| 
 
 | |||
| Security and Privacy Resources | 
|---|
 AV-Test
   
AV-Test is a top-ranked virus testing organization.  It conducts independent, objective tests of
antivirus programs, and did a test of antivirus programs on Microsoft Windows operating systems for About.com.
The top five products all scored 100% on the general antivirus tests and 97% or greater on detecting and
disinfecting the more uncommon security problems. The winners were:
http://www.av-test.org/  
Although they didn't make the top five, McAfee, PC-cillin, and F-Secure all ranked highly on the test, the full results of which are available on AV-Test's website at http://www.av-test.org/sites/test_all.php3?test=2001-11&lang=en.
Firewalls are a must have layer of protection for those with high speed always-on connections to the Internet. The following are some of the top rated firewalls:
 ZoneAlarm
   
ZoneLabs' ZoneAlarm is one of the highest rated firewalls on the market (PC Magazine Editor's choice, 2000, 2001 -- 5 of 5 stars;
PC World award, 2000, 2001).  It monitors both inbound and outbound connection attempts, and provides superb protection against
remote access Trojans and hackers. There is a free version for personal/home use, while ZoneAlarm Pro costs $39.95 for a single user license.
http://www.zonealarm.com/  
 BlackIce Defender
   
This firewall, by Internet Security Systems (formerly Network Ice) received four out of five stars from PC Magazine.
The shareware product costs $39.95.
http://www.iss.net/  
 McAfee Firewall Products
   
The McAfee Firewall got 3 of 5 stars from PC Magazine. It costs $29.95 for one year, $49.95 for two years.
  McAfee's Internet Security got 5 stars and integrates a number of McAfee's security products together for $79.95.
http://www.mcafee.com/myapps/firewall/ov_firewall.asp?  
 Norton Personal Firewall
   
The Norton Personal Firewall received 3 of 5 stars from PC Magazine and costs $49.95.
http://www.symantec.com/  
 Tiny Personal Firewall
   
Tiny Software's Tiny Personal Firewall was the winner of the FOSE 2001 Award for Best New Technology.  It is free for
home use and costs $29.95 for business use.
http://www.tinysoftware.com/  
There are other products that help keep your system safe.
 GoBack 3 Deluxe
   
GoBackŪ is a highly rated program that monitors and saves key information on your computer, allowing you to
revert back to an earlier state when problems arise.  Different than a traditional backup, which usually involves just
data, GoBack can take a drive back to its "pre-ops" state, even if your system is unbootable.  The one drawback
to this program is that it requires about ten percent of the hard drive be allocated for GoBack's use. $39.95 downloaded.  $49.95 packaged.
http://www.roxio.com/en/products/goback/  
 MailDefense
   
MailDefense acts as an additional layer of defense against email-borne threats.  It keeps viruses from getting
into your inbox and from leaving your system.  MailDefense uses advanced filtering technology to quarantine potentially
harmful attachments, removing scripts, ActiveX controls, and macros out of Microsoft Office files, leaving email safe.  $29.95.
http://www.indefense.com/  
 CERTŪ Advisory Mailing List 
   
The CERTŪ Coordination Center (CERT/CC) is a major center of Internet security expertise at the Software Engineering Institute,
a federally funded research & development center operated by Carnegie Mellon University.  CERTŪ studies Internet security vulnerabilities,
handles computer security incidents, publishes security alerts, researches long-term changes in networked systems, and develops information
and training to help improve site security.  Subscribe to the mailing List to receive copies of the CERTŪ advisories and summaries.
http://www.cert.org/contact_cert/certmaillist.html  
 Crypto-Gram
   
Crypto-Gram, which has over 60,000 subscribers, is security expert Bruce Schneier's free monthly e-mail newsletter on computer security and
cryptography.  Crypto-Gram contains provactive commentaries on security policy issues and has fully referenced security news
summaries and analyses.
http://www.counterpane.com/crypto-gram.html  
 DOE-Computer Incident Advisory Capability (CIAC)
   
CIAC issues the computer security advisories for the U.S. Department of Energy.  CIAC HoaxBusters is the top website for finding what is a real security threat and what is not.
http://www.ciac.org/ciac/  
 Extreme Tech Security
   
This is a Ziff-Davis newsletter with timely alerts, commentary, and solutions about computer systems and privacy issues.
http://www.extremetech.com/  
 Information Security Magazine
   
This hard copy magazine, published by TruSecure Corporation, has a corporate focus. It covers issues such as scripting security,
network forensics analysis tools, encryption issues, vulnerability management, and security-related software and hardware comparisons.
You can also subscribe to the twice weekly Security Wire Digest e-newsletter, free.
http://www.infosecuritymag.com/  
Microsoft Security Information
   
Microsoft has a quite a bit of information about security issues on its website.  The
Microsoft Security Advisor page describes what Microsoft's security packs are,
explains how to subscribe to the
Microsoft Security Bulletins that
alert users to security problems with Microsoft software, links to articles on how to understand enterprise security issues, how to develop
secure operations, and other related security issues.  The
Microsoft Technet Security Site is
another way to see how Microsoft deals with security issues. It includes hot topics, best practices, Microsoft policies, government issues,
Microsoft security essays, the bulletins, a number of product-specific newsgroups, and much more.
http://www.microsoft.com/security/  
 Virus Bulletin
   
The Virus Bulletin is an international hard copy publication on computer virus prevention, recognition and removal.  Although
the Bulletin doesn't have a free e-zine, the website offers a list of virus hoaxes, monthly virus prevalence tables that list the
number of incidents by virus type, the monthly wildlist that lists viruses reported around the world, a list of antivirus
product developers, and the Virus Bulletin 100% awards that recognize those products best able to detect viruses known to be
in the wild.
http://www.virusbtn.com/  
 SANS Institute
   
