MODULE 7: SECURITY IN ICT Session 1: Introduction
Description: MODULE 7: SECURITY IN ICT Session 1: Introduction to ICT Security 1 Introduction ICT has permeated many industries and insecurity of data and ICT components is becoming a major point of concern. The goal of this course is to equip learners
Related Topics
Download Presentation
"MODULE 7: SECURITY IN ICT Session 1: Introduction" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. MODULE 7: SECURITY IN ICTSession 1: Introduction to ICT Security 1<br>
slide2. Introduction ICT has permeated many industries and insecurity of data and ICT components is becoming a major point of concern.
The goal of this course is to equip learners with knowledge on contemporary issues on ICT security, so that the users can achieve information confidentiality, integrity and availability. 2<br>
slide3. Module Outcomes At the end of the module, learners will be able to
Demonstrate understanding of what ICT security comprises
Describe how to offer protection to standard threats that ICT industry is exposed to.
Discuss contemporary issues in ICT security like cyber bullying, terrorism and hacking
Design a high level security policy that protects data and information
Describe the set up and running of a disaster recovery strategy 3<br>
slide4. Introduction to ICT Security 1A 4<br>
slide5. Learning outcomes By the end of this session, you will be able to:
Describe ICT security triad
Explain the challenges that ICTs are faced with in today’s global village
Describe the general threats that affect computer environments 5<br>
slide6. Introduction Information and Communication Technology (ICT) refers to technologies that provide access to data and information through the use of computers, tablets, phones and telecommunications networks.
Computer security, also known as cybersecurity or IT security is the protection of computer systems from the theft or damage to the hardware, software or the information on them, as well as from disruption or misdirection of the services they provide.
Information security, sometimes shortened to InfoSec, is the practice of preventing unauthorized access, use, disclosure, disruption, modification, inspection, recording or destruction of information. 6<br>
slide7. Key Threats to Data Security Data can be
lost or damaged during a system crash - especially one affecting the hard disk
corrupted as a result of faulty disks, disk drives, or power failures
lost by accidentally deleting or overwriting files
lost or become corrupted by computer viruses
hacked into by unauthorised users and deleted or altered
destroyed by natural disasters, acts of terrorism, or war
deleted or altered by employees wishing to make money or take revenge on their employer 7<br>
slide8. The Security Triad ICT security policies address the risk of destruction or corruption of data due to an attack or some other unexpected incident.
The three types of risks addressed by enterprises having a formally defined ICT security policy correspond essentially to the core elements of the ICT security definition, i.e. integrity, confidentiality and availability of data and systems.
The CIA triad of confidentiality, integrity, and availability is at the heart of information security 8<br>
slide9. The Security Triad Confidentiality: - Only authorized users can access the data resources and information.
Integrity: - Only authorized users should be able to modify the data when needed.
Availability: - Data should be available to users when needed. 9<br>
slide10. 10<br>
slide11. The Security Triad The security triad has been extended to include authenticity, accountability and non-repudiation, as a result of increased security threats and expansion of the scope of every increasing use of ICTs. 11<br>
slide12. 12<br>
slide13. Threats to Computing environments in the global village The Global village is a view that that people are connected by easy travel, mass media and electronic communications, and have become a single community. 13<br>
slide14. 14<br>
slide15. Hardware Security This refers to the protection of physical systems from harm.
Equipment destruction attacks, for example, focus on computing devices and networked non-computing devices such as the ever-increasing number of connected devices IoT (Internet of Things) environments.
These environments are bringing connectivity and communications to large numbers of hardware devices that must be protected through either hardware- or software-based security. 15<br>
slide16. Software Security Software Security - Software security is an idea implemented to protect software against malicious attack and other hacker risks so that the software continues to function correctly under such potential risks.
Any compromise to integrity, authentication and availability makes a software insecure. Software systems can be attacked to steal information, monitor content, introduce vulnerabilities and damage the behavior of software. Malware can cause DoS (denial of service) or crash the system itself. 16<br>
slide17. Personnel Security Personnel Security – is used to provide a level of assurance as to the honesty, trustworthiness, in the use of ICT resources.
The aim is to reduce the risk of loss, damage or compromise of ICT resources, create an environment where those accessing ICT resources are aware of the responsibilities that come with that access and abide with their obligations 17<br>
slide18. Cybersecurity Statistics and Trends Recent security research suggests most companies have unprotected data and poor cybersecurity practices in place, making them vulnerable to data loss. To successfully fight against malicious intent, it’s imperative that companies make cybersecurity awareness, prevention and security best practices a part of their culture. 18<br>
slide19. 2021 Cybersecurity Trends to Watch For COVID-19 has forced companies to create remote workforces and operate off cloud-based platforms. Here are some industry trends and also predictions to watch for in 2021 and beyond.
