Chapter 12 Flashcards
What is Identity Theft?
Vital info such as a person’s name, address, date of birth, social insurance number, and mothers maiden name are required to complete impersonation.
With identity theft, what can the theifs access?
- Finanacial accounts
- Open new bank accounts
- transfer bank balances
- Apply for loans, credit cards, and other services
What is PIPEDA?
Perosonal Information Protection & Electronic Documents Act.
What is PIPEDA in place to do?
- To balance an inividuals right to the privacy of his or her personal information.
- Governs how data are collected and used.
PIPEDA says that organizations can’t use personal info of their customers for anything other than what is agreed upon.
PIPEDA does not facilitate individuals suing organizations.
What are the 3 types of security threats organizations face?
- Human Errors and Mistakes
- Malicious Human Activity
- Natural Events and Disasters
Explain what types of problems cause Human Errors and Mistakes.
- Poorly written programs
- Poorly designed procedures
- Physical accidents
- Accidental problems
What are some examples of Malicious Human Activity?
- Intentional destruction of data
- Destroying System components
- Hackers
- Virus & worm writers
What are examples of Natural events and disasters?
- Fires, floods, hurricanes, eathquakes.
- Initial losses of capability and service
What are the 5 Types of Security problems?
- Unauthorized data disclosure
- Incorrect data modification
- Faulty service
- Denial of service
- Loss of infrastrucutre
What are the 3 categories of security safeguards?
- Technical safeguards
- Data Safeguards
- Human Safeguards
What are some examples of Technical Safeguards?
- Identification and authentication
- Encrytion
- Firewalls
- Malware Protection
- Design for secure applications
What do data safeguards do?
Protect databases & other organizational data.
What does data administration do?
- Develops data policies and enforces data standards.
What are some examples of data safeguards?
- Encryption Keys
- Back-up copies
- Physical Security
- Third party contracts
- Safeguards written into contracts which ives the right to inspect premises & interview personnel.
Explain Human Safeguards.
- User access restriction requires authentication & account management.
What are some examples of human safeguards for employees?
- User accounts with limited privileges
- Hiring and screening employees
- Employees are made aware of policies & procedures
- Create policies & procedures for employee termination.
What are some examples of human safeguards for non-employee personnel?
- Contacts that include specific provisions and provide accounts with least privileges.
- Protect users from internal company security problems.