The SANS (System Administration, Networking, and Security) Institute is a top research and
education organization "through which more than 156,000 security professionals, auditors, system administrators, and
network administrators share the lessons they are learning and find solutions to the challenges they face."
The SANS site contains descriptions of security training programs, web-based forums on a number of security issues, experts'
consensus on the twenty most critical Internet vulnerabilities, information on global information assurance certification
(GIAC), a link to incidents.org which
has statistics on security-related incidents, a link to the SANS Reading Room
which has more than 1300 articles in 63 different categories, and more.
SANS offers two newsletters.  SANS NewsBites is a weekly security news overview with summaries of the major security-related
news and links to the full articles.  For a free subscription, e-mail sans@sans.org
with the subject: Subscribe NewsBites.  The Security Alert Consensus newsletter, published in conjunction with Network Computing, sends
you security information specific to the platform categories in which you are most interested:
Windows (95, 98, NT, 2000), Linux, BSD, SUN, AIX, NetWare, HP/UX, SGI, SCO, Cross-platform, Other OSes (MAC, BeOS, etc.), and Network
Appliances.  Subscribe to this newsletter at http://www.networkcomputing.com/consensus/.
http://www.sans.org/  
 Electronic Frontier Foundation (EFF)
   
The EFF was founded in July of 1990 in response to a basic threat to speech, and continues to be at the forefront in
identifying threats to our basic rights online and advocating on behalf of free expression in the digital age. Their
Privacy, Security, Crypto, & Surveillance Archive is a history of the threats to
privacy and intellectual freedom online.
http://www.eff.org/  
 Electronic Privacy Information Center (EPIC)
   
EPIC is a public interest research center in Washington, D.C. established in 1994 to focus public attention on
emerging civil liberties issues and to protect privacy, the First Amendment, and constitutional values. The website includes guides
to practical privacy tools and online privacy resource, tracking pending legislation related to privacy and civil liberties in the
U.S. Congress, and archives on computer security, cyrptography policy, free speech, freedom of information, and privacy.
http://www.epic.org/  
 Privacy.org
   
Privacy.org is a joint project of EPIC and Privacy International.  It contains news, calls to action, and privacy-related resources.
http://www.privacy.org/  
 Chilling Effects Clearinghouse
   
Chilling Effects is a joint project of the Electronic Frontier Foundation and Harvard, Stanford,
Berkeley, and University of San Francisco law school clinics.  This website was setup to teach web users
about their online rights.  These site will help you understand the protections intellectual property laws
and the First Amendment give to your online activities. It describes how the excuse of anti-terroism and
"national security" are being used to silence free expression and other Internet activity.
http://www.chillingeffects.org/  
 Privacy Journal: Resources to Help Protect Your Privacy
   
The Privacy Journal is a monthly hardcopy newsletter founded in 1974 to report on new technology and its impact on
personal privacy. The website contains subscription information, privacy tips, and information on model privacy policies.
http://www.townonline.com/privacyjournal/  
 Privacy Forum
   
The Privacy Forum, created in 1992 by Lauren Weinstein, is a moderated e-mail discussion list (with archives)
for the discussion and analysis of issues relating to privacy in the information age. To subscribe, send a message to:
privacy-request@vortex.com with subscribe privacy in the body of the message.
http://www.vortex.com/privacy  
 Privacy Exchange
   
This site is a resource on consumers, commerce and data protection worldwide. It contains news alerts, a legal library,
privacy policies of individual companies and industry associations, trans-border data flow issues, studies, surveys, and other resources.
http://www.privacyexchange.org/  
 Online Privacy Alliance
   
The Online Privacy Alliance is made up of a diverse group of corporations and associations who are working together to
promote "business-wide actions that create an environement of trust and foster the protection of individuals' privacy online."
The site has guidelines for company online privacy policies, resources about enforcement, principles for children's online activities,
and member news and efforts.
http://www.privacyalliance.org/  
 OECD Privacy Policy Generator
   
This is a tool to help organizations develop privacy policies. It offer guidance on conducting an internal review
of existing personal data practices and on developing a privacy policy statement.  The Generator uses a questionnaire to
learn about your personal data practices; has a Help Section that provides explanatory notes and practical guidance; warning
flags appear where appropriate. Your answers are then fed into a pre-formatted draft policy statement which you must assess
to make sure that it is it an accurate reflection of your personal data practices and policy.  The site also has links to
private, non-profit, and public sector privacy policies and resources.
http://cs3-hq.oecd.org/scripts/pwv3/pwhome.htm  
 Web Bug FAQ
   
This Frequently Asked Questions piece describes what web bugs are, how they can be identified, whether they are
legal or ethical, and related issues.
http://www.cybersync.com/help/web-bugs/wbfaq.htm  
 Cyberspace Law
   
This site includes a wide range of online legal issues including intellectual property, privacy, freedom of speech, and related
issues. It also has an extensive list of law and technology reviews, online articles, resource pages and courses.
http://jurist.law.pitt.edu/sg_cyb.htm  
![]()
 
Antivirus Resources   
 Security News  
Privacy Issues   
InfoQuest!
![]()
Copyright 2002 InfoQuest! Information Services
Last updated: March 8, 2002
Please send any comments to 
tbchad@tbchad.com or 503-228-4023.
Terry Brainerd Chadwick
InfoQuest! Information Services
2324 NW Johnson St., Ste.4
Portland, OR 97210-5221