Securing Information Systems

Slides:



Advertisements
Similar presentations
Lecture 14 Securing Information Systems
Advertisements

Security and Trust in E- Commerce. The E-commerce Security Environment: The Scope of the Problem  Overall size of cybercrime unclear; amount of losses.
E-Commerce Security Issues. General E-Business Security Issues Any E-Business needs to be concerned about network security. The Internet is a “ public.
7.1 Copyright © 2011 Pearson Education, Inc. 7 Chapter Securing Information Systems.
7.1 © 2007 by Prentice Hall 7 Chapter Securing Information Systems.
7.1 Copyright © 2011 Pearson Education, Inc. publishing as Prentice Hall 7 Chapter Securing Information Systems.
Lecture 10 Security and Control.
Lecture 10 Security and Control.
10.1 © 2006 by Prentice Hall 10 Chapter Security and Control.
8.1 © 2007 by Prentice Hall 8 Chapter Securing Information Systems.
8.1 © 2007 by Prentice Hall 8 Chapter Securing Information Systems.
8.1 © 2007 by Prentice Hall 8 Chapter Securing Information Systems.
7.1 © 2007 by Prentice Hall 7 Chapter Securing Information Systems.
Lecture 11 Electronic Business (MGT-485). Recap – Lecture 10 Transaction costs Network Externalities Switching costs Critical mass of customers Pricing.
Misbahuddin Azzuhri SE. MM. CPHR.
Security. If I get 7.5% interest on $5,349.44, how much do I get in a month? (.075/12) = * 5, = $ What happens to the.004? =
Chapter 8 Security and Control.
1.1 © 2007 by Prentice Hall 7 Chapter Securing Information Systems.
10.1 © 2006 by Prentice Hall 10 Chapter Security and Control.
Securing Information Systems
Information Security in Corporation
7.1 © 2007 by Prentice Hall 10 Chapter Securing Information Systems.
CHAPTER 3 Information Privacy and Security. CHAPTER OUTLINE  Ethical Issues in Information Systems  Threats to Information Security  Protecting Information.
PART THREE E-commerce in Action Norton University E-commerce in Action.
7.1 © 2007 by Prentice Hall 7 Chapter Securing Information Systems.
Prepared by: Dinesh Bajracharya Nepal Security and Control.
1.Too many users 2.Technical factors 3.Organizational factors 4.Environmental factors 5.Poor management decisions Which of the following is not a source.
8.1 CSC 601 Management Information Systems Chapter 8 Securing Information Systems.
C8- Securing Information Systems
8.1 © 2007 by Prentice Hall Minggu ke 6 Chapter 8 Securing Information Systems Chapter 8 Securing Information Systems.
Management Information Systems Chapter Eight Securing Information Systems Md. Golam Kibria Lecturer, Southeast University.
1 Class 15 System Security. Outline Security Threats (External: malware, spoofing/phishing, sniffing, & data theft: Internal: unauthorized data access,
Chapter 7 Securing Information Systems. Security & Controls Security: – Policies, procedures, and technical measures used to prevent unauthorized access,
7.1 Copyright © 2011 Pearson Education, Inc. 7 Chapter Securing Information Systems.
C8- Securing Information Systems Facebook Virus Update your Adobe Flash! Security and Control ***
Chapter 7 1Artificial Intelligent. OBJECTIVES Explain why information systems need special protection from destruction, error, and abuse Assess the business.
Information Systems Week 7 Securing Information Systems.
8.1 © 2010 by Prentice Hall 8 Chapter Securing Information Systems.
ESTABLISHING AND MANAGING IT SECURITY Prepared by : Siti Mahani Mahmud Yong Azua Mat Zaliza Azan.
10.1 © 2006 by Prentice Hall 10 Chapter Security and Control.
UNIT V Security Management of Information Technology.
7 Chapter Securing Information Systems 1. The Boston Celtics Score Big Points Against Spyware Problem: frequency of wireless usage exposed Celtics’ proprietary.
8.1 © 2010 by Prentice Hall 7 Chapter Securing Information Systems.
Securing Information Systems
Securing Information Systems
Add video notes to lecture
INFORMATION SYSTEMS SECURITY AND CONTROL.
IT Security and Control
Securing Information Systems
INFORMATION SECURITY The protection of information from accidental or intentional misuse of a persons inside or outside an organization Comp 212 – Computer.
Securing Information Systems
Securing Information Systems
Target Problem 2nd largest retailer in the US, 1797 stores
Securing Information Systems
Securing Information Systems
Risk of the Internet At Home
Week 7 Securing Information Systems
Target Problem 2nd largest retailer in the US, 1797 stores
Securing Information Systems
E-Commerce Security and Fraud Issues and Protections
Securing Information Systems
Chapter 10 Security and Control.
Control , Audit & Security of Information
INFORMATION SYSTEMS SECURITY and CONTROL
Securing Information Systems
Chapter # 3 COMPUTER AND INTERNET CRIME
MIS COURSE: CHAPTER 8 SECURING INFORMATION SYSTEMS
Securing Information Systems
Presentation transcript:

Securing Information Systems Chapter 7 Securing Information Systems

Assess the business value of security and control. Essentials of Business Information Systems Chapter 7 Securing Information Systems STUDENT OBJECTIVES Analyze why information systems need special protection from destruction, error, and abuse. Assess the business value of security and control. Design an organizational framework for security and control. Evaluate the most important tools and technologies for safeguarding information resources.

Demonstrates IT’s role in combating cyber crime. Essentials of Business Information Systems Chapter 7 Securing Information Systems Phishing: A Costly New Sport for Internet Users Problem: Large number of vulnerable users of online financial services, ease of creating bogus Web sites. Solutions: Deploy anti-phishing software and services and a multilevel authentication system to identify threats and reduce phishing attempts. Deploying new tools, technologies, and security procedures, along with educating consumers, increases reliability and customer confidence. Demonstrates IT’s role in combating cyber crime. Illustrates digital technology as part of a multilevel solution as well as its limitations in overcoming discouraged consumers.

Interactive Session: Phishing Essentials of Business Information Systems Chapter 7 Securing Information Systems Phishing: A Costly New Sport for Internet Users Interactive Session: Phishing Discuss suspicious e-mails that members of the class have received: What made you suspicious of a particular e-mail? Did you open the e-mail? Were there any consequences to this action? Did you report the suspicious e-mail to anyone? What measures have you taken to protect yourself from phishing scams?

Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse An unprotected computer connected to the Internet may be disabled within a few seconds Security: policies, procedures and technical measures used to prevent unauthorized access, alteration, theft, or physical damage to information systems Controls: methods, policies, and organizational procedures that ensure the safety of the organization’s assets; the accuracy and reliability of its accounting records; and operational adherence to management standards

Why Systems Are Vulnerable Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Why Systems Are Vulnerable Hardware problems (breakdowns, configuration errors, damage from improper use or crime) Software problems (programming errors, installation errors, unauthorized changes) Disasters (power failures, flood, fires, etc.) Internet vulnerabilities Wireless security challenges

Contemporary Security Challenges and Vulnerabilities Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Contemporary Security Challenges and Vulnerabilities The architecture of a Web-based application typically includes a Web client, a server, and corporate information systems linked to databases. Each of these components presents security challenges and vulnerabilities. Floods, fires, power failures, and other electrical problems can cause disruptions at any point in the network. Figure 7-1

Malicious Software: Viruses, Worms, Trojan Horses, and Spyware Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Malicious Software: Viruses, Worms, Trojan Horses, and Spyware Malware Viruses Worms Trojan horses Spyware Key loggers

Interactive Session: Malicious Software Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Interactive Session: Malicious Software Visit the Web site of Panda Software at www.pandasoftware.com What are the top viruses in terms of rate of infection? What are the latest virus threats? Read descriptions of the top viruses and latest threats What downloads does Panda Software offer to help users protect and repair their computers? Compare and contrast the content available from Panda Software’s Web site with the offerings on Symantec’s Web site, www.symantec.com

Hackers and Cybervandalism Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Hackers and Cybervandalism Hackers vs. crackers Cybervandalism Spoofing Sniffing Denial-of-service (DoS) attack Distributed denial-of-service (DDoS) attack Botnets

Cyber Blackmail and Network Zombies: New Threats from DoS Attacks Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Cyber Blackmail and Network Zombies: New Threats from DoS Attacks Read the Focus on Organizations and then discuss the following questions: What problem faced the companies in this discussion? How did they detect the problem? How did the problem affect their business? What solutions were available to the companies to help solve the problem? What other solutions might they have considered? How did people, organization, and technology issues factor into the problem?

Computer Crime and Cyberterrorism Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Computer Crime and Cyberterrorism Computer crime: “any violations of criminal law that involve knowledge of computer technology for their perpetration, investigation, or prosecution” –U.S. Department of Justice U.S. companies lose $14 billion annually to cybercrime Identity theft (phishing, evil twins, pharming, computer abuse [spamming]) Cyberterrorism and cyberwarfare

Worldwide Damage from Digital Attacks Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Worldwide Damage from Digital Attacks This chart shows estimates of the average worldwide damage from hacking, malware, and spam since 1998. These figures are based on data from mi2G and the authors. Figure 7-3

Internal Threats: Employees Software Vulnerability Essentials of Business Information Systems Chapter 7 Securing Information Systems System Vulnerability and Abuse Internal Threats: Employees Security threats often originate inside an organization Social engineering Software Vulnerability Commercial software contains flaws that create security vulnerabilities Patches

