<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title> CSC 408 Management Information Systems  by Ummi Azhani</title>
      <link>https://padlet.com/azhaniummi19/814j7i869kg9</link>
      <description>Chapter 7/8 Securing Information Systems </description>
      <language>en-us</language>
      <pubDate>2018-12-23 14:47:32 UTC</pubDate>
      <lastBuildDate>2026-01-25 16:58:56 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url>https://padlet-uploads.storage.googleapis.com/344467744/119df43c3f526421e813784f766fddac/MANAGEMENT_INFORMATION_SYSTEM.jpg</url>
      </image>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316559170</link>
         <description><![CDATA[<div><strong>Question 1</strong><br>Briefly explain the following computer crimes.<br>a)<strong> Sniffer<br>&gt;</strong>an eavesdropping program that monitors information travelling over network. It also enables hackers to steal proprietary information such as e-mail, company files, and many more.<br>b) <strong>Phishing</strong><br><strong>&gt;</strong>When cybercriminal try to get sensitive information from you, like credit card numbers and passwords. Some specific techniques include <strong>spear phishing</strong> (targets specific people or departments), <strong>whale phishing</strong> (targets important people like CEOs), and <strong>SMiShing</strong> (phishing via text messages) and <strong>vishing</strong> (voice phishing that takes place over the phone, usually through impersonation)<br>c)<strong>Pharming</strong></div><div><strong>&gt;</strong>When website traffic is redirected to a bogus website, usually an e-commerce or banking site.<br><br><strong>d) Spoofing<br>&gt;</strong>When cybercriminals try to get into your computer by masquerading as a trusted source. Examples include <strong>email spoofing</strong> (using email header that appears to be from someone you trust), <strong>IP spoofing</strong> (using a fake IP address to impersonate a trusted machine) and <strong>address bar spoofing</strong> (using malware to force you to view a specific web page).<br>(8 marks)<br><br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-23 15:05:27 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316559170</guid>
      </item>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316560089</link>
         <description><![CDATA[<div><strong>Question 2 <br></strong> a) Distinguish the <strong>TWO (2) </strong>methods for encrypting network traffic on the Web.  (4 mark)<br><strong>i)Secure Sockets Layer (SSL)</strong> and successor Transport Layer Security (TLS) enables client &amp; server computers to manage encryption &amp; decryption activities; so they communicate with each other during a secure web session. </div><div><strong>ii)Secure Hypertext Transfer Protocol (S-HTTP)</strong> is another protocol used for encrypting data flowing over the Internet, but it is limited to individual messages. </div><div><strong><br></strong>b) Briefly explain the following terms <br><strong>i. Cyber warfare</strong> <br><strong>&gt;</strong>Cyber warfare involves the actions by a nation-state or international organization to attack and attempt to damage another nation's computers or information networks through, for example, computer viruses or denial-of-service attacks. <br><strong>ii. Computer Forensic </strong><br><strong>&gt;</strong> Recovery and investigation of material and legal evidence found in computers and digital storage media used with computers. </div><div> </div><div>(4 marks) </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-23 15:32:21 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316560089</guid>
      </item>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316599733</link>
         <description><![CDATA[<div><strong>QUESTION 3<br> a)Briefly explain these THREE (3) tools.<br> i) Firewall- </strong>a combination of hardware and software that prevents unauthorized users from accessing private networks which technologies include Static packet filtering, stateful inspection, network address translation (NAT)<br><strong>ii)Intrusion detection system-</strong> to monitors hot spots on corporate networks to detect and deter intruders and examines events as they are happening to discover attacks in progress.<br><strong>iii)Antivirus software-</strong> it checks computers for presence of malware and can often eliminate it as well. It requires continual updating. <br><br><strong>b)Contrast between General Controls and Application Controls.</strong><br> <strong>i)General Controls <br></strong>These are policies and procedures that relate to many applications and support the effective functioning of application controls by helping to ensure the continues proper operation of information systems. It governs design, security and use of computer programs and security of data. It basically applies to all computerized applications. Example of the type are implementation controls and software controls.<br><strong>ii)Application Controls<br></strong>Application controls are the controls specific to a particular accounting application. It is a specific control unique to each computerized applications such as payroll or order processing. It includes automated and manual procedures and IPO controls. Example of the type are input and output controls.<br> <br><br><br><br> <br> </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-24 09:17:38 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316599733</guid>
      </item>
      <item>
         <title>QUESTION 4</title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316638348</link>
