Philosophy
At IHSYSTEM we take security very seriously. We do not
believe in security by obscurity. We invest our time, money
and effort in secure programs that withstood the test of
time as well as the scrutiny of sharp developers all over
the world.
We do not activate on our servers services that we never
expect to run. We make sure that only those programs that
we really need are running. We upgrade our software regularly
and we make sure to close common holes and proactively prevent
common attacks. We make sure that all adminstration work
on our systems by operators or clients are through encrypted
channels. While nobody can guarantee absolute security (some
may say that absolute security does not exist), we use our
skill and expertise to set up reliable secure systems so
that we can rest well at night knowing that our data is
safe.
We also realize that one of the biggest threats to security
is what is known as 'Social Engineering.' This is the act
of getting privileged information (for example, a password)
from a person rather than by attacking a system. Our administrators
always use digital signatures for email correspondence,
so you can be sure that no one can masquerade as us. Conversely,
when dealing with client requests, we only deal with people
that the client has authorized to speak on their behalf.
'Security' isn't an ornament we use to adorn our projects.
It is the way we conduct our day-to-day business. It is
established in everything we do.