report

profilejeevanraj
milestone_3_complete_information_assurance.pptx

INFORMATION ASSURANCE

Information assurance refers to the process of protecting information systems (computers and networks) through ensuring confidentiality, availability, authentication, integrity and nonrepudiation of information during exchange.

The need for Information Assurance

Information assurance is important because information kept in systems face a lot of risks in different forms which can cause detrimental effects to organizations and businesses. e. g. financial losses or imprisonment.

It usually guarantees the availability of information only to authorized users in the organization

2

Type of security risks

Malware infection

Phishing

Laptop/mobile theft

Bots on network

Abuse of Net access by staff

Financial fraud

lack of encryption

Lack of management support

Exploit of wireless network

Denial of service

Password sniffing

overreliance on security monitoring software

inadequate system logging, outdated operating systems

Countermeasures to security risks

Security threats can be countered through use of:

User authentication

Network port security

IP address filtering

Firmware validation

Job logs/access logs.

Security for fax line

Locked print etc.