Data Security: Threats and Controls
Data Security: Threats and Controls
Review Questions
1. Differentiate between private and confidential data.
2. Why is information called a resource?
3. (a) Explain the term ‘Information security’.
(b) Recently, data and information security has become very important.
Explain.
Sources of viruses.
a) Contact with contaminated systems:
If a diskette is used on a virus infected computer, it could become
contaminated. If the same diskette is used on another computer, then
the virus will spread.
b) Use of pirated software:
Pirated software may be contaminated by a virus code or it may have
been amended to perform some destructive functions which may
affect your computer.
c) Infected proprietary software:
A virus could be introduced when the software is being developed in
laboratories, and then copied onto diskettes containing the finished
software product.
d) Fake games:
Some virus programs behave like games software. Since many people
like playing games on computers, the virus can spread very fast.
e) Freeware and Shareware:
Both freeware & shareware programs are commonly available in
Bulletin board systems.
Such programs should first be used in controlled environment until it
is clear that the program does not contain either a virus or a
destructive code.
f) Updates of software distributed via networks:
Viruses programs can be spread through software distributed via
networks.
4). THEFT
The threat of theft of data & information, hardware & software is real.
Some information is so valuable such that business competitors or some
governments can decide to pay somebody a fortune so as to steal the
information for them to use.
Review Questions
1. Explain any three threats to data and information.
2. Give two control measures one would take to avoid unauthorized access
to data and information.
3. Explain the meaning of ‘industrial espionage’.
4. (a) Define a computer virus.
(b) Give and explain two types of computer viruses.
(c) List three types of risks that computer viruses pose.
(d) List and explain five sources of computer viruses.
(e) Outline four symptoms of computer viruses.
(f) Explain the measures one would take to protect computers from virus
attacks
5. How can one control the threat of user’s errors to data and information?
COMPUTER CRIMES
A computer crime is a deliberate theft or criminal destruction of
computerized data.
The use of computer hardware, software, or data for illegal activities, e.g.,
stealing, forgery, defrauding, etc.
Committing of illegal acts using a computer or against a computer system.
Trespass.
Trespass refers to the illegal physical entry to restricted places where
computer hardware, software & backed up data is kept.
It can also refer to the act of accessing information illegally on a local or
remote computer over a network.
Trespass is not allowed and should be discouraged.
Hacking.
Hacking is an attempt to invade the privacy of a system, either by tapping
messages being transmitted along a public telephone line, or through
breaking security codes & passwords to gain unauthorized entry to the
system data and information files in a computer.
Tapping.
Tapping involves listening to a transmission line to gain a copy of the
message being transmitted.
Tapping may take place through the following ways:
a) A person may send an intelligent program to a host computer that sends
him/her information from the computer.
b) Spying on a networked computer using special programs that are able to
intercept messages being sent & received by the unsuspecting computer.
Cracking.
Cracking is the use of guesswork by a person trying to look for a weakness in
the security codes of a software in order to get access to data & information.
These weak access points can only be sealed using sealed using special
corrective programs called Patches, which are prepared by the manufacturing
company.
A program patch is a software update that when incorporated in the current
software makes it better.
NB: Cracking is usually done by people who have some idea of passwords or
user names of the authorized staff.
Piracy.
Software, information & data are protected by copyright laws. Piracy means
making illegal copies of copyrighted software, data, or information either for
personal use or for re-sale.
Ways of reducing piracy:
i) Enact & enforce copyright laws that protect the owners of data &
information against piracy.
ii) Make software cheap enough to increase affordability.
iii) Use licenses and certificates of authenticity to identify originals.
iv) Set installation passwords that prevent illegal installation of software.
Fraud.
Fraud is the use of computers to conceal information or cheat other people
with the intention of gaining money or information.
Fraud may take the following forms:
a). Input manipulation:
Data input clerks can manipulate input transactions, e.g., they can create
dummy (ghost) employees on the Salary file or a ghost supplier on the
Purchases file.
b). Production & use of fake documents:
E.g., a person created an intelligent program in the Tax department that
could credit his account with cents from all the tax payers. He ended up
becoming very rich before he was discovered.
Fraudsters can either be employees in the company or outsiders who are
smart enough to defraud unsuspecting people.
Sabotage.
Sabotage is the illegal or malicious destruction of the system, data or
information by employees or other people with grudges with the aim of
crippling service delivery or causing great loss to an organization.
Sabotage is usually carried out by discontented employees or those sent by
competitors to cause harm to the organization.
The following are some acts of saboteurs which can result in great damage to
the computer centres:
Using Magnets to mix up (mess up) codes on tapes.
