0% found this document useful (0 votes)
37 views15 pages

System and Data Security

this document has information about computer security risks and how to go about them

Uploaded by

kaggwa joseph
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
37 views15 pages

System and Data Security

this document has information about computer security risks and how to go about them

Uploaded by

kaggwa joseph
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SYSTEM AND DATA SECURITY

4.1 Introduction
4.2 Computer Security Risks
4.3 Securing a Computer system against risks
4.4 Ethical Practices while using ICTs
[Link]

4.1 Introduction
Data, information and programs used in a computer system are vulnerable to damage, misuse
or theft by unauthorized persons. This calls for ultimate security for the systems that keep the
data and information belonging to different stakeholders.
Computer system security and cyber security is aimed at protecting the computer system and
the user’s identification from theft, damage and unauthorized access.

Exploring the meaning of Computer security


Computer security refers to keeping the data/ information, programs and systems safe from
loss or damage.
Computer security is required because of computer security risks.
A computer security risk is any even or action that could cause a loss or damage to computer
hardware, software data or information.
In computer security there is system security and data security. System Security looks at
controlling and safeguarding an organization’s networks. This can be through the use of
firewalls, biometric systems and physical access controls to premises and computer networks.
Data security on the other hand looks at controlling and safeguarding an organizations data.
Data protection ensures that a company’s data is not accidentally deleted, modified or
deliberately accessed, manipulated, stolen, sold or misused.
Some measures for data security may include encrypting computers, protecting them with
strong passwords, regular changing of passwords, not sharing passwords and creating data
backups.
Importance of Computer security in a school
 It helps to keep the schools information safe from unauthorized access.
 It helps to prevent viruses and malware from infecting computers.

1
 It helps to improve the overall performance of the computer system since it would have
virus infections and so programs would run quicker.
How a school data can get damaged or misused
 When the data is accidentally deleted without having any data backups.
 Computer viruses and other malware programs that can corrupt and damage the data
on computers.
 Mechanical damages of the hard disk drive. At times when the hard disk breaks down
or crashes, data recovery may even be impossible.
 Liquids that are spilled into the computers can lead to fire sparks which may lead to
losing the information.
 Fire break outs and explosions in which the hardware is completely destroyed
especially the internal computer parts like the hard disk can lead to data loss.
 Theft of an entire computer when one has no back up of data.
How a school can safe guard data belonging to Teachers, learners, suppliers and creditors.
The school can create regular data backups on different devices.
BY using strong passwords on all devices holding the schools information
By encrypting data especially that which is being shared.
Using a firewall on the organization’s network.
Using various physical access controls like biometric machines.
Protecting passwords e.g. not sharing them. Not just leaving them written anywhere.

4.2 COMPUTER SECURITY RISKS

Definition:

Examples of different computer security risks include:-


Computer virus/Malware
Unauthorized access and use of computer systems.
Hardware theft and software theft.
Information theft and information privacy
System failure.

2
1. Malware/Computer viruses: - These are malicious programs that copy themselves to
other computer programs and files destroying them. There are various malicious programs
like viruses and worms. These are capable of corrupting data, deleting data stealing credit
card data and passwords.
TYPES OF VIRUSES/MALWARE
(a) Boot sector virus. This executes when a computer starts up because it resides in the
boot sector of a floppy disc or the master boot record of a hard disk.

