Английский язык (Информационные системы в управлении). Учебное пособие
.pdfWhat means and methods of information protection can you name?
Which ones do you personally use?
TEXT A
Read and translate the text.
Vocabulary list:
security policy - политика безопасности threat - опасность, угроза
secure - безопасный priority - приоритет
national Security Council (NSC) - Совет национальной безопасности, СНБ
pursue - заниматься
encompass - выполнять, осуществлять pursuit - преследование, исполнение securities - ценные бумаги
share-акция
lender, obligee - кредитор
THE CONCEPT OF SECURITY
Security is a word in common use, used in relation to a wide variety of personal and collective activities and conditions:
-thestate of being free from danger or threat;
-the safety of a state or organization against criminal activity such as terrorism, theft, or espionage;
-procedures followed or measures taken to ensure the security
of a state or organization;
- the state of feeling safe, stable, and free from fear or anxiety. One can distinguish between security in normal daily activi-
ties (job, economy, sex, transport, food), security for positive, desirable conditions (democracy, freedom, prosperity, development,
31
a good life), and security against negative conditions (War, pollution, crime, all kinds of threats).
"Security" as a concept and as a phenomenon at the end of the cold war has taken on new forms. There are new security agendas, new security manifestations, and new rules of the game for security policy. In a way we have three different realms for the term "security." first, the broad, day-to-day use of the word, referring to a position aspired to: of being safe, secure, protected. Second, the political use of the word, referring to political actions, processes, or structures that can secure the safety of a political unit. In the political sphere the term "security" is used as a political tool, for example, to provide a certain phenomenon with a specific priority by placing it in the realm of high politics. Finally,"security" can be used as an analytical concept to identify, describe, understand, explain, or even predict phenomena in the general social realm; phenomena such as "security policy,” "security policy interaction,” or “"security institutions and structures”.
A significant change in the political use of the term "security" was, however, the invention of the concept of security policy. The United States, as one of the most important unit in the international system, was the initiator. In 1947 the US administration introduced the National Security Council, which became a model for several countries around the world. This also involved the introduction of a new concept, "security policy." Now it became possible for states, in linguistic terms, to conduct or pursue a security policy. Security policy was more than defense policy, more than military policy, more than a policy aimed at being prepared for war. Security policy also aimed at avoiding war. Security policy encompassed internal, domestic security, economic-development policy, and policy for influencing the international system so as to create a peaceful environment, regionally as well as globally, including foreign aid to developing countries.
Security policy became an important tool for individual nation states to further their national interests by attempting to influence the international system. The pursuit of international security policy was the task of the United Nations (UN). The political notion of security was extended, from referring primarily to matters related to defense and the military, such as the avoidance of military aggression, to deal-
32
ing with economic, political, and societal matters, domestic as well as international.
1. Finance: A financing or investment instrument issued by a company or government agency that denotes an ownership interest and provides evidence of a debt, a right to share in the earnings of the issuer, or a right in the distribution of a property. Securities include bonds, debentures, notes, options, shares, and warrants but not insurance policies, and may be traded in financial markets such as stock exchanges.
2. Banking: An asset pledged to guaranty the repayment of a loan, satisfaction of an obligation, or in compliance of an agreement. Security gives a lender or obligee a legal right of access to the pledged asset and to take their possession and title in case of default for a foreclosure sale.
3. Computing: The extent to which a computer system is protected from data corruption, destruction, interception, loss, or unauthorized access.
4. The prevention of and protection against assault, damage, fire, fraud, invasion of privacy, theft, unlawful entry, and other such occurrences caused by deliberate action.
Task 1. Answer the following questions to the text.
1.What is the common use of the word "security"?
2.What new forms has the concept of "Security" taken?
3.What are the three different realms for the term "security"?
4.What was the role of the invention of the concept of security
policy?
5.What types of policy did security policy encompass?
6. Why |
is |
security |
important |
in |
Finance? |
Banking? |
Computing? |
|
|
|
|
|
|
Task 2. State if the following statements are true or false.
1. There are new security agendas, new security manifestations, and new rules of the game for security agency.
33
2.Security is a word used in relation to a wide variety of personal and collective activities and conditions.
3.One can distinguish between security in normal daily activities, security for positive, desirable conditions, and security
against negative conditions.
4.There are four different realms for the term "security."
5.The broad, day-to-day use of the word, refer to a position
aspired to: political actions, processes, or structures that can secure the safety of a political unit.
6.The political use of the word refers to: of being safe, secure, protected.
7."Security" can be used as an analytical concept to identify, describe, understand, explain, or even predict phenomena in the general social realm.
8.A significant change in the political use of the term "security" was the invention of the concept of security policy.
Task 3. Complete the text using the words given below.
Amateur hackers |
|
|
|
access individuals |
along with |
advantage |
websites |
Before 2004, much of the online |
nuisance came from amateur |
||
hackers who defaced ………… and wrote malicious software in pursuit of bragging rights. Some of these ………… were self-taught computer savants, such as Kevin Mitnick (2011), who attempted to gain ………… tointernal data in order to gain status or to test the lim-
its of what they could get away with. Others were small-time hackers who took ………… of poor security in order to gain small payoffs, such as increasing their hours on internet service provider AOL. Today, amateur hackers still exist ………… crackers, IP pirates, and leechers, but they do not represent the most significant economic threats on the internet.
34
TEXT B
Read and translate the text.
Vocabulary list:
evolve – to develop gradually.
access – (noun) the means or opportunity to approach or enter a
place.
to access - (verb) approach or enter (a place); obtain or retrieve (computer data or a file). Information can be accessed from several files and displayed at the same time .
sensitive data – information that must be protected from unauthorized access to safeguard the privacy or security of an individual or organization (personal, business and classified information).
infiltrate - to secretly become part of a group in order to get information or to influence the way that group thinks or behaves.
unauthorized user - someone who gains access to a website, program, server, service, or other system using someone else's account
or other methods without official permission.
INFORMATION SECURITY IN THE ENTERPRISEAND
MODERN CHALLENGES
Securing enterprise information has never been more challenging. The 21st century has been bombarded with technological innovations aimed at a tech savvy youthful market and communication is getting more open in a world that is truly getting smaller by the day; we are living in a global village. Traditionally, security has been seen as a government or a political function and many people are used to the thinking that security is taken out of taxpayers money paid to the taxman. While this assumption may be true, the trend of modern technology in the 21st century and beyond definitely shows that the traditional views of securing information, data and assets within the enterprise needs a rethink.
In the early days of computing and programming, hackers were hacking systems just to show they were cool or more knowledgeable. Hacking a system at that time was seen as a way to prove a level of competence and understanding; you had to be a very good computer
35
code developer or network expert to be able to hack a system. Those days are long gone and over. The motives for modern attacks have
been |
mostly for |
financial |
gain |
or revenge by disgruntled ex- |
employees. Hackers are breaching security controls of banking data- |
||||
bases and stealing valuable personal account information for illegal |
||||
reuse. |
Companies |
are also |
being |
held to ransom by information |
thieves who have succeeded in breaking into their infrastructure and compromising existing controls to steal valuable enterprise information. In other cases, equipment containing sensitive enterprise data has been stolen. You do not need to be a computer geek or a programming expert to be able to breach security on the Internet. There are so many free tools online available to people who are not computer savvy with easy-to-configure interfaces and single click activation processes, that cracking into their machines is almost too easy. This is probably the most potent and fastest growing security concerns for the enterprise in the modern era.
Confidentiality, Integrity and Availability are the three core fundamental principles of all security systems. The three are sometimes referred to as the C-I-A triad of information security. Confidentiality deals with controls that need to be put in place to guarantee that an adequate level of security with enterprise data, asset and information is ensured at different stages of business operations to prevent unwanted or unauthorized disclosure. Confidentiality should be maintained when information is stored and also when in-transit through the rank and file of the organization no matter the format – hard or soft, physical or electronic – from source to destination. Strict access control, user awareness training and data encryption are some very good countermeasures that help to secure enterprise information against confidentiality breaches.
Integrity deals with the controls that have to do with ensuring that enterprise information is both internally and externally consistent. Integrity also guarantees that unauthorized modification of information is prevented. Integrity also certifies that there is no unexpected alteration of information in the system. All the information systems infrastructure should normally work in concert to ensure integrity of data and information within the enterprise operating environment. Applications should come equipped with capabilities to check input
36
the data for errors; authorization should also be given on a need-to- know basis with proper classification to make certain that sensitive data is not inadvertently tampered with.
Availability ensures that data is accessed by authorized individuals in a reliable and efficient way. The network environment should behave in a predictable manner so that information and data are accessible whenever it is necessary. Recovery from system failures
is an important factor when talking about information availability and such recovery should also be in a manner that does not affect operations negatively. Backup systems should be in place to replace critical systems, single point of failure should be avoided, and information systems should be deployed in controlled environmental conditions. Installing patches on systems, adequate router configuration, workstation configuration management and deploying a firewall are some of the ways to mitigate attacks aimed at system availability.
Task 1. Summarize the changes in information security area, give the examples of C-I-A breaches and the countermeasures.
Task 2. Answer the following questions to the text.
1.How do you understand the author's statement:“we are living in a global village”?
2.How has security been seen traditionally?
3.Why do the traditional views concerning securing information, data, and assets within the enterprise need a rethink now?
4.What was the aim of hackers in the early days of computing and programming?
5.What are the motives for modern attacks?
6.What are the three core fundamental principles of all security
systems?
7.How do you understand the principle “confidentiality”?
8.What does integrity deals with?
9.What does availability ensure?
37
Task 3. Translate the following phrases from the text into Russian and memorize them.
a computer geek, authorized individuals, enterprise information, fundamental principles, banking databases, sensitive data, system failures, strict access control, computer code developer, network expert, an adequate level of security, unauthorized modification, modern attacks, illegal reuse
Task 4. Work in groups of three. Think of common measures taken to ensure the information safety.
Task 5. Complete the text using the words and phrases given below.
identity theft corporations specific victims disrupt involve
Cybercrime - the use of a computer as an instrument to further illegal ends, such as committing fraud, trafficking in child pornography and intellectual property, stealing identities, orviolating privacy.Cybercrime, especially through the Internet, has grown in importance as the computer has become central to commerce, entertainment, and government.
Types of cyber crimes
Cybercrime ranges across a spectrum of activities. At one end are crimes that ………… fundamental breaches of personal or corporate privacy, such as assaults on the integrity of information held in digital depositories and the use of illegally obtained digital information to blackmail a firm or individual. Also at this end of the spectrum is the growing crime of ………… Midway along the spectrum lie transac- tion-based crimes such as fraud, digital piracy, money laundering, and counterfeiting. These are specific crimes with ………… , but the criminal hides in the relative anonymity provided by the Internet.
Another part of this type of crime involves individuals within
………… or government bureaucracies deliberately altering data for either profit or political objectives. At the other end of the spectrum are those crimes that involve attempts to ………… the actual work-
38
ings of the Internet. These range from spam, hacking, and denial of serviceattacks against specific sites to acts of cyberterrorism - that is, the use of the Internet to cause public disturbances and even death. Cyberterrorism focuses upon the use of the Internet by nonstate actors to affect a nation's economic and technological infrastructure
Task 6. These phrases and sentences have been removed from the following text. Read the text and complete it. There is one extra sentence that you don’t need.
-implement comprehensive information security policies
-these people became the first groups of hackers
-cloud technologies reduced document storage costs
-were added to devices
-putting their personal information online
-as punishment for cybercriminal activity…
-hacking had already grown into an international crime issue.
The History of Information Security
These days, information flows throughout computer systems like fish flow through the sea. This presents a range of opportunities for people to steal data; that is why information security is a necessity.
But how has information security evolved over the years? Let's take a look at the history of information security.
1960s: Organizations start to protect their computers. The largest security concerns at this interval were at the points of access. Anyone with enough knowledge about how to work a computer could break into a facility and start accessing sensitive data. In order to secure terminals, passwords and multiple layers of security protection____________________________.
1970s: The first hacker attacks begin. At this point in the history of information security, network computing was in its infancy (the internet as we know it today wouldn't exist until the end of the 1980s). However, while there was no massive global network connecting every device that wanted to be connected, large organizations, especially governments, were starting to link computers via telephone lines. Recognizing this, people started to seek ways to infiltrate phone
39
lines connected to computers, so that they could steal data._____________________________.
1980s: Governments become proactive in the fight against cybercrime. By the 1980s,______________________. Limited information security systems could not keep up with the constant barrage of clever approaches hackers used to break into computer systems. This fact became extremely prominent when a small group of teenagers from Milwaukee, known as "the 414s," broke into over 60 military and corporate computer systems and stole over $70 million from U.S. banks. In response to this information security crisis, governments started to actively pursue hackers, including the 414s. At this point in time, the sentences were exceedingly light, ranging from stern warnings to probation.
1990s: Organized crime gets involved in hacking. After the worldwide web was made available in 1989, started______________________; organized crime entities saw this
as a potential revenue source, and started to steal data frompeople and |
|
||||||
governments via the web. Firewalls and antivirus programs helped |
|
||||||
protect against this, but the web was a mostly unsecured and rapidly |
|
||||||
burgeoning network. |
|
|
|
|
|
|
|
2000s: Cybercrime becomes treated like a crimeWhile. |
gov- |
|
|||||
ernments had been pursuing cyber criminals for decades, most pun- |
|
||||||
ishments were light, often being limited to a confiscation of computer |
|
||||||
equipment and a ban from computer use for a certain period of time. |
|
||||||
This changed in the 2000s as governments started to recognize the |
|
||||||
dangers |
of |
hacking. |
Hackers |
were |
jailed |
for |
|
_______________________. Jeanson James Ancheta, for example, who used hacking to steal less than a millionth of a percent of the amount that "the 414s" stole, was sentenced to five years of jail time. By 2010, high-profile hackers were getting decades in prison for cybercrimes.
2010s: Information security becomes serious.Although criminal prosecutions, firewalls and antivirus software had served as deterrents to cybercriminals, they did not stop hackers. At this point in the history of information security, security experts started to realize that the best way to protect data was to make it truly inaccessible to hackers. To this end, data encryption, which scrambles data to render it
40