Planting of bombs.
Cutting of communication lines.
Alteration.
Alteration is the illegal changing of stored data & information without
permission with the aim of gaining or misinforming the authorized users.
Alteration is usually done by those people who wish to hide the truth. It
makes the data irrelevant and unreliable.
Alteration may take place through the following ways:
a). Program alteration:
This is done by people with excellent programming skills. They do this
out of malice or they may liaise with others for selfish gains.
b). Alteration of data in a database:
This is normally done by authorized database users, e.g., one can adjust
prices on Invoices, increase prices on selling products, etc, and then
pocket the surplus amounts.
Security measures to prevent alteration:
i) Do not give data editing capabilities to anybody without vetting.
ii) The person altering the data may be forced to sign in order for the system
to accept altering the information.
Review Questions
1. (a) Define the term ‘Computer crime’.
(b) State and explain various types of computer crimes.
2. Differentiate between Hacking and Cracking with reference to computer
crimes.
3. What is a program patch? Why are patches important?
4. Give two reasons that may lead to computer fraud.
5. How can piracy be prevented in regard to data and information.
6. What is data alteration? Explain its effects on data.
7. Explain the meaning of Tapping while dealing with computer crimes.
Data encryption
Data being transmitted over a network faces the dangers of being tapped,
listened to, or copied to unauthorized destinations.
To protect such data, it is mixed up into a form that only the sender & the
receiver can be able to understand by reconstructing the original message
from the mix. This is called Data encryption.
The flow diagram below shows how a message can be encrypted and
decrypted to enhance security.
Cyphertext
Plain text Plain text
Encryption key Decryption key
The message to be encrypted is called the Plain text document. After
encryption using a particular order (or, algorithm) called encryption key, it is
sent as Cyphertext on the network.
After the recipient receives the message, he/she decrypts it using a reverse
algorithm to the one used during encryption called decryption key to get the
original plain text document.
This means that, without the decryption key, it is not possible to reconstruct
the original message.
Log files
These are special system files that keep a record (log) of events on the use of
the computers and resources of the information system.
Each user is usually assigned a username & password or account. The
information system administrator can therefore easily track who accessed the
system, when and what they did on the system. This information can help
monitor & track people who are likely to violate system security policies.
Firewalls
A Firewall is a device or software system that filters the data & information
exchanged between different networks by enforcing the access control policy
of the host network.
A firewall monitors & controls access to or from protected networks. People
(remote users) who do not have permission cannot access the network, and
those within cannot access sites outside the network restricted by firewalls.
LAWS GOVERNING PROTECTION OF INFORMATION
Laws have been developed that govern the handling of data & information in
order to ensure that there is ‘right of privacy’ for all people.
The following rules must be observed in order to keep within the law when
working with data and information.
1. Data & information should be kept secure against loss or exposure.
2. Data & information should not be kept longer than necessary.
3. Data & information should be accurate and up-to-date.
4. Data & information should be collected, used & kept for specified lawful
purposes (i.e., it should not be used for unlawful gain).
5. The owner of the data has a right to know what data is held by the person
or organization having it.
6. Data should not be transferred to other countries without the owner’s
permission.
7. Do not collect irrelevant and overly too much information for a purpose.
Review Questions
1. What do the following control measures against computer crimes involve?
(i) Audit trail.
(ii) Data encryption.
(iii) Log files.
(iv) Firewalls.
2. Give four rules that must be observed to keep within the law when
working with data and information.
COMPUTER SECURITY
What is Computer security?
Safeguarding the computer & the related equipments from the risk of
damage or fraud.
Protection of data & information against accidental or deliberate threats
which might cause unauthorised modification, disclosure, or destruction.
A computer system can only be claimed to be secure if precautions are taken
to safeguard it against damage or threats such as accidents, errors &
omissions.
The security measures to be undertaken by the organization should be able to
protect:
i) Computer hardware against damage.
ii) Data, information & programs against accidental alteration or deletion.
iii) Data & information against hazards.
iv) The computer against unauthorised use.
v) Data, information & programs against piracy or unauthorised copying.
vi) Data & programs used by the computer system against illegal or
unauthorised modification.
vii) Storage media, e.g., diskettes, tapes, etc against accidental destruction.
viii) Policies of the organization.
ix) Buildings.
x) Accidental interruption of power supply or communication lines.
xi) Disclosure of confidential data or information.
xii) Ensure that both hardware & software have longer life span.
1). Fire.
Fire destroys data, information, software & hardware.
Security measures against fire:
Use fire-proof cabinets & lockable metal boxes for floppy disks.
Use of backups.
