<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>CSC408 MANAGEMENT INFORMATION SYSTEM by nur liana</title>
      <link>https://padlet.com/nliana246/kz89l7sz5qt2</link>
      <description>NURLIANA BINTI MOHD HISHAM
AM2284C</description>
      <language>en-us</language>
      <pubDate>2018-12-29 12:08:11 UTC</pubDate>
      <lastBuildDate>2018-12-29 13:39:40 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>1. Briefly explain the following computer crimes.</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833066</link>
         <description><![CDATA[<div><strong>a.Sniffer</strong> – it is eavesdropping program that monitors information traveling over networks. It also enables hackers to steal proprietary information like email, company files and others. <br><br></div><div><strong>b.Phishing</strong> – it is setting up fake Web sites or sending email messages that look like legitimate business to ask users for confidential personal data. <br><br></div><div><strong>c.Pharming</strong> – it redirects users to a bogus Web page, even when individual types correct Web page address into his or her browser.<br><br></div><div><strong>d.Spoofing</strong> – it misrepresenting oneself by using fake email addresses or masquerading as someone else. It also redirecting Web link to address different from  intended one, with site masquerading as intended destination.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:15:50 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833066</guid>
      </item>
      <item>
         <title>2. a)  Distinguish the TWO (2) methods for encrypting network traffic on the Web.</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833117</link>
         <description><![CDATA[<div>- <strong>TLS</strong> is a cryptographic protocol that provides end-to-end communications security over networks and is widely used for internet communications and online transactions. It is an IETF standard intended to prevent eavesdropping, tampering and message forgery. Common applications that employ TLS include Web browsers, instant messaging, e-mail and voice over IP.</div><div><strong>- SSL</strong> (Secure Sockets Layer) is the standard security technology for establishing an encrypted link between a web server and a browser. This link ensures that all data passed between the web server and browsers remain private and integral. SSL is an industry standard and is used by millions of websites in the protection of their online transactions with their customers.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:18:08 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833117</guid>
      </item>
      <item>
         <title>2.b)  Briefly explain the following terms.</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833198</link>
         <description><![CDATA[<div><strong>i. Cyber warfare</strong> - Cyber warfare includes the activities by a country state or global association to assault and endeavor to harm another country's PCs or data organizes through, for instance, PC infections or refusal of-benefit assaults. RAND research provides recommendations to military and regular citizen chiefs on strategies for shielding against the harming impacts of digital fighting on a country's advanced framework.<br><strong> ii. Computer Forensic</strong> - Computer forensics is the practice of collecting, analyzing and reporting on digital data in a way that is legally admissible. It can be used in the detection and prevention of crime and in any dispute where evidence is stored digitally. Computer forensics follows a similar process to other forensic disciplines, and faces similar issues.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:21:47 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833198</guid>
      </item>
      <item>
         <title>3.a) Without protection against malware and intruders, connecting to the Internet could be very dangerous. Firewalls, intrusion detection system and antivirus software have become the tools to overcome this problem. Briefly explain these THREE (3) tools.</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833248</link>
         <description><![CDATA[<div><strong>1.Firewalls</strong></div><div>Combination of hardware and software that prevents unauthorized users from accessing private networks whereby it consists of Static packet filtering, Stateful inspection, Network address translation (NAT), and Application proxy filtering.<br><br></div><div><strong>2</strong>.<strong>Intrusion Detection System</strong></div><div>Monitoring hot spots on corporate networks to detect and deter intruders and examines events as they are happening to discover attacks in progress.</div><div> </div><div><strong>3</strong>.<strong>Antivirus Software</strong></div><div>Checks computers for presence of malware and can often eliminate it as well whereby it requires continual updating.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:23:32 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833248</guid>
      </item>
      <item>
         <title>3. b) Information systems controls is one of the components of an organizational framework for security and control. Information systems controls consist of two - general and application control. A company must know how and where to deploy security tools and security personnel must know what controls a company must have in place to protect its information system. Contrast between General Controls and Application Controls.</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833375</link>
         <description><![CDATA[<div><strong>1.General control</strong> – It govern design, security and use of computer programs and security of data files in general throughout organization’s information technology infrastructure. It also apply to all <br>computerized application.  General control also combination of hardware, software and manual procedures to create overall control environment. <br><br></div><div><strong>2. Application control</strong> – it specific controls unique to each computerized application like payroll and order processing. It include both automated and manual procedures which to ensure that only authorized data are completely and accurately processed by that application.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:28:29 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833375</guid>
      </item>
      <item>
