Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

English for Information Security. Учебник

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
11
data; that is why information security is a necessity. _______________________ Let's take a look at the history of information security.
1960s: Organizations start to protect their computers
The largest security concerns at this interval were at the points of access. Anyone with enough knowledge about how to work a computer could break into a facility and start accessing sensitive data. _________________________, passwords and multiple layers of security protection were added to devices. 1970s: The first hacker attacks begin
At this point in the history of information security, network computing was in its infancy (the internet as we know it today wouldn't exist until the end of the 1980s). However, while there was no massive global network connecting every device that wanted to be connected, large organizations, especially governments, were starting to link computers via telephone lines. Recognizing this, people started to seek ways to infiltrate phone lines connected to computers, so that they could steal data._____________________________. 1980s: Governments become proactive in the fight against cybercrime
By the 1980s, hacking had already grown into an international crime issue. Limited information security systems could not keep up with the constant barrage of clever approaches hackers used to break into computer systems. This fact became extremely prominent when a small group of teenagers from Milwaukee, known as "the 414s," broke into over 60 military and corporate computer systems and stole over $70 million from U.S. banks. In response to this information security crisis, governments started to actively pursue hackers, including the 414s. At this point in time, the sentences were exceedingly light, ______________________. 1990s: Organized crime gets involved in hacking
After the worldwide web was made available in 1989, people started putting their personal information online; ________________________, and
12
started to steal data from people and governments via the web. Firewalls and antivirus programs helped protect against this, but the web was a mostly unsecured and rapidly burgeoning network. 2000s: Cybercrime becomes treated like a crime
While governments had been pursuing cyber criminals for decades, most punishments were light, often being limited to a confiscation of computer equipment and a ban from computer use for a certain period of time. This changed in the 2000s as governments started to recognize the dangers of hacking. Hackers were jailed for years _______________________. Jeanson James Ancheta, for example, who used hacking to steal less than a millionth of a percent of the amount that "the 414s" stole, was sentenced to five years of jail time. By 2010, high-profile hackers were getting decades in prison for cybercrimes.
2010s: Information security becomes serious
Although criminal prosecutions, firewalls and antivirus software had served as deterrents to cybercriminals, they did not stop hackers . At this point in the history of information security, security experts started to realize that the best way to protect data was to make it truly inaccessible to hackers. To this end, data encryption, which scrambles data to render it unreadable to unauthorized users, became more widespread. In many cases, encryption occurs at multiple levels, including on digital files, networks and during data transmissions. Organizations now also implement comprehensive information security policies that prevent their employees from making any mistakes that make data accessible to intruders [2].
Vocabulary Section
9. Complete the text using the words given below Primary, leans, allowed, dedicated, facets, vulnerability, unsecure, evolved
13
Early IS records identified confidentiality, integrity and availability as
             
the Hexad include confidentiality / control, information integrity, authenticity,
         
