1 / 22100%
BUSI 417 - Studies in Information Security
Introduction to Information Security
Information Security and its popular abbreviation Info Sec is one of the fields that is valuable
in the world that is fast becoming inter-connected. This consists of the measures put in place
to ensure that information that should not be viewed or shared with other people or
organizations, altered or deleted, is not viewed or shared with other people or organizations,
altered or deleted. As organizations, governments and individuals permit themselves to be
informed and supported by digital data so has the security of this data become exponentially
mandatory. Below is a definition of Information Security, and a discussion of its principles,
history, importance, and major concepts.
&At the heart of Information Security are three core principles, often referred to as the CIA
triad: This can be broadly defined by the three principle attributes of data protection namely
the confidentiality, integrity and availability of data.
&Confidentiality ensures that information is only accessible to be viewed by those who have
such access rights. It is a method that engages entities such as encryption, and access control
together with authentication to prevent disclosure of information to other non-permissible
entities. For example encryption is the conversion of information to a form that can only be
understood by authorized persons using a decryption code.
&It guarantees that information remains credible, consistent and unchanged all the time it is
out there. This is for those technical reasons to make certain that the information stored in the
database, cannot be changed in a very wrong way or incorrectly by a wrong person.
Techniques like hashing and checksums are applied to prevent any modifications to the data
in the process of transferring or storing the information.
&Availability is expected to mean that all the required information and materials are made
available to the various users with the right level of access required at the right time is
available. The principle is about the usefulness of the systems and the provision for the
availability of the data even when the equipment fails, or there are disasters or even intrusions
by hackers. Some of the methods used to implement maintenance of availability are
duplication, aggregation and recovery.
It makes it impossible for the sender to deny having sent the message. Accountability is a
process of documenting events in a system to determine who is to blame for an occurrence or
that is the root cause of a security breach.
Nature and Development of Historical Context
&Information Security is a concept that has grown and developed throughout several decades.
This was so because, in the early stages of the advent of computers, systems security was
mainly centered on how one could physically gain access to the computer. Security was
handled in a very primitive manner, as it was normally a question of locks and restricted
access to computer centers.
&When computer networks started forming up, more specifically with the coming of the
internet, Information Security became a much larger field. Information Security as a science
was quite progressive in the 70s as modern cryptography was established during this period.
The idea of secure sending messages over an insecure channel was first made possible by the
Diffle- Hellman key exchange of 1976. At the same time, the US government started the
process of codification of security measures, primarily in the military and intelligence sphere.
&The two decades of the 1980s to the 1990s are advocates of personal computing and the
internet and with it came different security issues. Viruses, worms and other forms of
malware became rampant underlining the need for better measures of security. One of the key
markers was the creation of the Advanced Encryption Standard (AES) in 1997, giving way to
a sound approach to data protection.
&Indeed, as the status of Information Security in the 21st century shows, Information Security
is far from being a simple issue. Today due to the presence of e-commerce, social media,
cloud computing, and mobile devices, the threat level is boundless and diverse. Those attacks
are now even more specific in their aims and objectives and can hit not only private people,
and firms, but also core infrastructure elements of a state or themselves. While Information
Security represents a subfield of cybersecurity, the latter also now refers to the Protection of
cyber-physical systems.
&, hence can be summarized as the increase in demand and awareness for Information
Security with the development of Information Technology. Every advance in computing and
networking seems to bring with it new risks and thus new ways of protecting the system.
Relevance in the current generation
Information has to be considered one of the primary resources of the current digital age.
Information technologies employed in organizations entail that organizations assemble,
preserve and analyze humongous information which includes but is not limited to personal
information, financial information, ideas and business information among others. This
information therefore has to be protected to reassure customers and subjects included in the
data and to respect their right to privacy as well as legal and lawful requirements.
From a failure in security an organization is disposed to loss of both financial and non-
financial resources; the organization is likely to lose its market share, customers may turn
away from the organization, and the legal authority may take legal action against the
organization. Some of the examples of popular data breaches include Target, Equifax, and
Yahoo and have waken many organizations up to Information Security measures and
controls.
&Individuals also have keen regard especially for data and information they feed within the
various interfaces. Owing to the gaps in online security, one becomes a candidate for having
their identity stolen, being fraud and or having their privacy violated. Data retention in this
case is very important so that people’s privacy can be respected, and that confidence in the
service can be upheld.
&At an even national level, Information Security is a security issue. Since governments and
countries continue to integrate virtually every aspect of the social existence from the
electricity grid to the communication system, capability for cyber war has become a reality.
The cyber-attacks perpetrated by the state actors on other countries’ critical infrastructures or
election processes have exacerbated the preconditions for the best state-level cybersecurity.