         <title>4 .Malicious Software programs are referred to as Malware. Describe FOUR (4) types of malicious software. </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833455</link>
         <description><![CDATA[<div><strong>1.Viruses.</strong> Rogue software program that attaches itself to other software programs or data files in order to be executed.</div><div><strong>2.Worms</strong>. Independent programs that copy themselves from one computer to other computers over a network.</div><div><strong>3.Trojan horses. </strong>Software that appears benign but does something other than expected. For example, Zeus Trojan that runs on computers with MS Windows OS were used to steal login credentials for banking.</div><div><strong>4.Spyware.</strong> Small programs install themselves surrptitiously on computers to monitor user web surfing activity and serve advertising.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:32:03 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833455</guid>
      </item>
      <item>
         <title>5.a) Nowadays securing information systems has become an important issue in organization to protect itself against computer crime. Define computer crime and provide an appropriate example. </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833506</link>
         <description><![CDATA[<div>Computer crime can be defines as any violations of criminal law that involve a knowledge of computer technology for their perpetration, investigation, or prosecution. For example, they will be using computer as their instrument to be a theft of trade secrets and using e-mails for threats or harassment where this can be called as identity theft where they will theft of personal information such as security ID.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:34:01 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833506</guid>
      </item>
      <item>
         <title>5b) Briefly explain THREE (3) reasons why information systems are vulnerable to destruction, error and abuse? </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833964</link>
         <description><![CDATA[<div><strong>1.</strong> Accessibility of networks where everyone at anytime can access with the system.</div><div><strong>2.</strong> Wi-Fi networks can easily be penetrated by intruders using sniffer programs to obtain an address to access the resources of the network.</div><div><strong>3.</strong> Software presents problems because software bugs may be impossible to eliminate and because software vulnerabilities can be exploited by hackers and malicious software.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:48:41 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833964</guid>
      </item>
      <item>
         <title>5.c) Discuss the THREE (3) most important tools and technology for safeguarding information resources. </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833997</link>
         <description><![CDATA[<div><strong>1. Firewall.</strong> It prevents the accesses of private network or systems when connected to the internet from the unauthorized users.</div><div><strong>2. Intrusion detecting systems. </strong>Monitors the private networks and provides access to the corporate systems.</div><div><strong>3. authentication techniques. </strong>Provides authentication by passwords, tokens, biometric and smart card. </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:49:51 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316833997</guid>
      </item>
      <item>
         <title>6.a) Identity management software automates the process of keeping track of all information systems users and their system privileges, assigning each user a unique digital identity for accessing each system. </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834022</link>
         <description><![CDATA[<div>Authentication is the  process or action of verifying the identity of a user or process.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:51:08 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834022</guid>
      </item>
      <item>
         <title>6.b) Identify and briefly describe FOUR (4) authentication technologies. </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834179</link>
         <description><![CDATA[<div><strong>1. Iris scanner</strong>. An iris scan is a highly secure way to verify a person’s identity, even more so than a fingerprint scan or voice pattern recognition.</div><div><strong>2. Voice Recognition Security System.</strong>Voice biometric authentication identifies an individual based on the patterns unique to each person’s voice. </div><div><strong>3. Palm Vein Pattern Authentication.</strong>The system records the pattern of veins in the hand, and is safe and accurate. The user does not need to directly touch the device.</div><div><strong>4. Facial Recognition</strong>.A biometric software application capable of uniquely identifying or verifying a person by comparing and analyzing patterns based on the person's facial contours</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:55:16 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834179</guid>
      </item>
      <item>
         <title>7.a) Describe ransomware. </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834274</link>
         <description><![CDATA[<div>A type of malicious software designed to block access to a computer system until a sum of money is paid.The motive for ransomware attacks is nearly always monetary, and unlike other types of attacks, the victim is usually notified that an exploit has occurred and is given instructions for how to recover from the attack. Payment is often demanded in a virtual currency, such as bitcoin</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:57:28 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834274</guid>
      </item>
      <item>
         <title>7. b) State how do we prevent and protect our computer from ransomware.</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834344</link>
         <description><![CDATA[<div><strong>1.</strong> Do make sure that all systems and software are up-to-date with relevant patches</div><div><strong>2</strong>.Use reputable antivirus software and a firewall.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 12:59:39 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834344</guid>
      </item>
      <item>
