0% found this document useful (0 votes)
21 views5 pages

Computer Security: Threats & Measures

The document discusses the importance of computer security for organizations that rely on data processing, highlighting the need to protect data from various security threats such as viruses, unauthorized access, theft, and environmental hazards. It outlines specific security measures to combat these threats, including the use of anti-virus software, passwords, data encryption, and physical safeguards like fire extinguishers and security personnel. The document emphasizes the necessity of implementing comprehensive security protocols to ensure the integrity and safety of computer systems and data.

Uploaded by

Alice Akello
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views5 pages

Computer Security: Threats & Measures

The document discusses the importance of computer security for organizations that rely on data processing, highlighting the need to protect data from various security threats such as viruses, unauthorized access, theft, and environmental hazards. It outlines specific security measures to combat these threats, including the use of anti-virus software, passwords, data encryption, and physical safeguards like fire extinguishers and security personnel. The document emphasizes the necessity of implementing comprehensive security protocols to ensure the integrity and safety of computer systems and data.

Uploaded by

Alice Akello
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

COMPUTER SECURITY

1.1 Meaning and Importance

Most organisations and some businesses use computers to process data. Organisations store a lot of
data in the computers, and such data are very vital for their operations. In most cases, data does not
originate where it is processed, and so it has to be collected at the origin and transmitted to where it is
processed. In some cases, the result is also transmitted to an end user in a different location. These
situations give rise to data transmission.
Data stored in the computer and data on transmission, both need to be protected against the security
threats, such as unauthorised access and damage, to which they are vulnerable. Organisations must
therefore adopt measures to safeguard the computer, its related equipment, and data, from the risk of
these threats. Such security threats mostly include computer crimes, accidents, terrorism, sabotage,
environmental hazards, and natural calamities. The elements to be protected include computer hardware,
software, data, storage media, transmission equipment, and personnel, and extend to include buildings,
power supply, the policies of an organisation, etc.
Measures designed to combat such threats have to be put in place for an organisation to run smoothly.

1.2 Security Threats

Computer Crimes

(a) Spread of Viruses


A computer virus is a computer program which is designed to automatically replicate and be passed
from one computer to another to perform that illicit function for which it is intended. Such programs
are developed by unscrupulous computer experts with selfish motives. They can be introduced into
the computer system of an organisation or an individual from internal or external sources.

Possible sources of viruses are:


 Pirated software
 Free software
 Shared software
 Data transmission on the Internet
 Data transmission on a network (LAN or WAN)
 Sharing of removable secondary storage media e.g. diskette, CD, flash memory.
 Sabotage. An employee or an outsider intentionally infecting a computer.

Typical symptoms of viruses are:


 Programs taking too long to load
 Unusual error messages appearing too often automatically
 Programs giving unusual results
 Frequent system crashes
 Changes in sizes of files by files occupying bigger portion of the storage space
 Changes in the dates of files
 Corrupted program and data files

(b) Unauthorised Access


This can take the form of hacking, electronic eavesdropping, or cracking.
Computer hacking refers to the act of gaining unauthorised access to data stored on a computer
storage medium. In a nutshell, it is theft of computer data.
Electronic eavesdropping refers to the unauthorised tapping of information along a communication
line over which computer data and messages are transmitted.
Computer cracking, also called supper zapping, refers to the act of developing a way of by-passing or
breaking into the controls built in a program or the system software which is built to limit access to the
information stored in the computer.

(c) Theft
Computer hardware, storage media and related equipment are usually vulnerable to acts of theft and
burglary. This threat usually comes from outside, but sometimes comes from inside in the form of
vandalism. This poses a threat as it can lead to loss of hardware and valuable data.

(d) Software Piracy


This refers to the unauthorised copying or duplication of computer software without permission from
the developer. It constitutes a breach of the copyright law which aims at protecting the intellectual
property right.
Though illegal, computer software piracy is very rampant due to some of the following reasons:
 Computer software is generally very expensive for most users.
 Lack of tough legislation on computer software piracy.
 Lack of goodwill on the side of law enforcement.

(e) Fraud
The computer has on some occasions been used to commit financial fraud by involving in illegal
financial transactions such as theft, money laundering, and illegal transfer of property.

