Chapter 10 Flashcards
CERT
Computer emergency response team
Formed at Carnegie Mellon university with DoD support
Security of information assets
Protected with encryption passwords certifications and coding
Laws are slow to catch up with cyber crime
Now a federal crime but with light sentences
Why networks need security
Vulnerable due to dependency on internet access for computers and networks
Average 350,000 loss per incident
Cost of internet protection
value of data and application far exceeds the cost of networks
Firms spend about 1250/ employee on network security
Primary security goals CIA
Confidentiality- protection of data from unauthorized disclosure
Integrity- assurance that data has not been altered
Availability- providing continuous operations of hardware and software for uninterrupted service
Disruptions
Loss of network service
Minor or temporary - like a circuit failure
Destruction of data
Viruses destroying files, crash of hard disk
Natural disasters
Can destroy host computers or sections of networks
Effects 20 percent of organizations each year
Intrusion
Hackers gain access to data files
Most incidents involve employees
Will be charged with industrial spying or fraud
Average 100,000 dollars per incident
Preventative controls
Mitigate or stop a person from action or an event from occurring
Discouraging or restraining act as a deterrent
Detective controls
Reveal or discover unwanted events through auditing
Document events for potential evidence
Corrective controls
Remedy an unwanted event or a trespass
Reinitiating a network circuit