ISPA to launch cyber security code in South Africa
SECURITY| May 4, 2012, 8:13 a.m.
South Africa's Internet Service Providers' Association (ISPA) has announced it will lead the development of a new voluntary code of practice to improve cyber security for end-users.
Known as the icode, and developed in conjunction with Australia's Internet Industry Association, which pioneered the approach in 2010, the code will provide a consistent approach for South African ISPs to help inform, educate and protect their customers in relation to cyber security. South Africa would become the second country in the world to implement network level protection of vulnerable end users under the icode banner.
By following the code, ISPs will contribute to reducing the number of compromised computers in South Africa and enhance the overall security of the South African and international Internet.
"The increasing threat of zombied computers - computers which have been essentially hijacked and are under the control of criminals or other third parties - presents a real risk to users. Identity theft, fraud, and increases in spam are all possible consequences of compromised computers."
"The problem we now face as an industry," said ISPA spokesperson Ant Brooks, "is the sophistication of attacks on end-user computers. Scanning at the network level by ISPs can provide an early warning to users when the user may be completely unaware there's a problem with their computer."
"An infected computer is not only bad for the end-user, it's also a problem for the integrity of networks themselves because it increases the amount of spam and other "bad traffic". This is why ISPs are telling us they will support the scheme."
Australia's Internet Industry Association chairman Bruce Linn welcomed the announcement. "The Australian experience has shown that end-users appreciate knowing that their ISP is watching for signs of infection on the network.
Most users are initially very surprised to find out that their machine may be infected by 'malware' such as viruses. But they are relieved when they are given the information and tools to restore their computer's security."
The initiative was also welcomed by the banking sector. "South Africa's banks are committed to educating consumers about online security, and constantly review security measures to offer South African Internet users as safe an online banking experience as possible," says Mrs Kalyani Pillay, CEO of the South African Banking Risk Information Centre (SABRIC).
"SABRIC welcomes the launch of the icode project, and is encouraged by the commitment of ISPs towards assisting their customers with the security of their computers and their personal information."
ISPA spokesperson Ant Brooks emphasised that the new code was designed to protect the privacy of end-users.
"The network level scanning that allows ISPs to detect signs of infected machines does not in any way involve looking at what users are themselves doing online. On the contrary, the scheme is designed to reduce the incidence of the single biggest threat to end-user privacy -- the presence of malware which can steal personal information and relay it to criminals overseas."
The code is designed to respond to this challenge by providing a consistent approach for South African ISPs to help inform, educate and protect their customers in relation to cyber security. ISPA believes a uniform national (and international) approach is warranted. The code will deliver a standard set of best practices for ISPs to follow to preserve the integrity of their networks.
The icode is expected to contain four main elements:
- A notification/management system for compromised computers
- A standardised information resource for end users
- A comprehensive resource for ISPs to access the latest threat information
- A reporting mechanism in cases of extreme threat back to national security agencies to facilitate a national high level view of attack
MORE SECURITY NEWS
Safe Deposit: Defeating cyber-attacks against banksWith online heists once again hitting the headlines, how should banks and their customers protect themselves against similar attacks? Read More
Large organisations gear up to address aggressive cyber-security business disruption attacksAlthough the frequency of a cyber-security attack on a large scale is low, by 2018, 40 per cent of large organisations will have formal plans to address aggressive cyber-security business disruption attacks, up from none this year, says Gartner. Read More
Identity and access management trends for 2015CA Technologies has identified five key trends for security and identity and access management (IAM) that will impact organisations and security professionals in 2015 as they compete in the application economy. Read More
Leading newspaper site hackedBotswana is seeing unprecedented cases of internet hacking with one of the latest attacks targeting one of the country’s leading private newspapers, Mmegi. Read More
Senegal hit by wave of cyber attacksSenegal has been hit by a wave of hackings in the past two weeks, two of which hit the popular news website Seneweb.com and ADIE. Read More
Cyber attacks may get more virulent, Cisco, Kaspersky warnCyber attackers are using more subtle methods to infiltrate corporate networks with the aim of stealing vital information or simply causing mayhem. This is according Kaspersky Lab and Cisco, who say IT security experts should up their game in educating users how to ward off potential attackers. Read More
SIM box task team steps up successes with help from ICT firmGhana’s efforts to crack down on SIM boxing fraud have been given a boost by the efforts of Subah Infosolutions Ghana Limited, which now partners with the authorities in the fight against this crime. Read More
Software vulnerability led to Ghana govt site hackA software vulnerability and failure to update software led to the hacking of some websites on the government of Ghana’s official portal. Read More
CBN issues directive on two factor authentication for internal banking processesThe Central Bank of Nigeria has issued a directive requiring all deposit money banks (DMBs) to implement two factor authentication for internal processes this year. Read More
SA: 57% could not recover money stolen in online fraudA recent survey conducted by Kaspersky Lab and B2B International found that more than half of those respondents in South Africa who lost money in fraudulent online transactions did not get all – or sometimes any – of their funds back. Read More
FEATURED STORY2bn priced out of internet access
A new report from the Alliance for Affordable Internet shows that the price of broadband remains prohibitive for billions in developing and emerging countries, with women and rural dwellers hardest hit.
BEST READ NEWS
IN DEPTHKenya’s digital TV battle hots up
Kenya’s journey to Digital TV broadcasting took a new turn this week, when the Communication Authority of Kenya (CAK) accused three local media firms of intent to disrupt the process.
COMPANY NEWSVMware unveils vCloud for NFV with Integrated OpenStack to accelerate service innovation
VMware, the global leader in virtualisation and cloud infrastructure, today debuted VMware vCloud for NFV, an integrated Network Functions Virtualization (NFV) platform that will combine VMware’s production-proven ...