&However, Information Security is also the act of protecting an organization from threats
internal to that organization. Insider risks, for example, are as damaging as external risks such
as hackers, and similarly frightful. Management must also put measures for handling,
training, and checking to reduce cases of insider events.
Some of these are the General Data Protection Regulation (GDPR) in the European Union,
the Health Insurance Portability and Accountability Act (HIPAA) in the United States, and
the Payment Card Industry Data Security Standard (PCI DSS).
Important Concepts and Terms
To understand Information Security fully, it is essential to be familiar with the key concepts
and terminologies used in the field:For effective grasp of Information Security it becomes
necessary to have some basic understanding of terms and concepts commonly used in the
field:
&Attack Vector: The course an adversary takes in order to compromise a system and gain
illicit access into the same system. Some examples of cyber threats comprise of the
following: To be able to come up with the best defense mechanism in case you are invaded, it
is important that you are conversant with its attacks.
Vulnerability: A weakness or any feature within the aforesaid systems and environment which
the adversaries may need to take advantage of. It can be also pointed out that risks may reside
in software applications and the hardware components of a system or in human behaviour.
Daily vulnerability scan is necessary with intent to check for vulnerability and patching is, a
must to be instituted so as to reduce the possibility of the attackers.
&Threat: A common name given to any potential cause that can result to an undesirable
outcome that may negatively affect a system or an organisation. A threat can be internal and
can also be external, it may concern disasters, an act of violence, and a system breakdown.
&Risk: When a threat is met taking advantage of a specific weakness, repercussions that ensue.
Risk management include the assessment of risks and deciding for choosing those risks also
implementing procedures to handle those risks.
&Countermeasure: An organizational guard that is proffered in a bid to protect against threats
and risks. Examples of countermeasures may be technical- firewalls, IDS and or
administrative measures- security policies, and educating ordinary users.
&Incident Response: This is the prescribed manner of recognizing, analyzing and managing
threats that are directed to the security of your firm. A good incident response plan is always
needed to ensure that impacts of security breaches and their impacts on Sodexo are reduced
to a minimum and that business continuity is made as soon as possible.
Challenges and risks bound to information protection in a firm
&In ISM, threat and vulnerability are basic data that must be defined to protect systems and
the information processed in them. These two are the most fundamental aspects of
cybersecurity as they help in devising the gyrations that organizations and persons endure in
modern society. This essay will endeavor to look at some of the characteristics of threats and
vulnerabilities as a feature; define threats and vulnerabilities; types of threats and
vulnerability relationship as about IT systems; and protection measures vis-à-vis the
identified threats and vulnerabilities.
Threats
Threats and vulnerabilities cannot be described in their entirety through references; firstly,
they need to be described in their entirety, and then their distinction needs to be described.
The threat can be defined as any factor that is threatening to a vulnerability and poses risk or
harm Opportunity is something that lies in a threat and speaks of a prospect for an attack or
harm. Threats can come from anywhere:_script Children, Hoods, Traitors, storms and
dullards. ‘They are the potential of an adverse event to affect the confidentiality, integrity or
availability of information or systems in the organization.
&The same on the other hand is a threat, whereas a threat is a danger or a threat that has the
potential of exploiting an opening in a system, a network or a process to cause harm. There
can be a failure on the software side of the system, in the hardware side of the system, or the
operational activities; and due to the mode of design failure, wrong settings failure, no
upgradation failure or due to the inherent nature of the technology failure. While threats are
more or less about risk, vulnerabilities are more oriented toward how that risk could be
realized.
&These threats and vulnerabilities in this respect may be intertwined in the sense that one
forms the premise for the other to be actualized. For instance an installed application that has
not been upgraded with the latest security patch (vulnerability) may be used by an attacker
(threat) for unauthorized access the confidential information. Therefore, from experience,
cybersecurity also entails identifying the dangers or the risks within the probability of the
hackers’ strategies.
1. 2 Types of Threats
&Threats in Information Security are many and generic and can be grouped under several
forms that are distinctive in one way or the other.
&1. 2. 1 External Threats
&External threats can be defined as those threats that start from an external environment and
may involve cybercriminals, hackers and nation-state actors. Such threats are more often
oriented =for money, politically motivated or for the sake of causing havoc. Common
external threats include:
&Malware: Viruses, worms, ransomware, spyware; these refer to violent softwares whose
intent is to have ill effects on systems. For example, ransomware attacks a victim’s files and
data and then demands a payment for a decryption key from the affected organization and
therefore resulting in operational and financial damage.
&Phishing: One common type of social engineering in which the attackers disguise themselves
as genuine parties and compel people into surrendering their password, PIN, or even other
confidential information. Phishing attacks are normally a delusive email or website that tries
to elicit sensitive information.
&Distributed Denial of Service (DDoS) Attacks: These attacks involve flooding the system
with an enormous amount of traffic so as to prevent authorized users from having access.
DDoS attacks can create a lot of problems, mainly for online services and platforms.
&Advanced Persistent Threats (APTs): These are elaborate, specific invasions where the
perpetrator is in a position to invade a certain network, and he continues to do so incessantly.
APTs are usually related to the nation-state actors and can be employed for spying or
destructive purposes.
1. 2. 2 Internal Threats
&Internal risks are risks that arise within an organisation’s structure and it is for this reason
that they can be planned or unplanned. These threats are often not easy to identify and effects
of insiders are high because the insider must have previous knowledge on the firm. Common
internal threats include:
&Insider Threats: This is the wrongfully motivated insiders for instance an angry employee or
a contractor who has plan to embezzle authority to steal or to manipulate the proprietary
information or corrupt the organizational databases. For instance, Edward Snowden, who
leaked classified information can be best described as an insider threat.
&Human Error: However, by someone’s own volition, sometimes by some lapse the employee
himself negates the organizational interest through mistakes such as misconfiguration, data
deletion or simply relenting to the phishing traps. From this study, at least 27% of the cyber
security incidences are as a result of the users so there is a need to train the users.
&1. 2. 3 Environmental Threats
&Threats that can be incurred on Information Systems are environmental if physical, natural or
act of other actors. These threats are often beyond human control and include: Human
influence threats are as follows of the threats are as follows:
&Natural Disasters: On this level they consist of earthquakes, floods, hurricanes, fires and
others that may cause loss of the physical infrastructure of data centers, servers and other
structures that are required in the running of the system leading to loss of data and system
failure.
&Power Failures: Voltage fluctuations or voltage drops, voltage spikes and surges, and
lightning have a dental effect on equipment and data that could have not been backed up.
&Hardware Failures: Disaster can be physical in that, for instance, hard disks, servers and
other equipment used to handle data can fail hence loss of data or working time if backup has
not been provided.
&1. 3 Types of Vulnerabilities
&That is why the following is a list of categories that may be used for the classification of
vulnerabilities in Information Security by their origin and nature. The threats have to be
managed in a way that the effects that these threats have on the organization should not be
exploited hence minimizing the chances.
&1. 3. 1 Software Vulnerabilities
&Software vulnerabilities can be better understood in terms of the opportunity points of soft
spaces that the boomers can manipulate to incite mayhem in software Space. These
deficiencies are usually caused by a mistake in the scripts in writing the code; having old
software or a lack of appropriate security features. Common software vulnerabilities include:
&Buffer Overflows: Buffer overrun, on the other hand, is the case whereby a program writes
more data into a buffer than it can process; the program is then made to do whatever the
attacker wishes it to.
&SQL Injection: This is a situation where the attacker can inject into an already existing
populated query an unwanted SQL code, to have control of the operations of the database and
in the process gain access to private information.
&Cross-Site Scripting (XSS): XSS vulnerabilities enable the attacker to deliver his or her
scripts to the target Websites that the rest of the world can view and get robbed of their details
not forgetting the virus.
&1. 3. 2 Hardware Vulnerabilities
&Among the above kinds of vulnerabilities, those, that relate to the actual physical layers of a
system, are called hardware vulnerabilities and refer to the sinful traits of the physical layers
that enable a cracker to penetrate the security of a given system. Such vulnerabilities may be
a result of defective or poorly coded products and systems or as a result of other bad practices
in design. Examples include:
&Spectre and Meltdown: These are the hardware risks in the CPU architecture where attackers
are permitted to employ the speculative execution on the data in the memory.
&Unpatched Firmware: It is not rare to see routers or other Internet of Things devices with
firmware that has much older and unpatched versions to allow one to enter into the network
and conduct attacks.
&1. 3. 3 Human Vulnerabilities
&All of them portray real-life ordinary people who can be abused by adversaries. These are
compounded by security ignorance, training deficiency or insecurity engineering. Common
human vulnerabilities include:
&Phishing Susceptibility: Some individuals receive insufficient briefing about the ways one
should avoid being enticed into providing the attackers with the details that they want, and
are easily deceived into passing such vital information.
&Weak Passwords: When using such easily hackable or easily recyclable passwords while
doing the computations; then there is a high likelihood of unauthorized login to the respective
accounts.
&Social Engineering: The attacker is most of the time aiming at outcompeting human vices
and behavior to compel the targeted individuals into undertaking actions dangerous to their
security like clicking an email link, or providing the password of an organization among
others.
&1. 4 Risk reduction and Management of exposure
&Consequently Information Security cannot be inactive and only respond to threats and contra
inactive & only respond to susceptibilities. That is why it requires the use of technical and
non-technical measures, which includes putting essentials like firewalls and ‘cloaking’ on the
one hand and coming up with policies that govern the use of the same on the other hand.
&1. 4. It is heading an organization’s Risk Management and the process of its assessment.
&Thus, risk management is another activity that involves risk evaluation and selection and the
assessment of the opportunities to threaten and to evaluate the probability of their realization
and consequences. They are then managed to eliminate or transfer all the risks embedded in
them. Regarding the threats or possibly the more important vulnerabilities it helps
organizations to learn how to resource these adequately.
1. 4. 2 Implementing Security Controls
&Security controls are measures designed for use in the prevention and handling of threats to a
system or data. They include:
&Preventive Controls: These are for the purpose of preventing security incidences from
occurring. The measures of the organizational IT security include both technical and physical
and some of the technical measures include firewalls and antivirus and physical measures
include; encryption and controls on the physical access to the IT systems.
&Detective Controls: These are applied in a system for the real-time tracking of the systems
with the intent of capturing incidents as these occur. The applications of NetFlow include
intrusion detection systems, siem systems, and the monitoring of logs.
&Corrective Controls: They are intended to cope with the event and consequences of security
threats. Some of the documentation and plans are; Incident response plan, Data backup and
Disaster recovery procedure.
&1. 4. 3 Training of User and Education
&All human factors of susceptibility can have possible solutions in terms of proper and regular
user training and education programs. These programs should be aimed at keeping people
aware of what the key risks are: scams like phishing and social-engineering, what are specific
dos and don’ts: creating good passwords and recognizing anything suspicious. These
practices can be instilled as habits through training and also through constant exposure of
links such as simulated phishing to reduce the occurrence of human error and therefore of
creating security openings.
&1. 4. 4 S4 Patch Management and Software Updates
&The first of the main needs is the constant updating of the software and the use of the patches
in accordance with the known issues of the security risks. Patch management includes: The
list of versions, a security patch when it is present, checking for patch throughout the
systems. Hence, the practice aims at reducing exploitable vulnerabilities by the attackers to
the bare minimum possible.
&1. 4. 5 Redundancy and Disaster Recovery
&Redundancy and disaster recovery should be part of organizations in order to be ready for the
challenges of environmental threats. This includes having contingency devices, insuring
failovers and having good thought out disaster recovery solutions. Therefore, these measures
ensure that major systems and information can equally be promptly recovered in case of a
breakdown.
Information Security Management
&The Information Security Management (ISM) is one of the governance operational children
whose goal is to safeguard the organisations’ information resources against threat and to
safeguard the confidentiality, integrity and availability of the organisations’ information
assets to conform to the ISMS in respect to the organisations goals. As informational threats
are characterized by steadily growing novelty and complication, appropriate IMS has turned
into one of the essential prerequisites in safeguarding information, establishing trust, and
satisfying the legal and normative requirements. It will therefore discuss the principles of
Information Security Management, available frameworks, process and some of the
difficulties involved in Information Security Management.
&1. 1. 1 Principle of Information Security Management
&ISM was based on couple of main assumptions about the Information Security that can form
the foundation for the proper security management. These principles include:
&Confidentiality: Ensuring that any confidential information is accessible only by the persons
and companies they are supposed to be disclosed to. An example of how confidentiality is
maintained is by restricting the access of the information, use encryption and there is
classification of the data.
&Integrity: Protecting information and technologies; the access of which is restricted; or the
tampering of or attempts to corrupt. As an attribute, integrity guarantees that information is
credible, dependable and is not switched over the course of its existence. Security of data is
maintained with assistance of hashing, checksums, and also versioning methods.
&Availability: The need to ensure that information and systems are to be accessed by the right
people at the right time. Availability is available in multiples, with multiplications, hot
standby systems, and well-structured disaster tolerance plans.
&Accountability: To manage the security operations and ensure there is coordination addition
to offering direction concerning security operation or decision taken on the company. Recall
that auditing is about counting and recording activities, ensure that users are responsible for
their action, and entitle the entity investigate in the case of a breach.
&Non-repudiation: Just rendering it impossible for a person to give a platonic denial
concerning security of information. The non-repudiation is usually served through some
number of techniques including the digital signatures, auditing along with the right
authentication methods.
&These principles are sometime summarized in what is referred to as the CIA triad
(Confidentiality, Integrity, and Availability) on which Information Security Management
System is based. While both accountability and non-repudiation may be seen as adversaries
to some extent, they are clearly factors that are of significance in security.
&1. 2 Information Security Management Framework
&It is however however noteworthy that in as much as the organizations require Information
Security Management to be adequate, the organizations always integrate the standard
frameworks that are used in managing risk within the organizations. These guidance contain
for an organisation suggested processes, policies and best practices to be followed when
implementing and maintaining controls on the data and IT resources.
&1. 2. 1 ISO/IEC 27001
&ISO/IEC 27001 is an ISMS that both the International Organisation for Standardisation
(ISO) and the International Electrotechnical Commission (IEC) have developed. It is a broad
approach of addressing matters pertaining to identity, that definitely touches on people,
processes and technology. It is a guide on how an organisation should structure an ISMS that
it wants to implement, the process of implementing and maintaining the ISMS as well as how
to check on its effectiveness after some time.
&That the establishment arises from the implementation of the risk management speaks real
volume for ISO/IEC 27001, where the various risks for security are identified and an
evaluation of the prospective impact envisioned. The standard also concentrates on the
systematic examination of the developed ISMS for its efficiency, from time to time, review
and audit.
&1. 2. 2 NIST Cybersecurity Framework
&Global organisations have also responded to the call to develop comprehensive best practice
frameworks with the NIST Cybersecurity Framework also widely established in the United
States. The framework consists of five core functions: The five main activities that make up
the whole strategic framework are as follows; The Identify activity, the Protect activity, the
Detect activity, the Respond activity and the Recover activity.
&Identify: Information system investments and threats that are attached to the information
systems that the organisation possesses, the role of the organisation in a competitive context.
&Protect: Protection of critical sectors that will be offered and security measures;
&Detect: Constructing and functioning on opportunities for the identification of cybersecurity
occurrences.
&Respond: Action plan when the leakage has been defined:
&Recover: The activities of the planning and management of activities in case of cyber threats
and attacks and also in the process of the recovery.
&The NIST Cybersecurity framing has the ability to be integrated into any company regardless
of the ownership or the business it conducts. It emphasise on the initiation of security
measures and on the coordination of the security on its goals and objectives together with the
integration of security on risks and vulnerability, of the organisation.
&1. 2. 3 COBIT
&For acknowledgement of the satisfactory management and governance of IT in the
enterprise, there is a framework called the COBIT which stands for Control Objectives for
Information and Related Technologies by ISACA. This makes OWA by far the most
comprehensive in giving you control and guide on Management of IT and this comprises of
information security management.
&COBIT provides more concentration on the integration of IT goals with the organizational
goals and indicates more complete framework for the IT governance for assuring the
dependability of ISs as well as the conformity with the legislation norms. It is structured to
assist organisations to develop framework for managing risks, responses to incidents and,
compliance features; making it very useful for the integration of ISMS into enterprise IT
governance systems.
1. 3 Information Security Management Processes
&Information Security Management encompasses several activities that individually form part
of a guarantee of information assets. All these are cycle processes and in an ideal world, they
should be done for as long as possible while the clients make occasional evaluation to look
for more improvement.
&1. 3. 1 Risk S/E and Management
&The risk assessment is often seen as the basis and the principle which is inherent to
Information Security Management. They include the risk factors, risk analysis and risk
appropriation that is designed to assess the risks which, if occurred, may hinder attainment of
set goals. Therefore, the strategies for managing of these risks are by minimizing, transferring
or accepting the risks as the case may be.
&The risk assessment process typically includes the following steps:The general identified
sequences of risk assessment process include the following:
&Asset Identification: This is the process of classification of information that need to be
protected and it involve information databases, IT systems and the intellectual property of the
organization.
&Threat Identification: As a result, one is able to recognize the threats that worsen the
vulnerability and take undue advantage of it such as cyber threats, inside threats and natural
calamities.
&Vulnerability Assessment: The process of assessing the strengths and weaknesses of system,
process and technologies in the face of potential threats that can impact on it.
&Impact Analysis: Analyzing all the potential outcomes which may be resultant when
networks’ protection is violated concerning the company, its image and its measurable
performance.
&Risk Prioritization: The measuring of risks and factors that enable risks to be ranked
depending on the likelihood of their occurrence also the impact that will occur once they
happen.
&1. 3. 2 Security Policy Development
&An effective security policy that should be implemented to provide direction in the ISMS
should include the following: Security policy comprise of security objectives, the part that
individuals have to play in the security process and the steps necessary to build and
implement security measures.
&Security policies should comply with the objectives of the business, and strategy and should
be updated frequently to meet with new threats, new technologies, and legal requirements of
the law. Some of the topics may be as follows; access control policy, data protection policy,
response to an incident and user awareness.
&1. 3. 3 Incident Response and Management
&This is quite an important branch within Information Security Management as it comprises
the identification, investigation as well as management of security incidents. Incident
response plans assist an organization in minimizing the effects and length of time that a
particular incident has on an organization to bring back the functionality of the organization.
&The incident response process typically includes the following phases:Essential phases of the
incident response process are as follows:
&Preparation: Designing specific procedures on all the possible processes that may occur,
developing a team that will respond to emergencies and enacting the designed procedures.
&Detection and Analysis: Sighting of alerts and coordinating and managing the ones that are
possible to be organized to look for signs of security incidents; determining the type of
security attack as well as the overall assessment of the magnitude of the attack.
