6.2 Risks Flashcards
Unauthorised access to data
What are the two main reasons why data may be viewed by someone who shouldn’t?
Espionage
Poor information management
Espionage
Collecting data so that it can be used against an organisation
E.g competition acquiring information on their rivals product before the launch
Poor information management
Data is insecurely stored
OR
Too many people have access to sensitive information (unauthorised access)
*Espionage and poor information management
Competitors benefit from unauthorised access
Breaches the Data Protection Act 2018
Accidental loss of data
Information is irretrievably lost:
Original file cannot be accessed in any format and copies of the original file
What is three common reasons for accidental loss of data?
Equipment failure
Technical loss leading to data corruption e.g database crash, hard drive fails
Humman error
Provide another reason for accidental loss of data
(Hint: we make mistakes)
Human error: Employee may accidentally delete a file or discard an important document without reading
What would happen if data is accidentally lost, relate this to an organisation
EXTEND: what legislation has been breached and which security principle?
Delays dependant processes such as analysis and trend recognition
The security principle of availability and the data protection act
Intentional destruction of data
Purposely damaging an organisation by deleting or denying access to data
E.g Viruses that corrupt software
Targeted malicious attacks (DDOS)
Ransomware
What will data destruction lead to?
Relate this in a business context
Loss of reputation: Customers wont want to have their information stored in a system they see as unreliable and insufficiently protected
Loss of reputation (2): Lead to customer loss and a decrease in profits and if the loss is ignored and unreported it could result in a huge loss of trust
Intentional Tampering With Data
Data is changed and no longer accurate
Could occur through hacking
Business example:
Company tampering with financial data to display larger profits and smaller losses to boost investment or please stakeholders
What happens if data tampering is found out about?
Loss of reputation: Organisation cannot be trusted to report data accurately
Personal data altered: Security principle of integrity will have been broken as data is no longer accurate
Protection systems will need to be reviewed if data has been tampered with
What happens if an employee data tampers?
Fired
Face legal action
Intentional destruction of data
What is Ransomware and what does it do?
Encrypts files so that they can only be accessed again when a certain criteria has been met
E.g paying a massive fee