cryptography in order to guard against threats.
During the early years of computing, the mainframes used by the military
           ts between the data centres and the public. 
10. Complete the text by translating Russian phrases given in brackets
Information held by (1    
) is a critical resource that enables organisations to succeed in their
mission. Additionally, individuals have a reasonable expectation that their (2  , ) IT products or systems remains private, be available to them as needed, and not be subject to (3  ). IT products or systems (4    ) while exercising proper control of the information to ensure that it (5 
 ) such as (6    ,   ). The term IT security is used to cover prevention and
mitigation of these and similar hazards.
Many consumers of IT (7   ,   ) necessary to judge whether their confidence in the security of their IT products or systems is appropriate, and they (8        ).
14
Consumers may therefore choose to increase their confidence in the security measures of an IT product or system by ordering (9  ).
The CC can be used to select the appropriate IT security measures and it contains criteria for evaluation (10  ).
11. Render the following sentences into English
.
2.      
.
3.      
    , , .
4.         ,       ( ),     (, ,     .),     .
5. .
Speaking Section
12. Work in groups of three. Think of common measures taken to ensure the information safety
Reading Section
15
13. Read the text. Summarize the changes in information security area,
give the examples of C-I-A breaches and the countermeasures
Text B. Information Security in the Enterprise and Modern Challenges
Securing enterprise information has never been more challenging. The 21st century has been bombarded with technological innovations aimed at a tech savvy youthful market and communication is getting more open in a world that is truly getting smaller by the day; we are living in a global village. Traditionally, security has been seen as a government or a political function and many people are used to the thinking that security is taken out of taxpayers money paid to the taxman. While this assumption may be true, the trend of modern technology in the 21st century and beyond definitely shows that the traditional views of securing information, data and assets within the enterprise needs a rethink.
In the early days of computing and programming, hackers were hacking systems just to show they were cool or more knowledgeable. Hacking a system at that time was seen as a way to prove a level of competence and understanding; you had to be a very good computer code developer or network expert to be able to hack a system. Those days are long gone and over. The motives for modern attacks have been mostly for financial gain or revenge by disgruntled ex­employees. Hackers are breaching security controls of banking databases and stealing valuable personal account information for illegal reuse. Companies are also being held to ransom by information thieves who have succeeded in breaking into their infrastructure and compromising existing controls to steal valuable enterprise information. In other cases, equipment containing sensitive enterprise data has been stolen. You do not need to be a computer geek or a programming expert to be able to breach security on the Internet. There are so many free tools online available to people who are not computer savvy with easy-to-configure interfaces and single click activation processes, that cracking
16
into their machines is almost too easy. This is probably the most potent and fastest growing security concerns for the enterprise in the modern era.
Confidentiality, Integrity and Availability are the three core fundamental principles of all security systems. The three are sometimes referred to as the C-I­A triad of information security.
Confidentiality deals with controls that need to be put in place to guarantee that an adequate level of security with enterprise data, asset and information is ensured at different stages of business operations to prevent unwanted or unauthorized disclosure. Confidentiality should be maintained when information is stored and also when in-transit through the rank and file of the organization no matter the format hard or soft, physical or electronic from source to destination. Strict access control, user awareness training and data encryption are some very good countermeasures that help to secure enterprise information against confidentiality breaches.
Integrity deals with the controls that have to do with ensuring that enterprise information is both internally and externally consistent. Integrity also guarantees that unauthorized modification of information is prevented. Integrity also certifies that there is no unexpected alteration of information in the system. All the information systems infrastructure should normally work in concert to ensure integrity of data and information within the enterprise operating environment. Applications should come equipped with capabilities to check input the data for errors; authorization should also be given on a need-to-know basis with proper classification to make certain that sensitive data is not inadvertently tampered with.
Availability ensures that data is accessed by authorized individuals in a reliable and efficient way. The network environment should behave in a predictable manner so that information and data are accessible whenever it is necessary. Recovery from system failures is an important factor when talking
17
about information availability and such recovery should also be in a manner that does not affect operations negatively. Backup systems should be in place to replace critical systems, single point of failure should be avoided, and information systems should be deployed in controlled environmental conditions. Installing patches on systems, adequate router configuration, workstation configuration management and deploying a firewall are some of the ways to mitigate attacks aimed at system availability [1].
Video Section
14. Watch the following video and create your own video on Security Basics and IT Security Tips
https://www.youtube.com/watch?v=7L9JerWIT3Y
18
UNIT 2 CRYPTOGRAPHY LEAD-IN
Cryptography  [Gr., hidden writing], science of secret writing. There are many devices by which a message can be concealed from the casual reader, e.g., invisible writing, but the term cryptography strictly applies to translating messages into cipher or code. The code is the agreed upon set of rules whereby messages are converted from one form to another. The beginnings of cryptography can be traced to the hieroglyphs of early Egyptian civilization (c.1900 BC). Ciphering has always been considered vital for diplomatic and military secrecy; the Bible is replete with examples of ciphering, and many figures throughout history have written in ciphers, including Julius Caesar, Charlemagne, Alfred the Great, Mary Queen of Scots, and Louis XIV. Francis Bacon's celebrated biliteral cipher (1605) was an arrangement of the letters a and b in five-letter combinations, each representing a letter of the alphabet. This code illustrates the important principle that a code employing only two different signs can be used to transmit information.
Pronunciation
1. Make sure you pronounce the following words correctly
Hieroglyph [h()rlf]
identity [dntti]
sophisticated [sfstketd]
cipher [sf]
entrepreneur [ntrprn]
variable [vb()l]
biliteral [blt()r()l]
supremacy [msi]
consequence [knskw()ns]
incentivization [ntv  zen]
Caesar []
insurance [r()ns]
inherent [r()nt]
unauthorized [rzd]
threat [t]
19
Word Study
2. Study the following definitions and memorize the terms
ad hoc - done only when needed for a specific purpose,
without planning or preparation. Synonyms: random, arbitrary, spontaneous, not planned. E.g. She has a very ad hoc approach to management.
Amend - to make changes to
a document, law, agreement etc, especially in order to improve it. Synonyms: improve, change, alter, modify. E.g. A law amending the
Chilean constitution was approved on 22nd January.
Coin (v) – to invent and introduce, especially a new term.
Synonyms: invent, introduce, think of. E.g. The term was coined in the 20th
century.
Conceal - to prevent someone from seeing or knowing, to keep
something secret. Synonyms: hide, cover, obscure. E.g. The letters had
been concealed under a mattress.
Fuel (v) - to make something increase or
become worse, especially something unpleasant. Synonyms: worsen, escalate, aggravate. E.g. People‟s fear of crime is fuelled by sensationalist reports.
Garbled message - confusing, or not accurate. Synonyms:
complicated, difficult, confusing. E.g. a garbled and unconvincing explanation.
Intruder - someone who enters a place where they are not allowed to
go, especially to commit a crime. Synonyms: cybercriminal, forger, hacker. E.g.
The dog scared off intruders who had tried to break into the house.
Invisible watermarking - a type of steganography that aims at
concealing information in a medium to prove ownership, integrity or provide additional information. If it's used to support copyright, its first priority is robustness against destruction and spoofing.
20
Plaintext - text that is not computationally tagged, specially formatted, or written in code.
Replete - fully or abundantly provided or filled. Synonyms: full, complete. E.g. For him, the city was replete with memories.
Retrieve - to find information that is stored in a computer in order to use it again. Synonyms: access, archive, back up. E.g. retrieve the original message.
Sophisticated - highly complicated or developed, advanced in design. Synonyms: complex, complicated, intricate. E.g.
highly sophisticated surveillance equipment.
Unintended – not deliberate or planned, undesired. E.g. unintended recipient.
3. Match the words with their antonyms. Give the Russian equivalents
conceal
ciphertext
clear
nonauthor
intruder
regress
planned
reveal
plain, simple
retrieve
decline
lose, damage
ad hoc
sophisticated
scribe
authorized user
garbled
evolve
plaintext
proliferation
4. Match the terms and their Russian equivalents
incentivization
supremacy
 
 
merit
evidence
 
 
broadcast
backbone
 

variable
entrepreneur


common
inherent


Grammar Section
Present Tenses, Active and Passive (see Appendix)
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]