Showing posts with label Information. Show all posts
Showing posts with label Information. Show all posts

Friday, January 8, 2016

Data, Information and Knowledge

Data Information and Knowledge
 Hello. Welcome to this part on systems and software development we're going to start to look at some basic concepts for software and systems development that are data information and knowledge.
 What is data?
 data are facts that are unprocessed and unorganized, data can be anything we know like numerical data which are numbers in order to represent for example ages or quantities; we have alphabetic data which is just text to represent names or street names all kinds of text we can find and we have alphanumerical data which is a mixture of numbers and alphabetical data for an address for example which has a name of the street and the number forty in the address. Another data is for example images, photos and pictures that has been digitalized. Audio is also data which can be music or voice recording. We have videos and if we all have it together and we have multiple types of data then we call it multimedia. So this data is unprocessed and unorganized. If we get all these data and we process it, we get information.



 How could we process it?
we can for example organize it, categorize it, classify it, sort it, filter it - to filter out certain data that we don't want to know of, we can contextualize it put into different contexts or make calculations on it for example if we have got lots of data on student's course we can for example puts it into the context of the nationality of the students and look at what are the scores of the students if we put it into the context of nationalities we can also contextualize it for example by sex female and male or we can contextualize it based on the background and studies that students have done and then we can process the information and we can process the data and get information. And we have this information we can make decisions based on this information. Because if we have information we can infer and draw conclusions we can understand what is going on we can understand different things within different contexts and we can make decisions and if we have sufficient information that enables us to make decisions then we have the knowledge so let's look at an example for example again with student's test scores student score is a piece of data and if we calculate the average score of the entire school for example then we have information we have information about the average score of all the students in an entire school and from this information we can infer conclusions and we can make decisions related to the study load, the learning materials and maybe even the quality of the teachers. Another example is a customer's invoice this is data it contains all kinds of data related to the customer so we can take this data and process it, so that we can for example have information on which items have been sold most what sizes of clothes or shoes have been sold most and we can take this information and infer conclusions and make decisions about planning and control of sales inventory or logistics. So we have seen that we have data which is raw and unprocessed facts which can be numbers, letters, text, images, videos, whatever from these data if we process it we filter, contextualize organize or sort or whatever we get information and if we have information and can use this information to infer conclusions we have the knowledge to make decisions. So, these are the basic concepts we are going to work on this module. In the next video we will talk about information systems.



 Information System
  What is an information system? An information system is actually a computerized system composed of people, hardware, software and procedures that work together to collect and store data and process it in such a way that we get information that we can use to take decisions and create knowledge. Data consists of collecting and storing it, organizing it, contextualizing it, sorting it, filtering it... this type of things to calculations everything in order to get information.
  Different parts an information system is composed of.
  First we have hardware. Hardware in an information system is any physical component that can be touched or seen or basically any physical component of a computerized system that you can break, it includes, for example, the computer which has the central processing unit that processes and does all the calculations. It consists of a monitor that you can use to display the information that you have processed from the data, you have a keyboard that permits to input data into the system, a printer for example that allows you to print, a storage service that can store data like hard disks or flash drives, USB sticks and if you have communication devices like for example you can maybe connect your mobile or your tablet or the modems that are connected to the system. So this is all hardware, it's can break, you can touch it and you can see it.
  The other component is data, obviously, because this is an information system and data is the foundation of all the information we can obtain. And its artifacts, the raw and the unprocessed facts that you use to get information. This data is normally stored in databases and that is just a way of storing data on a disk in the form that is readable by the machine.



