Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:English for Information Security. Учебник
.pdf
51
Reading Section
7. Read the following text and state if the following statements are true or false
Text A. What is Data Leakage?
Data leakage is the unauthorized transmission of data from within an
organization to an external destination or recipient. The term can be used to
describe data that is transferred electronically or physically. Data leakage threats
usually occur via the web and email, but can also occur via mobile data storage
devices such as optical media, USB keys, and laptops.
Barely a day goes by without a confidential data breach hitting the
headlines. Data leakage, also known as low and slow data theft, is a huge
problem for data security, and the damage caused to any organization,
regardless of size or industry, can be serious. From declining revenue to a
tarnished reputation or massive financial penalties to crippling lawsuits, this is a
threat that any organization will want to protect themselves from.
There are many different types of data leakage and it is important to
understand that the problem can be initiated via an external or internal source.
Protective measures need to address all areas to ensure that the most common
data leakage threats are prevented.
The Accidental Breach
"Unauthorized" data leakage does not necessarily mean intended or
malicious. The good news is that the majority of data leakage incidents are
accidental. For example, an employee may unintentionally choose the wrong
recipient when sending an email containing confidential data. Unfortunately,
unintentional data leakage can still result in the same penalties and reputational
damage as they do not mitigate legal responsibilities.

52
The Disgruntled or Ill-Intentioned Employee
When we think of data leakages, we think about data held on stolen or
misplaced laptops or data that is leaked over email. However, the vast majority
of data loss does not occur over an electronic medium; it occurs via printers,
cameras, photocopiers, removable USB drives and even dumpster diving for
discarded documents. While an employee may have signed an employment
contract that effectively signifies trust between employer and employee, there is
nothing to stop them from later leaking confidential information out of the
building if they are disgruntled or promised a hefty payout by cybercriminals.
This type of data leakage is often referred to as data exfiltration.
Electronic Communications with Malicious Intent
Many organizations give employees access to the internet, email, and
instant messaging as part of their role. The problem is that all of these mediums
are capable of file transfer or accessing external sources over the
internet. Malware is often used to target these mediums and with a high success
rate. For example, a cybercriminal could quite easily spoof a legitimate business
email account and request sensitive information to be sent to them. The user
would unwittingly send the information, which could contain financial data or
sensitive pricing information.
Phishing attacks are another cyber attack method with a high data
leakage success rate. Simply by clicking on a link and visiting a web page that
contains malicious code could allow an attacker to access a computer or network
to retrieve the information they need.
Prevent damaging data leakage with DLP (Data Leakage Prevention)
The threat is real, and real threats need serious data leakage
prevention. Data loss prevention (DLP) is a strategy that ensures that end users
do not send confidential or sensitive information outside of the enterprise

53
network. These strategies may involve a combination of user and security
policies and security tools.
DLP software solutions allow administrators to set business rules that
classify confidential and sensitive information so that it cannot be disclosed
maliciously or accidentally by unauthorized end users. DLP solutions allow you
to discover and control all sensitive data easily and identify your riskiest users
within seconds. Whether you need to apply controls to source code, engineering
drawings, financial data or sensitive trade secrets, such solutions give you
granular control over the data that matters without affecting productivity and
progress [5].
1. Data leakage is far from being rare.
2. Data leakage always causes financial loss.
3.
4. Accidental breaches are not punished as strictly as intended ones.
5. E-mails are the most common source of data leakage.
6. Data exfiltration is usually caused by technical disorders.
7. Business e-mail accounts can be easily faked.
8. DLP is a set of rules intended to prevent security breaches.
9. DLP covers various spheres of an enterprise activity.
Vocabulary Section
8. Replace the words in italics by their synonyms
Quantitative and qualitative methods are two fundamental groups of
methods are applied for analysis of risk on which assets are exposed in
organizations.
Quantitative, where estimation of risk value is connected with
application of numerical measures value of resources is defined in amounts,
the frequency of threat occurrence in the number of cases, and susceptibility by

54
the value of probability of its loss, those methods present results in the shape of
indicators.
The examples of quantitative methods: Annual Loss Expected,
Qualitative, which do not operate on numerical data, presenting results
in the form of descriptions, recommendations, where risk assessment is
connected with:
scales for the frequency of threat occurrence and susceptibility for a given threat
or:
Description of so called threat scenarios by prediction of the main
risk factors.
The examples of quantitative methods: FMEA/FMECA, The Microsoft
Corporate Security Group Risk Management Framework, NIST SP 800-30,
CRAMM.
9. Render the following sentences into Russian
Analysis of IT risk is undoubtedly key element of the process of
Information Systems security management and therefore management of risk.
Publications connected with these problems both domestic and international
seem to treat it in arbitrary way. It manifests in multitude of definitions of risk
analysis, and also in the fact that risk analysis is often identified with its
management. Risk analysis is main and the most important process of risk
management, identifies and evaluates risk which has to be controlled, minimized
or accepted.
Risk analysis is comprehensive identification of threats and susceptibility
determined measures at previously stated level. The aim of risk analysis is

