6.2 Risks Flashcards

1
Q

Unauthorised access to data

What are the two main reasons why data may be viewed by someone who shouldn’t?

A

Espionage

Poor information management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Espionage

A

Collecting data so that it can be used against an organisation

E.g competition acquiring information on their rivals product before the launch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Poor information management

A

Data is insecurely stored

OR

Too many people have access to sensitive information (unauthorised access)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

*Espionage and poor information management

A

Competitors benefit from unauthorised access

Breaches the Data Protection Act 2018

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Accidental loss of data

A

Information is irretrievably lost:

Original file cannot be accessed in any format and copies of the original file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is three common reasons for accidental loss of data?

A

Equipment failure

Technical loss leading to data corruption e.g database crash, hard drive fails

Humman error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Provide another reason for accidental loss of data

(Hint: we make mistakes)

A

Human error: Employee may accidentally delete a file or discard an important document without reading

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What would happen if data is accidentally lost, relate this to an organisation

EXTEND: what legislation has been breached and which security principle?

A

Delays dependant processes such as analysis and trend recognition

The security principle of availability and the data protection act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Intentional destruction of data

A

Purposely damaging an organisation by deleting or denying access to data

E.g Viruses that corrupt software

Targeted malicious attacks (DDOS)

Ransomware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What will data destruction lead to?

Relate this in a business context

A

Loss of reputation: Customers wont want to have their information stored in a system they see as unreliable and insufficiently protected

Loss of reputation (2): Lead to customer loss and a decrease in profits and if the loss is ignored and unreported it could result in a huge loss of trust

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Intentional Tampering With Data

A

Data is changed and no longer accurate

Could occur through hacking

Business example:

Company tampering with financial data to display larger profits and smaller losses to boost investment or please stakeholders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What happens if data tampering is found out about?

A

Loss of reputation: Organisation cannot be trusted to report data accurately

Personal data altered: Security principle of integrity will have been broken as data is no longer accurate

Protection systems will need to be reviewed if data has been tampered with

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What happens if an employee data tampers?

A

Fired

Face legal action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Intentional destruction of data

What is Ransomware and what does it do?

A

Encrypts files so that they can only be accessed again when a certain criteria has been met

E.g paying a massive fee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly