report
INFORMATION ASSURANCE
Information assurance refers to the process of protecting information systems (computers and networks) through ensuring confidentiality, availability, authentication, integrity and nonrepudiation of information during exchange.
The need for Information Assurance
Information assurance is important because information kept in systems face a lot of risks in different forms which can cause detrimental effects to organizations and businesses. e. g. financial losses or imprisonment.
It usually guarantees the availability of information only to authorized users in the organization
2
Type of security risks
Malware infection
Phishing
Laptop/mobile theft
Bots on network
Abuse of Net access by staff
Financial fraud
lack of encryption
Lack of management support
Exploit of wireless network
Denial of service
Password sniffing
overreliance on security monitoring software
inadequate system logging, outdated operating systems
Countermeasures to security risks
Security threats can be countered through use of:
User authentication
Network port security
IP address filtering
Firmware validation
Job logs/access logs.
Security for fax line
Locked print etc.