5 slide rewriting work in 6 hrs

profilere.bertyh.elpsfuben.t
CMGT245AssignmentWeek4InformationSecurityPolicyAccessControlsAuthorizationAndAuthentication1.pptx

Information Security Policy Benefits of Implementing Access control

It increases safety

Increases security of sensitive data

Helps to reduce theft and accidents

Account for incoming and outgoing individuals

Curtails unwanted strangers

(Rittinghouse & Ransome, 2016)

Increases safety

it increases the safety of employees getting into the business. It becomes faster to swipe access cards and it is not easily duplicated by malicious persons.

Increases security of sensitive data

The employees with the required clearance are the only ones that are given access to the company’s sensitive data. through this, the company is able to regulate the number of people that have access to some data that is deemed sensitive to be disclosed to the competitors or the general public.

Reduce theft and accidents

The business will be able to give only approved employees the access to some designated areas. This makes usre that theft or accidents are greatly reduced.

Account for incoming and outgoing individuals

Each individual accessing the system should be accounted for as this will be useful in ensuring that their actions are always accounted. Some of them might access the systems with malicious intent which needs to be identified fast for the good of the company.

Curtail unwanted strangers

Access control denies unwanted strangers the ability to log into the company’s systems to cause havoc in them or steal confidential data.

1

Ways to use Authentication and Authorization to protect Company Data

Single-factor and Multi-factor authentication

Biometrics

Federations

(Ting et al., 2015).

Single and multi-factor authentication

Single-factor and multi-factor authentication will require any employee to produce some credentials e.g. passwords or PINS as well as usernames before they can be granted access to the company’s data or information

Biometrics

it is one of the secure ways to implement access control. They include fingerprint scanners, full hand scanners, eye scanners, facial recognition and voice recognition. This will help protect company data and sensitive information from malicious persons

Federations

Set by a means of federated identity that links system users identity with their privileges and hence restricting from accessing data and information that is beyond their clearance.

2

How Temporary Employees Make Data Vulnerable To Social Engineering Works.

Temporary employees make data vulnerable due to various reasons;

Lack of adequate knowledge about the working of the organization. This way the employees make the data vulnerable because they do not understand the threats facing the system (Berson, 2011).

Some have malicious intentions and therefore expose data to social engineering works.

Vulnerabilities to Social Engineering works

Some employees have ill-intentions and therefore expose data to vulnerabilities. Such employees can distribute confidential information over the internet.

Ignorance among some of employees maybe harmful to an organization. Such employees may fail to follow important data security protocols which in turn exposes data to vulnerabilities.

3

Methods To Mitigate Social Engineering Threats

Ways of mitigating social engineering threats include;

Educating employees about securing their personal information that can be used for social engineering attacks.

Ensuring that the software in use is up-to date.

Establishing policies that protect confidential information from exposure (DeLuccia,2008).

Mitigating Social Engineering Threats

Most social engineering criminals tend to success due to ignorance among people. It is the responsibility of the organization to teach its employees about these attacks to prevent future attacks.

Criminals ten to exploit updated software when executing their attacks. It is therefore important for organizations to ensure that they software are always up to date.

Having a security policy is a step towards mitigating social engineering threats.

4

This image depicts how

social engineering

attacks are planned

and executed

REFERENCES

Rittinghouse, J. W. & Ransome, J. F. (2016). Access Control: implementation, management and security. CRC Press.

Berson, A., & Dubov, L. (2011). Master data management and data governance. New York: McGraw-Hill.

DeLuccia, J. J. (2008). IT compliance and controls: Best practices for implementation. Hoboken, N.J: John Wiley & Sons.

Ting, D. M. Hussain, O., & LaRoche, G. (2015). Systems and methods for multi-factor authentication.