Need Re phrase the paper

profilekeekov
chetan_module_8-2.docx

IT 650: Principles of Database Design

Project Milestone – 5

Topic: .

Under the guidance of

ProfessorDr. Steven. Case

 

Submitted by

 

Nikhil Balusani.

LAW, ETHICS, AND SECURITY

Legal and ethical Standards

Availability – the system should allow data to be available to the authorized person at the right time and with less effort needed to access it.

Integrity – data in the database should modified by only the authorized persons and in the correct way. Such that such modification or alterations do not bring conflict in the database meaning data should not be tampered with. If tampered this could amount to misuse.

Confidentiality factor- a system should be designed in such a way that it does not allow unauthorized person to access information which they don’t have permission for Vinyl records . There should be restriction to data accessed by different parties.

The system being developed should not negatively affect the health, safety and welfare of the users instead it should make life better.

A system developed should not perform illegal actions such as corrupting data, leaking of information or used in spying.

The policies and procedures used in the operation to the system being developed should must assure reliable data.

A system developed should be licensed; the legal process of obtaining license should be used.

One should not use software product that they don’t have license or are not authorized to use by the owner. Intellectual rights should not be violated.

Legal compliance

To ensure accurate data is entered every time the system should be able to validate data before Restricting access to data in the database through separating data into different tables with where user privileges are restricted. The design of the database should enable separating different object attributes of entities to restrict access to the whole entity information hence able to protect data from unauthorized access.

Database design methodology used in this case must allow scalability of the information such that the database will continue to function properly even when the data is increasing and hence ensure availability and reliability.

Integrity of the data should be done by setting access privileges in the physical design of the database which is implemented.

Security should be incorporated in all phases of the database development cycle. In the design phase the system.

Standards

The access to different types of databases is done through DBMS only, so for this the standards are easier to enforce. Standards may include and relate to structure of data, format of data, naming of data etc.... generally standardized data is used for the purpose of data exchange between various systems.

· The design of the database should be organized in a manner that the database system provides the overall service which is best for the organization. By this it can give response for the high critical applications when compared to less critical applications.

· The storage of the data in the database in an easy way, but sometimes due to threats or any damage the data stored might be lost. But in these days we have a centralized systems and databases. Centralizing a database provides schemes such as data recovery and backups, though the methods are complex.

· The data use in the database is carried according to the operations performed by the database administrator. The responsibility of the data administrator is to design and structure the data files in a way that it gives a quick response for all the users. Because it would be helpful to identify organization needs and to balance the needs of the other units.

· The security of the database has been improvised and can be done more. It is easier to have control on who access to what parts of database, through establishing checks for each type of access some of them like retrieve, modify, validate etc...

· From these standards and by improving the flexibility, integrity and secrecy of the database system the DBMS can provide better services to the users.

Ethical Practices:

A database is a logically coherent collection of data with some inherent meaning, representing some real world and which is designed, built and populated with data for specific purpose. The database and DBMS software together is called as Database System. The role of the database administrator has changed according to the recent technologies and as well as the needs of the owners of the databases. Some of the relevant ethical standards that need to be considered during the design of a database are:

· According to the database the data to be built should be adequate and relevant.

· The data should be processed by the data controller until he/she satisfies the conditions for processing out the data.

· The processing of data is necessary for the administrators and users as well.

· Increasing the co-ordination with other databases and trying to vast the applications of data

· The convenience to access mechanisms has to be increased which tend towards the analysis and away from mere query.

· The security should be increased for the database administrators (owners) but not for the consumers.

· The ethical implications of a database should be evident in a way that the information in databases is collected and used.

· Here the database owners and consumers not only have the values because of their work but also the databases themselves have the values for which it carries on the overall operations in a system to succeed.

· An organization has obligation of storing accurate and up-to-date information, example when one withdraws money in a bank or changes bank account name or even address, this changes should be reflected in the database immediately or within a short time.