Install fire fighting equipments, e.g., fire extinguishers.
Have some detectors.
Training of fire-fighting officers.
Observe safety procedures, e.g., avoid smoking in the computer rooms.
Have well placed exit signs.
Contingency plans.
Security measures:
Install facilities to control power fluctuations, e.g., use of Uninterrupted
power source (UPS)
Use power stabilizers.
Have standby power generators/sources.
Have lightening arresters in the building.
8). People.
People threats include:
Carelessness.
Clumsiness.
Accidental deletion of data, information or programs.
Vandalism, i.e., theft or destruction of data, information or programs &
hardware.
Piracy of copyrighted data & software.
Security measures against Carelessness & Clumsiness:
Better selection of personnel.
Have a good office layout.
Improve employee training and education.
Limit access to data and computers.
Regular backups.
Use of Undelete & Unformat utilities.
Security measures against Vandalism:
Should have a sensitive attitude to office behaviour.
Tighten security measures, e.g., install alarm systems, burglar-proof
doors/windows, & roofs).
Limit access to sensitive company information.
Use Keyboard lock on terminals used by authorised users.
Use of disk locks.
Punitive measures.
9). Earthquakes.
Review Questions
1. (a) What is Computer security?
(b) Mention various threats to computer security.
2. Discuss the environmental problems affecting the operation of computers.
2. Computer viruses:
A computer virus destroys all the data files & programs in the computer
memory by interfering with the normal processes of the operating system.
Precautions against computer viruses:
a) Anti-virus software.
Use Antivirus software to detect & remove known viruses from
infected files.
Some of the commonly used Antivirus software are: Dr. Solomon’s
Toolkit, Norton Antivirus, AVG Antivirus, PC-Cillin, etc
NB: The best way to prevent virus is to have a memory-resident
antivirus software, which will detect the virus before it can affect the
system. This can be achieved by installing a GUARD program in the
RAM every time the computer boots up. Once in the RAM, the
antivirus software will automatically check diskettes inserted in the
drives & warn the user immediately if a disk is found to have a virus.
For an antivirus to be able to detect a virus, it must know its
signature. Since virus writers keep writing new viruses with new
signatures all the time, it is recommended that you update your
antivirus product regularly so as to include the latest virus
signatures in the industry.
The Antivirus software installed in your computer should be
enabled/activated at all times.
You should also perform virus scans of your disks on a regular
basis.
Evaluate the security procedures to ensure that the risk of future
virus attack is minimized.
Review Questions
1. Describe two ways of preventing data loss due to power outage.
2. (a) What is a Computer virus?
(b) What are Anti-viruses? Explain how they detect and remove viruses.
3. Accidental erasure:
Commands such as DELETE & FORMAT can be dangerous to the
computer if used wrongly.
Both commands wipe out the information stored on the specified
secondary storage media, e.g., formatting the Hard disk (drive C:) will
destroy all the software on that system.
Precautions against Accidental erasure:
a) Use of Undelete utilities.
Use the Undelete facilities in case you accidentally delete your files.
There are two Undelete facilities depending on the operating system
you are using.
MS-DOS 6.0 Undelete facility:
To undelete at the DOS prompt, change to the drive & directory
whose files were deleted, then type, e.g.,
C:\>UNDELETE <directory that contain the deleted
file>
A list of all deleted files will be displayed with the first letter
missing. Type in the first letter and the file will be recovered.
Norton utilities & PC Tools:
Norton utilities & PC Tools also have an undelete facility, which is
similar to the DOS Undelete facility.
Windows Recycle Bin:
The Recycle Bin temporarily stores all deleted files & can be used to
recover your files.
1. Double-click the Recycle Bin on the desktop.
2. Click on the files you want to undelete.
3. Click on File, choose Restore.
The Recycle Bin will restore all selected files to their original
folders and disks.
NB: If you delete a file accidentally, don’t copy any files or install any
applications to the disk that contains the deleted file. If you write
anything to the disk, you might destroy parts of the deleted file,
making it unrecoverable.
b) Use of Unformat utilities.
MS-DOS 6.0 has an Unformat facility which can be used to recover
information stored on disks that have been accidentally formatted.
c) Use of Backups.
All data must be backed up periodically either on diskettes, tapes or
CDs so that in case of any accidental loss, the backed up copy can be
used to recover the data.
For small files, use the Copy command to make a copy of the data on a
diskette. For larger amounts of data, use the Backup command to
copy the data to several diskettes or to a tape drive.
Review Questions
1. Name two commands that can erase the information from a disk.
2. Define ‘Data backup’ and state its importance.
5. Unauthorised access:
Unauthorised access refers to access to data & information without
permission.
