0% found this document useful (0 votes)
31 views34 pages

Understanding Information Security Basics

Uploaded by

love the animal
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
31 views34 pages

Understanding Information Security Basics

Uploaded by

love the animal
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Security and Cryptography (BIT8322 )

INTRODUCTION
Dr. Nadia IRADUKUNDA

E-mail: iradukundanadia1@[Link]
niradukunda@[Link]

Kigali, Rwanda
What is the difference between
Data and Information?

2
Information Vs Data
v Data can be described as unprocessed facts and figures.
n Plain collected data as raw facts cannot help in decision-making.
v Information is interpreted data; created from organized, structured, and processed
data in a particular context.
n Information is a data that has been processed into a form that is meaningful to recipient and is of
real or perceived value in the current or the prospective action or decision of recipient.

Processing involves selecting, organizing, and manipulating data


3
Information Vs Data typical Example

4
INFORMATION CHARACTERISTICS

vWhat is Information?
n Information comprises the meanings and interpretations that people place upon
facts.
n The value of information springs from the ways it is interpreted and applied to
make products, to provide services, etc.
vInformation has three characteristics:
n 1. It can be recorded and retrieved;
n 2. It has value & meaning.

n 3. It can exist in many forms, e.g., written, printed, electronically stored,

physically transmitted or transmitted in electronic form.


v A database is an organized collection of structured information, or data,
typically stored electronically in a computer system.

5
Classification Of Information
v Information can be classified in a number of ways, you will learn two of the most
important ways to classify information.

6
Classification based on the decision making

v Based on Anthony’s, from the view of


management classification of
information that is gathered for the
purpose of decision making can be
classified as shown in figure 4 below:

7
Information Security?
v Information Security is the practice of preventing unauthorized access, use,
disclosure, disruption, modification, inspection, recording or destruction of
information.
v This is to mean, even though information is important to all of us, not all information
should be accessed by anyone.
n The access should be controlled.

n Every organization uses information, most are dependent on it.

v Information is an asset, which can be: Business records, Client and contact databases,
Personnel information, Financial records and transactions, E-commerce transaction details.

8
TYPES OF INFORMATION SECURITY

9
Basic security components

n Confidentiality
n Integrity

n Availability

10
1. Confidentiality
v Means information is not disclosed to unauthorized individuals, entities and
process. For example:
n If we say I have a password for my Gmail account but someone saw while I was

doing a login into Gmail account. In that case my password has been
compromised and Confidentiality has been breached.
n Someone watching you type in your pin code at an ATM, is compromising the

confidentiality of that pin code.


n If you leave your PC while you are still logged on, and someone starts

browsing through your files in your absence, this would be considered as an


attack on confidentiality of your information.

11
2. Integrity
v Used to indicate whether information has been changed or whether that information
has errors in it.
n So, someone who changes the data in a file without proper authorization will have

compromised the integrity of that data.


n The most common attack on integrity, however, simply consists of input errors

when that data/information is first put on a system or is updated.


v Examples:
n If an employee leaves an organization, then in that case data for that employee in

all departments like accounts, should be updated to reflect status to JOB LEFT so
that data is complete and accurate and only authorized person should be allowed
to edit that employee’s data.
n Attacks on the integrity of information can have an objective fraud (e.g., falsifying

the records in a payroll system) or a political motive (e.g., modifying the contents of
a website).
12
3. Availability

v Its used to indicate whether a user has access to any information, or the system that
contains/processes that information, when the user needs this access.
v An attack on availability can involve deleting information or crashing a system, but
it may also prevent access to the system by cutting or overloading the
communication channel to that system.
n The most common attacks on availability are, however, simple things like hardware

failure or power failure.

13
Information Security Controls

vTypes of information security controls include:


n Authentication

n Encryption

n Integrity controls

n Backups

n Access control

n Auditing
1. Authentication

vAuthentication is the process or action of verifying the identity of a user


or process.
vis the process of Ensuring that both ends of the connection are in fact
who they say they are.
Authentication: Three Types
vSingle Factor Authentication
n Password
n Easy to remember
n Easy to crack
n People are predictable…passwords are usually a pets name, a birth date, etc.

vTwo Factor Authentication


n Password + token (security device for users to keep in possession)
n Safer and more complex than single factor

16
Cont…

v Three factor Authentication


n Password + token + biometric authentication (fingerprint, retinal scan)

n Safer and more complex than single or double factor types;

n used for high security purposes (ex. Government documents)

vA token is a security device for authorized users to keep in


possession.
vSome examples include:
n Security ID Card, Challenge/response method, and USB token