         <title>7.c) Discuss the effects of computer crime to an organization. </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834381</link>
         <description><![CDATA[<div>A company suffers losses due to computer crime when a hacker steals confidential information and future plans of the company. And he simply sells the information to a competitor company and they use the information to get benefits. Wastage of time is another problem because many IT personals spend a lot of time on handling harmful incidents which may be caused due to computer crimes. This time should be spend on the development. And if the company is attacked by a computer criminal it would cost a lot and much time is needed to recover from the loss.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 13:00:57 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834381</guid>
      </item>
      <item>
         <title>Chapter 7: Securing Information Systems                                                   1. Security isn’t simply a technology issue, it’s a business issue. Discuss.</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834479</link>
         <description><![CDATA[<div>Security become a business issue because all organisations depend on a wide variety of IT systems to enable and support their business processes. This ranges from email and instant messenger for communication, to document management systems for collaboration, to ERP systems for performing integrated business processes.<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 13:05:41 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834479</guid>
      </item>
      <item>
         <title>2. Who poses the biggest security threat: insiders or outsiders? </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834518</link>
         <description><![CDATA[<div>Outsiders are more likely to act in a malicious way with a company’s data, but the source of the greatest risk is nearly always the insiders. Outside bad-actors are constantly looking for weaknesses to exploit, and the greatest vulnerability is typically careless or misguided actions by insiders. When insiders fail to be vigilant about protecting the fort, they fall victim to phishing schemes or social engineering attacks, or they open emails they don’t recognize, or they access corporate systems while sitting in an internet cafe or any one of the myriads of careless behaviors that create vulnerabilities. It is the insiders that provide opportunities for outsiders to storm the gates and cause damage.<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 13:07:21 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834518</guid>
      </item>
      <item>
         <title>3. Suppose your business had an e-commerce Web site where it sold goods and accepted credit card payments. Discuss the major security threats to this Web site and their potential impact. What can be done to minimize these threats? </title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834542</link>
         <description><![CDATA[<div> E-commerce websites are vulnerable to fraud from internal and external sources. Fraud incidents include credit card fraud, which exposes the website to threat from clients and any other external sources and internal fraud. Any fraudulent transactions being entered into the system from employees. Such transactions can also be introduced into the system by hackers or Trojan Horses, which resemble the real customers’ transactions. To prevent fraud, Fraud scoring must be used. It is a system of predictive fraud detection models or technologies that payment processors use to identify the highest-risk transactions in card-not-present environment that require additional verification. All card-not-present transactions must be authorized before they are processed. The authorization response will typically be approval or decline. You should develop a process for handling transactions after the authorization response has been received and apply it consistently.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 13:08:07 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834542</guid>
      </item>
      <item>
         <title>Case Study :1.Is cyberwarfare a serious problem? Why or why not?</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834701</link>
         <description><![CDATA[<div>Cyber warfare is becoming a very serious problem. Attacks have become much more widespread, sophisticated, and potentially devastating. The U.S. Department of Defense networks experience 250,000 probes every hour and cyber attacks on U.S. federal agencies in general have increased 150 percent since 2008. Cyberwarfare comes in the form of distributed denial-of-service attacks that have taken down Websites at the White House, the Treasury, the Federal Trade Commission, the Defense Department, the Secret Service, and many others. The </div><div>attacks slowed down most of the U.S. sites and forced several sites in foreign countries to stop operating altogether. Over the years, hackers have stolen plans for missile tracking systems, satellite navigation devices, surveillance drones, and leading-edge jet fighters.</div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 13:13:50 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834701</guid>
      </item>
      <item>
         <title>2. What solutions are available for this problem? Do you think they will be effective? Why or why not?</title>
         <author>nliana246</author>
         <link>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834975</link>
         <description><![CDATA[<div>The solution that the country must take to prevent from this problem is Computer crimes or rules should therefore be established, maybe in combination with an organization monitoring the cyberspace, with large and serious consequences against states violating these rules. Cyber weapons won’t go away and their spread can’t be controlled. Instead, as we’ve done for other destructive technologies, the world needs to establish a set of principles to determine the proper conduct of governments regarding cyber conflict. They would dictate how to properly attribute cyber-attacks, so that we know with confidence who is responsible, and they would guide how countries should respond. </div>]]></description>
         <enclosure url="" />
         <pubDate>2018-12-29 13:23:41 UTC</pubDate>
         <guid>https://padlet.com/nliana246/kz89l7sz5qt2/wish/316834975</guid>
      </item>
   </channel>
</rss>
