Security Interests Flashcards
what is information security?
the protection of information systems from accidental or intentional misuse by persons inside or outside an organization
the info needs to be protected from both digital and physical threats
outside threats
natural disasters
internet (unauthorized users, denial of service, malware eg viruses, worms etc)
human-made disasters
inside threats
employees
other insiders eg cleaners
hardware threats
systems software
viruses
software written with the malicious intent to cause annoyance or damage
- trojan- horse virus
- backdoor programmes
What is a denial of service attack (DoS) ?
cyberattack in which the perpetrator seeks to make a machine or network source unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the web
What is the trojan horse virus?
exploit: contains code that attacks a weakspot in software
backdoor: gives malicious users remote access to the infected computer
rootkit: these are designed to effectively prevent malicious programs being detected
trojan-banker: its purpose is to steal your account data for online banking systems; e-payment systems and credit or debit cards
what is phishing?
a technique to gain personal information for the purpose of identity theft, usually by means of fraudulent email
What is risk?
an incident or occurrence emanating from internal or external sources that prevents implementation of strategy or achievement of objectives
What are the Risk management responses ?
mitigate: implement effective internal controls
accept: do nothing, accept likelihood of risk
transfer: buy insurance, outsource
avoid: do not engage in activity that produces risk