1/23
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What are some information security problems?
5 factors contributing to vulnerability:
growing interconnected/interdependent networked business environment
smaller, faster, cheaper devices (smartwatch, raspberry pie airplane trakcer)
less skills needed to be a computer hacker (hacked via iphone)
lack of management support → org doesn’t spend much on security

What is cybercrime?
Illegal activities conducted over computer networks/internet
high monetary losses from computer crimes
can be committed from anywhere in the world
What are human errors?
*People within organization are biggest threat
higher level employees have more privileges → target & threat of hacks
human resources & info systems are usually targets
fired employees, janitors, guards, contract labour also big threat
What are some common human errors?
Carelessness with devices (lose memory stick), workspace (leave laptop unlocked), discarded equipment (need to wipe hardrives), environmental hazards (floods/fires)
opening questionable emails → phising
careless internet surfing → donwloading viruses
poor password selection → using same password
What is social engineering?
An attack where the perpetrator uses social skills to trick/manipulate employees into providing confidential info (passwords)
ex. phishing call over phone
What is tailgating?
Perpetrator enters restricted area by closely following behind employee
What is shoulder surfing?
Perpetrator watches an employee’s screen over their shoulder
ex. peeping at pin number or password
What are deliberate threats to information?

Why is phishing a really big issue?
Only 1 person needs to click on a faulty link for hacker to have access to everything
→ info leaks should be communicated to customers
What are software attacks?
Target all internet-connected devices (smart TV’s too)
may or may not require user action (virus)
User action (see photo)
No user action:
denial of service attack (DDOS)
Developed system:
trojan horse, back door, logic bomb

What is alien software?
Undercover software installed on your computer through deceitful methods
Not as malicious as viruses & worms but uses system resources:
adware
spyware
keyloggers (see what remove workers type → see bank numbers)
spamware
cookies (tracks what sites you visited)
What is a SCADA attatck?
A large scale distributed measurement & control system (water system controls)
if attackers gain access to the network, they can cause a lot of damage
→ ex. tank responsible for dispensing chlorine → if hacked, could poison a lot of people
What is cyberterrorism?
Premeditated & politically motivated attack against info systems that result in violence against targets
electronic devices used to generate fear
What is cyberwarfare?
A war where a country’s info systems could be paralyzed from a massive attack by destructive software
using electronic devices as a weapon/battle tool
What are organizations doing to protect information resources: risk probability, assessment, & mitigation?
Risk probability → low/high risk probability
a small business has low risk, Amazon has high risk
Risk assessment → if someone hacks, how big of an impact?
Heartbreakers has small impact, Dominos has big impact
Risk mitigation → based on damage, do I need to pay to protect it?
small business doesn’t need protection, Amazon pays a lot in security
What is risk mitigation?

What is information systems auditing?
Auditing → program checks & balances
auditing is done by collecting info, seeing if numbers match, investigating issues
What are physical controls?
To prevent unauthorized individuals from gaining access to company facilities
walls, doors, fencing, gates, locks, badges, guards, alarm systems
What is business continuity?
Chain of events linking planning to protection and to recovery → used to prepare for, respond to, & recover from events
Expensive
How long would it take IT systems to recover if it blew up?
some systems not priority (HR & email systems)
What is business continuity planning?
Disaster recovery plan
hot site → any key system that makes you money is hot
→ ex. Amazon has a site automatically ready to take over at any time
warm site → data transferred here to slowly recover
cold site → starting from scratch (difficult as systems rely on other systems)
What are access controls: authentication

What are basic guidelines for passwords
Responses to password challenges:
use password managers
multi-factor authentication (another level of security after password)
passwordless authentication
adaptive authentication

What are access controls: authorization
Rights & privileges where users are entitled on the organization’s systems are established
least privilege → principle that users are granted the privilege for some activity only if it’s justifiable
What are communication controls?