&Containment, Eradication, and Recovery: Some of the approaches include: palliative
measures to prevent the situation from aggravation, measures to dismantle the source of the
problem, and measures to recover all vandalized computers and files.
&Post-Incident Review: A critical examination of the entire event and assessment of the strong
and weak points of the present position to use them in future endeavors.
&1. 3. 4 Security Awareness and Training
&In Information Security Management, Human aspects are imperative, employees/ users are
proved to be the weakness most of the time in the security system. Security awareness and
training should be made available so that the employees can study safety threats, measures,
and other matters.
&Desirable training must be organization-specific and must include such contents as how to
identify phishing scams, how to use good passwords and how to share information when the
suspicion arises. Training and awareness education among employees also develop a security
culture in the organizations by reducing the probability of humans making security
contradictions.
&1. 3. 5 Compliance and Auditing
&Information Security Management includes the following legal and regulatory requirements
as a part of it. The security measures have to be proportional to the current legal standards
and regulations as well as organisation-specific standards such as those of the GDPR, HIPAA
or PCI DSS.
&Equally, the auditing should be done frequently to ensure that one confirms that the controls
are of the desired effectiveness and that they have been implemented correctly. These may be
transported internally or through a third party and must concern problems in areas such as
access, security, managing of an incident, and risk among others. Findings made in the course
of assessments should be used in assessing the extent of a deficiency of security measures
and also in the process of improvement.
1. Here are some of the difficulties that information security managers are likely to encounter:
&Information Security Management as a discipline is a tough and lively area of specialization
and has several difficulties. Such challenges need to be overcome to foster effectiveness as
far as security endeavors are concerned.
&1. 4. 1 Evolving Threat Landscape
&The ever-changing nature of the threats in the cyber realm constitutes a real problem for
Information Security Management. Cybercriminals are always in the process of evolving
different attack methods and tools thus making it very hard for organizations to counter them.
To that end, organizations have to focus on being more proactive and spend more on threat
intelligence, new-generation security solutions, and monitoring.
&1. 4. 2 Working on Both Security Aspects and Convenience
&As in any other if not the most important aspect one of the major issues facing organizations
while implementing Information Security Management is how to achieve the best balance
between security measures and user friendliness coupled with a well-oiled organization
machinery. This is a vivid realization of the fact that measures that are too strict will act as a
brake on productivity and create enormous frustration among the users, while measures that
are too liberal will open up the organization to a range of risks. Staking the right balance
entails consultancies to understand the risk appetite of the organization to develop proper
strategies.
&1. 4. 3 Resource Constraints
&Most institutions therefore experience resource barriers in their capacity to put in place
optimum safety policies. Lack of funds, manpower and knowledge can seriously jeopardize
the growth and sustenance of efficient and sound Information Security Management
programs. Thus, to eliminate the problem, organizations should focus on security investment
by threat analysis and potentially use collaboration with third-party contractors, like managed
security providers.
&1. 4. 4 Regulatory Compliance
&Adherence to an increasing trend of regulations and standards can prove a real challenge to
organizations. Regulations can be vastly different from the other meaning that each kind of
regulation could prescribe data protection, reporting or incident management differently, in
turn making compliance a nightmare. Regulations need to be monitored by organizations and
compliance has to become an integral part of the security management system and needs to
be audited periodically.
&1. 4. 5 Insider Threats
&Risk from an internal source can be a complex problem for Information Security
Management since the culprit is likely to be an authorized user of the company’s systems and
databases. Countermeasures against insider threats include a set of technical and
organizational countermeasures: True detection and prevention of insider threats require
technical controls, including monitoring, and anomaly detection, as well as Non-Technical
controls, including background checks on users, user awareness and training, positive
organizational climate, etc.
&Certainly! The following are analysis of each of the sub-theme that is; “Cryptography and
Data Protection,” “Network Security,” “Security Policies and Compliance,” “Ethical and
Legal Aspects in Information Security,” and “Trends in Information Security” subtopics
where each subtopic is elaborated in paragraphs to give right information.
&1. Cryptography and Data Protection
&Cryptology is the fundamental technology for protecting data being in motion and at rest as it
holds a critical place in data protection. That involves the use of a set of computations to
make the data in a system difficult to understand by unauthorized persons. The process of
encryption is the conversion of the plain text into cipher text and can only be read by those
who have the decryption key. There are two primary types of cryptographic algorithms: are
the two forms of the encryption, namely symmetric and asymmetric encryption. In symmetric
encryption, there are the same key both for encryption and decryption, but then the process is
much more rapid, but one essential problem remains, the key exchange. As to irregularity, it
is based on two keys: public and private where the public key encrypts data and the private
key decrypts it though is more suitable for the security of key exchange processes.
