Information Security1
Information Security Overview
Definition: Security is the degree of protection against criminal activity, danger, damage, or loss.
Information Security: Processes and policies to protect an organization’s information from unauthorized access, use, disclosure, disruption, modification, or destruction.
Threats: Unlawful activities intending to exploit vulnerabilities leading to data loss or sabotage.
Vulnerability: Exposure of an organization to threats.
Standards/Objectives of Information Security
Confidentiality
Protects information from unauthorized disclosure.
Example: Password compromise when viewed by unauthorized persons.
Integrity
Ensures accuracy and completeness of data.
Threatened by corruption or damage during storage/transmission.
Availability
Ensures authorized users access information without obstruction.
Example: Libraries restrict access to authorized users; denial of service attacks hinder availability.
Types of Threats
Human Errors
Description: Mistakes by employees leading to security risks.
Examples:
Device Carelessness: Losing devices, malware introduction.
Questionable Emails: Opening suspicious emails or clicking on links.
Careless Internet Surfing: Visiting inappropriate sites, exposing to malware.
Poor Password Practices: Unsafe desk practices like leaving devices unlocked.
Social Engineering
Definition: Tricking employees into revealing confidential information.
Common Techniques:
Impersonation: Attacker pretends to be someone else (e.g., calling for a password).
Tailgating: Following employees into restricted areas.
Shoulder Surfing: Observing screen over an employee's shoulder in public areas.
Espionage or Trespass
Definition: Unauthorized access to organizational information.
Distinction:
Competitive Intelligence: Legal methods of gathering information.
Industrial Espionage: Illegal methods such as data theft.
Information Extortion
Definition: Attacker threatens to steal or has stolen information and demands payment not to disclose it.
Sabotage or Vandalism
Definition: Deliberate acts damaging an organization's image or website.
Example: Hacktivism as a form of civil disobedience promoting political/social agendas.
Theft of Equipment or Information
Description: Increasing theft of smaller and powerful devices (e.g., laptops, smartphones).
Impact: Loss of data, increased costs, and legal issues.
Example: Dumpster diving for discarded sensitive information.
Identity Theft
Definition: Assume another person's identity to gain financial access or frame them for crimes.
Methods of Acquisition:
Theft of mail or dumpster diving.
Breaching databases.
Phishing via trusted electronic communications.
Impact: Costly recovery, credit issues, and difficulties in job acquisition.