Question

Please complete below Information Security Incidents and their impacts as relating to CIA? is that incident...

Please complete below Information Security Incidents and their impacts as relating to CIA?

is that incident is confidentiality, Integrity or Avablilty?

and how will you address your incident

Incident

CIA area(s) affected

How you address this issue?

I LOVEYOU Virus  

If your company Information System accessible intermittently due to heavy traffic

You are unable to access ATM machine to withdraw cash

You are able to withdraw cash but receipt information is wrong.

You are able to access your institute Information System and access your midterm grades but system is very slow.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Brief Introduction to CIA

The CIA triad (also called CIA triangle) is a guide for measures in information security. Information security influences how information technology is used.The measures should protect valuable information, such as proprietary information of businesses and personal or financial information of individual users. Information security teams use the CIA triad to develop security measures.The CIA triad serves as a tool or guide for securing information systems and networks and related technological assets.

The CIA triad is a model that shows the three main goals needed to achieve information security.

These factors are the goals of the CIA triad, as follows:

  • Confidentiality
  • Integrity
  • Availability

Confidentiality-

Confidentiality is the protection of information from unauthorized access. This goal of the CIA triad emphasizes the need for information protection. Confidentiality requires measures to ensure that only authorized people are allowed to access the information.

Integrity-

The CIA triad goal of integrity is the condition where information is kept accurate and consistent unless authorized changes are made. It is possible for information to change because of careless access and use, errors in the information system, or unauthorized access and use.n the CIA triad, integrity is maintained when the information remains unchanged during storage, transmission, and usage not involving modification to the information.

Availability-

The CIA triad goal of availability is the situation where information is available when and where it is rightly needed. The main concern in the CIA triad is that the information should be available when authorized users need to access it. Availability is maintained when all components of the information system are working properly. Problems in the information system could make it impossible to access information, thereby making the information unavailable.

INCIDENT -- I LOVE YOU virus

  • CIA area(s) affected --

Since the ILY virus is a worm and it's working is that it inflicts damage on the local machine, overwriting random types of files (including Office files, image files, and audio files; however after overwriting MP3 files the virus hides the file), and sends a copy of itself to all addresses in the Windows Address Book used by Microsoft Outlook. So the Confidentiality is compromised. The Integrity is also compromised as well as the avalaiblity of the resources.

  • Issue Resolution --

On the machine system level, ILY virus relied on the scripting engine system setting (which runs scripting language files such as .vbs files) being enabled, and took advantage of a feature in Windows that hide file extensions by default, which malware authors would use as an exploit. So proper Anti-Virus and disabling scripting would help such a threat.

INCIDENT --  If your company Information System accessible intermittently due to heavy traffic

  • CIA area(s) affected --

In this case the heavy traffic can cause the Non-Avalaibility of the resources, but the cause of the Heavy Traffic is to be determined and make sure that it is legitimate. Distributed Denial of Service attacks causes the service to go down due to increase in garbage traffic, in this case the Confidentiality and the Integrity both are compromised.

Since i'm taking into consideration that the company has proper security systems and firewall installed so there is no threat to the Confidentiality Integrity.

  • Issue Resolution --

The heavy traffic is an issue of load-balancing and no proper failover servers have been installed. I would ask the server manager to build a proper load-balancing architecture which will hold the fail-over machines in order to maintain a distributive network.

INCIDENT -- You are unable to access ATM machine to withdraw cash

  • CIA area(s) affected --

Here i would consider that the ATM machine is out of cash and is unable to provide service.
In this case i would blame the Avalaibility, keeping in mind the Confidentiality and the Integrity is not compromised.

  • Issue Resolution --

The ATM manager would have to take responsible of the cash deposit in order to provide a seamless transaction for the customers.

INCIDENT -- You are able to withdraw cash but receipt information is wrong

  • CIA area(s) affected --

Here i would consider the malfunction in the system and then would blame the Intergrity, the Confidentiality and the Avalability is not compromised.

  • Issue Resolution --

As i have mentioned in the Integrity section that it is possible for information to change because of careless access and use, errors in the information system, or unauthorized access and use. So in that case the server manager or anyone incharge to authorize the system should take care that malfunction do not happen.

INCIDENT -- You are able to access your institute Information System and access your midterm grades but system is very slow

  • CIA area(s) affected --

Here i would blame the blame the Avalaibility, keeping in mind the Confidentiality and the Integrity is not compromised. I would not consider any Distributed Denial of Service Attack and would probably focus on just network / server lag, due to heavy traffic.

  • Issue Resolution --

The heavy traffic is an issue of load-balancing and no proper failover servers have been installed, there could be even network connectivity issue so I would ask the server manager to check for the fail-over machines in order to maintain a distributive network and also to see the ISP network is being properly working or not and fix the lag.

