Discussion: Security Threats and Vulnerabilities (150+150 = 300 words)

profiledk1913
Discussion2Sofin.docx

Security Threats and Vulnerabilities

There are various types of security threats that and information infrastructure processes that can affect the operations in their infrastructure.

Malware infiltration via external hardware and removable media: Removable media such as external hard drives and USB flash drives are used by various users to store and maintain software and data. These external hard drives and removable media can contain malware and virus codes that when attached to the system used in the organisation can cause infection and correct the system.

Human error: the users of systems which include employees and external personals are also liable for threats to the infrastructure. The security of the system can be compromised when these employees mistakenly install any malware through emails, games or by inserting infected USB drives in their system.

DDoS attacks and IoT botnet: various organisations now operate different kinds of IOT technologies which are connected to the networks of the organisation which include GPS tracking, security sensors, Wi-Fi, etc. but these technologies come with their own security challenges and IOT botnet have become a well-known cyber threat where in the hacker runs Control and command networks which can be used to launch distributed denial of service attacks.

Malware infection via internet: Browsers or emails that are connected to the Internet can bring in new vulnerabilities to the systems by deploying malware or causing critical and sensitive data of the organisation to be obtained by unauthorised users. (Infradata, 2019)

The security threats pose a serious risk to the safety of data and technology equal infrastructure of an organisation therefore an organisation must undertake various risk mitigation strategies to safeguard their infrastructure.

Next generation firewalls or a solution that offers security intelligence to organisations and enable them to apply security controls at network perimeter. Authentication techniques are another way to secure the information infrastructure which include key management, two factor authentication and automated key management which provides encryption and decryption without a centralised team management and protects files. Implementation of our cyber security framework helps the organisation in spreading the awareness of cyber security and develop initiatives to control and mitigate this risk. (Policies To Mitigate Cyber Risk, n.d.)