(b) File virus. This attaches itself to program files, and is loaded into memory when the
program is run.
(c) Macro virus. This uses the macro language of an application (e.g. word processor or
spread sheet) to hide the virus code.
(d) A logic bomb. This is a virus that activates when it detects a certain condition.
(e) A time bomb. This is a kind of logic bomb that activates on a particular date.
(f) A worm. This copies itself repeatedly in memory or on a disk drive until no disk space
remains, which makes the computer stops working.
(g) A Trojan horse. This is a program that hides within or looks like a legitimate program
but executes when a certain condition or action is triggered.
(h) Ransomware-a type of malicious software designed to block access to a computer system
until a sum of money is paid.
(i) Rootkits- is a malicious piece of software that grants a remote operator complete access to
a computer system illegally without being detected.
(j) Adware- is a type of malware or unwanted software designed to deliver targeted
advertisements on infected computers. While some adware is relatively harmless, others can
track user activity, collect personal information, and even redirect to unsafe websites
(k) Spyware - While some adware is relatively harmless, others can track user activity, collect
personal information, and even redirect to unsafe websites
(l) Bots - a bot is an automated piece of software that performs predefined assignments,
usually over a network. It is an automated malware program that can infect a system, steal data, or
commit other fraudulent.

(m) Key-loggers - A key-logger, a type of spyware, is software or hardware that secretly


records every keystroke typed on a keyboard. It's a form of malware used by cybercriminals
to steal sensitive information like passwords, credit card details, and usernames.

3
VIRUS SYMPTOMS
The presence of a virus can be indicated if one or more of the following
symptoms appear on your computer. Any evidence of these or similar events
should be an immediate cause for concern to isolate the PC at once and
investigate.
- Unfamiliar graphics or quizzical messages appearing on screens.
- Programs taking longer than usual to load.
- Disk access seeming excessively slow for simple tasks.
- Less memory available than usual.
- Access lights turning on for non-referred devices.
- Computer tends to restart itself.
- Computer files disappearing from the computer.
- Multiple files opening up when only file is opened up.

PRECAUTIONS TO PREVENT VIRUS INFECTION

 Install an antivirus utility and update its virus definitions frequently for
detecting and removing viruses.
 Never start up a computer with a floppy disk (removable storage medium) in
the drive.
 Ensure that the e-mail is from a trusted source before opening or executing
any e-mail attachment.
 Scan all floppy disks and file for possible virus infections before opening
them.
 Back up data on a regular basis to avoid massive data loss.

AN ANTIVIRUS UTILITY
This a program that prevents, detects and removes viruses from a computer’s memory or
storage devices, one popular antivirus program is Norton Antivirus. Others include;
 McAfee antivirus
 F secure antivirus
 Avira antivirus
 AVG antivirus
 Avast antivirus
 Norton antivirus
4
 Kaspersky antivirus
 Bitdefender antivirus e.t.c.
N.B:- to go through antivirus installation processes practically with learners.
Why is Commercial antivirus the best version of antivirus to use?
Because it contains anti-spyware, firewall, spam filters and many other things. Giving the
computer more secure coverage.

2. Unauthorized access and Use of Computer systems


Unauthorized access is the use of a computer or a network without permission.
while
Unauthorized use is the use of a computer or its data for unapproved or possibly illegal
activities.

The illegal access to a computer or network is referred to as hacking. Hacking can be done
in the following ways:-
i) Password theft: - This is where a third party manages to steal or guess your password, then
logs into your computer or any account of yours. They can even change the passwords
denying you access to your information.
Soln.
Use strong passwords that cannot be easily guessed and change them regularly.
Guidelines on password creation
 Use atleast 8 characters if supported by the system.
 Mix letters, numbers and other characters/symbols.
 Do not use easily guessable things e.g. your name, D.o.B, Phone number etc.
 But ensure you can remember it easily.
Tips on safeguarding a password.
 Do not write down. If you write down put it in a place not easily accessible by other
people.
 Do not share your password.
 Make sure when typing in the password you can type it in without looking at the
keyboard.

