Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

English for Information Security. Учебник

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
51
Reading Section
7. Read the following text and state if the following statements are true or false
Text A. What is Data Leakage?
Data leakage is the unauthorized transmission of data from within an organization to an external destination or recipient. The term can be used to describe data that is transferred electronically or physically. Data leakage threats usually occur via the web and email, but can also occur via mobile data storage devices such as optical media, USB keys, and laptops.
Barely a day goes by without a confidential data breach hitting the headlines. Data leakage, also known as low and slow data theft, is a huge problem for data security, and the damage caused to any organization, regardless of size or industry, can be serious. From declining revenue to a tarnished reputation or massive financial penalties to crippling lawsuits, this is a threat that any organization will want to protect themselves from.
There are many different types of data leakage and it is important to understand that the problem can be initiated via an external or internal source. Protective measures need to address all areas to ensure that the most common data leakage threats are prevented.
The Accidental Breach
"Unauthorized" data leakage does not necessarily mean intended or malicious. The good news is that the majority of data leakage incidents are accidental. For example, an employee may unintentionally choose the wrong recipient when sending an email containing confidential data. Unfortunately, unintentional data leakage can still result in the same penalties and reputational damage as they do not mitigate legal responsibilities.
52
The Disgruntled or Ill-Intentioned Employee
When we think of data leakages, we think about data held on stolen or misplaced laptops or data that is leaked over email. However, the vast majority of data loss does not occur over an electronic medium; it occurs via printers, cameras, photocopiers, removable USB drives and even dumpster diving for discarded documents. While an employee may have signed an employment contract that effectively signifies trust between employer and employee, there is nothing to stop them from later leaking confidential information out of the building if they are disgruntled or promised a hefty payout by cybercriminals. This type of data leakage is often referred to as data exfiltration.
Electronic Communications with Malicious Intent
Many organizations give employees access to the internet, email, and instant messaging as part of their role. The problem is that all of these mediums are capable of file transfer or accessing external sources over the internet. Malware is often used to target these mediums and with a high success rate. For example, a cybercriminal could quite easily spoof a legitimate business email account and request sensitive information to be sent to them. The user would unwittingly send the information, which could contain financial data or sensitive pricing information.
Phishing attacks are another cyber attack method with a high data leakage success rate. Simply by clicking on a link and visiting a web page that contains malicious code could allow an attacker to access a computer or network to retrieve the information they need.
Prevent damaging data leakage with DLP (Data Leakage Prevention)
The threat is real, and real threats need serious data leakage prevention. Data loss prevention (DLP) is a strategy that ensures that end users do not send confidential or sensitive information outside of the enterprise
53
network. These strategies may involve a combination of user and security policies and security tools.
DLP software solutions allow administrators to set business rules that classify confidential and sensitive information so that it cannot be disclosed maliciously or accidentally by unauthorized end users. DLP solutions allow you to discover and control all sensitive data easily and identify your riskiest users within seconds. Whether you need to apply controls to source code, engineering drawings, financial data or sensitive trade secrets, such solutions give you granular control over the data that matters without affecting productivity and progress [5].
1. Data leakage is far from being rare.
2. Data leakage always causes financial loss.
3. 
4. Accidental breaches are not punished as strictly as intended ones.
5. E-mails are the most common source of data leakage.
6. Data exfiltration is usually caused by technical disorders.
7. Business e-mail accounts can be easily faked.
8. DLP is a set of rules intended to prevent security breaches.
9. DLP covers various spheres of an enterprise activity.
Vocabulary Section
8. Replace the words in italics by their synonyms
Quantitative and qualitative methods are two fundamental groups of methods are applied for analysis of risk on which assets are exposed in organizations.
Quantitative, where estimation of risk value is connected with application of numerical measures value of resources is defined in amounts,
the frequency of threat occurrence in the number of cases, and susceptibility by
54
the value of probability of its loss, those methods present results in the shape of indicators.
The examples of quantitative methods: Annual Loss Expected,

Qualitative, which do not operate on numerical data, presenting results
in the form of descriptions, recommendations, where risk assessment is connected with:
   
scales for the frequency of threat occurrence and susceptibility for a given threat or:
Description of so called threat scenarios by prediction of the main
risk factors.
The examples of quantitative methods: FMEA/FMECA, The Microsoft Corporate Security Group Risk Management Framework, NIST SP 800-30, CRAMM.
9. Render the following sentences into Russian
Analysis of IT risk is undoubtedly key element of the process of Information Systems security management and therefore management of risk. Publications connected with these problems both domestic and international seem to treat it in arbitrary way. It manifests in multitude of definitions of risk analysis, and also in the fact that risk analysis is often identified with its management. Risk analysis is main and the most important process of risk management, identifies and evaluates risk which has to be controlled, minimized or accepted.
Risk analysis is comprehensive identification of threats and susceptibility
 
determined measures at previously stated level. The aim of risk analysis is
55
provision of information which is indispensable for decision on application of specified methods, security resources in the enterprise.
10. Complete the text by translating Russian phrases given in brackets
Establish Information Risk Management (IRM) Policy. A sound IRM program is founded on (1    IRM) that effectively addresses all elements of information security.
(2    ) currently being developed based on an Authoritative Foundation of supporting documents and guidelines will be helpful (3   ). IRM policy should begin with a high-level policy statement and supporting (4 ), scope, constraints, responsibilities, and approach.
This high-level policy statement should drive subordinate controls policy, (5    ) to facilities security, (6    ).
Finally, IRM policy should be effectively communicated and enforced to all parties. Note that this is important both for (7  ) and, with EDI, the Internet, and other (8  ), for secure interface with the rest of the world.
11. Translate into English
              
