1/64
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
A digital security risk is
any event or action that could cause a loss of or damage to computer hardware, software, data and/or processing capability.
Computer crime is
any illegal act involving the use of a computer
Cybercrime refers to
Internet-based illegal acts
Hackers are
people who access a computer or network illegally
A zombie is
a computer that is being controlled remotely by a hacker without the knowledge of the computer's owner.
A botnet is a
group of zombies that are used to attack other networks.
A back door is
software that allows a user to bypass security controls when accessing a computer.
When hackers gain access to a computer they often install a back door, which allows them to continue to access the computer remotely without the user's knowledge
Spoofing is
when a hacker tries to make an email or website look legitimate in order to trick the user into downloading malware or providing confidential information
Malware (malicious software)
are programs created by hackers that harm the computer's operations.
Malware can get installed
on a computer without a user's knowledge when a user opens an infected file, an infected program or a malicious email file attachment or connects a secondary storage device (flash drive, hard drive) to an infected computer.
Computer virus:
software that is attached to a data file, program file, or email message.
Virus attacks can delete files, erase the hard drive, slow system performance, display screen messages, and/or send emails to everyone in your address book
A Trojan horse is
a malicious program that is disguised as (or within) a legitimate program.
When the program is run, it executes whatever malicious code the hacker has written.
Unlike viruses, Trojan horses cannot replicate themselves.
Denial of service attack:
a program that floods a web server or network server with so many requests for action that it or can no longer handle legitimate requests
Spyware:
A program that is installed on a computer without the user’s knowledge.
secretly gathers information about the user (Web site activity and/or keystrokes) and transmits it back to the person who created the spyware.
Ransomware:
A program that encrypts the victim’s data so it is not accessible.
The hacker demands the victim to pay a ransom (in untraceable bitcoins) in order to have their data restored
Malware can often be detected and deleted/disabled
by an antivirus program.
However, in some cases the only way to remove malware from a device is to reformat a computer's hard drive or reset a mobile device to its factory settings.
Thus, it is important to always backup important files and programs so they can be copied back onto the device after a reformat.
Strategies to protect a device from a malware attack are:
Use antivirus SW.
Use a firewall
Only download SW and file attachments from well-known Web sites
Do not share external storage devices between computers
Only open email file attachments from people you know and do not open attachments that have an executable file extension (such as .exe, .com, .bat, or .vbs)
Regularly download and install the latest security patches for your operating system, browser, email and antivirus programs
Avoid downloading files from peer-to-peer Web sites
Back up your data regularly
Use antivirus SW:
An effective antivirus application continuously checks emails, instant messages, and downloaded files for malware and can perform a virus scan of the entire PC
Use a firewall
that scans incoming data and filters out any data that might be a malware attack
Unauthorized access occurs
when a person gains access to a computer or network without permission.
Unauthorized use
involves using a computer resource for unauthorized (and possibly illegal) activities.
Install and/or turn on a firewall:
Use a CAPTCHA,
Use two-step verification.
Have an acceptable use policy (AUP)
Require users to frequently change passwords, require passwords to have a combination of at least eight numbers, symbols, and letters, and revoke an employee’s password immediately after an employee quits or is terminated.
Require usernames and passwords to log into the computer and network.
Disable file and print sharing on your operating system.
Use possessed object access systems such as magnetic cards/badges
Use biometric devices that use fingerprint, hand, eye, or voice data to allow computer access
Require usernames and passwords to log into the computer and network.
The login should only allow employees to access the files, data and programs they need to do their job.
Have an acceptable use policy (AUP)
that outlines what employees can and cannot do when using company computers.
Install and/or turn on a firewall:
A firewall can either be a program or it can be a specialized hardware device.
prevents unauthorized users from hacking into a personal computer or computer network by screening incoming messages for possible malware attacks.
Use a CAPTCHA
a program that displays an image with a series of distorted characters that the user must enter into a textbox.
prevents automated, computer-generated attempts to log into a website
Use two-step verification
requires a user to use two separate methods to login to a computer or network (ATM card and PIN, password and a texted code, etc.)
Software theft occurs when
someone steals software media or illegally registers a program or illegally copies a program.
Strategies to prevent software theft are provided below:
Software media (installation CDs) should be locked in a secure location
Require a user to activate software before it can be installed.
This prevents software from being copied to multiple devices
Require the user to sign a single-user license agreement that legally prevents the user from copying a program onto another device
Information theft occurs when
someone steals personal or confidential information.
Strategies to prevent information theft are provided below:
Secure sensitive emails and/or confidential data on hard drives with encryption
Encryption
Use a virtual private network (VPN)
Use digital signatures
Use digital certificates
A certificate authority
Secure site
Use a trusted cloud computing company
Encryption
codes data into a form that is unreadable to an unauthorized party.
The encrypted data is then decrypted back into its original form when it reaches its destination or when a user enters an encryption password.
Use a virtual private network (VPN)
enables mobile users to have a secure connection to an organization's network.
It uses software installed on both the company server and the user's computer to encrypt data sent remotely over the Internet.
Use digital signatures:
an encrypted code that a person, website or organization attaches to an electronic message to verify the identity of the message sender.
Use digital certificates:
a notice that guarantees a user or a website is legitimate.
E-commerce web sites commonly use digital certificates.
A certificate authority
is an organization that issues digital certificates
Secure site
A website that uses encryption
Encrypt data that is sent back and forth between a web site and a user.
Web addresses of secure sites often begin with https.
Browsers often display a padlock symbol in the address bar of a secure site.
Use a trusted cloud computing company
Companies such as Amazon and Microsoft spend millions of dollars annually to ensure that their customer's data is secure and available.
The security expertise offered by cloud computing companies is normally superior to that of a company's own network administrators.
Hardware Theft and Vandalism
Secure servers, switches, routers, WAPs and other critical hardware in unmarked, locked rooms that require magnetic badges to enter
The server rooms should also have surveillance cameras and alarms that trigger when there is a forced entry or if the temperature in the room gets too warm.
Physically lock down computers and other equipment
Install device tracking software on mobile computers
Hardware Failure
Use a surge suppressor
Use an uninterruptible power supply (UPS) device
Save backup files of all critical data on
Have redundant devices
Purchase servers
Avoid exposing your computer
Save backup files of all data and programs in a fireproof safe or offsite
Use a trusted cloud storage company
Have a disaster recovery plan
Use a surge suppressor to
prevent an electrical surge from damaging your hardware
Use an uninterruptible power supply (UPS) device
that provides electricity to network equipment when there is a power blackout
Save backup files of all critical data on
removable (or online) storage devices
Have redundant devices
so that, if one device malfunctions, the other can seamlessly assume the workload with no interruption.
Purchase servers with
multiple CPUs, hard drives and NICs so that, if one of these components fail, the server continues to function
Avoid exposing your computer to
extreme heat, direct sunlight or dusty areas
Don’t put your computer on a soft surface such as couch or a bed to prevent overheating
Do not hold or place liquids close to the computer system
Save backup files of all data and programs in
a fireproof safe or offsite.
The offsite location should be far enough away that any natural or man-made disaster that destroys the original data does not also destroy the backup data.
Use a trusted cloud storage company
for primary or secondary data storage
Have a disaster recovery plan that
lists the actions an organization should take if a natural or mad-made disaster occurs to their computer systems.
should include:
employee evacuation procedures
the mobile phone numbers of all employees
where new equipment can be purchased
an alternative office/building location in case the original office/building is destroyed,
where backup data is located and how it will be restored, disaster coverage insurance information
how the disaster plan will be tested and an overall plan for bringing the company back to normal operations.
Wireless Security
Change the default administrator password of the wireless access point (WAP)
Keep the WAP in a secure area so unauthorized people cannot access it
Turn off the SSID broadcast feature of the WAP to hide the wireless network from other devices
Encrypt data traveling across a wireless network by using Wi-Fi Protected Access (WPA).
The latest version is WPA3.
Enable and configure the media access control (MAC) address control feature so you can restrict what devices are able to connect to your network.
Limit the range that your WAP can send and receive signals (if your WAP has that functionality)
Inaccurate data on social media and other websites
can cause many different types of personal and business problems
Intellectual property rights
are the legal rights to which the creators of intellectual property (music, paintings, movies, videos, written work, etc.) are entitled.
Today much intellectual property is available digitally and can be easily distributed or altered without the creator's permission.
People who access, distribute or alter intellectual property without the consent of the owner violate the owner's legal copyright and can be sued in court.
Businesses and schools often have a code of conduct
that users of their computers are required to follow.
A code of conduct
are written guidelines that define what actions are allowed and not allowed when using an organization's computers and network.
Green computing means
considering the environment by reducing electricity and environmental waste.
Green computing concepts include:
Using computers with the “Energy Star” logo
Buy recycled paper and use paperless methods when possible
Shutting off computers when not in use
Recycle computers, mobile devices, printers, ink and toner cartridges.
Telecommute and use videoconferencing for meetings
With so much personal information available on public and private networks, lack of personal privacy is a major concern.
computers with the “Energy Star” logo
indicating that the computer meets the minimum federal standards for reduced energy consumption.
A cookie is
a small text file that is created and stored in a cookie folder on your hard drive by a Web server to identify return visitors and their preferences.
created by background programs that record and save information entered by the user when on a website.
information about cookies
A website can read data only from its own cookie file stored on your hard drive.
It cannot access any other data on your hard drive--including other cookie files.
Users can change their browser settings to prevent cookies from being saved on their device.
Phishing
is a scam in which a hacker sends an official looking message that attempts to obtain your personal and/or financial information
(social security number, bank account login info, credit card info).
Spam
refers to unwanted (often automated) emails sent by individuals or companies that can quickly fill up your email inbox.
can be controlled by configuring an email filter that will send spam to a separate "junk" folder.
Spyware refers to SW
that is installed without the user’s knowledge to secretly gather information about the user’s internet activities and transmits that information through the user’s internet connection to advertisers or other third parties.
Spyware programs were originally designed
to obtain user preference information that can be used for marketing purposes.
Spyware
can be accidently downloaded to your computer without your knowledge when you download a file, click on a link, or open an email file attachment.
Malicious spyware
can be downloaded to your computer by hackers to record your keystrokes in order to steal confidential data such as bank account login, credit card number/expiration date and social security number.
Adware is a
program that displays unwanted, online advertisements in a banner, pop-up window or other location on the computer screen.
To remove spyware or adware you can
obtain software (appropriately named spyware removers or adware removers) that can detect and delete these unwanted programs.