Please complete below Information Security Incidents and their impacts as relating to CIA?
is that incident is confidentiality, Integrity or Avablilty?
and how will you address your incident
|
Incident |
CIA area(s) affected |
How you address this issue? |
|
I LOVEYOU Virus |
||
|
If your company Information System accessible intermittently due to heavy traffic |
||
|
You are unable to access ATM machine to withdraw cash |
||
|
You are able to withdraw cash but receipt information is wrong. |
||
|
You are able to access your institute Information System and access your midterm grades but system is very slow. |
||
Brief Introduction to CIA
The CIA triad (also called CIA triangle) is a guide for measures in information security. Information security influences how information technology is used.The measures should protect valuable information, such as proprietary information of businesses and personal or financial information of individual users. Information security teams use the CIA triad to develop security measures.The CIA triad serves as a tool or guide for securing information systems and networks and related technological assets.
The CIA triad is a model that shows the three main goals needed to achieve information security.
These factors are the goals of the CIA triad, as follows:
Confidentiality-
Confidentiality is the protection of information from unauthorized access. This goal of the CIA triad emphasizes the need for information protection. Confidentiality requires measures to ensure that only authorized people are allowed to access the information.
Integrity-
The CIA triad goal of integrity is the condition where information is kept accurate and consistent unless authorized changes are made. It is possible for information to change because of careless access and use, errors in the information system, or unauthorized access and use.n the CIA triad, integrity is maintained when the information remains unchanged during storage, transmission, and usage not involving modification to the information.
Availability-
The CIA triad goal of availability is the situation where information is available when and where it is rightly needed. The main concern in the CIA triad is that the information should be available when authorized users need to access it. Availability is maintained when all components of the information system are working properly. Problems in the information system could make it impossible to access information, thereby making the information unavailable.
INCIDENT -- I LOVE YOU virus
Since the ILY virus is a worm and it's working is that it inflicts damage on the local machine, overwriting random types of files (including Office files, image files, and audio files; however after overwriting MP3 files the virus hides the file), and sends a copy of itself to all addresses in the Windows Address Book used by Microsoft Outlook. So the Confidentiality is compromised. The Integrity is also compromised as well as the avalaiblity of the resources.
On the machine system level, ILY virus relied on the scripting engine system setting (which runs scripting language files such as .vbs files) being enabled, and took advantage of a feature in Windows that hide file extensions by default, which malware authors would use as an exploit. So proper Anti-Virus and disabling scripting would help such a threat.
INCIDENT -- If your company Information System accessible intermittently due to heavy traffic
In this case the heavy traffic can cause the Non-Avalaibility of the resources, but the cause of the Heavy Traffic is to be determined and make sure that it is legitimate. Distributed Denial of Service attacks causes the service to go down due to increase in garbage traffic, in this case the Confidentiality and the Integrity both are compromised.
Since i'm taking into consideration that the company has proper security systems and firewall installed so there is no threat to the Confidentiality Integrity.
The heavy traffic is an issue of load-balancing and no proper failover servers have been installed. I would ask the server manager to build a proper load-balancing architecture which will hold the fail-over machines in order to maintain a distributive network.
INCIDENT -- You are unable to access ATM machine to withdraw cash
Here i would consider that the ATM machine is out of cash and is
unable to provide service.
In this case i would blame the Avalaibility, keeping in mind the
Confidentiality and the Integrity is not compromised.
The ATM manager would have to take responsible of the cash deposit in order to provide a seamless transaction for the customers.
INCIDENT -- You are able to withdraw cash but receipt information is wrong
Here i would consider the malfunction in the system and then would blame the Intergrity, the Confidentiality and the Avalability is not compromised.
As i have mentioned in the Integrity section that it is possible for information to change because of careless access and use, errors in the information system, or unauthorized access and use. So in that case the server manager or anyone incharge to authorize the system should take care that malfunction do not happen.
INCIDENT -- You are able to access your institute Information System and access your midterm grades but system is very slow
Here i would blame the blame the Avalaibility, keeping in mind the Confidentiality and the Integrity is not compromised. I would not consider any Distributed Denial of Service Attack and would probably focus on just network / server lag, due to heavy traffic.