Remote workers will continue to be a target for cybercriminals.
As a side effect of remote workforces, cloud breaches will increase.
The cybersecurity skills gap will remain an issue.
As a result of 5G increasing the bandwidth of connected devices, IoT devices will become more vulnerable to cyber attacks. 19<br>
slide20. Impactful Cybersecurity Facts and Stats 95% of cybersecurity breaches are caused by human error. (Cybint)
88% of organizations worldwide experienced spear phishing attempts in 2019. (Proofpoint)
68% of business leaders feel their cybersecurity risks are increasing. (Accenture)
On average, only 5% of companies’ folders are properly protected. (Varonis)
86% of breaches were financially motivated and 10% were motivated by espionage. (Verizon)
45% of breaches featured hacking, 17% involved malware and 22% involved phishing. (Verizon)
The top malicious email attachment types are .doc and .dot which make up 37%, the next highest is .exe at 19.5%. (Symantec)
An estimated 300 billion passwords are used by humans and machines worldwide. (Cybersecurity Media) 20<br>
slide21. Ransomware and Malware Attacks In 2018, an average of 10,573 malicious mobile apps were blocked per day. (Symantec)
94% of malware is delivered by email. (CSO Online)
48% of malicious email attachments are office files. (Symantec)
Ransomware detections have been more dominant in countries with higher numbers of internet-connected populations, and the U.S. ranks highest with 18.2% of all ransomware attacks. (Symantec)
Most malicious domains, about 60%, are associated with spam campaigns. (Cisco)
About 20% of malicious domains are very new and used around one week after they are registered. (Cisco) 21<br>
slide22. IoT, DDos, and Other Attacks 1 in 13 web requests lead to malware. (Symantec)
Phishing attacks account for more than 80% of reported security incidents. (CSO Online)
By 2023, the total number of DDoS attacks worldwide will be 15.4 million. (Cisco)
Attacks on IoT devices tripled in the first half of 2019. (CSO Online)
30% of data breaches involve internal actors. (Verizon)
IoT devices experience an average of 5,200 attacks per month. (Symantec)
90% of remote code execution attacks are associated with cryptomining. (Purplesec)
1 in 36 mobile devices have high- risk apps installed. (Symantec) 22<br>
slide23. Geography of Mobile Threats TOP 10 countries by number of attacked users *percentage of attacked users in the country from total number of attacked users 23<br>
slide24. TOP 20 mobile threats of 2019 24<br>
slide2. Introduction ICT has permeated many industries and insecurity of data and ICT components is becoming a major point of concern.
The goal of this course is to equip learners with knowledge on contemporary issues on ICT security, so that the users can achieve information confidentiality, integrity and availability. 2<br>
slide3. Module Outcomes At the end of the module, learners will be able to
Demonstrate understanding of what ICT security comprises
Describe how to offer protection to standard threats that ICT industry is exposed to.
Discuss contemporary issues in ICT security like cyber bullying, terrorism and hacking
Design a high level security policy that protects data and information
Describe the set up and running of a disaster recovery strategy 3<br>
slide4. Introduction to ICT Security 1A 4<br>
slide5. Learning outcomes By the end of this session, you will be able to:
Describe ICT security triad
Explain the challenges that ICTs are faced with in today’s global village
Describe the general threats that affect computer environments 5<br>
slide6. Introduction Information and Communication Technology (ICT) refers to technologies that provide access to data and information through the use of computers, tablets, phones and telecommunications networks.
Computer security, also known as cybersecurity or IT security is the protection of computer systems from the theft or damage to the hardware, software or the information on them, as well as from disruption or misdirection of the services they provide.
Information security, sometimes shortened to InfoSec, is the practice of preventing unauthorized access, use, disclosure, disruption, modification, inspection, recording or destruction of information. 6<br>
slide7. Key Threats to Data Security Data can be
lost or damaged during a system crash - especially one affecting the hard disk
corrupted as a result of faulty disks, disk drives, or power failures
lost by accidentally deleting or overwriting files
lost or become corrupted by computer viruses
hacked into by unauthorised users and deleted or altered
destroyed by natural disasters, acts of terrorism, or war
deleted or altered by employees wishing to make money or take revenge on their employer 7<br>
slide8. The Security Triad ICT security policies address the risk of destruction or corruption of data due to an attack or some other unexpected incident.
The three types of risks addressed by enterprises having a formally defined ICT security policy correspond essentially to the core elements of the ICT security definition, i.e. integrity, confidentiality and availability of data and systems.
The CIA triad of confidentiality, integrity, and availability is at the heart of information security 8<br>
slide9. The Security Triad Confidentiality: - Only authorized users can access the data resources and information.
Integrity: - Only authorized users should be able to modify the data when needed.
Availability: - Data should be available to users when needed. 9<br>
slide10. 10<br>
slide11. The Security Triad The security triad has been extended to include authenticity, accountability and non-repudiation, as a result of increased security threats and expansion of the scope of every increasing use of ICTs. 11<br>
slide12. 12<br>
slide13. Threats to Computing environments in the global village The Global village is a view that that people are connected by easy travel, mass media and electronic communications, and have become a single community. 13<br>
slide14. 14<br>
slide15. Hardware Security This refers to the protection of physical systems from harm.
Equipment destruction attacks, for example, focus on computing devices and networked non-computing devices such as the ever-increasing number of connected devices IoT (Internet of Things) environments.
These environments are bringing connectivity and communications to large numbers of hardware devices that must be protected through either hardware- or software-based security. 15<br>
slide16. Software Security Software Security - Software security is an idea implemented to protect software against malicious attack and other hacker risks so that the software continues to function correctly under such potential risks.
Any compromise to integrity, authentication and availability makes a software insecure. Software systems can be attacked to steal information, monitor content, introduce vulnerabilities and damage the behavior of software. Malware can cause DoS (denial of service) or crash the system itself. 16<br>
slide17. Personnel Security Personnel Security – is used to provide a level of assurance as to the honesty, trustworthiness, in the use of ICT resources.
The aim is to reduce the risk of loss, damage or compromise of ICT resources, create an environment where those accessing ICT resources are aware of the responsibilities that come with that access and abide with their obligations 17<br>
slide18. Cybersecurity Statistics and Trends Recent security research suggests most companies have unprotected data and poor cybersecurity practices in place, making them vulnerable to data loss. To successfully fight against malicious intent, it’s imperative that companies make cybersecurity awareness, prevention and security best practices a part of their culture. 18<br>
slide19. 2021 Cybersecurity Trends to Watch For COVID-19 has forced companies to create remote workforces and operate off cloud-based platforms. Here are some industry trends and also predictions to watch for in 2021 and beyond.
Remote workers will continue to be a target for cybercriminals.
As a side effect of remote workforces, cloud breaches will increase.
The cybersecurity skills gap will remain an issue.
As a result of 5G increasing the bandwidth of connected devices, IoT devices will become more vulnerable to cyber attacks. 19<br>
slide20. Impactful Cybersecurity Facts and Stats 95% of cybersecurity breaches are caused by human error. (Cybint)
88% of organizations worldwide experienced spear phishing attempts in 2019. (Proofpoint)
68% of business leaders feel their cybersecurity risks are increasing. (Accenture)
On average, only 5% of companies’ folders are properly protected. (Varonis)
86% of breaches were financially motivated and 10% were motivated by espionage. (Verizon)
45% of breaches featured hacking, 17% involved malware and 22% involved phishing. (Verizon)
The top malicious email attachment types are .doc and .dot which make up 37%, the next highest is .exe at 19.5%. (Symantec)
An estimated 300 billion passwords are used by humans and machines worldwide. (Cybersecurity Media) 20<br>
slide21. Ransomware and Malware Attacks In 2018, an average of 10,573 malicious mobile apps were blocked per day. (Symantec)
94% of malware is delivered by email. (CSO Online)
48% of malicious email attachments are office files. (Symantec)
Ransomware detections have been more dominant in countries with higher numbers of internet-connected populations, and the U.S. ranks highest with 18.2% of all ransomware attacks. (Symantec)
Most malicious domains, about 60%, are associated with spam campaigns. (Cisco)
About 20% of malicious domains are very new and used around one week after they are registered. (Cisco) 21<br>
slide22. IoT, DDos, and Other Attacks 1 in 13 web requests lead to malware. (Symantec)
Phishing attacks account for more than 80% of reported security incidents. (CSO Online)
By 2023, the total number of DDoS attacks worldwide will be 15.4 million. (Cisco)
Attacks on IoT devices tripled in the first half of 2019. (CSO Online)
30% of data breaches involve internal actors. (Verizon)
IoT devices experience an average of 5,200 attacks per month. (Symantec)
90% of remote code execution attacks are associated with cryptomining. (Purplesec)
1 in 36 mobile devices have high- risk apps installed. (Symantec) 22<br>
slide23. Geography of Mobile Threats TOP 10 countries by number of attacked users *percentage of attacked users in the country from total number of attacked users 23<br>
slide24. TOP 20 mobile threats of 2019 24<br>