Chapter 9: Security and Privacy Notes
Chapter 9: Security and Privacy
Learning Objectives
- Understand the importance of security and privacy concerning computing devices, networks, and the Internet.
- Identify risks associated with hardware loss, damage, and system failure, along with safeguards for devices.
- Learn about unauthorized access, use, and sabotage, and protective measures against them.
- Discuss online threats such as theft, identity theft, spoofing, and phishing, plus protective steps individuals can take.
- Recognize personal safety risks related to Internet use and strategies to mitigate them.
- Explore privacy issues concerning databases, electronic profiling, spam, and telemarketing, and how to protect personal privacy.
- Examine surveillance methods and current legislation regarding network and Internet security and privacy.
Importance of Security and Privacy
- Computer Crime (Cybercrime)
- Encompasses illegal acts involving computers, significant financially for criminals.
- Information Privacy
- Individuals' rights to control the collection and use of their personal data.
- Includes privacy of website activities and emails, as well as security breaches.
- Awareness
- Vital for all computer users to understand security concerns and necessary precautions.
Hardware Loss and Damage
- Hardware Loss
- Theft, damage, or loss of PCs, USB drives, smartphones, etc., poses both security and privacy risks.
- Theft
- Can be for information or the value of the hardware.
- Damage Risks
- Caused by power issues, heat, dust, water, and physical abuse.
System Failure and Disasters
- A complete malfunction can stem from hardware issues, software problems, sabotage, or disasters.
- Risks include data loss from various causes, including accidental deletions.
Protection Strategies
- Hardware Protection
- Use locks, cable locks, laptop alarms, and wireless tethering to secure devices in schools and businesses.
- Encryption
- Temporarily makes data unreadable to unauthorized users (e.g., full disk encryption (FDE)).
- Device Tracking Software
- Helps locate lost or stolen devices, often through GPS or Wi-Fi, with remote lock features.
- Care & Maintenance
- Use protective cases and surge suppressors, and implement UPS for power backup.
Unauthorized Access and Use
- Unauthorized Access
- Involves gaining access without permission.
- Unauthorized Use
- Refers to using computing resources for unapproved activities.
- Codes of Conduct
- Establish guidelines for behavior regarding computer use.
Hacking and Network Security Threats
- Hacking
- Involves breaking into systems, posing risks to individuals and national security.
- Wireless Network Vulnerabilities
- Types of attacks include war driving and Wi-Fi piggybacking.
- Interception
- Communication interception through unsecured networks poses serious data security issues.
Safeguarding Against Unauthorized Access
- Access Control Systems
- Use identification and authentication technology to ensure only authorized users access sensitive data.
- Password Strategies
- Create strong passwords, use two-factor authentication for enhanced security.
Protecting Against Computer Sabotage
- Implement security software to combat malware, and ensure access control.
- Monitor network activity for potential threats.
Understanding Online Theft and Fraud
- Online Theft
- Involves data theft through hacking or compromised devices.
- Identity Theft
- Stealing personal information for fraudulent activities; commonly obtained online or through social engineering.
Phishing and Social Engineering
- Phishing
- Fraudulent attempts to gain sensitive data via spoofed communications or websites.
- Spear Phishing
- Targeted phishing attacks aimed at specific individuals.
Cyber Safety and Privacy Issues
- Cyberbullying and Cyberstalking
- Online harassment and threats pose risks to personal safety, requiring legal and preventive measures.
- Sexting and Sextortion
- Responsible sharing and potential exploitation of intimate content must be acknowledged.
Personal and Workplace Privacy Protections
- Maintain security for employee and customer information, while monitoring necessary workplace activity.
Network and Internet Security Legislation
- Overview of laws designed to protect computer and Internet users; challenges in defining privacy and balancing freedoms.
Summary
- Recognizing the various types of cyber threats and implementing protective measures is essential for safeguarding both personal and organizational data as well as ensuring user privacy.