55
provision of information which is indispensable for decision on application of
specified methods, security resources in the enterprise.
10. Complete the text by translating Russian phrases given in brackets
Establish Information Risk Management (IRM) Policy. A sound IRM
program is founded on (1 IRM) that
effectively addresses all elements of information security.
(2 )
currently being developed based on an Authoritative Foundation of supporting
documents and guidelines will be helpful (3 ).
IRM policy should begin with a high-level policy statement and supporting (4
), scope, constraints, responsibilities, and approach.
This high-level policy statement should drive subordinate controls policy,
(5 ) to facilities security, (6
).
Finally, IRM policy should be effectively communicated and enforced to
all parties. Note that this is important both for (7 ) and,
with EDI, the Internet, and other (8 ), for secure interface
with the rest of the world.
11. Translate into English

56
Speaking Section
12. Work in groups. Analyze the security measures used at the university,
categorize them and present to the class
Reading Section
13. Read the following text and present the ideas basing on a plan or a diagram
Text B. Stages of Risk Management Within an Organization
1. Reviewing of Activities and Internal Environment
By reviewing the internal environment of an organisation we can assume
how we can identify the risks and find if the risk in the organisation is acceptable
or unacceptable. If it is unacceptable, then how we can manage that risk to avoid
an upcoming danger or threat. It can be found by an audit committee or by a
group. Risk can affect the internal environment of the organisation. It depends on
ed by the management, it
depends on the skills of the staff and how they will handle it or if they will
handle it themselves or will report to the management of the organisation.
The staff and management should perform their duties with
responsibilities and complete their assignments on the given time frame by the
management. There should be a continuous monitoring of activities in the
organisation and the management should do something for the development of

57
the staff and give them a proper and continuous training so they can be perfect in
performing their duties.
2. Setting Objectives
All the organisations face the risks from internal and external
environments. Objectives should exist before the management can identify risks
affecting the achievements of the organisation. An agency should develop related
objectives. There are three broad categories of objectives operations, reporting,
and compliance. In operations the company should do all the operations and
work very effectively and in a progressive way, there should not be minor faults
in the formulations of the products and services of the company. If there are any
risks around the operation, the management should make a report and find the
solutions of the involved risks. If they avoid it, there will not be compliance risks
for the company, and the company can achieve their target successfully.
There are some questions about what risks a company should not accept,
for example, quality and environmental compromises, rules and regulations set
by the government. They must not accept the legal risks. All the product and
services should be a standard quality. The worst outcomes should be assessed for
the development of the company.
3. Event identification
An event is an incident arising from external and internal sources that can
affect implementation of strategy. There are some external and internal factors
through which we can identify events. Economic changes can affect the
company financially. Ups and downs in the currency of the country can affect
import and export of the company. Natural environment can also affect the
company. Environmental damage can be caused by failure in the rules and
regulations set by law. Loss of funds through frauds can be a serious problem for
contractors and partners can be another bad situation for the company. Technical

58
faults can also be costly for it as they can be time consuming and affect the
4. Risk Assessment
It is possible that an event can occur and affect successful achievements
of the objectives. It can decrease the value of the goods and services, so such risk
should be analysed. Management should consider the future events, expected or
unexpected. They should always find what is worst that can happen or damage
the reputation of the organisation. Risk assessment can use quantitative and
qualitative methods.
5. Risk Response
Management determines how it can respond to the risk, analysing the
risk tolerance. Management should keep trying to avoid the risk if there are other
alternatives in front of company. By doing that we can find out what is good for
the company. If the risk occurs the specific actions should be taken by the
management to reduce the risk level.
It is easy to analyse the cost side in spite of benefit side. Management
should first find the risks in each division or in each business unit. A view of risk
can be depicted in several ways focusing on major risks and event categories
across divisions.
6. Control Activities
Control activities should be tested to ensure that there is no material
weakness or difficulties. Management also should ensure that control activities
are carried out in a timely manner. Internal auditor can also support management
by providing assurance on the effectiveness and efficiency of control activities.
In an organisation they must provide the receipt to customers, cash should be
handled with care, information system and data processing system should be
strong enough, financial reporting, accounts receivable and investments should

59
reports should be investigated properly.
The management should focus on the core areas like information system,
contracts, purchasing, grants and other programs, services provided to the
community, revenue collection, salaries of employees, and property. Risk with
large and moderate impacts should be addressed with control activities.
7. Information Communication
Information is major source to identify risks, and respond them in an
appropriate way whether it is external or internal. Information should available
for widespread use, all the transactions should be recorded and tracked in actual
timing, management should have immediate access to operating and financial
rwise an action
should be taken immediately. Data reliability in information system should be
assessed carefully, poor assessment or bad management decisions can affect the
targets. Communication is another way to be safe from risks, managers and staff
need to discuss the matters with each other, and try to find the solutions for the
problems. If necessary they should take actions immediately.
8. Monitoring
Ongoing monitoring activities should be continuous process in an
organisation. Ongoing monitoring activities will occur through management
activities. Division head, line manager, controller, senior management, internal
auditor, and external auditor can evaluate the monitoring process. A variety of
evaluation techniques are available like checklist, questionnaire, flowchart
techniques, performance steps etc. Reporting to the management about the risks
is a good way to keep an eye in the organization. It will be far seeing process
which can keep safe the organisation from unwanted danger and threats [6].
Video Section

60
14. Watch the following video and summarize its ideas
https://www.youtube.com/watch?v=3rud2zpKH58&list=PL6L7K6JgIjATleXyY
0OJqG-DlOYO2x7b3&index=8&t=0s
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
