P3 - 8. Cybersecurity Risk Flashcards
What are the 3 drivers of the importance of security of data?
- Commercial sensitivity
- Competitive advantage
- Legal duty to protect personal information
What are the 4 objectives of cybersecurity?
- Availability
- Confidentiality
- Integrity of data
- Integrity of processing
What are 4 of the biggest technology factors that impact of cyber security risk?
- Outsourcing of IT
- Use of mobile devices
- Network structure
- Dependence on emerging technologies
What are 4 of the biggest organisational factors that impact of cyber security risk?
- Structure and size of IT department
- Types of user group
- Geographic location (+ legal issues)
- Organisational structure
What is malware?
Software specifically designed to disrupt, damage or gain unauthorised access to a computer system
What are the 5 main types of malware?
- Virus
- Worm
- Trojan
- Spyware
- Ransomware
What are the 3 main defences against malware?
- Antivirus software
- Regular updates
- User vigilance
What are application attakcs?
Targeting websites to alter their functionality and presentation or extract sensitive information
What are the 4 main types of application attack?
- Bot
- Distributed Denial of Service
- Cross site scripting
- SQL injection
What are the 3 main defences against application attacks?
- Anti-bot software
- Firewalls
- Data validation fields
What is a hacker?
A skilled computer programmer who circumvents and organisation’s security systems to access sensitive information
What 2 factors are most likely to make an individual more susceptible to a social engineering attack?
- Level of access
- Routine
What are the 3 aims of a cybersecurity policy?
- Protect
- Detect
- Respond
What 4 elements of governance can an organisation implement to help strengthen cybersecurity?
- Establishing and communicating ethical values
- Board oversight and commitment
- Establishing accountability
- Hiring and developing qualified personnel
What 4 ways can an organisation ensure communication of their cyber security objectives?
- Training and awareness programmes
- Policy and procedures manual
- Code of conduct
- Promotion of whistle-blower hotlines