(f) Alteration of Data


Systems which are compromised by not having security measures in place may have the data stored
easily altered. For example someone breaking into a banking system to illegally change account
details or transfer money, or breaking into a payroll system to change payment details, or a student
breaking into a system to alter examination results.

(g) Sabotage
This refers to the intentional act of paralysing a computer system or communication network. Acts of
sabotage are usually carried out secretly. They pose great risks to governments, organisations or
even individuals. Communication lines can be cut, magnets can be used to destroy or alter data
stored on magnetic storage media, storage media can be infected by viruses, access to computers,
data or devices can be locked using passwords by disgruntled employees, fire can be set by
arsonists, bombs can be planted, etc.

Environmental Hazards
This refers to those external problems around the computer system and related equipment. In most cases,
computers are installed in buildings which were not originally designed for them. This makes computer systems
more vulnerable to environmental hazards. These hazards may include; water leakage through the roof, dust
from outside, external radiation usually through the window, high humidity, high temperature, power blackout,
power brownout (temporary fluctuations in power supply), presence of magnetic fields created by electric
motors in the vicinity, poor ventilation and poor lighting system for users, etc.

Natural Calamities
Computer installations have on some occasions been destroyed by natural catastrophes like floods,
cyclones, hurricanes, lightning, earthquakes, tremors, etc. These natural disasters pose a serious threat
to computer hardware and communication equipment. Therefore areas prone to natural disasters should
be avoided when choosing sites for computer installations.

Fire Outbreak
Fire outbreak usually results from an electrical fault or by an act of arson. Whatever the cause, by itself
fire is a real problem since it causes physical damage to the system as a whole, and also to extinguish
fire is another problem because water which is the most commonly used can cause damage to computer
hardware and storage media, while carbon-dioxide may endanger the life of any human user trapped in
the computer room. The best fire extinguishers which should be installed which are friendly to both
hardware and live ware are expensive e.g. halon.

1.3 Security Measures

Spread of computer viruses:


To combat the spread of computer viruses, the following measures can be used:
 Anti-virus software should be installed in the computer. Such software is designed to detect, locate
and remove viruses from the infected media. Anti-virus software is designed in such a way that
immediately the computer is booted, it automatically gets loaded onto the RAM, and remains resident
there as long as the computer remains on. Since for a virus to infect a storage medium from a source,
it must pass through the RAM, hence the anti-virus resident in the RAM will intercept it there. Since
new viruses keep on coming all the time, the anti-virus software installed on a computer should be
updated regularly, e.g. weekly or monthly, usually through the Internet, to enable it tackle the new
viruses. Some of the anti-virus software in the market are: Norton Anti-virus, McAfee, Dr Solomon’s,
AVG, Kaspersky, Pennicilin, Avast, etc. New ones also keep on coming into the market.
 Avoiding foreign removable media: The use of removable storage media such as diskettes, flash
memories and CDs from outside should not be allowed in the computer room. Similarly, such media
used within the organisation should not be carried out of the computer room.
 Avoiding pirated software: Pirated software should not be allowed to be installed in the computer
room.

