1/37
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Goals
Big, long term targets to be achieved. Hard to measure if or when they have been achieved.
Objectives
Specific, measurable steps towards achieving a larger goal. Can be proved using data.
APIs
APIs create vulnerabilities by exposing endpoints that can be exploited. Insufficient authentication and authorisation, lack of input validation and improper error handling. Leads to data breaches and unauthorised access.
Malware
Suspicious code that enters computer without user knowledge to cause harm. Deliberate threat
Unpatched software
Leaves known security flaws unaddressed which can be exploited. Can lead to unauthorised access, data breaches, compromising the security and integrity of the entire system.
Poor identity and access management practices
Allows unauthorised access to sensitive data. Including: inadequate password policies, lack of multi-factor authentication and insufficient monitoring of access logs.
Man in the middle attacks
an eaves dropping attack where unauthorised third party intercepts WIFI transmissions. To mitigate: use strong encryption, server certificate verification, use of secure networks, multi-factor authentication, ensure up-to-date software and systems.
Insider threats
an attack from someone who the business trusts, former employees, partners etc: causing data breach, fraud, theft of intellectual property and sabotage.
Cyber security incidents
Social engineering, DDoS, Bots
Software acquired by a third party
the user is reliant on the developer to notify about patch fixes and improvements
Ineffective code review practices
lead to deployment of insecure software, resulting in data breaches, system outages and compromised user data.
Combined development environments
allows potentially untested code to enter production environments. Separates people who should not be touching production data.
Types of vulnerabilities and risks
Use of APIs, Malware, Unpatched software, Poor access management, Man-in-the-middle attacks, insider threats, cyber security incidents, using third party software, ineffective code review practices, combined development environments.
Version control and code repositories
Can record each stage of the development so that is is possible to ‘roll back’ to any previous point in development.
Robust identity management
clearly documenting and training employees in cyber security. Only authorised individuals have access to resources and system.
Encryption
recognises that data will be exposed so data should be encrypted so attackers cannot read the data.
Code review
examining code to identify and eliminate vulnerabilities before deployment.
Regular updates and patches
Can fix potential vulnerabilities in the software
Seperate Environments
prevent untested or insecure code from the live environment. Enforces stricter access controls.
Software development practices
Version control and code repositories, identity and access management, encryption, code review, regular updates and patches and separated environments.
Accidental threats
accidental deletion or overwriting of data cause by user inattention or carelessness. Confusing screen design with lookalike interface.
Event based threats
natural disasters, power or network outages, hardware failures and data corruption
Deliberate threats
insider threats, unauthorised access, theft of data, malware and DDoS
Copyright Act 1968
Any person wishing to use another person’s work must obtain permission or pay for a license. Covers websites and software. If broken will lead to fines and imprisonment. (Federal)
Privacy Act 1988
Govern how organisations collect, use and share personal information. Applies to government organisations, organisations that are contracted with the government, organisations with a turnover of > $3 million, if they store medical info and if they sell or distribute personal info. (Federal)
Privacy and Data Protection Act 2014
Protects information held by Victorian government Agencies, including contractors working for government. (State)
Essential Eight
It is an industry standard framework design to assist businesses to become cyber secure and resistant. Application whitelisting, patch applications, configure Microsoft office macro settings, user application hardening, restrict admin privileges, patch operating system, multi-factor authentication and daily backups
Cyber security principles
Segregated areas for development, protection of software source, secure by design, use of memory safe languages, vulnerability disclosure, providing patches.
Ethics
Issues that arise that challenge moral standards, principles or expectations and tha can impact individuals and/or expectations.
Ineffective security practices
exposes users to risks such as data breaches and identity theft
Use of artificial intelligence
AI could contain biases present from training data that may lead to the system to produce inaccurate results based on stereotypes.
Intellectual Property
can limit access to ideas and technologies which can slow down creativity and progress. Can stop developers from working together creating monopolies
Copy right issues
Can restrict access to educational materials raising concerns about fair use. Creators rights vs public access to information
Strategies to improve security
Onboarding and induction programs to teach now employees and developer training
Advantages of developing externally
Up to date security tools, continuous security, responsibility and compliance with regulations.
Disadvantages of developing software externally
increased development costs, limited control over development, dependence on external for issues, data security and privacy risks.
Risk management plans
plans to identify, assess and mitigate risks to software development and operations, ensuring continuity and security.
Development of risk management plans
Identifying and evaluating risks, developing and implementing mitigation strategies, Preparing detailed incident response plans and Regularly monitoring and reviewing the risk management plan