6.1 - principles of info security Flashcards
The dog’s travel paperwork can be uploaded to an online storage area.
Identify one method which could be used to maintain the confidentiality of this information.
Justify your choice.
(4)
(User names and) Passwords (1st) When combined with user names secures the on-line areas (1) as only those with the correct / matching user name / password (1) can access the secure location of the storage area / documents (1).
Encryption (1st) Uses an algorithm to convert the text to an unreadable format (1) Documents can be encrypted so only these with the correct key (1) will be able to read the documents (1).
7- Progress Vision is reviewing its information security and personal data protection measures.
Confidentiality is one of the principles of information security.
Identify two other principles of information security.
2 marks.
· Integrity (1)
· Availability (1)
9 - Each time a team is sent to a disaster area, PHDA sends records of the attending team members to
the network coordinator.
Explain why it is important to maintain the integrity of these records
4 marks
The records need to be up to date (1) in case there’s an emergency (1)
if the records are not accurate this (1), this could lead to delays in contacting emergency (1).
or delays in travels (1) meaning team members may not get to diaster area - 1
A crime prevention charity provides help and assistance to people who have been the victims of crime.
The charity also collects and collates crime statistics for publication on neighbourhood websites.
The statistics are stored securely but need to conform to the information security principle of
availability.
One information security risk to the stored data is intentional tampering with the data.
Explain what is meant by the information security principle of availability.
3 marks
· Information is always available to (1) and usable (1) by the individuals / groups / processes that need it. (1)
· Information is accessible (1) when needed (1)
A UK-based university provides a range of free online courses each academic year.
The university should ensure that the stored personal information demonstrates the information
security principle of confidentiality.
Explain what is meant by the information security principle of confidentiality.
3 marks
· Information can only be accessed (1) by authorised people (1)
· Is a legal requirement under GDPR / DPA (1)
· Requires data to be kept safe (1) and take measures to ensure this (1)
21 - Each race, PH GP collects data from the sensors on the bike.
Explain, using an example, why it is important that the data collected from the sensors demonstrates
the integrity principle of data security.
4
· Integrity means the collected data is accurate / up to date / complete / fit for purpose (1)
· If the collected data does not demonstrate integrity (1) then incorrect decisions could be made (1) by the technical team (1)
· If the collected data does not demonstrate integrity (1) then incorrect decisions could affect the performance (1) of the bike during the races (1)
· Examples (1) e.g. fuel settings
24 - ETVS collects surveys from its clients. The survey results are stored securely, conforming to the
information security principles of confidentiality and availability.
Using an example related to ETVS, explain what is meant by the information security principles of
confidentiality and availability
4
· Information is always available to (1) and usable (1) by the individuals / groups / processes that need it. (1)
· Example (1) e.g. people analysing the results of the surveys must be able to access the data at all times
26 - During the competition the spreadsheet is used to record the times for each competitor.
The data stored in the spreadsheet must demonstrate the information security principle of integrity.
Describe what integrity means.
2
Data is maintained / up-to-date (1) so that it is accurate / complete / fit-for-purpose (1)
· Data that is changed / edited (1) may decrease level of integrity (1)
26b - The spreadsheet is password protected.
Explain how a password would maintain the integrity of the data shown on the spreadsheet.
3 marks
· Only people (1) who have the password can access (1) and edit / steal the data (1)
· Security is a requirement of the DPA (1)
· A password will stop/ reduce (1) unauthorised access to the data (1) and editing / stealing the data (1)
29 - An insurance company must ensure that stored customer details demonstrate the information security
principle of confidentiality.
Explain, using an example, what is meant by the information security principle of confidentiality.
4 marks
· Information can only be accessed (1) by authorised people (1)
· Is a legal requirement under GDPR / DPA (1)
· Requires data to be kept safe (1) and take measures to ensure this / example i.e user names / passwords (1)
· Example (1) e.g. customers name / address / DoB / Phone number / email address / medical records