Chapter 8: Securing Information Systems Flashcards Preview

Computer Information Systems 5620 > Chapter 8: Securing Information Systems > Flashcards

Flashcards in Chapter 8: Securing Information Systems Deck (67)
Loading flashcards...
1
Q

Acceptable Use Policy (AUP)

A

Defines acceptable uses of the firm’s information resources and computing equipment, including desktop and laptop computers, wireless devices, telephones, and the Internet, and specifies consequences for noncompliance.

2
Q

Antivirus Software

A

Software designed to detect, and often eliminate, computer viruses from an information system.

3
Q

Application Controls

A

Specific controls unique to each computerized application that ensure that only authorized data are completely and accurately processed by that application.

4
Q

Authentication

A

The ability of each party in a transaction to ascertain the identity of the other party.

5
Q

Biometric Authentication

A

Technology for authenticating system users that compares a person’s unique characteristics such as fingerprints, face or retinal image, against a stored set profile of these characteristics.

6
Q

Botnet

A

A group of computers that have been infected with bot malware without users’ knowledge, enabling a hacker to use the amassed resources of the computers to launch distributed denial-of-service attacks, phishing campaigns or spam.

7
Q

Bugs

A

Software program code defects.

8
Q

Business Continuity Planning

A

Planning that focuses on how the company can restore business operations after a disaster strikes.

9
Q

Click Fraud

A

Fraudulently clicking on an online ad in pay per click advertising to generate an improper charge per click.

10
Q

Computer Crime

A

The commission of illegal acts through the use of a computer or against a computer system.

11
Q

Computer Forensics

A

The scientific collection, examination, authentication, preservation, and analysis of data held on or retrieved from computer storage media in such a way that the information can be used as evidence in a court of law.

12
Q

Computer Virus

A

Rogue software programs that attaches itself to other software programs or data files in order to be executed, often causing hardware and software malfunctions.

13
Q

Controls

A

All of the methods, policies, and procedures that ensure protection of the organization’s assets, accuracy and reliability of its records, and operational adherence to management standards.

14
Q

Cybervandalism

A

Intentional disruption, defacement, or destruction of a Web site or corporate information system.

15
Q

Cyberwarfare

A

State-sponsored activity designed to cripple and defeat another state or nation by damaging or disrupting its computers or networks.

16
Q

Deep Packet Inspection (DPI)

A

Technology for managing network traffic by examining data packets, sorting out low-priority data from higher priority business-critical data, and sending packets in order of priority.

17
Q

Denial-of-Service (DoS) Attack

A

Flooding a network server or Web server with false communications or requests for services in order too crash the network.

18
Q

Digital Certificates

A

An attachment to an electronic message to verify the identity of the sender and to provide the receiver with the means to encode a reply.

19
Q

Disaster Recovery Planning

A

Planning for the restoration of computing and communications services after they have been disrupted.

20
Q

Distributed Denial-of-Service (DDoS) Attack

A

Numerous computers inundating and overwhelming a network from numerous launch points.

21
Q

Downtime

A

Period of time in which an information system is not operational.

22
Q

Drive-By Download

A

Malware that comes with a downloaded file a user intentionally or unintentionally requests.

23
Q

Encryption

A

The coding and scrambling of messages to prevent their being read or accessed without authorization.

24
Q

Evil Twin

A

Wireless networks that pretend to be legitimate to entice participants to log on and reveal passwords or credit card numbers.

25
Q

Fault-Tolerant Computer Systems

A

Systems that contain extra hardware, software, and power supply components that can back a system up and keep it running to prevent system failure.

26
Q

Firewall

A

Hardware and software placed between an organization’s internal network and an external network to prevent outsiders from invading private networks.

27
Q

General Controls

A

Overal control environment governing the design, security, and use of computer programs and the security of data files in general throughout the organization’s information technology infrastructure.

28
Q

Gramm-Leach-Blilely Act

A

Requires financial institutions to ensure the security and confidentiality of customer data.

29
Q

Hacker

A

A person who gains unauthorized access to a computer network for profit, criminal mischief, or personal pleasure.

30
Q

High-Availability Computing

A

Tools and technologies, including backup hardware resources, to enable a system to recover quickly from a crash.

31
Q

HIPAA

A

Law outlining rules for medical security, privacy, and the management of health care records.

32
Q

Identity Management

A

Business processes and software tools for identifying the valid users of a system and controlling their access to system resources.

33
Q

Identity Theft

A

Theft of key pieces of personal information, such as credit card or Social Security numbers, in order to obtain false credentials.

34
Q

Intrusion Detection Systems

A

Tools to monitor the most vulnerable points in a network to detect and deter unauthorized intruders.

35
Q

Keyloggers

A

Spyware that records every keystroke made on a computer to steal personal information or passwords or to launch Internet attacks.

36
Q

Malware

A

Malicious software programs such as computer viruses, worms, and Trojan horses.

37
Q

Managed Security Service Providers (MSSPs)

A

Company that provides security management services for subscribing clients.

38
Q

MIS Audit

A

Identifies all the controls that govern individual information systems and assesses their effectiveness.

39
Q

Online Transaction Processing

A

Transaction processing mode in which transactions entered on-line are immediately processed by the computer.

40
Q

Password

A

Secret word or string of characters for authenticating users so they can access a resource such as a computer system.

41
Q

Patches

A

Small pieces of software to repair the software flaws without disturbing the proper operation of the software.

42
Q

Pharming

A

Phishing technique that redirects users to a bogus Web page, even when an individual enters the correct Web page address.

43
Q

Phishing

A

Form of spoofing involving setting up fake Web sites or businesses that ask users for confidential personal data.

44
Q

Public Key Encryption

A

Uses two keys: one shared (or public) and one private.

45
Q

Public Key Infrastructure (PKI)

A

System for creating public and private keys using a certificate authority (CA) and digital certificates for authentication.

46
Q

Recovery-Oriented Computing

A

Computer systems designed to recover rapidly when mishaps occur.

47
Q

Risk Assessment

A

Determining the potential frequency of the occurrence of a problem and the potential damage if the problem were to occur. Used to determine the cost/benefit of a control.

48
Q

Sarbanes-Oxley Act

A

Law passed in 2002 that imposes responsibility on companies and their management to protect investors by safeguarding the accuracy and integrity of financial information that is used internally and released externally.

49
Q

Secure Hypertext Transfer Protocol (S-HTTP)

A

Protocol used for encrypting data flowing over the Internet; limited to individual messages.

50
Q

Secure Sockets Layer (SSL)

A

Enables client and server computers to manage encryption and decryption activities as they communicate with each other during a secure Web session.

51
Q

Security

A

Policies, procedures, and technical measures used to prevent unauthorized access, alteration, theft, or physical damage to information systems.

52
Q

Security Policy

A

Statements ranking information risks, identifying acceptable security goals, and identifying the mechanisms for achieving these goals.

53
Q

Smart Card

A

A credit-card-size plastic card that stores digital information and that can be used for electronic payments in place of cash.

54
Q

Sniffer

A

Type of eavesdropping program that monitors information traveling over a network.

55
Q

Social Engineering

A

Tricking people into revealing their passwords by pretending to rrbe legitimate users or members of a company in need of information.

56
Q

Spoofing

A

Tricking or deceiving computer systems or other computer users by hiding one’s identity or faking the identity of another user on the Internet.

57
Q

Spyware

A

Technology that aids in gathering information about a person or organization without their knowledge.

58
Q

SQL Injection Attack

A

Attacks against a Web site that take advantage of vulnerabilities in poorly coded SQL (a standard and common database software application) applications in order to introduce malicious program code into a company’s systems and networks.

59
Q

Token

A

Physical device similar to an identification card that is designed to prove the identity of a single user.

60
Q

Trojan Horse

A

A software program that appears legitimate but contains a second hidden function that may cause damage.

61
Q

Unified Threat Management (UTM)

A

Comprehensive security management tool that combines multiple security tools, including firewalls, virtual private networks, intrusion detection systems, and Web content filtering and anti-spam software.

62
Q

War Driving

A

Technique in which eavesdropper drive by buildings or pack outside outside and try to intercept wireless network traffic.

63
Q

Worms

A

Independent software programs that propagate themselves to disrupt the operation of computer networks or destroy data and other programs.

64
Q

Why are information systems vulnerable to destruction, error, and abuse?

A

Digital data are vulnerable to destruction, misuse, error, fraud, and hardware or software failure. The Internet is designed to be an open system and makes internal corporate systems more vulnerable to actions from outsiders. Hackers can unleash denial-of-service (DoS) attacks or penetrate corporate networks, causing serious system disruptions. Wi-Fi networks can easily be penetrated by intruders using sniffer programs to obtain an address to access the resources of the network. Computer viruses and worms can disable systems and Web sites. The dispersed nature of cloud computing makes it difficult to track unauthorized activity or to apply controls from afar. Software presents problems because software bugs may be impossible to eliminate and because software vulnerabilities can be exploited by hackers and malicious software. End users often introduce errors.

65
Q

What is the business value of security and control?

A

Lack of sound security and control can cause firms relying on computer systems for their core business functions to lose sales and productivity. Information assets, such as confidential employee records, trade secrets, or business plans, lose much of their value if they are revealed to outsiders or if they expose the firm to legal liability. New laws, such as HIPAA, the Sarbanes-Oxley Act, and the Gramm-Leach-Bliley Act, require companies to practice stringent electronic records management and adhere to strict standards for security, privacy, and control. Legal actions requiring electronic evidence and computer forensics also require firms to pay more attention to security and electronic records management.

66
Q

What are the components of an organization framework for security and control?

A

Firms need to establish a good set of both general and application controls for their information systems. A risk assessment evaluates information assets, identifies control points and control weaknesses, and determines the most cost-effective set of controls. Firms must also develop a coherent corporate security policy and plans for continuing business operations in the event of disaster or disruption. The security policy includes policies for acceptable use and identity management. Comprehensive and systematic MIS auditing helps organizations determine the effectiveness of security and controls for their information systems.

67
Q

What are the most important tools and technologies for safeguarding information resources?

A

Firewalls prevent unauthorized users from accessing a private network when it is linked to the Internet. Intrusion detection systems monitor private networks from suspicious network traffic and attempts to access corporate systems. Passwords, tokens, smart cards, and biometric authentication are used to authenticate system users. Antivirus software checks computer systems for infections by viruses and worms and often eliminates the malicious software, while antispyware software combats intrusive and harmful spyware programs. Encryption, the coding and scrambling of messages, is a widely used technology for securing electronic transmission over unprotected networks. Digital certificates combined with public key encryption provide further protection of electronic transactions by authenticating a user’s identity. Companies can use fault-tolerant computer systems or create high-availability computing environments to make sure that their information systems are always available. Use of software metrics and rigorous software testing help improve software quality and reliability.