Physical safety
Physical safety : related to any danger that would cause a serious
problem or lead to death
Health safety : preventing people from becoming ill or effected by
daily contact with the computer
Prevention Causes Safety risks
Don’t allow liquids in ict rooms Spilling liquid on electric equipment , Electrocution
Check wires on regular basis exposed wires , unsafe equipment ,
Ensure all equipment is checked unsafe electrics
Use RCB
Fire extinguishers Overloaded sockets Fire Hazard
Clean out dust Overheating of equipment
Don’t close cooling vents Exposed wires
Increase number of sockets
Use ducts Trailing wires Tripping hazard
Cover exposed wires Damaged carpets
Use wireless connectivity
Use strong desks Heavy equipment Personal injury
Don’t leave things at the edge Desk collapsing
E-safety
DPA : legislation design to protect How to prevent the data being gained unlawfully :
individuals to prevent incorrect or
inaccurate data 1. Do not leave personal information kept on your desk
2. Do not leave data in the computer monitor , always log out
3. Use passwords that are difficult and change them regularly
Main principles of data protections 4. Make sure that emails don’t contain sensitive data
rules :
1. Data must be fairly and lawfully Personal information
processed
2. Data should only be processed for a Personal data : Sensitive data :
valid reason • Name • Race
3. Data must be relevant • Address or email • Political views
4. Data must be accurate address • Membership of political party
5. Data must not be kept for more • IP • Membership of trade union
time than needed • Date of birth • Religion
6. Data must be processed with data • Banking details • Criminal record
subject rights • Photographs • Medical history
7. Data must be kept secure • DNA
8. Data should not be transferred • Biometric data
How to minimize danger
E-safety
Using internet : Sending and receiving emails: Social media : Online gaming :
Make sure its trusted, Only open emails for known Do not publicly post or give Cyberbullying
https (padlock symbol) sources (don’t download any personal information to people Use of webcams
Don’t purchase unless file unless you make sure ) you don’t know Voice masking
the website is Make sure your ISP is effective Do not send photos to people
encrypted and secure and able to filter emails you don’t know
technology
Make sure the device Only reply if you know the Always make sure to make use of May get data
is set on “safe search” sender privacy settings when posting threats
Use websites Check that the addresses are Its important that your posts Violence in the
recommended by real don’t link to an address game can lead to
trusted sources Think carefully when replying Only make friends with people violent behavior in
Be careful what you with personal information you know real life
download (if its Never send photos Avoid using and forwarding
malware ), its imp to Be aware of phishing messages with inappropriate
run anti-virus and Use a strong password and language
anti-malware and change it on regular basis Block and report any suspicious
keep it up to date Don’t forward any email people , use a nicknames keep
Log put pf sites you Manually type the email your personal data private , stay
have finished from address in public chats not private , never
Its a good idea to make email arrange to meet someone on
groups your own, avoid using messages
Data threats
Hacking Phishing , smishing , vishing Pharming
This is the act of gaining The creator sends out This is a malicious code
unauthorized access to legitimate-looking (also appear installed on a user's computer
a computer system to be trusted) emails to target or on a web server , redirect Smishing
users , as soon as the recipient
the user to a fake website comes with the
• clicks on the link , they are sent same way as
Idenitiy theft , misuse of without their knowledge
to a fake website or fooled into phishing but in a
personal information
giving personal data while
• Data can be deleted , • The creator of the malicious short SMS form ,
replying
changed or corrupted code can gain personal data that contain URL or
• The creator gain personal
from the user while visiting telephone
• Use of firewalls their website
data
• Pharming can lead to fraud or Vishing
• Use of strong • Identity theft
identity theft
password Is another form of
• Use of anti-hacking • ISPs that filter out phishing phishing that uses
• Anti-spyware
software emails voicemail message
• Make sure it’s a trusted
• Use user ID and • Users should be careful to trick
when opening emails website (padlock or https )
passwords
• don’t click on executable
Data threats
Viruses Worms Adware
This is aa program code or Stand alone virus that can self Floods user computer with
software that can copy itself replicate , they do not need an unwanted advertising , usually
with the intention of deleting active host to work , worms in the form of pop ups , that Adware
or editing files they cause the frequently arrive as message frequently appear in the effects :
computer to malfunction attachment , browser address • Highlight
• Viruses cause the Viruses weaknesses in
computer to crash need an Torgan horse security