Firms are now more vulnerable than they have ever been Essentials of Business Information Systems Chapter 7 Securing Information Systems Business Value of Security and Control Failed computer systems can lead to a significant or total loss of business function Firms are now more vulnerable than they have ever been A security breach may cut into a firm’s market value almost immediately Inadequate security and controls also bring forth issues of liability

Legal and Regulatory Requirements for Electronic Records Management Essentials of Business Information Systems Chapter 7 Securing Information Systems Business Value of Security and Control Legal and Regulatory Requirements for Electronic Records Management Electronic records management (ERM): policies, procedures, and tools for managing the retention, destruction, and storage of electronic records HIPAA Gramm-Leach-Bliley Act Sarbanes-Oxley Act

Electronic Evidence and Computer Forensics Essentials of Business Information Systems Chapter 7 Securing Information Systems Business Value of Security and Control Electronic Evidence and Computer Forensics Evidence for legal actions often found in digital form Proper control of data can save money when responding to a discovery request Computer forensics: scientific collection, examination, authentication, preservation, and analysis of data from computer storage media for use as evidence in a court of law Ambient data

ISO 17799 Risk assessment Security policy Chief security officer (CSO) Essentials of Business Information Systems Chapter 7 Securing Information Systems Establishing a Framework for Security and Control ISO 17799 Risk assessment Security policy Chief security officer (CSO) Acceptable use policy (AUP) Authorization policies Authorization management systems

Ensuring Business Continuity Essentials of Business Information Systems Chapter 7 Securing Information Systems Establishing a Framework for Security and Control Ensuring Business Continuity Downtime Fault-tolerant computer systems High-availability computing Recovery-oriented computing Disaster recovery planning Business continuity planning Security outsourcing (managed security service providers)

Auditor conducts interviews with key individuals Essentials of Business Information Systems Chapter 7 Securing Information Systems Establishing a Framework for Security and Control The Role of Auditing MIS audit Identifies the controls that govern information systems and assesses their effectiveness Auditor conducts interviews with key individuals Examines security, application controls, overall integrity controls, and control disciplines

Biometric authentication Essentials of Business Information Systems Chapter 7 Securing Information Systems Technologies and Tools for Security Access Control Authentication Tokens Smart cards Biometric authentication

New Solutions for Identity Management Essentials of Business Information Systems Chapter 7 Securing Information Systems Technologies and Tools for Security New Solutions for Identity Management Read the Focus on Technology and then discuss the following questions: What problems were Monsanto, Clarian, and others having with identity management? What was the impact of those problems? What alternative solutions were available? What people, organization, and technology issues had to be addressed in developing solutions? Do you think the solutions chosen are effective? Why or why not?

Firewalls, Intrusion Detection Systems, and Antivirus Software Essentials of Business Information Systems Chapter 7 Securing Information Systems Technologies and Tools for Security Firewalls, Intrusion Detection Systems, and Antivirus Software Firewall: a combination of hardware and software that prevents unauthorized users from accessing private networks Intrusion detection systems monitor hot spots on corporate networks to detect and deter intruders Antivirus and antispyware software checks computers for the presence of malware and can often eliminate it as well

A Corporate Firewall Essentials of Business Information Systems Chapter 7 Securing Information Systems Technologies and Tools for Security A Corporate Firewall The firewall is placed between the firm’s private network and the public Internet or another distrusted network to protect against unauthorized traffic. Figure 7-6

Securing Wireless Networks Essentials of Business Information Systems Chapter 7 Securing Information Systems Technologies and Tools for Security Securing Wireless Networks WEP security can be improved by using it with VPN technology Wi-Fi Alliance/Wi-Fi Protected Access (WPA) specifications Extensible Authentication Protocol (EAP) Protection from rogue networks

Interactive Session: Securing Wireless Networks Essentials of Business Information Systems Chapter 7 Securing Information Systems Technologies and Tools for Security Interactive Session: Securing Wireless Networks Do you use wireless technology? If so, what kinds of information do you transmit over the wireless network? What kinds of information do you avoid sending over the wireless network? What are your concerns related to sending these kinds of information? If you do not have access to a wireless network, is it by choice due to security concerns?

Encryption and Public Key Infrastructure Essentials of Business Information Systems Chapter 7 Securing Information Systems Technologies and Tools for Security Encryption and Public Key Infrastructure Encryption: transforming text or data into cipher text that cannot be read by unintended recipients Secure Sockets Layer (SSL) Transport Layer Security (TLS) Secure Hypertext Transfer Protocol (S-HTTP) Public key encryption Digital signature Digital certificate Public key infrastructure (PKI)