click below
click below
Normal Size Small Size show me how
IS1106
Week4
| Term | Definition |
|---|---|
| Social Engineering | Manipulating people into revealing confidential data or giving access |
| Denial of Service Attacks | Flooding a system or website with traffic to make it unavailable |
| Backdoor Access | Using hidden access points to bypass security |
| Malicious Software | Software designed to destroy systems or steal data |
| Internal threats | Breaches caused by staff or insiders |
| Lack of security can cause: | Loss of revenue Lowered market value Legal Liability |
| Business Impact Analysis | Determines level of risk to firm if specific activity or process is not properly controlled |
| Security Policy | Defines rules and procedures for data protection, access control and acceptable use |
| Security Audit | Examines firm's overall security environment Lists and ranks all control weaknesses and estimates probability of their occurrence |
| Access and Communication controls | Policies and procedures to prevent improper access to systems by unauthorized insiders/outsiders |
| Whitelisting | A security process where an organisation identifies and approves specific software, applications, or websites that are allowed to run on its computers. |
| Blacklisting | A process where everything is allowed to run except items explicitly identified as dangerous or unapproved |
| Business Contingency Planning | A procedure to recover from a disaster and continue essential business operations |