· Data stored should be provided proper security. The security may be informed of unauthorized persons, alteration or loss. The software and the database dealing with the data should be safe.

· The method of obtaining and processing data should be legal and fair to the public

· Data obtained from clients should only be accessible to the authorized person. Illegal exposure should be avoided at all cost. Students in this scenario should not access each other confidential data.

· Data obtained and stored by organization should be kept for only legal purposes which are described in the organization register entry.

· Individuals should be able to view, modify or erase their records. This mechanism MUST be provided by organization holding individuals information. The organization may charge a reasonable amount for this service.

· The data stored should be sufficient, relevant and not excessive in relation to the reason for which they are held.

· Information about people should not be held longer than is required for the use in which they are held. When an organization doesn’t require a specified person data anymore then that data should be removed from the database. This may be done after a specified period. This could be information of an employee who has transferred.

Security Needs of Solution:

The DBMS chosen for should have the following features;

Should allow configuration so that the student cannot access each other records. It should have the capability to be configured to restrict access to it by unauthorized persons. The admin should be able to grant, deny or revoke privileges to the users depending on which data need be accessed.

Should not allow bypassing the normal process of database access. Backdoor and trap door should not be present in the DBMS system as these are pose security to the data stored.

The database should be secure in that it cannot easily be hacked. It should be able to reject certain request depending on the source.

Database Security Plan:

As we know DBMS is the collection of software programmes that provides functionalities for defining, maintaining, and accessing the data stored in the database. Besides accessing and processing each DBMS must also provide Security functionalities to ensure the secrecy, integrity, and availability of stored data. This is considered as one of the major issues for particularly those who use and store sensitive information of data. Example in a college the secrecy is concerned with preventing an employee in finding out the head of the authority salary, integrity is concerned with preventing an employee to change his salary, and availability is concerned whether he receives the check in time or not.

DBMS needs to protect a record of a file at each and every level, while an operating system protects data at file level. The life time and access of data stored in database is different from the data stored in the operating system. The SQL language provides a powerful mechanism for defining authorisations by using privileges. (Delete, Insert, Select, References.. etc). So certain standards and activities have to be performed at different levels during the design and maintenance of data in database. Some of them are:

· Database System: Some of the intruders try to modify the data where as few of them try to modify only query, so it is the job of the administrator to enforce the authorization rules.

· Operating System: Even though we provide security to database system, sometimes it serves as unauthorized access.

· Network: Most of the databases allow remote access, so hardware and software security is crucial.

In the there are several measures that need to be put in place to ensure that the data in the database is secure. These measures include.

The use of the licensed original database management system software to avoid bleaching the law while ensuring the security of the data in the database.

Database design should have at least the minimum quality standard specified by software development laws.

The machines in which the system runs should be secured by the putting them in rooms that are safe from theft and destruction. The computer storing the database should be in a more secure place and should only be accessed by the database administrator.

Proper procedure should be followed in the update of the software while ensuring that the changes do not violate the law or the requirements of the system.

The document containing the information about the development process should be prepared that can be used to guide in the modification of the software which may pose threat to data if not properly done.

References:

Computer Ethics - Lecture 10. (n.d.). Retrieved June 24, 2015, from http://www.cmpe.boun.edu.tr/~say/c150/intro/lit10.html

Cybersecurity: Tackling the threat from within - BBC News. (n.d.). Retrieved June 23, 2015, from http://www.bbc.com/news/technology-31164843

Tackling Global Cybersecurity Threats: Georgia Tech Is Developing Technologies and Strategies to Enable Cybersecurity Solutions | GT | Georgia Institute of Technology - Georgia Tech’s Research Horizons. (n.d.). Retrieved June 23, 2015, from http://www.rh.gatech.edu/news/340981/tackling-global-cybersecurity-threats-georgia-tech-developing-technologies-and

Threats and Countermeasures. (n.d.). Retrieved June 23, 2015, from https://msdn.microsoft.com/en-us/library/ff648641.aspx