3-12
Ethics in Information Technology, Sixth Edition
2. Explain that a next-generation firewall (NGFW) is a hardware- or software-based network
Routers
1. A router is a networking device that connects multiple networks together and forwards data
2. Explain that routers enable you to create a secure network by assigning it a passphrase so that
only individuals who have the passphrase can connect to your network. However, a skilled
Encryption
1. Introduce the term encryptionthe process of scrambling messages or data in such a way
that only authorized parties can read it.
2. Explain that an encryption key is a value that is applied (using an algorithm) to a set of
unencrypted text (plaintext) to produce encrypted text that appears as a series of seemingly
Proxy Servers and Virtual Private Networks
1. Explain that a proxy server serves as an intermediary between a web browser and another
2. A VPN enables remote users to securely access an organization’s collection of computing
and storage devices and share data remotely. To connect to a VPN, the user launches a VPN
3-13
Ethics in Information Technology, Sixth Edition
Intrusion Detection Systems
1. Introduce the term intrusion detection system (IDS)software and/or hardware that
2. Note that knowledge-based approaches and behavior-based approaches are two
fundamentally different approaches to intrusion detection.
C. Implementing CIA at the Application Level
1. Authentication methods, user roles and accounts, and data encryption are key elements of the
application security layer.
Authentication Methods
1. For many applications, users are required to enter a username and password to gain access.
2. Two-factor authentication requires the user to provide two types of credentials before being
User Roles and Accounts
1. Another important safeguard at the application level is the creation of roles and user accounts
Data Encryption
1. Explain that data encryption should be used within applications such as ERP, CRM, and
Implementing CIA at the End-User Level
1. Note that security education, authentication methods, antivirus software, and data encryption
3-14
Ethics in Information Technology, Sixth Edition
Security Education
1. Creating and enhancing user awareness of security policies is an ongoing security priority for
Authentication Methods
1. End users should be required to implement a security passcode that must be entered before
Antivirus Software
1. Introduce the terms antivirus software and virus signature.
2. Note that according to US-CERT, most virus and worm attacks use already known malware
Data Encryption
1. Point out that in order to fully protect their personal data (in the event that their device is
Critical Thinking Exercise: How Secure is Your Organizations?
1. Students answers to this question will vary. As part of the discussion, ask students to
identify which items on their list of proposed changes are of the highest priority. They should
Quick Quiz 3
1. Requiring users to enter a username and password; insert a smart card and enter the
associated PIN; or provide a fingerprint, voice pattern sample, or retina scan are all examples
of _____.
3-15
Ethics in Information Technology, Sixth Edition
2. _____ is a communications protocol or system of rules that ensures privacy between
communicating applications and their users on the Internet.
3. A(n) _____ is software and/or hardware that monitors system and network resources and
activities, and notifies network security personnel when it detects network traffic that
attempts to circumvent the security measures of a networked computer environment.
4. The _____ is often the weakest link in the organization’s security perimeter.
III. Response to Cyberattack
1. An organization should be prepared for the worsta successful attack that defeats all or
some of a system’s defenses and damages data and information systems.
A. Incident Notification
1. Explain that a key element of any response plan is to define who to notify and who not to
notify. Questions to cover include the following: Within the company, who needs to be
notified, and what information does each person need to have? Under what conditions should
Teaching
Discuss situations in which it would, or would not, be desirable to track down an
3-16
Ethics in Information Technology, Sixth Edition
Protection of Evidence and Activity Logs
1. An organization should document all details of a security incident as it works to resolve the
B. Incident Containment
1. Point out that the response plan should clearly define the process for deciding if an attack is
C. Eradication
1. Before the IT security group begins the eradication effort, it must collect and log all possible
D. Incident FollowUp
1. Explain that a review should be conducted after an incident to determine exactly what
happened and to evaluate how the organization responded. One approach is to write a formal
2. Note that the potential for negative publicity must also be considered. Discussing security
E. Using an MSPP
1. Introduce the term managed security service provider (MSSP).
2. Note that for most small and midsized organizations, the level of in-house network security
F. Computer Forensics
1. Computer forensics is a discipline that combines elements of law and computer science to
identify, collect, examine, and preserve data from computer systems, networks, and storage
2. Proper handling of a computer forensics investigation is the key to fighting computer crime
3-17
Ethics in Information Technology, Sixth Edition
3. Use Table 3-6 to aid a discussion of how a manager can assess their organization’s readiness
to prevent and respond to a cyberattack.
