[misc.security] Request for Risk Assessment

peter@thirdi.UUCP (Peter Rowell) (10/22/90)

My wife is the publications editor for a charitable organization.
In connection with a journal they are working on, they will be
receiving floppies from authors all over the U.S. (and possibly
elsewhere).  They may also be sending out floppies for review by
content editors, etc.

I expressed concern that they might very well be laying themselves wide
open to god-knows-what in the way of viruses/worms/whatever.  I also
thought that they could act as a very efficient spreader of these same
nasties to other unsuspecting victims.  Their local "expert" told them
that they had nothing to worry about, but that if "something happened"
to call him and he would "fix it".

QUESTIONS:
    Is my concern valid, even if they only read/write files in MS Word
	format (or Wordperfect or ??)?

    If it is valid:
	What is out there that they need to look out for?
	How do they detect it?
	How do they fix it?
	Can they (should they?) perform checking/sanitizing on a
	    machine on the net or on an isolated machine?
	Is there a source of information on this (book/mag/etc)?

The environment in question is a network of machines (mostly HP Vectras
+ some others) connected by ethernet, running DOS and applications such
as Word, Wordperfect, Lotus 1-2-3, some-sort-of-e-mail, etc.

Please e-mail any help you can offer.

----------------------------------------------------------------------------
Peter Rowell				peter@thirdi.uucp
Third Eye Software, Inc.		...!{apple,pyramid,sun}!thirdi!peter
750 Menlo Avenue, Suite 300		(415) 321-0967
Menlo Park, CA  94025