         <description><![CDATA[<div><strong>Question 4 </strong></div><div>Malicious Software programs are referred to as Malware. Describe <strong>FOUR (4) </strong>types of malicious software. </div><div>(8 marks) </div><div><strong>Virus</strong> – like a virus that can infect a person, a computer virus is a contagious piece of code that infects software and then spreads from file to file on a system. When infected software or files are shared between computers, the virus then spreads to the new host.</div><div>.<br><br></div><div><strong>Spyware</strong> – just like a spy, a hacker uses spyware to track your internet activities and steal the information without you being aware of it. </div><div> </div><div><strong>Worms</strong> – similar to viruses, worms also replicate themselves and spread when they infect a computer. The difference, however, between a worm and a virus is that a worm doesn’t require the help of a human or host program to spread. </div><div> </div><div><strong>Trojan</strong> – like the trojan horse from ancient greek mythology, this type of malware is disguised as a safe program designed to fool users, so that they unwittingly install it on their own system, and later are sabotaged by it. </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-25 09:04:51 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316638348</guid>
      </item>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316638939</link>
         <description><![CDATA[<div>QUESTION 5<br>a) Nowadays securing information systems has become an important issue in organization to protect itself against computer crime. <br><br>Define computer crime and provide an appropriate example.<br> <br>&gt;Computer crime describes a very broad category of offenses. Some of them are the same as non-computer offenses, such as larceny or fraud, except that a computer or the Internet is used in the commission of the crime. Others, like hacking, are uniquely related to computers. Read on to find out what kinds of activities are considered computer crimes and how to prevent them.<br><br>Examples of Computer Crimes<br>•	Using a computer in a scheme to defraud<br>•	Interfering with someone else's computer access or use<br><br> b) Briefly explain <strong>THREE (3) </strong>reasons why information systems are vulnerable to destruction, error and abuse? <br><br>•Communications: Tapping, sniffing, message alternation, theft and fraud, and radiation<br>•Corporate servers: Hacking, viruses and worms, theft and fraud, vandalism, and denial of service attacks<br>•Corporate systems: Theft, copying, or alteration of data, and hardware and software failure.<br><br> c) Discuss the <strong>THREE (3) </strong>most important tools and technology for safeguarding information resources.</div><div>                         </div><div>·         <strong>Firewalls</strong>: A combination of hardware and software that controls the flow of incoming and outgoing network traffic by identifying names, IP addresses, applications, and other characteristics of incoming traffic</div><div>·         <strong>Intrusion detection</strong>: Full-time monitoring tools placed at the most vulnerable points of corporate networks to detect and deter intruders continually. Scanning software looks for patterns indicative of known methods of computer attacks, such as bad passwords, checks to see if important files have been removed or modified, and sends warnings of vandalism or system administration errors</div><div> </div><div>·         <strong>Antivirus</strong>: Software that checks computer systems and drives for the presence of computer viruses and removes or quarantines them. However, antivirus software is effective only against known viruses. That’s why keeping an antivirus program must be kept up to date</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-25 09:28:21 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316638939</guid>
      </item>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316647339</link>
         <description><![CDATA[<div><strong>QUESTION 6<br> a)Identity management software automates the process of keeping track of all information systems users and their system privileges, assigning each user a unique digital identity for accessing each system. Define authentication.</strong></div><div> </div><div>Authentication is the technique by which a system checks the identification of a end User who wants to access it. Since entrance or access control is normally based on the identification of the user who demands access to a resource. Authentication is essential to effective security. <br> <br><strong>b)Four types of authentication technologies are<br> i)Password Based Technologies </strong>which isthe most common form of authentication. Password may be of any form (String of alphabets, numbers and special characters). This password is necessarily to be known by the entity or the thing or a person that is being authenticated.</div><div><strong>ii)E-Token Based Technologies</strong> which is a small device that develop/generates a new odd/random value every time it is used. This random value becomes the basis for authentication (an alternative to a password). It can be implemented on a USB key fob or on a smart card. Data is protected on the device itself.<br> <strong>iii)Biometric Based</strong> Technologies which is an authentication mention to the realization/recognition/identification of humans by their personality/characteristics such as Face, fingerprint, human voice, Retina, Iris pattern of the eye, vein pattern etc. It's used in computer science as a form of realization/recognition and access control. <br> <strong>iv)Two Factor Authentication</strong> also known as multi-step verification, which adds another layer of security, supplementing the username and password model with a code that only a specific user has access to (typically sent to something they have immediately to hand). </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-25 15:37:36 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316647339</guid>