5
ii) Eaves dropping or traffic interception: - This happens when a third party listens to and
steals information sent over a network. This can be done with the help of gadgets and certain
hacking software.
Soln.
Encrypt information sent over a network and avoid using unsecure websites.
iii) Phishing attacks:- This is a social engineering attack where sensitive information like
passwords and credit card numbers are attained from users through e-mail. An end user can
receive an email requesting for sensitive information and at times it looks legitimate.
Soln.
Avoid opening emails from unknown sources and do not share sensitive information over
email links unless you fully sure of the email source.
iv) Distributed Denial of Service (DDoS) :- This is an attack in which malicious parties target
to overload servers with data traffic. When the server can no longer handle incoming requests,
the website it hosts will shut down or slows down in performance rendering a service
unusable.
Soln.
Identify malicious traffic and halt access.
v) Trojan Horse:-
Soln.
Avoid downloading programs or executable files from unrecognized vendors.
vi) Ransomware: - This refers to malicious software that installs itself on a user system
network. Once installed, it prevents access to functionalities (partly or wholly) until a ransom
is paid to a third party.
Soln
Keep your antivirus program up to date and avoid malicious links.
vii) Social engineering: - This is a method for attempting to deceive others into giving away
sensitive details.
Soln.
Remain skeptical of suspicious messages, friend requests, emails or attempts to collect
information from unknown sources.

6
Activity Question
1. Identify and discuss security risks to computers around school and their potential
impact.

Under Unauthorized access and use of computer systems, there are other ways of securing
computer systems, these include:-
i) Using passwords
ii) Installing antivirus software
iii) Biometric security system: - this uses biometric security software to recognize
people automatically based on their physical characteristics. The most common
biometric system is the finger print recognition and iris scanner.
They are used today in many places including airports and hospitals.
Places where biometrics are used.
 In banks to authenticate people who can enter particular offices.
 At some schools or universities to track staff attendance.
 In school class rooms to track class attendance of students.
 In telecommunication companies when registering people for lines.
 By individuals when making their phone access safe

How biometrics work.


 A database is create containing all biological data of people allowed to access a
resource.
 Biometric access control analyses specific biological data e.g. finger prints or the face
when individuals try to access a system and they are scanned.
 If their biological data is on record, they are granted access, if not, they are denied
access.

Advantages of biometrics security technology over passwords.


 They are hard to steal unlike passwords
 They do not require the user to remember anything, you just use your body features.
 They are very unique and non-transferable.
 They also easily help verify identity

iv) Firewalls: - this is either a software or hardware or a combination of both that


provides a line of protection between your computer or network and other

7
networks (including the internet). It keeps track of every file that enters or leaves
the network so as to detect viruses (or malicious software) and other problems that
may enter the network.
v) Audit trails and system logs: - These are system files that can be followed to find
out what systems were logged into, by who (or which user account) what day and
time. These can be used to track activities carried out on computer systems

3. Hardware theft and software Theft:


Hardware theft refers to physical carrying off of the hardware components without
authorization, while
Software theft refers to carrying off of storage medium having the software or illegally
duplicating and distributing the software.
Illegal duplication of software is referred to as software piracy.
Hardware Security looks at protecting the physical machine and hardware peripherals from
damage due to vandalism, theft and electronic intrusion
How to protect computer systems form hardware theft:
a) Using strong metallic doors on the rooms housing the hardware.
b) Enhancing the doors and windows with burglar proofs.
c) Using strong padlocks on the rooms.
d) Having in place CCTV cameras to ensure 24 hour surveillance.
e) Having security guards in place especially in institutions like schools.
f) Keeping a record of the serial numbers of all the hardware
g) Securely labelling the hardware components.
h) You can lock the small components onto the desk after tying them up with a cable
tie.
For software theft:
a) Properly keep software disks in well locked lockers.
b) Use code wrappers to hide or scramble code so that attackers can't find and disable
the license check.
c) Make code difficult to reverse-engineer to prevent cracking.
d) Discourage software piracy by making legal versions more accessible at an affordable
price.
Information Theft and Privacy
This refers when someone takes someone else's personal information without permission and then
uses it for their own benefit.