  The next component is the software. So software compared to hardware is something you cannot see you, cannot touch, and you cannot break it physically. So these are the computer programs. Computer programs are machine readable instructions, that give instructions to the circuitry of the hardware in order to indicate what you to do to process data and get useful information out of it. So as a small example, imagine that we have a web store where we sell products and we want to provide a discount to customers that by something above a hundred dollars. So we say ok we obtain the price of the product from the database then we take that price and we process it in such a way to find out whether it's more than a hundred dollars and if it is we give the client a discount. So this is at a very high level some type of software procedure that indicates to the computer what it is you do in order to process data and give us information.
  The final component is people. People are always needed because if nobody's operating the system, the system is not really useful but these are not only the users, it's also other people that we need in order to operate systems. So for example people that administrate the computers, that install the software and do the updates. We also need people to maintain and the input the data, because if nobody maintains and inputs the data there's no data to process information from. And obviously also support the network of computer. If the computer breaks, it should be fixed. So this is a whole team of people that we need in order to make an information system work. And finally the last component of an information system are the procedures. The procedures actually describe how this hardware, this software, the databases and the data and the people should work together in order to  process the information and produce the preferred output. So this is for example one of the procedure says that if we know that the price is above hundred dollars then the customer gets a discount. This is a very tiny example of a procedure that we can use and describes how we use the hardware, the software, the data and the people in order to obtain the information.


UPValenciaX: ISC101.3x Information Systems and Computer Applications, Part 3: Software Development

Monday, June 1, 2015

Information Security - Evolution

An Introduction to Information Security
  • Information Security in an enterprise is a “well-informed sense of assurance that the information risks and controls are in balance”
  • Aligning information security needs with business objectives must be the top priority.
The History of Information Security
  • The history of information security begins with Computer Security.
  • The need for computer security - that is, the need to secure physical locations, hardware, and software from threats - arose during WWII when the first mainframes, developed to aid computations for communication code breaking, were put to use.
  • Multiple levels of security were implemented to protect these mainframes and maintain the integrity of their data.
  • Access to sensitive military locations, for example, was controlled by means of badges, keys, and facial recognition of authorized personnel by security guards.
  • The growing need to maintain national security eventually led to more complex and more technologically sophisticated computer security safeguards.
  • During these early years, information security was a straightforward process composed pre-dominantly of physical security and simple document classification schemes.
  • The primary threats to security were physical theft of equipment, espionage against the products of the systems, and sabotage.
  • One of the first documented security problems that fell outside these categories occurred in the early 1960s, when a system administrators was working on an MOTD (message of the day) file, and another administrator was editing the password file. A software glitch mixed the two files, and the entire password file was printed on every output file.

Sunday, May 24, 2015

Outsourcing/Offshoring and Cyber Threat - Why and How?

Outsourcing/Offshoring are solutions for lot of issues that businesses face, for example: - Cheaper human resources, - Infrastructure convenience, - Knowledge & skills and - Higher growth potential of businesses. By outsourcing the day to day back-office tasks, the business owner has more time to focus on generating income. However, taking into consideration today’s cyber threats, if cyber security standards are not uniformly upheld by the third party, the outsourcing/offshoring of business processes and supply does not come without risks. Risks of: - Identity theft, - Loss or destruction of sensible information and intellectual property, - Unauthorized access to the network service, - Infection with malicious code etc. Moreover, key risk that many businesses face when outsourcing/offshoring is that they themselves are not aware of what controls and policies should be adhered to by the third party. The real question ponder upon is: - Are financial saving the sole aim of outsourcing or has cyber security been factored into the third party considerations? - Even if cyber security has been taken into account, is it purely from a technical perspective, or has the effect on the overall business value chain been considered?

Outsourcing/offshoring are the realities of today’s businesses and it is essential for the decision makers to do the diligence in terms of risk assessment. Remember, there is always an answer to a problem, and threats to cyber security from outsourcing/offshoring can also be reduced, if not fully mitigated, by implementing various countermeasures. So what is the answer to the Cyber Security risk posed by Outsourcing/Offshoring? - Implement cyber security policies, procedures and guidelines for outsourcing / offshoring arrangements in accordance with the industry best practices i.e. NIST Cyber Security Frameworks, ISO 27K series and also includes risk assessment, threat profiling with respect to vendor / geographical locations respectively. - Ensure to contractually embed the necessary information security, business continuity and privacy controls to ensure continued compliance with internal policy and regulatory burdens. - Consider non-sensitive operational areas to be outsourced/offshored. Don't outsource something just because you don't want to do it. Sometimes there are things you don't want to do but they are important to your core business." Even experienced optimists accept that an information security incident is inevitable as 100% security is unachievable and there is no silver bullet; recognition of a long-term risk based approach is necessary. An example of outsourcing might be the IT support for your network. You may not be able to afford or need a full-time IT person, and it is easier to change to an outsourced provider with the right skill set as your IT needs change.