&Data protection is not simply confined to encryption but involves also a system of plans
including data classification, added access control, and data masking. Data classification is
thus carried out depending on the sensitivity of the data, when security controls are assigned
to it. For instance, complex data may entail more elaborate encryption techniques and fewer
users can access it than less complex data, which may be protected by relatively simpler
techniques of encryption. Some of the data controls include access control which limits the
amount of data that can be accessed by individuals in the organization while data masking
provides a way of presenting information which is in a way that is not intelligible to users
thus if they are accessed the data is useless to the unauthorized individual.
&It is also used together with electronic signature, censor, marked system, and access control
techniques in preserving and maintaining the integrity and authenticity of the data. For
example, hash functions produce a particular sized hashed value from the inputs to ensure
that the data has not been changed. Digital signatures use hashing and asymmetric encryption
to offer non-repudiation, which refers to a scenario whereby the sender of a message cannot
refute the occurrence of the transmission, and the recipient can as well validate the senders
credentials. As new threats arise, the development of new means of encryption is constant,
quantum cryptography is promising to become the solution to quantum computers, which can
decrypt any modern ciphering.
&2. Network Security
&Network security can refer to a large number of technologies, devices or practices that aim at
ensuring the accuracy, confidentiality and accessibility of data whether in transit or storage in
a fixed or mobile network. This is essential in preventing and protecting against invasion,
misuse, failure, tampering, destruction or improper use of resources connected to a network.
Network security basics are firewalls, intrusion detection systems and prevention IDS/IPS
and VPN.
&Firewalls are one of the first lines of defense against networks, they are used to separate the
internal network from the external world, and most commonly from the internet. Firewalls
can be used to screen traffic according to certain directional action standards and then deny
the wicked traffic while admitting the good traffic. In combination with firewalls, IDS and
IPS constantly scan the media for signs of anomalous behavior. Whereas IDS only scans the
network and reports to administrators of threat existence, IPS blocks threats in real time and
eliminates them from getting into the network.
&VPNs are currently considered an indispensable means of ensuring the protection of access
to corporate networks from a distance. VPN their objective involves the provision of
encryption and safe passages for the transfer of information as they work across dangerous
public networks. Besides these technologies, network segregation is one of the vital best
practices in network security. An organization splits a network into segments isolates them
and denies malware access to the network's critical assets, thus minimizing the available
target space and increasing protection.
&What we have adopted therefore in this current and new security architecture is known as
zero-trust architecture, which is a new philosophy in network security. In a zero-trust model,
all of the connections, even internal traffic, are considered to be malicious. This model entails
a much higher level of identity validation and most confined access across all the users and
devices regardless of their positioning in the network. This approach reduces the prospects of
internal threats and lateral progression in a network thus giving a firm protection against
multi-tiered cyber attacks.
&3. Security Policies and Compliance
&Security policies are documented procedures that outline how and organization will protect
its information resources. These policies set standards that need to be adopted to guard data
and all the stakeholders including employees, partners and contractors need to adhere to these
set standards. Security policies have to reflect the organization’s requirements and threats and
have to meet the regulations and standards.
&The formation of security policies can be initiated with the help of Threat and Risk
Assessment to set Identification of the primary threats and risks the organization is exposed
to. These assessments make it possible to develop security policies about parts like access
control, information security, incidents management and the proper utilization of information
systems. Some of the examples include the access control policy that may state how, where
and when the access to certain restricted data will be granted or withdrawn and the data
protection policy that may specify how the data will be protected through the use of
encryption and how data back up will be done.
&Legal and regulatory requirements are certain key parameters that have to be addressed in
management of information security. Companies are subject to numerous legal imperative
that relate to data security for individuals, for example, the GDPR in EU, the HIPAA in US,
or the PCI DSS for payment card information. Such regulations usually prescribe stringent
measures in relation to data protection, breach notification and audit, and stiff punitive
measures for regulatory infringement.
&For this reason, organizations have to create mechanisms which will ensure almost constant
monitoring and auditing. A simple security check is used to validate that all the implemented
security controls are working as it should, or else that the organization has not violated any
legal requirements. Compliance also encompass keeping records like the security policies,
risk analysis, and the incident management strategies that may be needed in an audit or a
legal proceedings. When compliance is incorporated into an organization’s security plan, one
is able to minimize chances of legal consequences, bad fraternity and possible losses.
4. Ethical and Legal Issues in Information Security
&The ethical and legal frameworks of Information Security is therefore a topic that involves a
broad perspectives on issues of privacy, ownership of data, as well as responsibilities and
accountability of organizations in protecting individual’s data. The growth of the digital
world then requires the institutions to confront the sphere of ethical issues and legal
requirements to avoid violation of individual’s rights or legal prohibition in the transmission
and storage of data.
