0% found this document useful (0 votes)
4 views10 pages

Understanding Risks in Information Security

Uploaded by

mohammedtarig94
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views10 pages

Understanding Risks in Information Security

Uploaded by

mohammedtarig94
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Faculty: Computer Science and Information Technology

Information Security
Lecture 2
Risk, vulnerabilities and threats
[Link] Mohammed Rashad
Risk, vulnerabilities and threats
Security is known as protection against risk and loss. In general, the
concept of security is similar to the concept of safety. The subtle
difference between the two concepts is the additional focus of security
on protection against external risks represented by individuals and
activities that violate the protection and are directly responsible for the
breach of security. The term security is generally used as a synonym for
the term safety, but from a technical point of view, the term security
means not only safety, but work to provide safety as well.
There are specific concepts that are repeated in
different areas of security, including:
1) Risk

A concept that refers to potential negative effects on assets and


valuable properties that may result from a current operation or future
event . In other words, risk is the possibility of a certain event
occurring that will have an impact on the achievement of goals. In the
field of engineering sciences, risk is defined quantitatively as the
product of multiplying the probability of occurrence of an accident
and the loss in one accident. Risk is a threat indicator and is based on
threats, vulnerabilities, impact on operations and uncertainty. There
are many ways and methods to assess and measure risk.
In information and network security, risk is determined using
three variables (factors):
• Possibly a threat.
• Possibly there are loopholes.
• potential impact of risk.
If any of these variables becomes zero, the overall risk to the system or
network is also close to zero.
Risk management is a human activity that aims to integrate risk
recognition, assessment and development of strategies to manage and
mitigate it by using administrative resources.
2) loopholes vulnerability (or not to immunize) and generally know
Sensitivity to physical or psychological harm or attack.
It also means the lack of necessary protection for valuable property
and assets. In computer and network security, the term
vulnerabilities are used to refer to vulnerabilities in these systems
that allow an attacker to attack the integrity of the system.
Vulnerabilities in computer and network security can be
classified into two categories:
1- Technical vulnerabilities, which are the result of weak immunization
resulting from the technologies used in systems and networks. In this case, the
attack on the network is known as a technical attack.

2- Administrative vulnerabilities, which are the result of non-technical


reasons. The attack on the network or computer, in this case, is known as a
social engineering attack

. attack
The loopholes can also be divided in terms of Difficulty
and ease are divided into two categories :
A- Top level loopholes High-level Vulnerability , It is easy to exploit
vulnerabilities, an example of which is writing program code to exploit this
vulnerability .

B- Low-level vulnerabilities and this kind from the loopholes hard Exploiting
it requires a lot of effort and resources on the part of the attacker.
Threats
Threats , which is the possibility of intrusion on assets and properties
Information) without the permission of its owner, forcibly, and through a
possible loophole in the system, with the aim of stealing or sabotaging it,
and in the event of its occurrence, threats pose a threat to the system. There
are three primary components of the threat Which:
• Objective: In computer and network security, it represents information stored
or transmitted over networks for the purpose of violating its confidentiality,
integrity, or existence .

• Client They are the programs and objects that constitute and create a threat,
and their use requires access to the computer or networks, in addition to
information about the characteristics of their operation and the security
mechanisms used in them, in order to search for a loophole through which to
access the system or network.
• The event, which represents the quality of the effect of the threat situation,
and is used for this in many ways, the most important of which is the abuse
of authorized access And change authorized Unauthorized to information or
system. It put malicious code Malicious is like virus codes in systems.

You might also like