IST Chapter 4

profileRain Ashbell
IST309_HE_Discussion_Ch-04_S.doc

In-Class Discussion

Chapter 4: Information Security

1. What security controls should you and your business partner have to adopt at a minimum?

2. Discuss the implications that different types of malware have for all of us.

3. Describe several reasons why it is difficult to protect information resources.

Julian Lao 

Chapter 4 Discussion

COLLAPSE

窗体顶端

3. Describe several reasons why it is difficult to protect information resources.

It is very difficult to protect information resources as their are hundreds of threats that exist, many individuals control or have access to information systems, rapid technology changes make some controls obsolete as soon as they come out, many computer crimes are undetected for a long period of time, preventative costs can be very high, minimal computer knowledge is necessary to commit.Some of these various issues on why it is difficult to protect information resources include spamming, hacking, jamming, malicious software, sniffing, spoofing, and identity theft; each one of these problems fit under one of two heading, computer abuse or computer crime. It is very difficult to always protect your personal information due to all the things that are trying to hack or find a way in that is why it is important to keep password secret and be cautious whenever you access anything with your information online. 

窗体底端

Alejandra Guerrero 

Chpt 4 Discussion

COLLAPSE

窗体顶端

With rapidly increasing technology our means of keeping all this information and data we input and transmit online is more susceptible of being leaked or taken than we think. One reason why the protection of information resources is difficult to maintain is due to intentional and unintentional threats. For example, an unintentional threat may be a result of human error. In fact, most of them are. Different employees have different access to private information within a company, thus the more access to important information, the more of a threat you are considered. These unintentional errors can arise from laziness, carelessness, or lack of awareness due to inadequate training on information system. In comparison, we are susceptible to intentional attacks as well. For example, we could fall victim to a phishing attach where we click on a bad link in a deceiving official looking email. Similar a whaling attack where sensitive information such as financial data or personal details are stolen from fraudulent emails or fake websites. These intentional threats can be grouped into three categories: remote attacks requiring user action, remote attacks needing no user action, and attacks by programmer developing a system.

窗体底端

PAGE