Computer hacking:
To combat the spread of computer viruses, the following measures can be used:
 Passwords can be used to limit access to data stored on the computer and also to limit access to the
use of s computer system or its components. A password is an access code which restricts access to
computer data or equipment only to a user who knows it. Hence a password should be known to an
authorised user only. Log on passwords can also be used to limit access to the use of some software.
In addition, passwords should be changed periodically and also passwords should be long by
comprising at least six characters (recommended). Avoid passwords which are easy to guess such
as name initials. Where a high level of security is required, a mixture of letter cases and/or a
combination of letters, digits and symbols should be used.
 Allowing only authorised users to get access to use the computers.
 In case the computer is linked by a telephone line, then the access telephone number of the
computer should not be listed in the internal or external telephone directory
 In case of a remote terminal, then a special key should be used to connect to the terminal on-line.
Such an access key should be known to only the authorised users of such terminals.
 In case of data where there are many users yet a high level of security has to be maintained,
especially databases, passwords with different access levels can be assigned to users depending
on the rank of the user and the level of sensitivity of the data each user handles. Also amending of
records should if possible be centralised and only one person be permitted to amend.
Data backup: Backup or simply duplicate copies of files (user data, documents and software) should be
made and kept elsewhere, preferably in a different geographical location, controlled by a responsible
person. Such backup should be kept in a fireproof safe in an off-site location.
Data encryption: This is the process of encoding information to be transmitted by converting it to a
format that is unreadable or does not make sense to other people unless and until it is made readable by
decoding it back to its original format by the intended recipient using a key.
Audit trails: Periodic audit trails should be carried out to trace the flow of data and transactions through
the system in order to detect any computer crime, especially fraud, which might have been committed
within the system.
Power blackout and brownout or surges:
 Power backup through the installation of a UPS (uninterruptible power supply). A UPS stabilises
power supply by continuing to supply power for a short time after a blackout. In the event of a
blackout, it protects the user from data loss as it enables him to save any document currently open,
backup any data which has been changed, and also to shut down the computer properly. In addition it
combats power fluctuation by supporting a steady and stable supply of power by maintaining a
constant voltage in the supply.
 Installation of an electric power surge protector.
 Installation of an automatic stand-by electric power generator. But since it takes a few seconds before
the generator turns on, during which computers may go off, this should be complemented with a
UPS.
Firewall: This is a part of a computer system or network which is designed to block unauthorised access
while permitting authorised communications. It is a device or set of devices configured to permit, deny,
encrypt, decrypt, or proxy all (in and out) computer traffic between different security domains based on a
set of rules and other criteria. Firewalls can be implemented in either hardware or software or a
combination of both. They are mostly used to prevent unauthorised Internet users from accessing private
networks connected to the Internet, especially intranets. All messages entering or leaving the intranet
pass through the firewall, which examines each message and blocks those which do not meet the
specified security criteria.
Sign in – sign out logs: Everybody entering the computer room should sign a register indicating time in
and time out and the activities performed during the stay. The equipment used should also be indicated.
Burning or shredding of printouts: Where the system produces confidential information and/or deals
with confidential data, the data and output documents should be destroyed after use, e.g. by burning,
cutting using shredders, etc.
Plastic covers: All equipment not in use should be covered by plastic covers. This provides protection
from dust and also from water which may leak through the roof or water which may be used to extinguish
fire in the event of a fire breakout.
Lock and key: The computer room when not in use should be locked. Removable storage media and
devices such as diskettes, compact disks, tapes, flash memory and external hard disks should be locked
preferably in fireproof safes.
Segregation of duties of programmers and data entry clerks. The person responsible for amending
program(s) should if possible be one.
For systems where a high level of security has to be maintained, no individual person or part of the
organisation should be in a position to have available at its disposal all the components or sub-systems
which can be assembled together to make a whole.
Two similar computer systems can be run side by side in parallel in different geographical locations to
give cover to each other.
The computer site should not contain signs which identify it to outsiders.
The system should have adequate recovery facility in place to recover data in case of system
breakdown or in case of any crime or catastrophe which leads to loss of data.
Arrangement: The design of layout or arrangement of computers should be such that no one from
outside can be able to read what is displayed on the screen or any printout from a printer.
To combat fire and burglary, general building safeguards should be put in place. Walls and ceilings of
the building should be constructed from slab. Walls and ceilings should have at least a one hour fire
rating. Also doors and windows should be constructed using burglar-proof steel grill. To combat external
radiation through the window, the computer room should be constructed in such a way that its orientation
is East- West and not North-South.
Fire extinguisher: Installation of a fire extinguisher which should be placed at point where it can easily
be accessed in the event of a fire breakout. This can be supplemented by the installation of smoke/fire
detectors which are designed to trigger an alarm in case fire is detected.
Badges: Use of colour coded badges such as red for programmers, blue for system analysts, and other
colours for other computer staff, with the holder’s name, employment number and photograph, should be
to easily identify authorised personnel and visitors.
Security guards: To combat sabotage, fraud and theft, security guards should be employed and
stationed at the entrance throughout to select and screen the people who are given access to the
computer room, terminals and storage facilities.
If possible, there should be only one entrance into the building with a guard stationed there. All packed
goods into and out of the building should be inspected.

You might also like