Please let me know if i missed anything or any point needs proper explanation.

Thanks

Add a comment
Know the answer?
Add Answer to:
Please complete below Information Security Incidents and their impacts as relating to CIA? is that incident...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Attacks: Passive – attempt to learn or make use of information from the system that does...

    Attacks: Passive – attempt to learn or make use of information from the system that does not affect system resources • Active – attempt to alter system resources or affect their operation • Insider – initiated by an entity inside the security parameter • Outsider – initiated from outside the perimeter Threat Consequences Unauthorized disclosure is a threat to confidentiality •Exposure: This can be deliberate or be the result of a human, hardware, or software error •Interception: unauthorized access to...

  • A new version of the operating system is being planned for installation into your department’s production...

    A new version of the operating system is being planned for installation into your department’s production environment. What sort of testing would you recommend is done before your department goes live with the new version? Identify each type of testing and describe what is tested. Explain the rationale for performing each type of testing. [ your answer goes here ] Would the amount of testing and types of testing to be done be different if you were installing a security...

  • Task This assessment aims to develop and gauge student understanding of the key topics covered so...

    Task This assessment aims to develop and gauge student understanding of the key topics covered so far by answering the following questions. Answering these questions will help you build some understanding for the next assessment item as well as for the entire subject. It is expected that answers to the assignment questions be succinct (i.e. precise and concise) with all sources of information fully referenced as per APA referencing style. You have to reference the text book and any additional...

  • The assignment is based on the case information below. While the Gold Coast City Council (GCCC)...

    The assignment is based on the case information below. While the Gold Coast City Council (GCCC) does exist, the financial data as well as the scenario in this case study are fictitious1, however the context is not. Many businesses and government departments face similar investment decisions in order to remain competitive as well as being more environmentally and socially responsible. The Gold Coast City Transport Strategy 2031 (hereafter ‘the Strategy’) is a plan founded by the City of Gold Coast...

  • The assignment is based on the case information below. While the Gold Coast City Council (GCCC)...

    The assignment is based on the case information below. While the Gold Coast City Council (GCCC) does exist, the financial data as well as the scenario in this case study are fictitious1, however the context is not. Many businesses and government departments face similar investment decisions in order to remain competitive as well as being more environmentally and socially responsible. The Gold Coast City Transport Strategy 2031 (hereafter ‘the Strategy’) is a plan founded by the City of Gold Coast...

  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

  • Below is the information: It is important to understand the different leadership styles employed by nursing...

    Below is the information: It is important to understand the different leadership styles employed by nursing leaders in healthcare organizations and to understand their significance on nursing practice and patient outcomes, for better or for worse. Objective: Read the articles from Nursing Standard (PDF) and Bradley University (PDF). In -250 words, formulate an opinion on the following: 1. Reflect on an occasion where you experienced ineffective leadership (doesn't have to be in the hospital). What behaviors did they display? What...

  • Please see the articles below… 1.  What is your opinion on the subject? 2.  Which ethical views (i.e.,...

    Please see the articles below… 1.  What is your opinion on the subject? 2.  Which ethical views (i.e., utilitarian view, moral rights view, justice view, practical view) you feel are being used by both sides of the argument (i.e., for and against downloading) to justify their positions? High Court Enters File-Sharing Spat; Justices Must Determine Software Providers' Liability For Copyright Violations by Anne Marie Squeo. Wall Street Journal. (Eastern edition). New York, N.Y.: Mar 30, 2005. pg. A.2 WASHINGTON -- The Supreme...

  • 10. The Beck & Watson article is a Group of answer choices quantitative study qualitative study...

    10. The Beck & Watson article is a Group of answer choices quantitative study qualitative study 11. Beck & Watson examined participants' experiences and perceptions using what type of research design? Group of answer choices particpant obersvation phenomenology 12. Select the participants in the Beck & Watson study Group of answer choices Caucasian women with 2-4 children Caucasian pregnant women 13. In the Beck & Watson study, data was collected via a(n) Group of answer choices internet study focus group...

  • 14. Select the number of participants in the Beck & Watson study Group of answer choices...

    14. Select the number of participants in the Beck & Watson study Group of answer choices 8 13 22 35 15. Beck & Watson determined their final sample size via Group of answer choices coding saturation triangulation ethnography 16.Through their study, Beck & Watson determined Group of answer choices after a traumatic birth, subsequent births have no troubling effects after a traumatic birth, subsequent births brought fear, terror, anxiety, and dread Subsequent Childbirth After a Previous Traumatic Birth Beck, Cheryl...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT