There's lots of innovation going on in security - we're inundated with a steady stream of new stuff and it all sounds like it works just great. Every couple of months I'm invited to a new computer security conference, or I'm asked to write a foreword for a new computer security book. And, thanks to the fact that it's a topic of public concern and a "safe issue" for politicians, we can expect a flood of computer security-related legislation from lawmakers. So: computer security is definitely still a "hot topic." But why are we spending all this time and money and still having problems?

There is another group of people who loudly call themselveshackers, but aren't. These are people (mainly adolescent males) whoget a kick out of breaking into computers and phreaking the phonesystem. Real hackers call these people ‘crackers’ andwant nothing to do with them. Real hackers mostly think crackers arelazy, irresponsible, and not very bright, and object that being ableto break security doesn't make you a hacker any more than being ableto hotwire cars makes you an automotive engineer. Unfortunately, manyjournalists and writers have been fooled into using the word‘hacker’ to describe crackers; this irritates real hackersno end.

The last of these offences in theory at least makes it illegal to write and distribute computer viruses.For most users and organizations, effective computer security and data integrity involves carefully considering the following key questions:Unless there are deemed to be no negative consequences that could arise, in order to address the potential implications of the above any computer user -- be they an individual or a large business organization -- needs to take the following measures.First and foremost, a back-up strategy should be implemented that provides resilience against flood, fire theft and media failure.