&The first ethical question that arises, and perhaps the most crucial one that is hard to find an
answer to, is the conflict of interest between the principles of security and privacy. More
often, organizations have the mandate of safeguarding organization or personal information
from unauthorized access and penetrations, but at the same time, they should endeavor to
respect the privacy a user has in their data. This balance is especially delicate in situations
where the measures demarcated as ‘secured’ recognition, observation, data monitoring, etc.
may be seen as abusive. Ethical elements mandate organizations to come up with security
procedures balancing the level of risk and, being truthful to the people on how data is
gathered, used, and secured.
&Legal matters about Information Security can be centered on data protection laws and
regulations that proscribe how personal data is to be processed. For example, GDPR requires
the organizations to collect data and process data in compliance with the legal basis, which is
consent from the individuals, and gives rights and opportunities to individuals, including the
right to access the data, correct it, or erase it. Offence of these laws attract severe penalties in
the form of fines and other legal consequences.
&Another ethical dilemma is the problem of the leakage of information and the obligation of
companies to inform the public about it. Companies maintain that it is ethically wrong for
them to keep quiet and ‘see no evil’ when a data breach occurs; instead, what is expected of
them is to notify the victims and other interested parties so that the latter can protect
themselves accordingly. Nevertheless, there are times when some organizations will prefer to
conceal this information lest they dent their reputation or suffer some losses. This gives rise
to many ethical issues about the responsibility of companies and their legal responsibility to
customers and shareholders.
&Other ethical issues are related to information privacy and data security and concern
cybersecurity research as well as the development of adversarial approaches to security.
While penetration testing and ethical hacking are fully legal methods of identifying and
correcting the weakness in the system, the creation and distribution of exploit tools can be
considered ethical, especially if such tools get into the wrong hands. As such, security
researchers as well as security practitioners can only tread these ethical dilemmas delicately
since there are usually two sides of the same coin between security on one side, and abuse on
the other.
&5. Lots of development is progressing in the area of Information Security since it is one of
the areas in computing that is concerned with the management of information in the most
efficient ways as it flows in the information superhighway.
&Information Security as an area of science is also in a state of constant development due to
the rapid development in information technology, and the changing threat exposure and legal
requirements. The following are some of the prominent trends that are emerging in the field
of Information Security and these trends present new opportunities and new risks in equal
measure to organizations.
&5. 1 Intelligenza artificiale eMachine Learning
&AI and ML are being incorporated into Information Security to supplement the discovery,
response to threats and the making of decisions. Because the AI tools can process large
volumes of data in real-time, potentially depicting inconsistencies characteristic of a security
threat, security can be enhanced using AI. This makes it easier for organizations to contain
the attack, and act faster, within or close to the right time, hence minimizing the effects of the
cyber attack. However, applying AI in the security line, there are certain issues which include
the eventuality of adversarial attacks where the attackers get a chance to influence the AI
systems and bend the rules for their benefit.
&5. 2 Zero Trust Architecture
&ZTA is a relatively new approach to security infrastructure that diverges from the convention
of authoritative internal and peripheral external networks. More of in a Zero Trust model the
network traffic is considered as a potential threat, and specified identification is needed
constantly for the appropriate resources to be granted access. This approach minimizes the
possibility of insiders, being used by attackers especially those who have infiltrated a
network. This is because the practice of Zero Trust is being enabled now that the new normal
means people are working remotely, and where cloud is at the core of most enterprises’
network topology.
&5. 3 Quantum Computing with Post- Quantum Cryptography
&Thus, Information Security is not protected from pressure from the active development of
quantum computing. As it stands, quantum computers, which hold the prospect of an upgrade
to computational power, come with the prospect of attacks against the current cryptographic
algorithms which is something that could soon be rendered ineffective. To this end, the fourth
sphere, known as post-quantum cryptography, is appearing that deals with developing
cryptographic algorithms that can be secured against attacks of quantum computers. It is
about time organizations start looking for and deploying approaches that can reliably offer
some defenses against these quantum threats; in fact, it is high time organizations start
looking at what is known as quantum-resistant encryption.
&5. 4 Cloud Security
&With so many different organizations shifting to cloud-based environments, cloud security is
another important factor. Cloud security therefore is the process of safeguarding cloud-based
data, applications, and services against attacks, for example, data loss, improper settings, and
unauthorized parties. Cloud security seems to adopt a shared responsibility model because the
cloud service customer and the cloud service provider are both expected to employ Security
controls. The new trends being practiced in the field of cloud security include the use of
container security, serverless, and Cloud Access Security Broker.
&5. 5 Privacy-Enhancing Technologies
&With people becoming sensitive with the data they feed on the internet, PETs are gaining
popularity because while feeding data for analysis, the identity of the data inputters is
concealed. PETs include tools like differential privacy and homomorphic encryption and
secure multi-party computation where organizations can make computations on encrypted
data and not have to reveal the underlying data. Such technologies are most useful in
industries that require the preservation of client and individual information such as medical
and banking.
Students also viewed