      </item>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316647470</link>
         <description><![CDATA[<div><strong>QUESTION 7 <br> a)Describe ransomware. </strong></div><div><strong> </strong>Ransomware is proliferating on both desktop &amp; mobile devices that try to extort money from users by taking control of their computers or displaying annoying pop-up messages such as CryptoLocker that encrypts an infected computer files, forcing users to pay hundreds of dollars to regain access.<br><strong>b) State how do we prevent and protect our computer from ransomware. </strong><br> i) Make sure one must installed up to date anti-malware or anti virus tool<br> ii) Scan attachments<br> iii) Ask before you open the email<br><strong>c) Discuss the effects of computer crime to an organization.</strong><br> <strong>i)  Reputational damage</strong></div><div>Trust is an essential element of customer relationship. Computer crime can damage business' reputation and erode the trust that customers have for the organization. This could potentially lead to loss of customer, loss of sales and reduction in profits</div><div><strong> ii) Legal consequences of computer crime</strong></div><div>Data protection and privacy laws require organizations to manage the security of all personal data they hold whether on the staff or their customers. If this data is accidentally or deliberately compromised, and they have failed to deploy appropriate security measures, they may face fines and regulatory sanctions.</div><div> <br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-25 15:42:27 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316647470</guid>
      </item>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316763980</link>
         <description><![CDATA[<div>Chapter 7: Securing information System<br><br></div><div>Question 1: Security isn't simply a technology issue it's a business issue. Discuss.<br><br></div><div>Information or data is a business enabler, it enables operations and productivity so, the security of it should be viewed as essential and promoted throughout the company but, in most cases it is not. This because we instinctively protect what we can see in front of us like buildings, personnel, hardware, the tangible assets but, we neglect the intangibles. IT Security should be seen as a task to minimize risk for an organization. This risk management is not just limited to the IT department or within the office because let’s face it, many of us do work a little when we get home even if it’s just checking our emails.<br><br></div><div>‘As many as 49% of individuals would use their personal device for work, found in a recent Norton Report’. Employees use of unauthorized personal mobile devices can be a threat because it is an unknown object on the IT network. For example, if a user was to save business data onto an unauthorized device and then it was infected by malware, the data could end up in the wrong hands! However, it is not about the IT department forbidding personal devices if devices are approved then it is safe to have on the network. It’s all about having policies in place and training employees on how to access business data securely. The training should not be limited to the use of mobile devices but, general IT security practices i.e. always encrypt email containing sensitive data or never write login credentials on a piece of paper.<br><br></div><div>There will always be a possibility of a breach in security for every company, it could be due to a cyber-attack, human error, social engineering etc. but, if risk management is a common goal amongst every employee not just the IT department, it can help manage and minimize security risks in the long run.<br><br></div><div>Question 2: Who poses the biggest security threat: insiders or outsiders<br><br></div><div>A recent infographic from Digital Guardian looking into the various threats posed by outside actors as well as those employed in your office makes for interesting reading. While state-sponsored hacking dominates today’s news cycle, other attacks orchestrated from within affected companies are perhaps a hidden problem. According to Digital Guardian’s findings, the motive changes when the source of the attack is discovered, with outsiders far more likely to be incentivized by financial gains than insiders. While outsiders use DDoS attacks or malicious USB drops, insiders have knowledge of systems, can physically steal data and, more often than many would care to admit, cause problems due to basic human error.<br><br></div><div>Question 3: Discuss the major security threats to this Web sites and their potential impact. What can be done to minimize these threats? <br><br></div><div><br>Ecommerce sites of all sizes are susceptible to attack because they process credit card information, email addresses, and passwords for user accounts. If not properly secured, credit card numbers can be taken and email/password combinations can be tried on other websites. In the following sections we will go through what security issues ecommerce sites face - download our full <a href="http://get.section.io/website-security-ecommerce-guide/">Guide to Website Security for Ecommerce Sites</a> for more information on threats and how to protect your website.