17
2. Encryption and Security (Cryptography)
v Encryption is a mechanism for hiding information by turning readable text
(PLAIN TEXT) into a stream of digital signatures (CIPHER TEXT) in such a
way that someone with the proper key can make it readable again.
3. Integrity controls

vAre designed to manage the integrity of data, which is a fundamental


component of information security.
vIn its broadest use, “data integrity” refers to the accuracy and consistency
of data stored in a database, data warehouse, data mart, or other
construct.
v This can be used by adopting:
1. scans,
2. bar code,
3. digital signatures, etc.
4. Access Controls

vis a security technique that regulates who or what can view or use
resources in a computing environment.
vAuthentication
n identity confirmation
vAuthorization
n permission often role-based
n Firewalls
vAccountability
n logging
5. Backup
vData backup is a copy of computer data taken and stored elsewhere
so that it may be used to restore the original after a data loss event.
v You can back up either to:
n 1. Backing up to an external device, such as tape, HDD, and then it can be

transferred and stored on another device in case of data loss.


n 2. Backing up to the cloud and then opening it on another computer by logging

into the cloud account.


Back Up And Restore in Windows

22
Reason for database security

vGuard firm’s reputation


vAvoid litigation(controversies)
vRetain competitive standing
vMaintain trust
n Customers

n Merchants

n Business partners/vendors
6. Information Auditing (IA)
v The role of the information audit is to provide a method for identifying, evaluating, and
managing information resources in order to fully exploit the strategic potential of
information.
v Information is representative of a resource which requires effective management and this
led to the development of interest in the use of an IA.
Information System Audit Principles

24
WHY INFORMATION SECURITY?

25
QUIZ - DISCUSSION

1. If you receive an e-mail from someone you don’t know, what


should you do to ensure the protection of your data?
2. Discuss the security for paper vs Electronic Records?
Discuss the pro’s and con’s of paper vs electronic record
keeping in terms of security.
3. Information is considered as an asset in this digital era.
Agree or disagree. Discuss

27
QUIZ - DISCUSSION

1. Why information systems are vulnerable NOWADAYS as


compared to back then in 20th century? Discuss in details.
2. The mouse on your computer screen starts to move around on its
own and click on things on your desktop. What do you do?
3. If you receive an e-mail from someone you don’t know, what
should you do to ensure the protection of your data?
4. Discuss the security for paper vs Electronic Records? Discuss
the pro’s and con’s of paper vs electronic record keeping in terms
of security.
5. Information is considered as an asset in this digital era. Agree or
disagree. Discuss

28
What is Information security management?
v Information security management is the process by which the value of each of
an organization’s information assets is assessed and, if appropriate, protected on
an ongoing basis.
n We can deduce that no single solution can address all possible security concerns.

n The only strategy is to engineer a fit-for-purpose solution that achieves a suitable

balance between risks and protection against them.


v How do we move forward?
n Implementing information security in an organization can protect the technology

and information assets it uses by preventing, detecting and responding to


internal and external threats.

29
Security risks to database systems
v A database is an organized collection of structured information, or data, typically
stored electronically in a computer system.
v Unauthorized or unintended activity or misuse by authorized database users,
n database administrators,

n or network/systems managers,

n or by unauthorized users or hackers (e.g. inappropriate access to sensitive data,

metadata or functions within databases,


n or inappropriate changes to the database programs, structures or security

configurations)

30
Cont.
v Malware infections -software that is specifically designed to disrupt, damage, or
gain unauthorized access to a computer system.
v causing incidents such as:
n unauthorized access,

n leakage or disclosure of personal or proprietary data,

n deletion of or damage to the data or programs,

n interruption or denial of authorized access to the database,

n attacks on other systems and the unanticipated failure of database services;

31
Cont.

vOverloads, performance constraints and capacity issues resulting in


the inability of authorized users to use databases as intended;
vPhysical damage to database servers caused by:
n computer room fires or floods,

n overheating,

n lightning,

n accidental liquid spills,

n static discharge,

n electronic breakdowns/equipment failures and

n obsolescence;

32
Cont..

vDesign flaws and programming bugs in databases and the


associated programs and systems. This can create various security
vulnerabilities such as:
n unauthorized privilege escalation,
n data loss/corruption,
n performance degradation etc.
vData corruption and/or loss caused by the entry of invalid data or
commands, mistakes in database or system administration processes,
sabotage/criminal damage etc.
Thank you for Your Attention
Dr. Nadia IRADUKUNDA
E-mail: iradukundanadia1@[Link]
niradukunda@[Link]

You might also like