The heavy traffic is an issue of load-balancing and no proper failover servers have been installed, there could be even network connectivity issue so I would ask the server manager to check for the fail-over machines in order to maintain a distributive network and also to see the ISP network is being properly working or not and fix the lag.
Please let me know if i missed anything or any point needs proper explanation.
Thanks
Please complete below Information Security Incidents and their impacts as relating to CIA? is that incident...
Attacks:
Passive – attempt to learn or make use of information from the
system that does not affect
system resources
• Active – attempt to alter system resources or affect their
operation • Insider – initiated by an entity inside the security
parameter
• Outsider – initiated from outside the perimeter
Threat Consequences
Unauthorized disclosure is a threat to confidentiality
•Exposure: This can be deliberate or be the result of a human,
hardware, or software error
•Interception: unauthorized access to...
A new version of the operating system is being planned for installation into your department’s production environment. What sort of testing would you recommend is done before your department goes live with the new version? Identify each type of testing and describe what is tested. Explain the rationale for performing each type of testing. [ your answer goes here ] Would the amount of testing and types of testing to be done be different if you were installing a security...
Task This assessment aims to develop and gauge student understanding of the key topics covered so far by answering the following questions. Answering these questions will help you build some understanding for the next assessment item as well as for the entire subject. It is expected that answers to the assignment questions be succinct (i.e. precise and concise) with all sources of information fully referenced as per APA referencing style. You have to reference the text book and any additional...
The assignment is based on the case information below. While the Gold Coast City Council (GCCC) does exist, the financial data as well as the scenario in this case study are fictitious1, however the context is not. Many businesses and government departments face similar investment decisions in order to remain competitive as well as being more environmentally and socially responsible. The Gold Coast City Transport Strategy 2031 (hereafter ‘the Strategy’) is a plan founded by the City of Gold Coast...
The assignment is based on the case information below. While the Gold Coast City Council (GCCC) does exist, the financial data as well as the scenario in this case study are fictitious1, however the context is not. Many businesses and government departments face similar investment decisions in order to remain competitive as well as being more environmentally and socially responsible. The Gold Coast City Transport Strategy 2031 (hereafter ‘the Strategy’) is a plan founded by the City of Gold Coast...
Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...
Below is the information:
It is important to understand the different leadership styles employed by nursing leaders in healthcare organizations and to understand their significance on nursing practice and patient outcomes, for better or for worse. Objective: Read the articles from Nursing Standard (PDF) and Bradley University (PDF). In -250 words, formulate an opinion on the following: 1. Reflect on an occasion where you experienced ineffective leadership (doesn't have to be in the hospital). What behaviors did they display? What...
Please see the articles below… 1. What is your opinion on the subject? 2. Which ethical views (i.e., utilitarian view, moral rights view, justice view, practical view) you feel are being used by both sides of the argument (i.e., for and against downloading) to justify their positions? High Court Enters File-Sharing Spat; Justices Must Determine Software Providers' Liability For Copyright Violations by Anne Marie Squeo. Wall Street Journal. (Eastern edition). New York, N.Y.: Mar 30, 2005. pg. A.2 WASHINGTON -- The Supreme...
10. The Beck & Watson article is a
Group of answer choices
quantitative study
qualitative study
11. Beck & Watson examined participants' experiences and
perceptions using what type of research design?
Group of answer choices
particpant obersvation
phenomenology
12. Select the participants in the Beck & Watson study
Group of answer choices
Caucasian women with 2-4 children
Caucasian pregnant women
13. In the Beck & Watson study, data was collected via
a(n)
Group of answer choices
internet study
focus group...
14. Select the number of participants in the Beck & Watson
study
Group of answer choices
8
13
22
35
15. Beck & Watson determined their final sample size via
Group of answer choices
coding
saturation
triangulation
ethnography
16.Through their study, Beck & Watson determined
Group of answer choices
after a traumatic birth, subsequent births have no troubling
effects
after a traumatic birth, subsequent births brought fear, terror,
anxiety, and dread
Subsequent Childbirth After a Previous Traumatic Birth Beck, Cheryl...