5 slide rewriting work in 6 hrs
Information Security Policy Benefits of Implementing Access control
It increases safety
Increases security of sensitive data
Helps to reduce theft and accidents
Account for incoming and outgoing individuals
Curtails unwanted strangers
(Rittinghouse & Ransome, 2016)
Increases safety
it increases the safety of employees getting into the business. It becomes faster to swipe access cards and it is not easily duplicated by malicious persons.
Increases security of sensitive data
The employees with the required clearance are the only ones that are given access to the company’s sensitive data. through this, the company is able to regulate the number of people that have access to some data that is deemed sensitive to be disclosed to the competitors or the general public.
Reduce theft and accidents
The business will be able to give only approved employees the access to some designated areas. This makes usre that theft or accidents are greatly reduced.
Account for incoming and outgoing individuals
Each individual accessing the system should be accounted for as this will be useful in ensuring that their actions are always accounted. Some of them might access the systems with malicious intent which needs to be identified fast for the good of the company.
Curtail unwanted strangers
Access control denies unwanted strangers the ability to log into the company’s systems to cause havoc in them or steal confidential data.
1
Ways to use Authentication and Authorization to protect Company Data
Single-factor and Multi-factor authentication
Biometrics
Federations
(Ting et al., 2015).
Single and multi-factor authentication
Single-factor and multi-factor authentication will require any employee to produce some credentials e.g. passwords or PINS as well as usernames before they can be granted access to the company’s data or information
Biometrics
it is one of the secure ways to implement access control. They include fingerprint scanners, full hand scanners, eye scanners, facial recognition and voice recognition. This will help protect company data and sensitive information from malicious persons
Federations
Set by a means of federated identity that links system users identity with their privileges and hence restricting from accessing data and information that is beyond their clearance.
2
How Temporary Employees Make Data Vulnerable To Social Engineering Works.
Temporary employees make data vulnerable due to various reasons;
Lack of adequate knowledge about the working of the organization. This way the employees make the data vulnerable because they do not understand the threats facing the system (Berson, 2011).
Some have malicious intentions and therefore expose data to social engineering works.
Vulnerabilities to Social Engineering works
Some employees have ill-intentions and therefore expose data to vulnerabilities. Such employees can distribute confidential information over the internet.
Ignorance among some of employees maybe harmful to an organization. Such employees may fail to follow important data security protocols which in turn exposes data to vulnerabilities.
3
Methods To Mitigate Social Engineering Threats
Ways of mitigating social engineering threats include;
Educating employees about securing their personal information that can be used for social engineering attacks.
Ensuring that the software in use is up-to date.
Establishing policies that protect confidential information from exposure (DeLuccia,2008).
Mitigating Social Engineering Threats
Most social engineering criminals tend to success due to ignorance among people. It is the responsibility of the organization to teach its employees about these attacks to prevent future attacks.
Criminals ten to exploit updated software when executing their attacks. It is therefore important for organizations to ensure that they software are always up to date.
Having a security policy is a step towards mitigating social engineering threats.
4
This image depicts how
social engineering
attacks are planned
and executed
REFERENCES
Rittinghouse, J. W. & Ransome, J. F. (2016). Access Control: implementation, management and security. CRC Press.
Berson, A., & Dubov, L. (2011). Master data management and data governance. New York: McGraw-Hill.
DeLuccia, J. J. (2008). IT compliance and controls: Best practices for implementation. Hoboken, N.J: John Wiley & Sons.
Ting, D. M. Hussain, O., & LaRoche, G. (2015). Systems and methods for multi-factor authentication.