it security cs5493(74293). it security q: why do you need security? a: to protect assets

16
IT Security CS5493(74293)

Upload: frank-owen

Post on 18-Jan-2018

215 views

Category:

Documents


0 download

DESCRIPTION

What are assets? Any item that has value: – People – Intellectual property – Physical property – Data – Services – Reputation Assets are the things you want to protect

TRANSCRIPT

Page 1: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

IT Security

CS5493(74293)

Page 2: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

IT Security

Q: Why do you need security?A: To protect assets.

Page 3: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

What are assets?

• Any item that has value:– People– Intellectual property– Physical property– Data– Services– Reputation

• Assets are the things you want to protect

Page 4: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

The SA and Assets

• People– Employees– Shareholders– Customers– Contractors

Page 5: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

The SA and Assets

• Physical- The information computing system (hardware,

software)

Page 6: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

The SA and Assets

• Intellectual property– Patents– Proprietary source code.– Formulas– plans

Page 7: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

The SA and Assets

• Data– Financial data– Customer database– Inventory– Scientific data

Page 8: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

The SA and Assets

• Services– Availability of services– Productivity of employees

Page 9: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

SA and Services

• Reputation– Brand image

Page 10: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

Attacks, Threats, &Vulnerabilities

• Assets are subject to– Threats– Vulnerabilities– Attacks

Page 11: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

SA: Threats

• A threat is a potential action that could compromise an asset.

Page 12: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

SA: Vulnerabilities

• A vulnerability is a weakness in a system that makes it possible for a threat to cause harm.

Page 13: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

SA: Attacks

• An attack is an action that compromises an asset.

Page 14: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

Risks

• All risk cannot be eliminated.• Risk is managed analytically through risk

analysis.

Page 15: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

Risk Analysis

• Quantifying (in monetary terms) the impact of attacks, threats, and vulnerabilities upon assets.

Page 16: IT Security CS5493(74293). IT Security Q: Why do you need security? A: To protect assets

Security Summary

• Protect your assets• Understand the threats• Eliminate the vulnerabilities• Reach an acceptable level of risk