<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Free version of Skype use on Corporate Network.  Thoughts  or Concerns in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9027#M786</link>
    <description>&lt;P&gt;Nothing is free, remember that. What are you giving up by using this "free" tool? Does it send info about your network out, etc.&lt;/P&gt;&lt;P&gt;Also make sure to read the EULA (End User License Agreement) to make sure it can legally be used on a corporate network. It used to be that free software was designed to be used by non-business customers and the EULA's clearly stated that it was not for use on corporate, business, or government networks. That may have changed, but I always like to check. You may want to have your legal department (if you have one) take a look at it. Look to see what data it collects and transmits.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maintenance has already been mentioned but make sure you have the people to support it.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Apr 2018 13:12:57 GMT</pubDate>
    <dc:creator>CISOScott</dc:creator>
    <dc:date>2018-04-02T13:12:57Z</dc:date>
    <item>
      <title>Free version of Skype use on Corporate Network.  Thoughts  or Concerns</title>
      <link>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/8987#M781</link>
      <description>&lt;P&gt;Hello everyone,&amp;nbsp; &amp;nbsp;I wanted to see what members thought about companies allowing the free version of Skype on their corporate network.&amp;nbsp; &amp;nbsp;I have been asked about this many times and have seen this as well.&amp;nbsp; There seems to be many different opinions on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After reviewing a couple of studies and reading many security articles related to free Skype on a corporate network, there have been vulnerabilities and there will be more in the future but many of these are no different than the vulnerabilities we have with our browsers, Adobe, Flash and Java.&amp;nbsp; As long as versions are kept current those risks should be low.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main disadvantage of allowing free Skype our network is lack of control and loss of information.&amp;nbsp; Then again is this really any different than allowing users to access social media or personal webmail?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I usually suggest free Skype is a bad idea on a corporate network but my latest research has me questioning myself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 16:12:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/8987#M781</guid>
      <dc:creator>bspicer</dc:creator>
      <dc:date>2018-03-30T16:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Free version of Skype use on Corporate Network.  Thoughts  or Concerns</title>
      <link>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/8991#M782</link>
      <description>&lt;P&gt;Bill,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that you need to go through the motions of a risk assessment.&amp;nbsp; The way that you referred to using other Internet applications on organization resources makes me think that this was trivialized in the past.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allowing each individual application in a vacuum may seem insignificant.&amp;nbsp; As you permit access you are making actual changes to your security posture that may be imperceptible to you, but not necessarily to an adversary (inside or outside).&amp;nbsp; The aggregate of all vulnerabilities in your enterprise may make you considerably more at risk than you think.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 18:38:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/8991#M782</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-03-30T18:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Free version of Skype use on Corporate Network.  Thoughts  or Concerns</title>
      <link>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/8992#M783</link>
      <description>&lt;P&gt;Software development is how I got into IT so I'll put that hat on...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Always the #1 question to ask -- what are your requirements?&amp;nbsp; If there is a business need to use a Skype-like product, then explore that some more in the context of requirements, drivers, enablers,etc.&amp;nbsp; If not, then there is your answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have concerns about Skype on your systems but the post didn't cover why someone wants to load Skype on your systems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a need for a Skype-like product, then have you done any internal trade studies on what meets the org's requirements best?&amp;nbsp; Skype isn't the only provider out there.&amp;nbsp; How does your org know Skype is what it wants?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Implementation before design is rarely a good thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the fun technical part.&amp;nbsp; How have you prototyped/tested any of the potential/candidate solutions?&amp;nbsp; Have you monitored network traffic while testing it to see all the things which are hitting your infrastructure?&amp;nbsp; If you're worried about vulnerabilities, have you researched that?&amp;nbsp; Like going out to something like exploit-db and others and seeing what can be done to Skype?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you've done this work, great.&amp;nbsp; If not, how does one make a recommendation one way or another?&amp;nbsp; Wouldn't someone along the way in the decision making process eventually look for facts?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 19:42:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/8992#M783</guid>
      <dc:creator>mgoblue93</dc:creator>
      <dc:date>2018-03-30T19:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Free version of Skype use on Corporate Network.  Thoughts  or Concerns</title>
      <link>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9017#M785</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/864591473"&gt;@bspicer&lt;/a&gt;, as&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/723530429"&gt;@Baechle&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/754920891"&gt;@mgoblue93&lt;/a&gt;&amp;nbsp;have already stated,&amp;nbsp;the risk&amp;nbsp;varies with the environment ---&amp;nbsp;and&amp;nbsp;will be&amp;nbsp;calculated using&amp;nbsp;many&amp;nbsp;factors, including but not limited to: -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Business requirements&lt;/LI&gt;&lt;LI&gt;Available solutions&lt;/LI&gt;&lt;LI&gt;Security controls&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;To use your example of Skype, it may be worth implementing in an organization that doesn't prioritize security but has a need for continuous easy communication between users' systems, but not in an organization where communication is to be tightly&amp;nbsp;controlled&amp;nbsp;&amp;amp; security is a&amp;nbsp;major concern.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Apr 2018 07:50:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9017#M785</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2018-04-01T07:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Free version of Skype use on Corporate Network.  Thoughts  or Concerns</title>
      <link>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9027#M786</link>
      <description>&lt;P&gt;Nothing is free, remember that. What are you giving up by using this "free" tool? Does it send info about your network out, etc.&lt;/P&gt;&lt;P&gt;Also make sure to read the EULA (End User License Agreement) to make sure it can legally be used on a corporate network. It used to be that free software was designed to be used by non-business customers and the EULA's clearly stated that it was not for use on corporate, business, or government networks. That may have changed, but I always like to check. You may want to have your legal department (if you have one) take a look at it. Look to see what data it collects and transmits.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maintenance has already been mentioned but make sure you have the people to support it.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 13:12:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9027#M786</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2018-04-02T13:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Free version of Skype use on Corporate Network.  Thoughts  or Concerns</title>
      <link>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9033#M788</link>
      <description>&lt;P&gt;Ken (&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1602421967"&gt;@CISOScott&lt;/a&gt;),&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's a good point.&amp;nbsp; I assumed Bill (&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/864591473"&gt;@bspicer&lt;/a&gt;)&amp;nbsp;was talking about letting folks just have access to their personal Skype accounts so they can coordinate their grocery shopping and the like with their spouse.&amp;nbsp; But, if it's for commercial use there's a liability there for unauthorized use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eric B.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 17:30:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9033#M788</guid>
      <dc:creator>Baechle</dc:creator>
      <dc:date>2018-04-02T17:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Free version of Skype use on Corporate Network.  Thoughts  or Concerns</title>
      <link>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9075#M795</link>
      <description>&lt;P&gt;Thank you everyone for your responses.&amp;nbsp; All very good points. Much to consider with apps like these.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 14:42:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Free-version-of-Skype-use-on-Corporate-Network-Thoughts-or/m-p/9075#M795</guid>
      <dc:creator>bspicer</dc:creator>
      <dc:date>2018-04-03T14:42:07Z</dc:date>
    </item>
  </channel>
</rss>

