Guarding Computer Data

Patrick James McFadden · Journal of accountancy online/Journal of accountancy · 1997

How safe are your computer files or documents? Do you protect them from prying eyes or, worse, from hackers who try to steal or destroy the data? Considering the priceless nature of your information, safeguarding data should be high on your priority list. But that's easier said than done -- unless you know some software tricks. If you don't read on. The problem with security is that if it's too loose -- easy to violate, that is -- it's useless. If it's too tight, it'll be too difficult even for you to access. The goal is to have a security system that's just right: too hard for an outsider to gain entry but easy enough for you. EN GARDE! This article is about ways to design a just-right security system. It outlines the different levels of security for different functions so you can pick the ones that best serve your needs. Be advised, though, they are not designed to block the experienced hacker. At best, they will block the curious onlooker or the average computer user. These techniques include password protection, masking and information-change detection. Masking techniques include disguising files inside the computer, hiding ranges of information inside a file and making information appear unreadable or even invisible. Change-detection techniques include audit trails -- such as byte count, hash-control totals and formula-difference locators, all of which are explained later. It's important to understand that an effective security system should not rely on a single technique. The most effective strategy is to use security layering -- placing many walls between an unauthorized user and sensitive information. Many people use password protection, mistakenly thinking that it alone will keep most, if not all, intruders at bay. Passwords can be sidestepped by reloading the computer's operating system and application software. Let's look at each software application and see what security options are available and which ones meet your special needs. SPREADSHEET PROTECTION TECHNIQUES Of all types of applications, spreadsheet software offers the most built-n security features. Both Lotus 1-2-3 and Microsoft Excel contain essentially the same protection methods. At the simplest level, a password can block an intruder from opening or changing a file. Also, both programs have a number of features for hiding, filtering or otherwise masking information. Excel has a slight edge in the number of features for detecting changes -- so you'll know if an intruder has altered the file. Password protecting spreadsheets (in Excel they are called worksheets) is easy. One password prevents opening a file and is activated when saving a File. For Lotus, a user clicks on File, Save As, checks the With Password box and enters a password. In Excel, a user clicks on File, Save As and Options and enters a password. To allow another Lotus user to input over a certain range of data, a user first unprotects the range by clicking Style Protection. The user then specifies the range, and checks the Keep Data Unprotected box. Next, the user clicks on File, Protect, checks the Seal box and enters a password of up to 15 characters. Excel uses the same basic technique. The user must unprotect the input range by highlighting the range, clicking on Format, Protect and then clearing the Locked box. The user then pulls down the Tools menu, selects Protection, Worksheet Protection and enters an appropriate password. In addition, Excel users can render a file read only by entering a password in the Write Reservation box of the Save As panel. Lotus provides a similar feature for networked users. Spreadsheets provide excellent information-masking techniques. It takes only a few keystrokes for a user to hide rows, columns, cells, graphics and even entire spreadsheets. Another element of security is the intruder alarm: It lets you know if someone has gained admission to your file and changed it. …

Read the paper · More papers on PaperTik