For your blog post, read the chapter and then define and explain the
following terms: (Due by 12 p.m. on 6/3/2013).
Controls (and the different types discussed in the chapter - general and application controls)
Types of malicious software (malware, virus, worms, trojan horses, spyware, and keylogger) - define all
Hackers
Spoofing
Sniffer
Denial-of-Service (DoS) attack
Distributed denial of service attack (DDoS)
Botnet
Identity theft
Phishing
Pharming
Click fraud
Social engineering
Bugs
Computer forensics
Risk assessment
Acceptable use policy (AUP)
Disaster recovery planning
Business continuity planning
Smart card
Biometric authentication
Firewall
Secure socket layer (SSL)
Public key encryption (PKE)
Online transaction processing (OLTP)
Digital certificate
Fault-tolerant computer systems
These terms need to be defined and explained in your own words (using the textbook as your reference and guide). Be sure to include the textbook APA
citation at the end of your blog post.
Next, identify and explain a concept from the Chapter 8 reading that you found interesting and discuss what it is, why you found it interesting, and any questions or comments you have about the concept. (This can be from any of your reading of the chapter - not limited to just the terms you defined above).
Remember, in order to post your response, just choose the "comment" option and comment on the post I made (rather than creating a new post). By doing this, I am able to see the date and time you posted your comment.
Controls (and the different types discussed in the chapter - general and application controls) – Controls are methods, policies, and organizational procedures that ensure the safety of the organization’s assets, the accuracy and reliability of its records, and operational adherence to management standards. General controls govern the desing, security, and use of computer programs and the security of data files in general throughout the organizations information technology infrastructure. Application controls are specific controls unique to each computerized applications, such as payroll or order processing. Types of general controls are software controls, hardware controls, computer operations controls, data security controls, implantation controls, administrative controls.
ReplyDeleteTypes of malicious software (malware, virus, worms, trojan horses, spyware, and keylogger) - define all – Malware – malicious software programs such as computer viruses, worms, and Trojan horses. Worms – Independent software programs that propagate themselves to disrupt the operation of computer networkds or destroy data and other programs. Trojan Horses – software programs that appear lefitimate but contain a second hidden function that may cause damage. Spyware – technology that aids in gathering information about a person or organization without their knowledge. Keylogger – Spyware the records every keystroke made on a computer to steal personal information or passwords or to launch Internet attacks.
Hackers – People who gain unauthorized access to a computer network for profit, criminal mischief, or personal pleasure.
Spoofing – may involve redirecting a web link to an address different from the intended one, with the site masquerading as the intended destination.
Sniffer – a type of eavesdropping program that monitors information traveling over a network.
Denial-of-Service (DoS) attack – hackers flood a network server or web server with many thousands of false communications or requests for services to crash the network.
Distributed denial of service attack (DDoS) - uses numerous computers to inundate and overwhelm the network from numerous launch points.
Botnet – a group of computers that have been infected with bot malware without users’ knowledge, enabling a hacker to use the amassed resources of the computers to launch distributed denial of service attacks, phishing campaigns, or spam.
Identity theft – Theft of key pieces of personal information, such as credit card of Social Security numbers, in order to obtain merchandise and services in the name of the victim or to obtain false credentials.
Phishing – Form of spoofing involving setting up fake web sites or sending email messages that resemble those of legitimate businesses that ask users for confidential personal data.
Pharming – phishing technique that redirects users to a bogus web page, even when a user enters the correct web page address.
Click fraud – fraudulently clicking on an online ad in pay per click advertising to generate an improper charge per click.
Social engineering – Tricking people into revealing their passwords by pretending to rrbe legitimate users or members of a company in need of information.
Bugs – Software program code defects.
Computer forensics – The scientific collection, examination, authentication, preservation, and analysis of data held on or retrieved from computer storage media in such a way that the information can be used as evidence in a court of law.
Risk assessment – Determining potential frequency of occurrence of a problem and the potential damage if the problem were to occur. Used to determine the cost/benefit of a control.
Acceptable use policy (AUP) – Defines acceptable uses of a firm’s information resources and computing equipment, including desktop and laptop computers, wireless devices, telephones, and the Internet, and specifies consequences for noncompliance.
Disaster recovery planning – Planning for the restoration of computing and communication services after they have been disrupted.
ReplyDeleteBusiness continuity planning – Planning that focuses on how the company can restore business operations after a disaster strikes.
Smart card – A credit card size plastic card that stores digital information and that can be used for electronic payments in place of cash.
Biometric authentication – Technology for authenticating system users that compares a person’s unique characteristics such as fingerprints, face, or retinal image, against a stored set profile of these characteristics.
Firewall – Hardware and placed between an organization’s internal network and an external network to prevent outsiders from invading private networks.
Secure socket layer (SSL) – Enables client and server computers to manage encryption and decryption activities as they communicate with each other during a secure Web session.
Public key encryption (PKE) – Uses two keys: one shared (or public) and one private.
Online transaction processing (OLTP) – Transaction processing mode in which transaction entered on-line are immediately processed by the computer.
Digital certificate – An attachment to an electronic message to verify the identity of the sender and to provide the receiver with the means to encode a reply.
Fault-tolerant computer systems – Systems that contain extra hardware, software, and power supply components that can back a system up and keep it running to prevent system failure.
The idea of chapter 8 that I felt was worth discussing further was the Gramm-Leach-Bliley Act. This act requires financial institutions to ensure the security and confidentiality of customer data. Data must be stored on a secure medium, and special security measures must be enforced to protect such data on storage media and during transmittal. To me this act is important and affects anyone that has a bank account.
Lauden, K.C., & Lauden, J.P.,(2011). Management Information Systems, Managing the Digital Firm. Upper Saddle River, NJ: Prentice Hal
Yes pretty interesting! And with your major you definitely will be working this as well. Good job and full credit.
ReplyDelete