Information Security1

Information Security Overview

  • Definition: Security is the degree of protection against criminal activity, danger, damage, or loss.

  • Information Security: Processes and policies to protect an organization’s information from unauthorized access, use, disclosure, disruption, modification, or destruction.

  • Threats: Unlawful activities intending to exploit vulnerabilities leading to data loss or sabotage.

    • Vulnerability: Exposure of an organization to threats.

Standards/Objectives of Information Security

  1. Confidentiality

    • Protects information from unauthorized disclosure.

    • Example: Password compromise when viewed by unauthorized persons.

  2. Integrity

    • Ensures accuracy and completeness of data.

    • Threatened by corruption or damage during storage/transmission.

  3. Availability

    • Ensures authorized users access information without obstruction.

    • Example: Libraries restrict access to authorized users; denial of service attacks hinder availability.

Types of Threats

Human Errors

  • Description: Mistakes by employees leading to security risks.

    • Examples:

      • Device Carelessness: Losing devices, malware introduction.

      • Questionable Emails: Opening suspicious emails or clicking on links.

      • Careless Internet Surfing: Visiting inappropriate sites, exposing to malware.

      • Poor Password Practices: Unsafe desk practices like leaving devices unlocked.

Social Engineering

  • Definition: Tricking employees into revealing confidential information.

    • Common Techniques:

      • Impersonation: Attacker pretends to be someone else (e.g., calling for a password).

      • Tailgating: Following employees into restricted areas.

      • Shoulder Surfing: Observing screen over an employee's shoulder in public areas.

Espionage or Trespass

  • Definition: Unauthorized access to organizational information.

  • Distinction:

    • Competitive Intelligence: Legal methods of gathering information.

    • Industrial Espionage: Illegal methods such as data theft.

Information Extortion

  • Definition: Attacker threatens to steal or has stolen information and demands payment not to disclose it.

Sabotage or Vandalism

  • Definition: Deliberate acts damaging an organization's image or website.

  • Example: Hacktivism as a form of civil disobedience promoting political/social agendas.

Theft of Equipment or Information

  • Description: Increasing theft of smaller and powerful devices (e.g., laptops, smartphones).

  • Impact: Loss of data, increased costs, and legal issues.

  • Example: Dumpster diving for discarded sensitive information.

Identity Theft

  • Definition: Assume another person's identity to gain financial access or frame them for crimes.

    • Methods of Acquisition:

      • Theft of mail or dumpster diving.

      • Breaching databases.

      • Phishing via trusted electronic communications.

  • Impact: Costly recovery, credit issues, and difficulties in job acquisition.