Sunday, May 10, 2015

Information Security

  • Information Security is an art, not a science, and the mastery of information security requires multi-disciplinary knowledge of a huge quantity of information, experience and skill.
  • Security controls and practices include logging on, using passwords, encrypting vital information, locking doors and drawers, motivating stakeholders to support security, and installing pipes to spray water down on your fragile computers in case of fire.
  • These are means of protection that have no benefits except rarely when adversities occur. Good security is when nothing bad happens, and when nothing bad happens, who needs security.
  • So why do we engage in security?
    Now-a-days we do it because the law says that we must do it; especially if we deal with the personal information of others, electronic money, intellectual property, and keeping ahead of the competition.
  • Information security is no job for perfectionists, because you will almost never be fully successful, and there will always be vulnerabilities that you aren't aware of or that you haven't fixed yet.
  • Therefore, enemy has great advantage over us. It is because he has to find only one vulnerability and one target to attack in a known place, electronically or physically while we must defend from potentially millions of enemies' attacks against all of our assets and vulnerabilities that are no longer in one computer room but are spread all over the world by wire and now by air.
  • It's like playing a game in which you don't know your opponents and where they are, what they are doing, why they are doing it, and are changing the rules as they play.
  • So, you must be highly ethical, defensive, secretive, and cautious about bragging about the great security that you are employing that might tip off the enemy.
  • When working in security, you are in a virtual army defending your employer and stakeholders from their enemies, and from your point of view they will probably think and act irrationally, but from their perspective they are perfectly rational with serious personal problems to solve and gains to be made by violating your security.
  • Most of your work, now, should be assisting potential victims to protect themselves from information adversities and dealing with your smart but often irrational enemies even though you rarely see or even get close to them.
  • Be trustworthy and develop mutual trust among your peers. Your most important objectives are not risk reduction and increased security; they are diligence to avoid negligence, exceeding compliance with all of the laws and standards and auditors, and enablement when security becomes a competitive or a budget issue.
  • To achieve these objectives, you must develop a trusting exchange of the most sensitive security intelligence among your peers in your and other security people's organizations so that you know where your organization stands in protection relative to them.
  • Your personal and ethical performance must be spotless, and you must protect your reputation at all costs.

Tuesday, April 21, 2015

Information Security - CIA - Examples


Examples
The three levels of impact on organizations or individuals should there be a breach of security (i.e. a loss of confidentiality, integrity and/or availability). These levels are defined in FIPS 199:
Low: The loss could be expected to have a limited adverse effect on organizational operations, organizational assets, or individuals. A limited adverse effect means that, for example, the loss of confidentiality, integrity, or availability might
·      Cause degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is noticeably reduced;
·      Result in minor damage to organizational assets;
·      Result in minor financial loss; or
·      Result in minor harm to individuals.
Moderate: The loss could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals. A serious adverse effect means that, for example, the loss might

·      Cause significant degradation in mission capability to an extent and duration that the organization is able to perform its primary functions, but the effectiveness of the functions is significantly reduced;
·      Result in significant damage to organizational assets;
·      Result in significant financial loss; or
·      Result in significant harm to individuals that do not involve loss of life or serious, life-threatening injuries.
High: The loss could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. A severe or catastrophic adverse effect means that, for example, the loss might
·      Cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions;
·      Result in major damage to organizational assets;
·      Result in major financial loss; or
·      Result in severe or catastrophic harm to individuals involving loss of life or serious, life-threatening injuries.


