1/31
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Information Systems
Are integrated sets of components for collecting, storing, processing, and communicating information.
1. Transaction Processing System (TPS)
2. Management Information System (MIS)
3. Decision Support System (DSS)
4. Executive Information System (EIS)
5. Enterprise Resource Planning Systems (ERPS)
Types of Information Systems:
Ensuring data integrity, confidentiality, and availability is critical to avoid data breaches, financial losses, and damage to an organization's
What is the importance of Security in IS?
1. Malware
2. Phishing
3. Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks
4. Insider Threats
5. Advanced Persistent Threats
6. Social Engineering
7. Zero-Day Exploit
What are the common security threats?
Malware
Software designed to disrupt, damage, or gain unauthorized access to computer systems.
Types:
1. Viruses
2. Worms
3. Trojan Horses
4. Ransomware
Types of Malware:
Viruses
Infect programs and replicate themselves.
Worms
Standalone software that replicates to spread to other computers.
Trojan Horses
Disguised as legitimate software but perform harmful activities.
Ransomware
Encrypts data and demands ransom for decryption.
Phishing
Fraudulent attempts to obtain sensitive information by pretending to be a trustworthy entity.
1. Email Phishing
2. Spear Phishing
3. Whaling
Common Tactics of Phishing:
Email Phishing
Deceptive emails designed to lure individuals into providing personal information.
Spear Phishing
Targeted phishing aimed at specific individuals or organizations.
Whaling
Phishing attacks directed at high-profile targets like executives.
Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks
Attacks aimed at disrupting the normal functioning of a system by overwhelming it with a flood of internet traffic.
Can cause websites or services to become unavailable to legitimate users.
Impact of Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks
Insider Threats
Security risks that originate from within the organization.
1. Malicious Insider
2. Accidental Insider
3. Mitigation
Types of Insider Threats:
Malicious Insider
An employee or contractor with intent to harm
Accidental Insider
Employees who unintentionally cause security breaches by mishandling data or systems.
Mitigation
Strong access controls, monitoring, and employee training.
Advanced Persistent Threats
Prolonged and targeted cyberattacks in which an intruder gains access to a network and remains undetected for an extended period.
Often involve sophisticated techniques and are aimed at stealing data or surveillance.
Characteristics of Advanced Persistent Threats
Social Engineering
Manipulation of individuals into performing actions or divulging confidential
information.
1. Pretexting
2. Baiting
Techniques of Social Engineering:
Pretexting
Pretending to be someone else to gain access to information.
Baiting
Luring victims with promises of goods or services to steal information.
Zero-Day Exploits
Attacks that exploit previously unknown vulnerabilities in software before developers can fix them.
Difficult to defend against due to the unknown nature of the threat.
Challenges of Zero-Day Exploits?
1. Financial Losses
2. Reputation Damage
3. Legal and Regulatory Consequences
4. Operational Disruptions
Impacts of Security Threats:
1. Regular Update and Patch Management
2. Implementing Strong Authentication Mechanisms
3. Employee Training and Awareness Programs
4. Data Encryption
5. Network Security Measures
6. Regular Security Audits and Penetration Testing
7. Incident Response Planning
8. Backup and Recovery
Best Practices for Mitigationg Security Threats: