Tuesday, January 13, 2015

Unit 7 Organisational Systems Security P1

P1 The impact of specific individual types of threats that exist to organisations.

Malicious damage is the intentional harming of property, and in large companies this usually means disgruntled employees who have just been fired and want to take it out on the company. It could also be stressed employees who have just had enough, this can potentially ruin a lot of equipment and the company will lose money in having to replace it, and if it is a small company with only 3 or 4 computers and someone breaks one then it could slow down or potentially completely stop work.
There are many types of potential threats to an organisation that involve access without damage, and these are;
Phishing and Identity theft , Phishing is a type of Internet fraud that seeks to acquire a user’s credentials by deception. It includes theft of passwords, credit card numbers, bank account details and other confidential information. Phishing messages usually take the form of fake notifications from banks, providers, e-pay systems and other organizations. The notification will try to encourage a recipient, for one reason or another, to urgently enter/update their personal data. Such excuses usually relate to loss of data, system breakdown, etc.
Piggybacking, which is gaining access to restricted communication channel by using session that another user has already established, can be defeated by logging off before leaving a workstation or terminal or by initiating a protected mode, such as via a screensaver that requires re-authentication before access can be resumed. This also is a cause for loss of information.
Hacking involves gaining unauthorized access to other computers. A hacker can "hack" his or her way through the security levels of a computer system or network. This can be as simple as figuring out somebody else's password or as complex as writing a custom program to break another computer's security software. Hacking is very bad as not only can there be massive data loss, if the company deals with a lot of personal information then the hacker will have access to all of it.

Website Defacement is an example of a threat related to ecommerce. Website defacement is an attack on a website that changes the visual appearance of the site or a webpage. These are typically the work of system crackers, who break into a web server and replace the hosted website with one of their own. This can lead to the company not being taken seriously or losing customers.

DOS attacks are denial of service attacks, which is where a group of people will bring it upon themselves to take a website down by flooding it with useless traffic and taking the server down so other people cannot access the website. This can lose the company customers and if they are an ecommerce website then it could lose them a lot of money, especially if it takes them a while to get the server back up and running again.  

1 comment: