Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Wednesday, November 7, 2007

Principle of information security

For over twenty years information security has held that three key concepts form the core principles of information security: confidentiality, integrity and availability. These are known as the CIA Triad. These are the part of the principles of information security.

The other part of the principle is the risk management. Here is a definition about it by the CISA Review Manual 2006: "Risk management is the process of identifying vulnerabilities and threats to the information resources used by an organization in achieving business objectives, and deciding what countermeasures, if any, to take in reducing risk to an acceptable level, based on the value of the information resource to the organization.”The risk management themselves is an ongoing recurring process. Risk means that something bad will happen which can cause harm.During the risk management the first step is the estimating their value. Conduct a threat assessment, then conduct a vulnerability assessment, and for each vulnerability, calculate the probability that it will be exploited. The next step is the calculating the impact with using qualitative and quantitative analysis. Identify, select and implement appropriate controls. Finally, evaluate the effectiveness of the control measures.

The control is one of the principles and it has three types The first is the administrative controls which consist of approved written policies, procedures, standards and guidelines.The second control is the logical control. They use software and data to monitor and control access to information and computing systems. The third one is the physical which monitor and control the environment of the work place and computing facilities.

Security classification of information. Not all information is equal and so not all information requires the same degree of protection. We have to assess the importance of information. Common information security classification labels used by the business sector are: public, sensitive, private, confidential, and labels used by government are: unclassified, sensitive but unclassified, confidential, secret, top secret.

Access control : access to protected information must be restricted to people who are authorized to access the information.

The cryptography is used by the information security’s technology which transforms the usable information into a form that renders it unusable by anyone other than an authorized user. Cryptography provides information security with other useful applications as well including improved authentication methods, message digests, digital signatures, non-repudiation, and encrypted network communications.

On of the most important principles is the defense in depth. The information must be protected during the motion and during the rest too. Using a defense in depth strategy, should one defensive measure fail there are other defensive measures in place that continue to provide protection. The three types of controls can be used to form the bases upon which to build a defence-in depth-strategy.
You can read more: www. infosecuritylab.com

Information security

The information security is one of the most important and indispensable factors. Today almost every data is on computer CD etc…We have to be very careful with the using of these equipments for reason maybe we do not have idea how people can steal information from us.

Information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction.
Governments, military, financial institutions, hospitals, and private businesses amass much confidential information about their employees, customers, products, research, and financial status. Most of this information is now collected, processed and stored on electronic computers and transmitted across networks to other computers.
That is why it is dangerous. We must have responsibility and be aware!
You can read more: www.infosecuritylab.com

Wednesday, October 24, 2007

New type of spam: loud spam

One of the most annoying factors in our digital mailbox is the spam. Nowadays there is a new form of spam namely the loud spam. This is a new security awareness threatment

Almost every mailing program contains spam-filter. Although much of them is quite week and we get almost every spam mail, although the others are too safety therefore we can not get those e-mails which would be important.

Now, there is a new spam type which contains mp3 file and when you play it, a robot’s speaker encourages buying shares on the stock exchange. First the sound tells you the advantages of this share then it spells you the code of the stock. The better spam-filters can sift out these mails.
You can read more: www.infosecuritylab.com

Thursday, October 4, 2007

Social networks and the information security

Nowadays we live in the social networking time. There are so many internet site, where if we register, we can find our friends and that people who we know. The main point of these pages: we can make contact with those people who we already knew. We can get some information about them, what they are working, where they are living, what they like doing in their free times, etc… In case of inform in these sites we just give our data (name, job, schools, telephone number, address, etc) and those people who we know can see it.

But many times you do not need to be registered for seeing other’s data, and you just give these information to other’s hand. But you never know who will misuse with these information. So many people on these sites trust in the data security. There are many people who publicize their personal data and their very near photos.

Some adepts are concerned about the data trail that people are routinely leaving behind them on social networking and other sites. Others believe that personal content will become accessible for marketing and other purposes. For instance the police use these programs for finding criminals. If you want to be safe do not give your address, phone number and those things with that others can misuse.

When we talk about information security awareness, these things are very important, too. It is not just about the computer viruses and hackers, or “look after your credit card” things. Having our personal data in safe is one of the most important security awareness.


You can read more: www.infosecuritylab.com

Friday, September 28, 2007

What bacn is?

Bacn is not a spam but isn’t exactly a personal message either. It is only a mail that we plan to read, because we are interested in it but not right now. Your electronic phone bill is bacn. Your Google alerts are bacn. When you just get a message: “George has admitted you!” These messages about another message are important for us but usually we do not read them.

The “bacn” name was born at a Podcamp2 conference in Pittsburgh. The bacon and the uninvited mails came up in the same conversation. This name was sticked on these mails when somebody mentioned the Canadian bacon’s other name is “peameal bacon”. It sounds similar to “e-mail bacon”.

