One of the best ways to securely provide Internet access to your users is to monitor Internet usage.
When you monitor Internet usage, you don’t have to parse log files of each and every website your users visit, nor do you have to question them about why they spent twenty minutes updating their status. The right way to monitor Internet usage is to use an Internet monitoring application that can automate all the different aspects of providing Internet access to your users in a safe and secure fashion, and that can enforce your company’s Internet Usage Policy while respecting users’ privacy, and administrators’ limited time.
There are a number of practices small to medium sized business should follow when monitoring Internet usage. The following should be a “must-do”:
1. Establish a clear policy
Every company, no matter how large or small, needs to have a clear and concise policy that addresses what is, and is not, appropriate when employees are using the company’s computer resources. Whether you incorporate Internet access into your Acceptable Use Policy or Information Security Policy, make sure you clearly spell out what is acceptable and what is not.
2. Educate users
Go over this policy with your employees. Do so at new hire orientation, and make it a part of your annual policy training with every user, every year. Keep the policy online where users can get to it, refer to it when appropriate, and consider some form of monthly or quarterly update/reminder so users are fully aware of what is expected.
3. Allow some personal use
You will probably find out quickly that permitting some personal use of the Internet goes a long way towards improving morale. Whether you expect managers to ensure it does not get out of hand, or you use bandwidth or time filters to enforce limits, it’s worth it to permit user some degree of freedom.
It shows trust, and softens the blow when users must take a call after hours, work late, or on the weekend.
4. Implement Internet monitoring
Deploy an application that can perform Internet monitoring automatically. Using network sniffing or monitoring DNS logs is not a practical or scalable way to monitor Internet usage. Use a server-based application and ensure that all Internet access flows through this system with no way to circumvent it.
If you deploy software to monitor Internet usage on your gateway, there won’t be a practical way to bypass or circumvent it. If you use a separate server and configure your browsers to use it as a proxy, make sure you block outbound web traffic from client subnets so no one can bypass it.
5. Protect users’ privacy
When you monitor Internet usage, you are doing so to protect the company, not to play the role of an Internet cop or to pry into the activities of individual users. Look for Internet monitoring software that can aggregate log data, or otherwise protect individual users’ identities unless there is a reason to investigate a specific user’s actions.
6. Use categories and block phishing, compromised, and suspicious sites
When you monitor Internet usage, use a solution that offers categorized lists of sites you can block based on the company’s policy, and that can also block phishing sites, hacked sites, and sites that are “suspicious”. Perfectly legitimate business websites are compromised every day, and your Internet monitoring software should be able to update and react quickly to new threats.
7. Provide a way to request exceptions
You will find times when a user feels they need to access a blocked site. This could be because of a miscategorization or special need, or simply a misunderstanding. Whatever the reason, provide a way for users to request exceptions so they won’t look for ways to violate the policy.
8. Keep awareness up
Make sure users are aware that the company monitors Internet usage, and why it does so. Send out updates when the Internet monitoring application blocks an infected download, prevents a user from accessing a compromised website, or blocks a phishing victim from visiting a fake site. This not only helps users to understand why the company monitors Internet usage, but can also help them be a little more cautious about what they do at home.
Implement these best practices for monitoring Internet usage within your organization, and you will provide your users with a safe, secure, and effective way to use the Internet, without anyone feeling untrusted or that their privacy has been violated.
This guest post was provided by Casper Manes on behalf of GFI Software Ltd. GFI is a leading software developer that provides a single source for network administrators to address their network security, content security and messaging needs. Learn more about why you need to monitor Internet usage.
All product and company names herein may be trademarks of their respective owners.
Mata description:
The MUST-DOs for organizations who want to monitor Internet usage the right way.
Keywords:
Monitor Internet usage, Internet monitoring software, Internet access, Internet usage policy, Acceptable Use Policy, Information Security, block phishing, hacked sites, bandwidth, DNS logs, privacy.