       
       
56
     

      

 
 
Speaking Section
12. Work in groups. Analyze the security measures used at the university, categorize them and present to the class
Reading Section
13. Read the following text and present the ideas basing on a plan or a diagram
Text B. Stages of Risk Management Within an Organization
1. Reviewing of Activities and Internal Environment
By reviewing the internal environment of an organisation we can assume how we can identify the risks and find if the risk in the organisation is acceptable or unacceptable. If it is unacceptable, then how we can manage that risk to avoid an upcoming danger or threat. It can be found by an audit committee or by a group. Risk can affect the internal environment of the organisation. It depends on         ed by the management, it depends on the skills of the staff and how they will handle it or if they will handle it themselves or will report to the management of the organisation.
The staff and management should perform their duties with responsibilities and complete their assignments on the given time frame by the management. There should be a continuous monitoring of activities in the organisation and the management should do something for the development of
57
the staff and give them a proper and continuous training so they can be perfect in performing their duties.
2. Setting Objectives
All the organisations face the risks from internal and external environments. Objectives should exist before the management can identify risks affecting the achievements of the organisation. An agency should develop related objectives. There are three broad categories of objectives operations, reporting, and compliance. In operations the company should do all the operations and work very effectively and in a progressive way, there should not be minor faults in the formulations of the products and services of the company. If there are any risks around the operation, the management should make a report and find the solutions of the involved risks. If they avoid it, there will not be compliance risks for the company, and the company can achieve their target successfully.
There are some questions about what risks a company should not accept, for example, quality and environmental compromises, rules and regulations set by the government. They must not accept the legal risks. All the product and services should be a standard quality. The worst outcomes should be assessed for the development of the company.
3. Event identification
An event is an incident arising from external and internal sources that can affect implementation of strategy. There are some external and internal factors through which we can identify events. Economic changes can affect the company financially. Ups and downs in the currency of the country can affect import and export of the company. Natural environment can also affect the company. Environmental damage can be caused by failure in the rules and regulations set by law. Loss of funds through frauds can be a serious problem for
          
contractors and partners can be another bad situation for the company. Technical
58
faults can also be costly for it as they can be time consuming and affect the 
4. Risk Assessment
It is possible that an event can occur and affect successful achievements of the objectives. It can decrease the value of the goods and services, so such risk should be analysed. Management should consider the future events, expected or unexpected. They should always find what is worst that can happen or damage the reputation of the organisation. Risk assessment can use quantitative and qualitative methods.
5. Risk Response
Management determines how it can respond to the risk, analysing the
          
risk tolerance. Management should keep trying to avoid the risk if there are other alternatives in front of company. By doing that we can find out what is good for the company. If the risk occurs the specific actions should be taken by the management to reduce the risk level.
It is easy to analyse the cost side in spite of benefit side. Management should first find the risks in each division or in each business unit. A view of risk can be depicted in several ways focusing on major risks and event categories across divisions.
6. Control Activities
Control activities should be tested to ensure that there is no material weakness or difficulties. Management also should ensure that control activities are carried out in a timely manner. Internal auditor can also support management by providing assurance on the effectiveness and efficiency of control activities. In an organisation they must provide the receipt to customers, cash should be handled with care, information system and data processing system should be strong enough, financial reporting, accounts receivable and investments should
59
        
reports should be investigated properly.
The management should focus on the core areas like information system, contracts, purchasing, grants and other programs, services provided to the community, revenue collection, salaries of employees, and property. Risk with large and moderate impacts should be addressed with control activities.
7. Information Communication
Information is major source to identify risks, and respond them in an appropriate way whether it is external or internal. Information should available for widespread use, all the transactions should be recorded and tracked in actual timing, management should have immediate access to operating and financial         rwise an action should be taken immediately. Data reliability in information system should be assessed carefully, poor assessment or bad management decisions can affect the targets. Communication is another way to be safe from risks, managers and staff need to discuss the matters with each other, and try to find the solutions for the problems. If necessary they should take actions immediately.
8. Monitoring
Ongoing monitoring activities should be continuous process in an organisation. Ongoing monitoring activities will occur through management activities. Division head, line manager, controller, senior management, internal auditor, and external auditor can evaluate the monitoring process. A variety of evaluation techniques are available like checklist, questionnaire, flowchart techniques, performance steps etc. Reporting to the management about the risks is a good way to keep an eye in the organization. It will be far seeing process which can keep safe the organisation from unwanted danger and threats [6].
Video Section
60
14. Watch the following video and summarize its ideas https://www.youtube.com/watch?v=3rud2zpKH58&list=PL6L7K6JgIjATleXyY 0OJqG-DlOYO2x7b3&index=8&t=0s
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]