Business Case 700 words + 300 words reflection + 10 min presentation pptx
BUSINESS PLUGIN B6
Information security
Copyright 2022 © McGraw Hill LLC. All rights reserved. No reproduction or distribution without the prior written consent of McGraw Hill LLC.
Because learning changes everything.®
BUSINESS PLUGIN B6 OVERVIEW
The First Line of Defense - People.
The Second Line of Defense - Technology.
© McGraw Hill
‹#›
LEARNING OUTCOMES
Describe the relationship between information security policies and an information security plan.
Provide an example of each of the three primary security areas: (1) authentication and authorization, (2) prevention and resistance, and (3) detection and response.
© McGraw Hill
‹#›
THE FIRST LINE OF DEFENSE – PEOPLE 1
Organizations must enable employees, customers, and partners to access information electronically.
The biggest issue surrounding information security is not a technical issue, but a people issue.
Insiders.
Social engineering.
Dumpster diving.
Pretexting.
© McGraw Hill
‹#›
THE FIRST LINE OF DEFENSE – PEOPLE 2
The first line of defense an organization should follow to help combat insider issues is to develop information security policies and an information security plan.
Information security policies.
Information security plan.
© McGraw Hill
‹#›
THE SECOND LINE OF DEFENSE - TECHNOLOGY
There are three primary information technology security areas.
© McGraw Hill
‹#›
AUTHENTICATION AND AUTHORIZATION 1
Identity theft – The forging of someone’s identity for the purpose of fraud.
Phishing.
Pharming.
Sock puppet marketing.
Astroturfing.
© McGraw Hill
‹#›
AUTHENTICATION AND AUTHORIZATION 2
Authentication – A method for confirming users’ identities.
Authorization – The process of giving someone permission to do or have something.
The most secure type of authentication involves:
Something the user knows.
Something the user has.
Something that is part of the user.
© McGraw Hill
‹#›
SOMETHING THE USER KNOWS SUCH AS A USER I D AND PASSWORD 1
This is the most common way to identify individual users and typically contains a user I D and a password.
This is also the most ineffective form of authentication.
Over 50 percent of help-desk calls are password related.
© McGraw Hill
‹#›
SOMETHING THE USER KNOWS SUCH AS A USER I D AND PASSWORD 2
Smart cards and tokens are more effective than a user I D and a password.
Tokens – Small electronic devices that change user passwords automatically.
Smart card – A device that is around the same size as a credit card, containing embedded technologies that can store information and small amounts of software to perform some limited processing.
© McGraw Hill
‹#›
SOMETHING THAT IS PART OF THE USER SUCH AS A FINGERPRINT OR VOICE SIGNATURE
This is by far the best and most effective way to manage authentication.
Biometrics – The identification of a user based on a physical characteristic, such as a fingerprint, iris, face, voice, or handwriting.
Unfortunately, this method can be costly and intrusive.
© McGraw Hill
‹#›
PREVENTION AND RESISTANCE 1
Prevention and resistance technologies stop intruders from accessing and reading data.
Privilege escalation - A network intrusion attack that takes advantage of programming errors or design flaws to grant the attacker elevated access to the network and its associated data and applications.
Vertical privilege escalation.
Horizontal privilege escalation.
© McGraw Hill
‹#›
PREVENTION AND RESISTANCE 2
Downtime can cost an organization anywhere from $100 to $1 million per hour.
Technologies available to help prevent and build resistance to attacks include:
Content filtering.
Encryption.
Firewalls.
© McGraw Hill
‹#›
PREVENTION AND RESISTANCE 3
Spam – A form of unsolicited email.
Content filtering - Prevents emails containing sensitive information from transmitting and stops spam and viruses from spreading.
© McGraw Hill
‹#›
PREVENTION AND RESISTANCE 4
Personally identifiable information (P I I) - Any data that could potentially identify a specific individual.
Sensitive P I I.
Nonsensitive P I I.
© McGraw Hill
‹#›
PREVENTION AND RESISTANCE 5
If there is an information security breach and the information was encrypted, the person stealing the information would be unable to read it.
Encryption.
Public key encryption (P K E).
Certificate authority.
Digital certificate.
© McGraw Hill
‹#›
PREVENTION AND RESISTANCE 6
One of the most common defenses for preventing a security breach is a firewall.
Firewall – Hardware and/or software that guards a private network by analyzing the information leaving and entering the network.
© McGraw Hill
‹#›
PREVENTION AND RESISTANCE 7
Sample firewall architecture connecting systems located in Chicago, New York, and Boston.
© McGraw Hill
‹#›
DETECTION AND RESPONSE
If prevention and resistance strategies fail and there is a security breach, an organization can use detection and response technologies to mitigate the damage.
Intrusion detection software – Features full-time monitoring tools that search for patterns in network traffic to identify intruders.
© McGraw Hill
‹#›
LEARNING OUTCOME REVIEW
Now that you have finished the chapter please review the learning outcomes in your text.
© McGraw Hill
‹#›
End of Main Content
Copyright 2022 © McGraw Hill LLC. All rights reserved. No reproduction or distribution without the prior written consent of McGraw Hill LLC.
Because learning changes everything.®
www.mheducation.com
21
Accessibility Content: Text Alternatives for Images
© McGraw Hill
‹#›
22
THE SECOND LINE OF DEFENSE - TECHNOLOGY – TEXT ALTERNATIVE
Return to parent-slide containing images.
People authenticate and authorize. Data is used to prevent and resist attacks. Attacks require detection and response.
© McGraw Hill
‹#›
PREVENTION AND RESISTANCE 7 – TEXT ALTERNATIVE
Return to parent-slide containing images.
From the database in Chicago, information is sent from the server through a firewall to the internet. The information then goes through firewalls in New York and Boston before it goes to the respective servers and on to the database in each location.
© McGraw Hill
‹#›