Skip to content

Authored by: PlexTrac Team

Posted on: October 22, 2019

Prevent Unauthorized Software from Contaminating Company Networks

End-users are one of the most common targets for the contamination of a Company network. These users can be easily manipulated if not well informed. Hackers use this to their advantage for personal gain of your information, or an overall sabotage of your company. This blog post clearly communicates the role of the user in preventing the introduction of unauthorized software. It also makes clear prohibitions against malicious “hacker-like” activities on Company networks for any purpose.

Users should adhere to the following directives in order to ensure a preventative strategy against malware and other unauthorized software:

1. Only Let Authorized Individuals Install Software

Only authorized staff or contractors, with express approval, are authorized to install or download any software. Any requests for changes to established baseline configurations of any information systems must be submitted to management or the designated representative. Staff will research potential business, security and financial impacts of the requested changes and disseminate this research to members of the Change Control Board.

2. Do Not Disable Endpoint Protection

Users must never disable or suspend endpoint protection software enabled on their machines. (e.g. Windows Defender or another anti-virus/endpoint protection).

3. End Users Must Not Introduce New Code

End Users must not intentionally write, generate, compile, copy, propagate, execute, or attempt to introduce any computer code designed to self-replicate, damage, or otherwise hinder the performance of any computer’s memory, file system, or software.

4. No Form of Network Monitoring is Allowed

Port scanning, security scanning or executing any form of network monitoring which will intercept data not intended for the employee’s host is expressly prohibited.

5. No Interfering with or Denying Service to Other Users

Interfering with or denying service to other user, or using any program/script/command, or sending messages of any kind, with the intent to interfere with, or disable, a user’s terminal session, via any means, locally or via the Internet/Intranet/Extranet is expressly prohibited. 

PlexTrac Team
PlexTrac Team Editorial Group At PlexTrac, we bring together insights from a diverse range of voices. Our blog features contributions from industry experts, ethical hackers, CTOs, influencers, and PlexTrac team members—all sharing valuable perspectives on cybersecurity, pentesting, and risk management.

Liked what you saw? We’ve got more content for you

CISOs Don’t Need Faster Decisions. They Need Trusted Execution.

The Gartner Security & Risk Management Summit wrapped up in National Harbor last week with the usual mix of analyst frameworks, threat-landscape predictions, and AI-flavored everything. If you’re a CISO, you probably watched the highlights, nodded at the right slides, and then went back to a backlog that didn’t get any shorter. Two themes ran...

Your Risk Score Is Only as Good as the Context Behind It

How PlexTrac’s configurable risk scoring puts business context back in the driver’s seat Security teams have always known that severity and priority aren’t the same thing, but most of the tools they rely on haven’t caught up to that reality. When a scanner hands back a list sorted by CVSS score, it’s ranking how dangerous...

Your scanners, your pentests, your exposure data, together in PlexTrac

Security teams do not buy a reporting and exposure management platform to acquire one more silo. They buy it to consolidate; to bring the findings their other tools generate into one place where work actually gets prioritized and reported. The more of your security stack that connects to that platform, the better it can do...

Request a Demo

PlexTrac supercharges the efforts of cybersecurity teams of any size in the battle against attackers.

See the platform in action for your environment and use case.