Critical Thinking Exercise: Selecting an MSSP Provider
1. When establishing criteria to use when selecting an MSSP, students could consider things
such as experience, staff expertise, company longevity, lists of existing clients, types of
Quick Quiz 3
1. (True or False) In a security incident, the primary goal must be to monitor or catch an
intruder.
2. Creating a detailed _____ of all events will document a security incident for later
prosecution.
3. A(n) _____ is a company that monitors, manages, and maintains computer and network
security for other organizations.
4. Proper handling of a _____ is the key to fighting computer crime successfully in court
Discussion Questions
1. If known vulnerabilities in software are entry points for an attacker, why are the software
vulnerabilities not corrected before the software is released?
Additional Projects
1. Design a security education program for employees.
3-18
Ethics in Information Technology, Sixth Edition
2. Write a paper about the Conficker, Storm, or ILOVEYOU worm, including an analysis of
3. Research the Equifax data breach that was announced in September of 2017. Write a one
Additional Resources
1. CERT/CC website (www.cert.org)
Key Terms
advanced persistent threat (APT): A network attack in which an intruder gains access to a
network and stays thereundetectedwith the intention of stealing data over a long period of
time (weeks or even months).
bring your own device (BYOD): A business policy that permits, and in some cases encourages,
employees to use their own mobile devices (smartphones, tablets, or laptops) to access company
computing resources and applications, including email, corporate databases, the corporate
intranet, and the Internet.
CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans
Apart): Software that generates and grades tests that humans can pass and all but the most
sophisticated computer programs cannot.
3-19
Ethics in Information Technology, Sixth Edition
computer forensics: A discipline that combines elements of law and computer science to
Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act: A
cyberespionage: The deployment of malware that secretly steals data in the computer systems of
organizations, such as government agencies, military contractors, political organizations, and
manufacturing firms.
cyberterrorism: The intimidation of government or civilian population by using information
Department of Homeland Security (DHS): A large federal agency with more than 240,000
employees and a budget of almost $65 billion whose goal is to provide for a “safer, more secure
America, which is resilient against terrorism and other potential threats.”
disaster recovery plan: A documented process for recovering an organization’s business
information system assetsincluding hardware, software, data, networks, and facilitiesin the
event of a disaster.
encryption key: A value that is applied (using an algorithm) to a set of unencrypted text
(plaintext) to produce encrypted text that appears as a series of seemingly random characters
(ciphertext) that is unreadable by those without the encryption key needed to decipher it.
3-20
Ethics in Information Technology, Sixth Edition
intrusion detection system (IDS): Software and/or hardware that monitors system and network
resources and activities and notifies network security personnel when it detects network traffic
that attempts to circumvent the security measures of a networked computer environment.
phishing: The act of fraudulently using email to try to get the recipient to reveal personal data.
ransomware: Malware that stops you from using your computer or accessing your data until you
meet certain demands, such as paying a ransom or sending photos to the attacker.
reasonable assurance: A concept in computer security that recognizes that managers must use
their judgment to ensure that the cost of control does not exceed the system’s benefits or the risks
involved.
security policy: An organization’s security requirements, as well as the controls and sanctions
needed to meet those requirements.
smishing: Another variation of phishing that involves the use of texting.
spam: The use of email systems to send unsolicited email to large numbers of people.
3-21
Ethics in Information Technology, Sixth Edition
U.S. Computer Emergency Readiness Team (US-CERT): Established in 2003 to protect the
nation’s Internet infrastructure against cyberattacks, it serves as a clearinghouse for information
on new viruses, worms, and other computer security topics.
virus: A piece of programming code, usually disguised as something else, that causes a
computer to behave in an unexpected and usually undesirable manner.