CONFIDENTIALITY Student grade information is an asset whose confidentiality is considered to be highly important by students. In the United States, the Family Educational Rights and Privacy Act (FERPA) regulate the release of such information. Grade information should only be available to students, their parents, and employees that require the information to do their job. Student enrollment information may have a moderate confidentiality rating. While still covered by FERPA, this information is seen by more people on a daily basis, is less likely to be targeted than grade information, and results in less damage if disclosed. Directory information (such as lists of students, faculty, or departmental lists) may be assigned a low confidentiality rating or indeed no rating. This information is typically freely available to the public and published on a school’s Web site.
INTEGRITY Several aspects of integrity are illustrated by the example of a hospital patient’s allergy information stored in a database. The doctor should be able to trust that the information is correct and current. Now suppose that an employee (e.g., a nurse) who is authorized to view and update this information deliberately falsifies the data to cause harm to the hospital. The database needs to be restored to a trusted basis quickly, and it should be possible to trace the error back to the person responsible. Patient allergy information is an example of an asset with a high requirement for integrity. Inaccurate information could result in serious harm or death to a patient and expose the hospital to massive liability.
An example of an asset that may be assigned a moderate level of integrity requirement is a Web site that offers a forum to registered users to discuss some specific topic. Either a registered user or a hacker could falsify some entries or deface the Web site. If the forum exists only for the enjoyment of the users, brings in little or no advertising revenue, and is not used for something important such as research, and then potential damage is not severe. The Web master may experience some data, financial, and time loss.
An example of a low-integrity requirement is an anonymous online poll. Many Web sites, such as news organizations, offer these polls to their users with very few safeguards. However, the inaccuracy and unscientific nature of such polls is well understood.
AVAILABILITY The more critical a component or service, the higher is the level of availability required. Consider a system that provides authentication services for critical systems, applications, and devices. An interruption of service results in the inability for customers to access computing resources and for the staff to access the resources they need to perform critical tasks. The loss of the service translates into a large financial loss due to lost employee productivity and potential customer loss.
An example of an asset that typically would be rated as having a moderate availability requirement is a public Web site for a university; the Web site provides information for current and prospective students and donors. Such a site is not a critical component of the university’s information system, but its unavailability will cause some embarrassment.

An online telephone directory lookup application would be classified as a low-availability requirement. Although the temporary loss of the application may be an annoyance, there are other ways to access the information, such as a hardcopy directory or the operator.


 Lecture Reference:

W. Stallings, “Network Security Essentials: Applications and Standards, Fourth Edition.”

Information Security - Introduction


Information Security
Introduction

1.      Introduction

The requirements of information security within an organization have undergone two major changes in the last several decades.
With the introduction of the computer, the need for automated tools for protecting files and other information stored on the computer became evident. This is especially the case for a shared system, such as a time-sharing system, and the need is even more acute for systems that can be accessed over a public telephone network, data network, or the Internet. The generic name for the collection of tools designed to protect data and to thwart hackers is computer security.
The second major change that affected security is the introduction of distributed systems and the use of networks and communications facilities for carrying data between terminal user and computer and between computer and computer. Network security measures are needed to protect data during their transmission. In fact, the term network security is somewhat misleading, because virtually all business, government, and academic organizations interconnect their data processing equipment with a collection of interconnected networks. Such a collection is often referred to as an Internet, and the term Internet security is used.
There are no clear boundaries between these two forms of security. For example, one of the most publicized types of attack on information systems is the computer virus. A virus may be introduced into a system physically when it arrives on an optical disk and is subsequently loaded onto a computer. Viruses may also arrive over an Internet. In either case, once the virus is resident on a computer system, internal computer security tools are needed to detect and recover from the virus.

1.1.      Computer Security Concepts

The NIST Computer Security Handbook [NIST95] defines the term computer security as
The protection afforded to an automated information system in order to attain the applicable objectives of preserving the integrity, availability, and confidentiality of information system resources (includes hardware, software, firmware, information/ data, and telecommunications).
This definition introduces three key objectives that are at the heart of computer security.
·      Confidentiality: This term covers two related concepts:
o   Data confidentiality: Assures that private or confidential information is not made available or disclosed to unauthorized individuals.
o   Privacy: Assures that individuals control or influence what information related to them may be collected and stored and by whom and to whom that information may be disclosed.
·      Integrity: This term covers two related concepts:
o   Data integrity: Assures that information and programs are changed only in a specified and authorized manner.
o   System integrity: Assures that a system performs its intended function in an unimpaired manner, free from deliberate or inadvertent unauthorized manipulation of the system.
Availability: Assures that systems work promptly and service is not denied to authorized users.
 