• The softoware can delete active
host ,
• Be hard to
files or data on the Is a legitimate software that
before Ransomware remove
computer
they can contain malicious • Hijack a browser
• The software can corrupt
actually instructions ,embedded within Programs that encrypt the data
operating system, so the and creates its
computer run slowly run and it that what carry out some on auser computer , a
cause harm to the users computer own requests
harm decryption key is sent back to
• Install anti-virus system pay and amount of money
software Key logging software
• Don’t use softwares
It gathers information by
from unknown users monitoring the users keyboard
• Be careful when activities and capture personal
opening emails from information
unknown senders
Card fraud • Shoulder surfing
Is the illegal use of a credit or debit card • Card cloning
• Key logging software
Shoulder surfing : is a form of data theft were criminals steal personal
information , ways
• Watching key being typed
• Somebody listening in when you're giving your card details
• Tiny digital cameras placed near the ATM
How to overcome this issue :
• Shield the keyboard with your other hand
• Never key in data in public places
• Make sure you’re writing the details near a place with no cameras
Card cloning : is the copying of a credit or debit card (magnetic stripe) this type is
known as skimmer , but the ones with micro chips are known as shimmers
Key logging : detect al, key presses ,
Number , security code ad PIN
Protection Of Data
Biometric
Disadvantages Advantages Biometric technique Intrusive : causing someone to
• Intrusive • Accurate Fingerprint scans feel uncomfortable or asking for
• Can make mistakes , if skin is dirty • Well developed
or damaged • Easy to use information that should not be
• Small storage needed
revealed
• If individuals don’t sign in • Non-intrusive Signature recognition
consistent manner there may be a • Little time to verify
problem • Relatively low cost Signature and voice
• High error
recognition are behavioral
• Intrusive • Accurate Retina scans biometric
• Slow to verify • Can't be replicated
• Very expensive
• Intrusive • Non-intrusive Iris recognition there is some factors that
• Uses a lot of memory • Little time to verify
• Very expensive plays a role in verifying a
Its affected by many factors (age, Non-intrusive Face recognition
face , distance between eyes
• •
light ) • Not expensive , width of the nose , shape
• A person voice can be easily • Non –intrusive Voice recognition of the cheek bones , shape
recorded • Not expensive
• Low accuracy • Little time to verify of eyebrows
• Some factors can change people
voice
Protection of Data
Digital certificates : a pair of files stored in users computer ,to make sure of the Encryption : it makes data meaningless for hackers , it uses
security of the files sent over the internet secret key that makes messages unreadable (cypher script)
• A Public key ( can be accessed by anyone ) unless secret key ( decryption key ) is used , it decodes it
• A Private key ( only the computer user can know )
Digital certificate have six parts : Sender
Encryption key Cypher
• The senders email address Encryption process
• The name of digital certificate owner Decryption process script
• Serial number Plain text
• Expiry data (to make sure its not expired ) Recipient
• Public key
• Digital signature for the certificate Firewalls : can be a software or hardware .it sits between a
the users computer and an external network , a firewall will
SSL ( Secure Socket Layer ) , type of a protocol that allows data to be sent and help to keep potentially destructive forces away by filtering
received securely over the internet. incoming and outgoing network traffic and the criteria for
The user will know that SSL is working when he sees (https ) or small padlock
filtering can be set by the user
Users Firewall (software or
If the hardware ) Internet
The user
browser, After computer
browser The The web
verify the receiving
connects browser send a
certificate the web
with the requests copy of
required the web to the SSL to
it sends a browser Tasks carried out by firewalls :
message starts
website be the
to the web using SSL-
• Examine the traffic between users
that uses identified browser
SSL
to allow encryption • Checks whether in and out data meets criteria
connection
• If it doesn’t match the criteria , the firewall block and give
a warning
Protection of Data
Two-factor authentication : is a form of verification which requires two
methods of authentication to verify who the user is
Authentication : refers to the ability of a user to prove who they are
• Something you know
• Something you have
• Something that is unique for you
User IDs and passwords : passwords are used to restrict access to data or
systems , they should be hard and changed frequently to maintain a high level of
security , how to protect passwords :
• Run anti spam ware software
• Change passwords frequently
• You should make the password strong but easy to remember
• Strong passwords should contain : at least one capital letter , at least one
numerical value , keyboard character
Many systems ask to enter the password twice as a verification check