8
Reasons for Information theft
- A company may want to learn about a competitor.
- An individual steals credit card number to make fraudulent purchases.
Prevention
- Implement access control to computers and networks
- Use data encryption techniques.
Information privacy refers to the right of individuals or organizations to deny or restrict the
collection and use of information about them.
1. Apply strong authentication over your accounts
2. Enable your browser privacy settings
3. Ensure you have installed antivirus software on your device
4. Be aware of the signs of a phishing attempt
5. Before entering personal information into a website, ensure the site is secure

System Failure:
A System failure is a prolonged malfunction of a computer that can also cause hardware,
software, data and information loss.
Common causes of system failure
- Aging hardware
- Natural disaster e.g. fires, floods, storms or earthquakes
- Electrical power variations. Electrical power variations can cause loss of
data or equipment. A single power disturbance can damage multiple
systems in a computer network.
A surge protector can be used to protect computer equipment against under voltage and
over voltage. Many users also connect an Uninterruptible Power Supply to the computer
for additional electrical protection.
Human-ware Safety
Human-ware are the people involved in installing, maintaining, operating and testing
computers.
Examples of human ware include: - programmers, Software engineer, System analysts, Data
entry operator, Database administrator, software engineer etc.

9
Ways of caring for computer users
A) Avoiding Repetitive strain injury
Have regular breaks for typing to rest the hands
Use wrist rests while typing
B) Ways to avoid back and neck pain
Using adjustable chairs for better height depending on the computer desk.
Sitting upright with the head up.
Taking regular breaks from the computer
C) Ways to avoid eye strain and head ache
Don’t use the PC when the sun is shining directly into the screen.
Make sure the eyes are at least 18 inches from the screen.
Practice the 20, 20 20 rule, 20 mins of using the ICT device, take 20s and look at something
in a 20m distance to relax the eyes.
D) To avoid Deep Vein Thrombosis
Stand and move around to allow normal blood flow in the legs.
Take regular breaks to stretch the body.

4.4 Ethical Practices while Using ICTS

Computer Ethics is the application of moral principles to use computers and the internet.
The ethical and moral concerns governing the use of ICT include the invasion of individual
and corporate privacy, intellectual property rights, individual and society rights, online
etiquette and accountability for the disadvantages arising from the use of ICTs.
(a) Codes of conduct. A code of conduct is a written guideline that helps determine whether a
specific action is ethical or unethical.

Sample IT codes of conduct

 Computers may not be used to harm other people.

 Users may not interfere with others’ computer work.

 Users may not meddle in others computer files.

10
 Computers may not be used to steal.

 Computers may not be used to bear false witness.

 Users may not copy or use software illegally.

 Users may not use others’ computers resources without authorization.

 Users may not use others output.

 Users should always use computers in a way that demonstrates consideration


and respect for other people.

Things that annoy when people using ICTs

 Playing loud music


 Shouting while talking on phone.
 Using loud speaker during a phone call in public
 Someone deletes your files on computers used by many people.

The effect of ICT ethical concerns.

 Accidental disclosure of confidential or private information. This may result in job loss.
 Unauthorized access to protected information. May result in Job Loss.
 Breach of copyright law. The violator may be prosecuted/sued in courts of law.
 Breach of a Patent Law. The violator may be prosecuted/sued in courts of law.

The important contents of any code of conduct are:-

 Ethical principles – includes workplace behavior and respect for all people.
 Values – includes an honest, unbiased and prejudiced work environment.
 Accountability - Here one takes responsibility for your own actions, ensuring appropriate use of
information, exercising diligence and duty of care obligations and avoiding conflict of interest.
 Standard of conduct – Complying with the job description, commitment to the organization and
proper computer, internet and email usage.
 Disciplinary actions – Includes complaints handling and specific penalties for any violation of the
code.

11
(b) Intellectual property rights.

Intellectual property (IP) refers to work created by inventors, authors and artists. These are creative
works that have economic value and are protected by law.

Intellectual property refers to creations of the mind: inventions; literary and artistic works; and
symbols, names and images used in commerce. Examples of intellectual property include; designs,
concepts, software, inventions, trade secrets, formulas and brand names, as well as works of art.
Intellectual property can be protected by copyright, trademark, patent or other legal measure.