These three concepts form what is often referred to as the CIA triad. The three concepts embody the fundamental security objectives for both data and for information and computing services.

1.1.1.     Confidentiality

Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information. A loss of confidentiality is the unauthorized disclosure of information. Confidentiality ensures that the necessary level of secrecy is enforced at each junction of data processing and prevents unauthorized disclosure.
Attackers can thwart confidentiality mechanisms by network monitoring, shoulder surfing, stealing password files, breaking encryption schemes, and social engineering. Users can intentionally or accidentally disclose sensitive information by not encrypting it before sending it to another person, by falling prey to a social engineering attack, by sharing a company’s trade secrets, or by not using extra care to protect confidential information when processing it.
Confidentiality can be provided by encrypting data as it is stored and transmitted, enforcing strict access control and data classification, and by training personnel on the proper data protection procedures.

1.1.2.     Integrity

Guarding against improper information modification or destruction, including ensuring information nonrepudiation and authenticity. A loss of integrity is the unauthorized modification or destruction of information. Integrity is upheld when the assurance of the accuracy and reliability of information and systems is provided and any unauthorized modification is prevented. Hardware, software, and communication mechanisms must work in concert to maintain and process data correctly and to move data to intended destinations without unexpected alteration. The systems and network should be protected from outside interference and contamination.
When an attacker inserts a virus, logic bomb, or back door into a system, the system’s integrity is compromised. This can, in turn, harm the integrity of information held on the system by way of corruption, malicious modification, or the replacement of data with incorrect data. Strict access controls, intrusion detection, and hashing can combat these threats.

1.1.3.     Availability

Ensuring timely and reliable access to and use of information. A loss of availability is the disruption of access to or use of information or an information system. Network devices, computers, and applications should provide adequate functionality to perform in a predictable manner with an acceptable level of performance. They should be able to recover from disruptions in a secure and quick fashion so productivity is not negatively affected. Necessary protection mechanisms must be in place to protect against inside and outside threats that could affect the availability and productivity of all business-processing components.
Ensuring the availability of the necessary resources within an organization sounds easier to accomplish than it really is. For example, Networks have so many pieces that must stay up and running (routers, switches, DNS servers, DHCP servers, proxies, firewalls). Software has many components that must be executing in a healthy manner (operating system, applications, antimalware software). There are environmental aspects that can negatively affect an organization’s operations (fire, flood, HVAC issues, electrical problems), potential natural disasters, and physical theft or attacks. An organization must fully understand its operational environment and its availability weaknesses so that the proper countermeasures can be put into place.

1.1.4.     Authenticity

Authenticity is the property of being genuine and being able to be verified and trusted; confidence in the validity of a transmission, a message, or message originator. This means verifying that users are who they say they are and that each input arriving at the system came from a trusted source.

1.1.5.     Accountability – Nonrepudiation

Accountability is the security goal that generates the requirement for actions of an entity to be traced uniquely to that entity. This supports nonrepudiation, deterrence, fault isolation, intrusion detection and prevention, and after-action recovery and legal action. Because truly secure systems are not yet an achievable goal, we must be able to trace a security breach to a responsible party. Systems must keep records of their activities to permit later forensic analysis to trace security breaches or to aid in transaction disputes.
The following provides a short list of some of these controls and how they map to the components of the CIA triad:
·      Confidentiality
o   Encryption for data at rest (whole disk, database encryption)
o   Encryption for data in transit (IPSec, SSL/TLS, PPTP, SSH)
o   Access control (physical and technical)
·      Integrity
o   Hashing (data integrity)
o   Configuration management (system integrity)
o   Change control (process integrity)
o   Access control (physical and technical)
o   Software digital signing
·      Availability
o   Redundant array of inexpensive disks (RAID)
o   Clustering
o   Load balancing
o   Redundant data and power lines
o   Software and data backups
o   Disk shadowing
o   Co-location and off-site facilities
o   Roll back functions
o   Fail over configurations
 

Lecture Reference:

W. Stallings, “Network Security Essentials: Applications and Standards, Fourth Edition.”