Critical Analysis.
Introduction'
Cybersecurity, is a combination of computer and information systems security, focuses on providing security for information and information systems that are accessed via cyberspace. It is designed to combat cybercrime (stolen of information or data online). Cybercrime is fraudulent activities carried out on the cyberspace – “Cyberspace is created when people and organizations use technology as a substitute for face-to-face interaction as they live, work, and play.”
Causes and Effects of a Threat
Importance of Cybersecurity in Business
It is of paramount importance for every organization either small or big to invest in cybersecurity. The rapid increase in targeted persistence cyber threats. Reputation matters a lot in business. Organization of various types conducts their business and traction on cyberspace. The types of information that pass through the cyberspace are crucial. Transmitting these data on the cyberspace without cybersecurity pose a tremendous threat. The Confidentiality, Integrity and Availability (CIA) of any organization that runs its activities carelessly without implementing on the cyberspace without appropriate cybersecurity place in place is heading for doom. Day-in-day-out it is often reported in the news how cyber crimes are committed against business; the recent IRS, Home Depot, and Target data breach, etc. examples of cyber crimes. According to Reuben, investing in cybersecurity “is to reduce the risk of a security breach to an acceptable level” (Reuben, 2014).
People, Process, and Technology
Another importance of cybersecurity investment is when the organization made efforts to improve their business by investing in people, process and technology improvements. It is of great benefit for organization to hire the right people for the right job. According to Kelso, he argues that “great technology systems without the right people and process around them will be unmanaged and underutilized” (Kelso, 2011). The cost of technology and staffing might be high, but it is always good to consider the cost and damages caused by an attack, “how much will an attack cost the company if its network is not adequately protected?” (Sweeney, 2013). No attack is minimal no matter how small the attack. The best thing to do is to improve the computer securities and keep the software updated. By doing this, it will be tough for any hacker to penetrate or try to gain access to the organizations’ computer system. They may try, but with tight security, they won’t succeed. It is recommended that the IT personnel to undergo subsequent training on what to do and following the necessary procedure of security check at all level. Third party vendor account should be isolated from the company’s account, that way if there is any threat coming from the third party, it won't’ be able to infiltrate into the company’s account.
Conclusion
Threats can sometimes be an attack from inside or outside. The security measure of every organization must be strong enough. The AAA’s of Security that checks the Authentication, Authorization and Accountability must be part of the security system. As an organization, authentication of any individual either an employee or contractor is necessary. Anyone grant access to the computer system needs to authenticate his or her identity (such as username and password), the system in return verifies the identity provided and grants him or her access. The system can eventually account for who and what each person did; by doing that, individuals are responsible for what they did and cannot repudiate (nonrepudiation) taking an action. It is the responsibility of every organization to make sure that the computer systems are upgraded; new security system installed and train the Security administrators. The introduction of Defense in Depth Security to tightening the safety of the organization is paramount. Access controls with the principle of least privilege to restrict access to data within the organization to reduce.
Reference:
Reuben, P. (2015, April). Why you should be spending more security. Retrieved from http://www.cio.com/article/2904364/security0/why-you-should-be-spending-more-on-security.html
Rabu, (2010, 10 November). Computer and Internet benefits. Retrieved from: http://fandicomputer.blogspot.com/
Kelso K. (2011, 25 February). Lessons Learned: Invest in people, process, technology. Retrieved from: http://www.bizjournals.com/nashville/print-edition/2011/02/25/invest-in-people-process-technology.html
Sweeney, P. (2013, August 13): Network-based attacks: How much can they cost you? Retrieved from: http://www.scmagazine.com/network-based-attacks-how-much-can-they-cost-you/article/307214/