<br><br></div><div>E-commerce websites are vulnerable to fraud from internal and external sources. Fraud incidents include credit card fraud, which exposes the website to threat from clients and any other external sources and internal fraud. Any fraudulent transactions being entered into the system from employees. Such transactions can also be introduced into the system by hackers or Trojan Horses, which resemble the real customers’ transactions. To prevent fraud, Fraud scoring must be used. It is a system of predictive fraud detection models or technologies that payment processors use to identify the highest-risk transactions in card-not-present environment that require additional verification. All card-not-present transactions must be authorized before they are processed. The authorization response will typically be approval or decline. You should develop a process for handling transactions after the authorization response has been received and apply it consistently.<br><br></div><div>A website that has been invaded by viruses and malicious software, can come crushing which will make the website lose the entire information causing losses to the e-commerce business. This can cause the clients to lose trust in the business, and as a result they can close their accounts on the website. Loss of information on a website can be devastating for both the business owner and the client especially if the information was not backed up.<br><br></div><div>One of the greatest threats to an e-commerce is poor management. When the management is not committed to ensuring security and does not support budgets for purchase of anti-virus software licenses, that keep internal networks robust will cause pose a big security threat. The lack of proper anti-virus makes the e-commerce vulnerable to viral attacks. To minimize or reduce this threat, Management should commit to regular IT security audits of the e-commerce website to ensure that security is optimized and all potential problems are dealt with as soon as they occur.<br><br></div><div>E-commerce security issues relate to internal business networks and an interface between transactions done by the customer and the network. Hackers pose a threat to the security of the network, because they can gain access to internal systems via the e-commerce website. Such threats can be avoided by using a firewall between the website and the internal network, and by encrypting all the transaction data.<br><br></div><div>Malicious software and computer viruses are some of the biggest security threats to any E-commerce website. Viruses are normally from external sources and can corrupt files on website if introduced into the internal network. Viruses can completely destroy a computer system and disrupt the operations of the website. Trojan horse is malicious software that has the ability to capture the clients’ information, before any encryption software can take effect. </div><div> <br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-27 23:12:44 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316763980</guid>
      </item>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316764035</link>
         <description><![CDATA[<div>CASE STUDY 1 THE LOOMING THREAT OF CYBER<br><br></div><div><strong>1)Is cyberwarfare a serious problem? Why or why not?</strong><br> Cyberwarfare is a serious problem. Through cyberwarfare the speed and scale of cyberwarfare has escalated.Not only does it affect the military, but also financial system and communication system. Hacker have been able to steal plans to weapons system, financial data, and nuclear weapon system.</div><div> </div><div><strong>2)What solutions are available for this problem? Do you think they will be effective? Why or why not?<br></strong>Congress is considering legislation that would require all critical infrastructure companies to meet newer, tougher cybersecurity standards. As cyberwarfare technologies develop and become more advanced, the standards imposed by this legislation will likely be insufficient to defend against attacks.</div><div> </div><div> </div><div> </div><div>Secretary of Defense Gates has ordered the creation of Cybercom which is the first headquarters that designed in order to coordinate government cybersecurity efforts and it was activated in 2010. The creation of the Cybercom will coordinate efforts to restrict access to government computers and protect systems that run the stock exchanges, managed the air traffic control system and cleared the global banking transactions. Besides, it will reinforced the operation and protection of military and pentagon computer networks. Its ultimate goal will be to prevent catastrophic cyberattacks against the U.S. Some insiders suggest that it might not be able to effectively organize the governmental agencies without direct access to the President, which it currently lacks. Because spy agencies like the CIA are prohibited by law from acting on American soil, some people are proposing to entrust some of the cyberwarfare work to private defense contractors. There is no effective way for a domestic agency to conduct computer operations without entering prohibited networks within the U.S. or even conduct investigations in countries that are American allies. Preventing terrorist or cyberwar attacks may require examining some email messages from other countries or giving intelligence agencies more access to networks or Internet service providers.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-27 23:15:31 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316764035</guid>
      </item>
      <item>
         <title></title>
         <author>azhaniummi19</author>
         <link>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316764771</link>
         <description><![CDATA[
help_outline
Help]]></description>
         <enclosure url="" />
         <pubDate>2018-12-27 23:38:46 UTC</pubDate>
         <guid>https://padlet.com/azhaniummi19/814j7i869kg9/wish/316764771</guid>
      </item>
   </channel>
</rss>
