Студопедия  
Главная страница | Контакты | Случайная страница

АвтомобилиАстрономияБиологияГеографияДом и садДругие языкиДругоеИнформатика
ИсторияКультураЛитератураЛогикаМатематикаМедицинаМеталлургияМеханика
ОбразованиеОхрана трудаПедагогикаПолитикаПравоПсихологияРелигияРиторика
СоциологияСпортСтроительствоТехнологияТуризмФизикаФилософияФинансы
ХимияЧерчениеЭкологияЭкономикаЭлектроника

Physical Information Security

Читайте также:
  1. A pop-quiz. How much you know about the movies? If you are not sure about something, find the information out.
  2. AERONAUTICAL INFORMATION SERVICE
  3. AIRPORTS, NAVIGATION FACILITIES AND AVIATION SECURITY
  4. APPENDIX. Use the table to tell about the four major geophysical methods used in oil exploration.
  5. As information hiding mechanism
  6. AVIATION SAFETY AND SECURITY
  7. BACKGROUND INFORMATION ON THE UNITED STATES OF AMERICA.
  8. Busy, over, took, run, survive, security, heart. Food
  9. Compare the advantages and disadvantages of three of the following as media for communicating information. State which you consider to be the most effective.
  10. Digestion and assimilation of advertised information

1. Physical information security is concerned with physically protecting data and means to access that data (apart from protecting it electronically). Many individuals and companies place importance in protecting their information from a software and/or network perspective, but fewer devote resources to protecting data physically. However, physical attacks to acquire sensitive information do frequently occur. Sometimes these attacks are considered a type of social engineering.

2. Many individuals and companies consider it important to protect their information for a variety of reasons, including financial, competitive, and privacy-related purposes. People who wish to obtain this information may be computer crackers, corporate spies, or other malicious individuals. This information may be directly beneficial to them, such as industrial secrets or credit card numbers. It may also be indirectly beneficial to them. For example, computer passwords do not have inherent value. However, they provide computer system access that may be used to get other information or to disable a person/company electronically. Sometimes these malicious individuals use electronic means or social engineering to gain information. However, sometimes they use direct physical attacks.

3. There are several ways to obtain information through physical attacks or exploitations. A few examples are described below.

Dumpster divingis the practice of searching through the trash of an individual or business in attempt to obtain something useful. In the realm of information security, this frequently means looking for documents containing sensitive information. However, as more and more information is being stored electronically, it is becoming increasingly useful to those seeking information through this means to search for computer disks or other computer hardware which may contain data. Sometimes this data can be restored to provide a wealth of information.

4. Overt document stealing Sometimes attackers will simply go into a building and take the information they need. Frequently when using this strategy, an attacker will masquerade as someone who belongs in the situation. The thief may pose as a copy room employee remove a document from someone's desk, copy the document, replace the original, and leave with the copied document. Alternatively, the individual may pose as a janitor, systematically collecting information and "throwing it away." The individual may then be able to walk right out of the building with a trash bag containing documents that were left out in the open or a sticky note which had been left in a partially open desk drawer on which a user had written his/her passwords.

5. There are many practices commonly used to decrease the possibility of success for these kind of attacks. Document shredding has become common, and the practice is still growing. Also electronic storage media are often prepared for disposal by purging, which erases files which may have been "deleted" by an operating system but never overwritten with other data.

6. Many choose to restrict access to areas where information is kept to those possessing a proper identification badge and/or other form of authorization. This attempts both to decrease the ease with which someone could access documents and to decrease the possibility of someone physically tampering with computer equipment. Along the same lines, many companies train their employees to physically protect documents and other sources of sensitive information on an individual level by locking the information in a file cabinet or by some other means. Also, companies request that employees memorize their passwords rather than writing them down as the paper with the password could be seen or stolen.

 




Дата добавления: 2015-09-10; просмотров: 19 | Поможем написать вашу работу | Нарушение авторских прав

I. Compare the meanings of the following English words with the Russian ones. They may have different meanings. | Software, Hardware and OS Technologies | II. Read the text and find out the topical sentences of the paragraphs. | UNIT II | Silicon Optics Aims to Combine the Best of Both Worlds | IX. Read the following statements and say whether they are true or false . Correct the false ones. | V. Find 1 or 2 sentences which we can omit as inessential in each logical part. | Magnetic Resonance Imaging | VI. Read the text and name the key points raised in it. | Clinical Systems |


lektsii.net - Лекции.Нет - 2014-2024 год. (0.006 сек.) Все материалы представленные на сайте исключительно с целью ознакомления читателями и не преследуют коммерческих целей или нарушение авторских прав