Ch 4: Ethics Part 2 - Info security & controls

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/23

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:54 AM on 10/10/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

24 Terms

1
New cards

What are some information security problems?

5 factors contributing to vulnerability:

  1. growing interconnected/interdependent networked business environment

  2. smaller, faster, cheaper devices (smartwatch, raspberry pie airplane trakcer)

  3. less skills needed to be a computer hacker (hacked via iphone)

  4. lack of management support → org doesn’t spend much on security


<p>5 factors contributing to vulnerability:</p><ol><li><p>growing interconnected/interdependent networked business environment</p></li><li><p>smaller, faster, cheaper devices (smartwatch, raspberry pie airplane trakcer)</p></li><li><p>less skills needed to be a computer hacker (hacked via iphone)</p></li><li><p>lack of management support → org doesn’t spend much on security</p></li></ol><p></p>
2
New cards

What is cybercrime?

Illegal activities conducted over computer networks/internet

  • high monetary losses from computer crimes

  • can be committed from anywhere in the world


3
New cards

What are human errors?

*People within organization are biggest threat

  • higher level employees have more privileges → target & threat of hacks

  • human resources & info systems are usually targets

  • fired employees, janitors, guards, contract labour also big threat


4
New cards

What are some common human errors?

  • Carelessness with devices (lose memory stick), workspace (leave laptop unlocked), discarded equipment (need to wipe hardrives), environmental hazards (floods/fires)

  • opening questionable emails → phising

  • careless internet surfing → donwloading viruses

  • poor password selection → using same password


5
New cards

What is social engineering?

An attack where the perpetrator uses social skills to trick/manipulate employees into providing confidential info (passwords)

  • ex. phishing call over phone


6
New cards

What is tailgating?

Perpetrator enters restricted area by closely following behind employee

7
New cards

What is shoulder surfing?

Perpetrator watches an employee’s screen over their shoulder

  • ex. peeping at pin number or password


8
New cards

What are deliberate threats to information?

knowt flashcard image
9
New cards

Why is phishing a really big issue?

Only 1 person needs to click on a faulty link for hacker to have access to everything

→ info leaks should be communicated to customers

10
New cards

What are software attacks?

Target all internet-connected devices (smart TV’s too)

  • may or may not require user action (virus)

User action (see photo)

No user action:

  • denial of service attack (DDOS)

Developed system:

  • trojan horse, back door, logic bomb


<p>Target all internet-connected devices (smart TV’s too)</p><ul><li><p>may or may not require user action (virus)</p></li></ul><p>User action (see photo)</p><p>No user action:</p><ul><li><p>denial of service attack (DDOS)</p></li></ul><p>Developed system:</p><ul><li><p>trojan horse, back door, logic bomb</p></li></ul><p></p>
11
New cards

What is alien software?

Undercover software installed on your computer through deceitful methods

Not as malicious as viruses & worms but uses system resources:

  • adware

  • spyware

  • keyloggers (see what remove workers type → see bank numbers)

  • spamware

  • cookies (tracks what sites you visited)


12
New cards

What is a SCADA attatck?

A large scale distributed measurement & control system (water system controls)

  • if attackers gain access to the network, they can cause a lot of damage

→ ex. tank responsible for dispensing chlorine → if hacked, could poison a lot of people


13
New cards

What is cyberterrorism?

Premeditated & politically motivated attack against info systems that result in violence against targets

  • electronic devices used to generate fear


14
New cards

What is cyberwarfare?

A war where a country’s info systems could be paralyzed from a massive attack by destructive software

  • using electronic devices as a weapon/battle tool


15
New cards

What are organizations doing to protect information resources: risk probability, assessment, & mitigation?

Risk probability → low/high risk probability

  • a small business has low risk, Amazon has high risk

Risk assessment → if someone hacks, how big of an impact?

  • Heartbreakers has small impact, Dominos has big impact

Risk mitigation → based on damage, do I need to pay to protect it?

  • small business doesn’t need protection, Amazon pays a lot in security


16
New cards

What is risk mitigation?

knowt flashcard image
17
New cards

What is information systems auditing?

Auditing → program checks & balances

  • auditing is done by collecting info, seeing if numbers match, investigating issues


18
New cards

What are physical controls?

To prevent unauthorized individuals from gaining access to company facilities

  • walls, doors, fencing, gates, locks, badges, guards, alarm systems


19
New cards

What is business continuity?

Chain of events linking planning to protection and to recovery → used to prepare for, respond to, & recover from events

  • Expensive

  • How long would it take IT systems to recover if it blew up?

  • some systems not priority (HR & email systems)


20
New cards

What is business continuity planning?

Disaster recovery plan

  • hot site → any key system that makes you money is hot

→ ex. Amazon has a site automatically ready to take over at any time

  • warm site → data transferred here to slowly recover

  • cold site → starting from scratch (difficult as systems rely on other systems)


21
New cards

What are access controls: authentication

knowt flashcard image
22
New cards

What are basic guidelines for passwords

Responses to password challenges:

  • use password managers

  • multi-factor authentication (another level of security after password)

  • passwordless authentication

  • adaptive authentication


<p>Responses to password challenges:</p><ul><li><p>use password managers</p></li><li><p>multi-factor authentication (another level of security after password)</p></li><li><p>passwordless authentication</p></li><li><p>adaptive authentication</p></li></ul><p></p>
23
New cards

What are access controls: authorization

Rights & privileges where users are entitled on the organization’s systems are established

  • least privilege → principle that users are granted the privilege for some activity only if it’s justifiable


24
New cards

What are communication controls?

knowt flashcard image