Intellectual property rights are the rights to which creators are entitled for their work.

It is aright that is had by a person or by a company to have exclusive rights to use its own plans, ideas, or
other intangible assets without the worry of competition, at least for a specific period of time. These
rights can include copyrights, patents, trademarks, and trade secrets.

A copyright gives authors and artists exclusive rights to duplicate, publish and sell their materials.

A copy right is a legal right which allows creative artists, authors and publishers to control use and
reproduction of their original works.

A trade mark protects a company’s logos and brand names. It is a word, phrase or symbol used by
sellers to identify their goods and distinguish them from the goods of other sellers. Trade mark law
protects words, symbols or slogans that identify different brands of goods from others.

Patent
A patent is a right, granted by the government, to exclude others from making, using, or selling your
invention. Patents protect inventions such as new processes, machines, or chemicals.

It is a legal certificate established by government to give an inventor or author exclusive rights to make
use and sell his invention for a specified number of years.

Trade secrets

This is formula, practice, process, design, instrument, pattern, commercial method not generally
known by others by which a business can obtain an economic/competitive advantage over
competitors.

12
SAMPLE AOI

Your district recently got computers form the Ministry of ICT and National Guidance to
establish a computer center. The district chairman has found out that the copies of the
correspondence and files sent by the district via these computers have been seen by other people
elsewhere being misused and modified for personal gain and that some of the computer with
sensitive information are missing. The District chairman is now much concerned and has sought
help from your school.

Tasks

1. Prepare a write-up on how you are going to work on physical security of computer
systems in the computer center.
2. How are you going to ensure that the security of information leaving and coming into the
district computer network is not accessed by unauthorized people virtually

13
Write-Up on Physical Security of Computer Systems in the Computer Center

Ensuring physical security of the computer center is critical to protecting sensitive district data
from theft, damage, and unauthorized access. The following measures will be implemented:

1. Secure Access Control

 Install lockable doors with keycard or biometric authentication.


 Limit access to authorized personnel only through an access control list.
 Implement visitor logs to track individuals entering the center.

2. Surveillance & Monitoring

 Set up CCTV cameras to monitor activity and deter theft.


 Employ security personnel to oversee access and respond to suspicious behavior.

3. Equipment Protection

 Lock computers to desks to prevent unauthorized removal.

 Attach physical tracking devices to valuable equipment.

 Use tamper-proof cases for high-security machines.

4. Preventing Unauthorized Use

 Require login credentials for all workstations.


 Auto-lock inactive computers to prevent unattended access.
 Restrict USB and external drive usage to mitigate data theft.

5. Backup & Recovery Measures

 Store backup servers in a secure room with limited access.


 Implement fireproof and waterproof storage for critical hardware.

14
Ensuring Security of Information Leaving & Entering the District Computer
Network

To secure the district’s data transmission, the following strategies will be applied:

1. Data Encryption & Secure Communication

 Use end-to-end encryption for emails and file transfers.


 Deploy Virtual Private Networks (VPNs) to protect online communications.

2. Firewall & Network Monitoring

 Install firewalls to filter unauthorized network traffic.


 Conduct real-time monitoring using Intrusion Detection Systems (IDS).

3. Multi-Factor Authentication (MFA)

 Require MFA for accessing sensitive data remotely.


 Restrict access based on user roles to minimize exposure.

4. Secure File Sharing Policies

 Implement digital rights management (DRM) to control document usage.


 Use cloud storage with role-based permissions instead of open-file transfers.

5. Regular Audits & Cybersecurity Training

 Conduct routine security audits to identify vulnerabilities.


 Train district personnel on cyber hygiene practices to prevent breaches.

Would you like a detailed step-by-step implementation plan for any of these measures?

5. Regular Audits & Cybersecurity Training

 Conduct routine security audits to identify vulnerabilities.


 Train district personnel on cyber hygiene practices to prevent breaches.

Would you like a detailed step-by-step implementation plan for any of these measures?

15

You might also like