LO6: Protection Methods Flashcards
To know all the protection methods and what they do to help protection.
Name 3 types of physical protection methods?
3 Of: Physical Locks Bio-metrics and keypads Backups Security Staff Putting computers in high ground places for floods Shredding old paper based records
Name 3 logical protection methods
Passwords/usernames Firewall Encryption Obfuscation Anti-malware/virus Permissions Encryption of data in transit
What is the difference between encryption at rest and in transit?
Encryption at rest is data encrypted on say a hard drive, Transit means the data is encrypted during communication/transmission across a network.
How does an anti-malware protect a device?
Stops infections from malware
Stops data from being stolen from said malware
Can help protect against phishing scams as they can scan domains you access
Stops infections spreading from device to device
Why are tiered levels of access to data effective?
They stop new employees from accessing data they don’t need and requires specific authorisation to access data at different parts of an organisation.
State some of the downsides to encryption at rest
Slow to decrypt/encrypt
If the encryption key is lost the data is most likely lost forever
How does shredding of paper documents help maintain security?
Destroys physical records
Ensures that it’s very difficult to figure out the original contents
Without it, full documents containing sensitive data could be taken when discarded of
What are some of the possible impacts of a security breach?
Loss of intellectual property
Loss of services and access to said services
Failure to secure confidential info
Loss of information belonging to a third party
Loss of reputation
National security threat
What are the impacts that come with a loss of reputation
Fewer sales
Less trust from consumers
Incident paints the organisation in a bad light for a long time to come
Loss of investment
What are the impacts that come with a Loss of information belonging to a third party?
Customers lose trust Possible legal issues if measures were not properly in place to protect third party data Loss of sales Loss of the data itself to attackers Data theft
Why might a company backup data to another location?
To mitigate data loss
To increase redundancy
In an area prone to environment threats it would be wise to backup data far away in the case of a disaster
As part of their Disaster Recovery Plan