Computer criminals can do the following harms:
Steal large amounts of funds belonging to various companies by
transferring them out of their computer accounts illegally.
Steal or destroy data & information from companies, bringing their
operations to a standstill.
Spread destruction from one computer to another using virus programs.
This can cripple the entire system of computer networks.
Spread computer worm programs. Worm programs are less harmful in
the beginning, but render the computer almost useless in the long-run.
Precautions against Unauthorised access:
a) Restrict physical access.
Physical access to computer systems should be restricted to ensure
that no unauthorised person gets access to the system.
Some of the ways of restricting physical access include:
Locking of doors.
Use of personal identification cards.
Use of fingerprint identification.
Use of special voice-recorders. They analyse the voice of a
trespasser & checks against the database containing the voice
patterns of valid users.
b) Password protection.
Install a password to restrict access to the computer system.
A Password is a secret code that can be used to prevent unauthorised
access of data in a computer.
Passwords can be put in at various levels:
At the point of switching on the computer – to restrict access to the
computer.
On folders/directories – to restrict access to entire
folders/directories.
On files – to restrict access to individual files within a directory.
On database systems – to restrict access to individual data elements.
When a valid password is entered, the user gets access to the
computer system. Usually, the user is allowed three (3) attempts to
get the password correct. If an invalid password is entered, access is
denied after the 3 attempts.
Some computer security systems may generate an alarm if someone
tries to use a fake password.
NB: You should never use passwords that can easily be linked to you,
e.g., your name, birth date, or names of people close to you.
Review Questions
1. State and discuss four causes of data loss in a computer system.
2. (a) Discuss two methods used to restrict unauthorised access to computer
systems.
(b) What is a Password? Give its main importance.
FACTORS TO CONSIDER IN CHOOSING HARDWARE
1. Hardware configurations/specifications
CPU-central processing unit
RAM –random access memory
HD- Hard Disk
FDD – Floppy Disk Drive
Printer:
UPS - Uninterruptible power supply unit
Mouse:
Monitors:
Keyboard
Anti glare:- Is a special type of screen that absorbs radiation.
Scanner-translates hard copy to soft copy.
2. Reliability:
This is determined by the rate of breakdown of the hardware it may be
assessed from those who are currently using type of hardware.
3. Simplicity
The architecture of the computer should be simple since simple systems
are probably best for small organization.
4. Ease of Communication
The system i.e. both h/w & s/w should be able to communicate well with
the users. The s/w should be user friendly and the h/w should be the
right size and with good interface facilities.
5. Flexibility
H/w should be able to meet new user requirements as they emerge e.g. It
should be powerful enough to be flexible.
6. Security
It should be able to keep out hackers and other unauthorized users. Its
easier to keep out hackers and other unauthorized user with more
powerful system although security can be a major problem for any
computer system.
7. Cost
The h/w should be cost effective i.e. it should be cheap but offer best
requirements.
8. Change over
Whichever is the choice of the hardware it should help with a smooth
change-over from old to the new system.
9. Net working
The hardware should have networking capability especially if its
purchased by a company own it. This caters for a future organizational
expandability requirements.
10. Software:
The hardware should be capable of running any software that has been
chosen.
SOFTWARE COMPONENTS
User requirements:
The selected software or package should fit user requirement as closely as
possible
Processing time
These involves the responses time e.g. if the response time slow the user
might consider s/w or package as unsuccessful.
Documentation
The software should be accompanied by manual, which is east to understand,
by non-technical person. The manual should not contain technical jargon.
User friendliness:-
The package should be easier to use with clear on screen prompts, menu
driven and extensive on screen help facility.
Controls:
The software should have in-built controls which may include password
options, validation checks, audit trail or trace facilities etc.
Up-to datedness:
The software should be up to date e.g. should have changes or corrections in
line with business procedures
Modification:
One should consider whether the software can freely be changed by the user
without violating copyright.
Portability:
One should consider how the s/w runs on the user computer and whether
there will be need for the user to upgrade his hardware.
Cost:
The use company should consider its financial position to establish whether it
can
afford the software required for efficient operations rather than the least cost
packages
s/w available.
Software contracts
Includes the costs, purpose and capacity of the s/w. It describes what it
cannot do the following are covered in s/w contracts:
Warrant terms.
Support available.
Arrangement for upgrades.
Maintenance arrangement.
Delivery period/time for especially written s/w
Performance criteria.
Ownership
Gan Siowck Lee (2000). IT and education in Malaysia: Problems issues and
challenges. Kuala Lumpur: Longman