The most important question is: how can we live with it? We are able to prohibit getting such mails, but otherwise we are just late for so many information. Professional users program scripts which can select the mails. Maybe this is the best way. Specialists say: the e-mail programs will be able to select the messages.

By the time it is not realized we have to switch the messages to other map.

More info: http://www.infosecuritylab.com/news.php?n_cat=2&n_id=200709171437163

If you are interested in this theme, just visit:

www.infosecuritylab.com



Wednesday, September 26, 2007

The virus hoax

The hoax is a false email message which warns the recipient of a virus. The message usually serves as a chain e-mail that tells the recipient to send it to everyone you know.
Most hoaxes are easily identified by the fact that they say the virus will make damage in your PC.
Virus hoaxes are usually harmless and just than annoy people. They just know it's a hoax or waste the time of people who forward the message. However there are so many hoaxes which just call people’s attention to if they delete the program, the computer will have damaged.
Hoaxes are not the same as computer pranks. Computer prank is a program that performs unwanted and annoying actions on a computer, like randomly move the mouse.
The anti-virus specialists advice: we should delete virus hoaxes instead of forwarding them. For example, McAfee says: "We are advising users who receive the email to delete it and DO NOT pass it on as this is how an email HOAX propagates.”
If you want to get more information about this topic,just visit:

Tuesday, September 25, 2007

Computer attackers

Computer virus is a computer program that can copy itself and infect a computer without permission or knowledge of the user. The original may modify the copies or the copies may modify themselves, as occurs in a metamorphic virus. It can spread from one computer to another by help of network connection or carrying it on a removable medium such as floppy disk, CD, DVD, USB drive or by the Internet. But viruses are not equal to computer worms and Trojan horses. A worm can spread itself to other computers without being transferred as a part of a host, and a Trojan horse is a file that appears harmless until executed.
Many PCs are now connected to the Internet and/or to local area networks. Today's viruses may also take advantage of network services (World Wide Web, e-mail, file sharing systems). Some viruses are programmed to damage the computer by damaging programs, deleting files, or reformatting the hard disk. Others are harmless, but simply replicate themselves and make their presence known by presenting text, video, or audio messages. Although these viruses are not dangerous, they can create problems for the computer user. As a result they often cause erratic behavior and can result in system crashes. In addition, many viruses are bug-ridden, and these bugs may lead to system crashes and data loss.

Wednesday, September 19, 2007

Internet privacy

Internet privacy consists of privacy over the media of the Internet: the ability to control what information one reveals about oneself over the Internet, and to control who can access that information. Many people use the term to mean universal internet privacy: every user of the internet possessing internet privacy.
Internet privacy is the part of computer privacy. So many experts of internet privacy have the same opinion that internet privacy does not really exist. Privacy advocates believe: it should exist.
Those people who use internet casually don’t need achieve total anonymity. Regular internet users have to take care of privacy. You never know who can misuse your personal information. So many people desire much stronger privacy. In that case, they may use Internet anonymity to ensure privacy.

Monday, September 17, 2007

Save your data!

Nowadays we keep almost every data on our PC. Our e-mails, wedding photos, family videos or the photos of your baby’s first birthday, etc… You never know who will break into your home, steal the computer and in this way you lose your memories.
For this reason, it’s very important to save your data on another media source. But not just private data, business data, too. In big companies it is done automatically but in little ones it is not such general practice. Therefore, you have to keep in mind data saving. Maybe you say: “I have a very serious alarm system. Nobody can break into it!” But you are not only threatened by criminals. Anything can happen such as a blackout or a virus or something which can destroy your database. Ahead of damage you have to save everything on a CD/DVD or some other form such as an external harddrive.

Friday, September 14, 2007

Satellite scrutinizing- eyes in the sky

These days, there are many movies in Hollywood where people experience films where the central figure is observed by the FBI via satellites. We can say that: “Oh, it is only a film! It is no more than fantasy!” But it is apparent that this is not so unjustified. Just take one of the satellite navigation equipments which are used by us everyday in our car. We just write down where we want to reach and this little tool navigates us to our destination. It knows exactly where you are. This is the reason why it can say to you: “Turn left after 10 meters!”
In addition, there is the Google Earth application. We are able to look for our house or our favorite restaurant. When you use such applications you are limited. You are not able to zoom so much, but there are establishments who can look what is the number-plate of your car or what color underwear you wear.


After the cold war, the American military scout satellites were not shutdown. Perhaps they are in use to monitor everything. Those people, animals or subjects, who carry such a suitable appliance, are observed by GPS everywhere in the world.

How can you make sure when you are walking on the street, you are not watched?