Google Site where you can find all the presentations we&#039;ve done in the past. In particular the &amp;quot;Corporate Brochure&amp;quot; presentation has general statements about Offi that you may want to embed or link in your presentation.&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Product_Presentation&amp;diff=508</id>
		<title>Product Presentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Product_Presentation&amp;diff=508"/>
		<updated>2017-11-21T09:55:19Z</updated>

		<summary type="html">&lt;p&gt;Duc: /* Main guidance */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Audience ==&lt;br /&gt;
You&#039;re so proud of what we have done for client X, and now you want to make a product presentation to sell it to other clients ? Here are a few advices on how to make your product presentation appealing.&lt;br /&gt;
&lt;br /&gt;
== Main guidance ==&lt;br /&gt;
For PowerPoint, here is my Bible, is very short to read, it&#039;s from my marketing guru Seth Godin (I&#039;ve read ALL his books !). It&#039;s called &amp;quot;[https://drive.google.com/a/officience.com/file/d/0Bzj0QwcgvarebmpzNUE0VTNjZjQ/view Really BAD powerpoint, and how to avoid it]&amp;quot;. Read it !&lt;br /&gt;
&lt;br /&gt;
The basic idea : for each side you should decide which &#039;&#039;&#039;emotion you want people to feel&#039;&#039;&#039;. And you start from that emotion to decide what you put in the slide. That will constraint you a lot in terms of idea. You&#039;ll have to put only one idea per slide. The role of the emotion is to make the idea sticky, by associating the two together. From one slide to another, the emotions will vary and that will form a story that drags your audience along.&lt;br /&gt;
&lt;br /&gt;
Next, you need &#039;&#039;&#039;a thesis&#039;&#039;&#039; You don&#039;t make slides to explain, you make slides to convince, to sell something. So you need to focus sharp on that thing you sell and which makes you &#039;&#039;&#039;unique&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Example :&lt;br /&gt;
&amp;quot;outsource your testing&amp;quot; : so many other people say that, why listen to you specifically ? :-(&lt;br /&gt;
&amp;quot;Vietnam is the best country for outsourcing testing&amp;quot; : wow, I&#039;m curious to hear how you can prove that ! :-)&lt;br /&gt;
&lt;br /&gt;
Now, unique does not mean selfish ! Here is another example :&lt;br /&gt;
&amp;quot;Officience is the best company for outsourcing testing&amp;quot; : Meh, this is just advertising. I won&#039;t believe a single word of it. :-(&lt;br /&gt;
&lt;br /&gt;
And the challenge is of course that you can&#039;t lie. So you need to find the right angle to tell your story. An angle that will make you friends, and where you are legitimate to be speaking about it. Note that I am specifically referring to &#039;&#039;&#039;you making friends&#039;&#039;&#039;, as an individual, because since Offi is a people-centric environment, the objective is not to convince customers to work with Officience, but to convince human beings to make projects with other human beings that is you. You don&#039;t need to sell Officience brand, sell your personal brand instead&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The side benefit is that you will get to work with people who appreciate you, life will be more fun :-) !&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Typical outline ==&lt;br /&gt;
&lt;br /&gt;
Intro about Officience&lt;br /&gt;
The service we offer&lt;br /&gt;
Our strengths (in which circumstances we are a good pick)&lt;br /&gt;
Some technical details (process or tool) to show it&#039;s real&lt;br /&gt;
* process design&lt;br /&gt;
* Logos of the technologies we prefer.&lt;br /&gt;
Success Story : an example of a past project that worked so well :&lt;br /&gt;
* Context and objectives&lt;br /&gt;
* The solutions we deployed&lt;br /&gt;
* The &amp;quot;extra mile&amp;quot; what we delivered extra the the custoemr didn&#039;t expect :-)&lt;br /&gt;
The team : highlight of the key engagement people surrounding this product&lt;br /&gt;
&lt;br /&gt;
== Where to get inspired ? ==&lt;br /&gt;
&lt;br /&gt;
[[marketing.officience.com]] is our Google Site where you can find all the presentations we&#039;ve done in the past. In particular the &amp;quot;Corporate Brochure&amp;quot; presentation has general statements about Offi that you may want to embed or link in your presentation.&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
	<entry>
		<id>https://wiki.officience.com/index.php?title=Product_Presentation&amp;diff=507</id>
		<title>Product Presentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.officience.com/index.php?title=Product_Presentation&amp;diff=507"/>
		<updated>2017-11-21T09:54:35Z</updated>

		<summary type="html">&lt;p&gt;Duc: How to make a product presentation slideware&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Audience ==&lt;br /&gt;
You&#039;re so proud of what we have done for client X, and now you want to make a product presentation to sell it to other clients ? Here are a few advices on how to make your product presentation appealing.&lt;br /&gt;
&lt;br /&gt;
== Main guidance ==&lt;br /&gt;
For PowerPoint, here is my Bible, is very short to read, it&#039;s from my marketing guru Seth Godin (I&#039;ve read ALL his books !). It&#039;s called &amp;quot;[https://drive.google.com/a/officience.com/file/d/0Bzj0QwcgvarebmpzNUE0VTNjZjQ/view Really BAD powerpoint, and how to avoid it]&amp;quot;. Read it !&lt;br /&gt;
&lt;br /&gt;
The basic idea : for each side you should decide which &#039;&#039;&#039;emotion you want people to feel&#039;&#039;&#039;. And you start from that emotion to decide what you put in the slide. That will constraint you a lot in terms of idea. You&#039;ll have to put only one idea per slide. The role of the emotion is to make the idea sticky, by associating the two together. From one slide to another, the emotions will vary and that will form a story that drags your audience along.&lt;br /&gt;
&lt;br /&gt;
Next, you need &#039;&#039;&#039;a thesis&#039;&#039;&#039; You don&#039;t make slides to explain, you make slides to convince, to sell something. So you need to focus sharp on that thing you sell and which makes you &#039;&#039;&#039;unique&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Example :&lt;br /&gt;
&amp;quot;outsource your testing&amp;quot; : so many other people say that, why listen to you specifically ? :-(&lt;br /&gt;
&amp;quot;Vietnam is the best country for outsourcing testing&amp;quot; : wow, I&#039;m curious to hear how you can prove that ! :-)&lt;br /&gt;
&lt;br /&gt;
Now, unique does not mean selfish ! Here is another example :&lt;br /&gt;
&amp;quot;Officience is the best company for outsourcing testing&amp;quot; : Meh, this is just advertising. I won&#039;t believe a single word of it. :-(&lt;br /&gt;
&lt;br /&gt;
And the challenge is of course that you can&#039;t lie. So you need to find the right angle to tell your story. An angle that will make you friends, and where you are legitimate to be speaking about it. Note that I am specifically referring to &#039;&#039;&#039;you making friends&#039;&#039;&#039;, as an individual, because since Offi is a people-centric environment, the objective is not to convince customers to work with Officience, but to convince human beings to make projects with other human beings that is you. You don&#039;t need to sell Officience brand, sell your personal brand instead&lt;br /&gt;
&lt;br /&gt;
*The side benefit is that you will get to work with people who appreciate you, life will be more fun :-) !*&lt;br /&gt;
&lt;br /&gt;
== Typical outline ==&lt;br /&gt;
&lt;br /&gt;
Intro about Officience&lt;br /&gt;
The service we offer&lt;br /&gt;
Our strengths (in which circumstances we are a good pick)&lt;br /&gt;
Some technical details (process or tool) to show it&#039;s real&lt;br /&gt;
* process design&lt;br /&gt;
* Logos of the technologies we prefer.&lt;br /&gt;
Success Story : an example of a past project that worked so well :&lt;br /&gt;
* Context and objectives&lt;br /&gt;
* The solutions we deployed&lt;br /&gt;
* The &amp;quot;extra mile&amp;quot; what we delivered extra the the custoemr didn&#039;t expect :-)&lt;br /&gt;
The team : highlight of the key engagement people surrounding this product&lt;br /&gt;
&lt;br /&gt;
== Where to get inspired ? ==&lt;br /&gt;
&lt;br /&gt;
[[marketing.officience.com]] is our Google Site where you can find all the presentations we&#039;ve done in the past. In particular the &amp;quot;Corporate Brochure&amp;quot; presentation has general statements about Offi that you may want to embed or link in your presentation.&lt;/div&gt;</summary>
		<author><name>Duc</name></author>
	</entry>
</feed>