Components of an information system, Computer Network Security

Assignment Help:

COMPONENTS OF AN INFORMATION SYSTEM

The components of an information system are software, data, hardware, people, procedures and Networks. These 6 components are critical to enable information to be input, then processed, output and finally stored. Each of these components of information system has its own weakness and strength.

Software


The software components of information system are consisting of applications, operating system and utility programs. This software is the most difficult to information system component to secure. Unfortunately, Software is at root of all the common computer security problems. If your software does not behave properly, a number of diverse sorts of problems can crop up: availability, reliability, safety, and security. The extra twist in security situation is that a bad guy is actively trying to make your software misbehave. This makes security certainly a tricky proposition.

Hardware

Security should be intertwined with every part of the system; the hardware is no exception. The interaction between software and hardware must be carefully planned. While doing so, the security of the whole system is strengthened. Hardware Security Module (abbreviated as HSM) is a physical device in form of a plug-in card or an external security device which can be attached to general purpose computer and servers.

The goals of an HSM are the:

a) Secure generation,
b) Secure storage, and
c) The use of cryptographic and data material which is sensitive.

HSMs provide logical and physical protection both of these materials from non- authorized use and potential adversaries. Several HSM systems have means to securely backup the keys they handle either in a wrapped form by means of the computer’s operating system or externally using a smartcard or some of the other security token. HSMs should never allow secrets exportation in the plaintext form, even when migrating between HSMs and performing the backup operations

Data Security

Data stored, processed, and transmitted through computer system should be protected. Data is the valuable asset possessed by an organization and it is the key target of intentional attacks.

People

People are the critical link in the information security program. Though often overlooked in computer security considerations, people have always acted as a thread to information security. Unless policy, training, education, awareness and technology are properly employed to prevent people from accidentally or intentionally damaging or losing the information, they will remain the weak link. Social network engineering can prey on potential to cut corners and the commonplace nature of human error. It can be used to manipulate actions of people to obtain access information about the system. It is imperative that managers continuously recognize the important role that people play in information security program

Procedures

Procedures are written instructions for accomplishing the specific task. When unauthorized user obtains an organization’s procedures, this poses a threat to integrity of the information. Procedures are information in their rights. Thus, knowledge of procedure, as with all critical information should be disseminated among the members of organization only on a need to know basis.

Networks

The IS component which created much of the requirement for the increased computer and information security is networking. When information systems are linked to each other to form the local area network (LAN), and these LAN’s, and these LAN’s are connected to the other networks like the Internet, new security challenges emerges rapidly.


Related Discussions:- Components of an information system

Illustrate the label switching procedure in an mpls network, QUESTION ...

QUESTION a) Explain the terms traffic engineering, class-based queuing, shaping and grooming in an MPLS network. b) Using an example topology, illustrate the label swi

Define checksum, The method used to check errors is checksum . In this m...

The method used to check errors is checksum . In this method data is treated as a sequence of integers and their arithmetic sum is calculated and the carry bits are added to the

Balancing security and access-information security, BALANCING SECURITY AND ...

BALANCING SECURITY AND ACCESS Even with best planning and implementation, it is impossible to obtain perfect security, that is, it is a process, not an absolute. Security should

Encryption, How safe is the encryption of virtual private networks?

How safe is the encryption of virtual private networks?

Elliptic Curves, #questioAn elliptic curve y^2=x^3+ax+b(mod29) includes poi...

#questioAn elliptic curve y^2=x^3+ax+b(mod29) includes points P=(7, 15) and Q=(16, 13) a)Determine the equation of the crve b) Determine all values of x for which there is no point

Name the various layers of the osi model, Problem (a) Name the various ...

Problem (a) Name the various layers of the OSI model. (b) Show, by means of a diagram, how  the TCP/IP  reference model  is different from the OSI-7 reference model? Why is

Explain the usage of digital signature, a) Explain the contents of the Cost...

a) Explain the contents of the Cost Assessment. b) Various Documents are needed for Configuration Management. State three of them, and describe their importance. c) Given tha

Explain about structure of management information, Question 1 a) What is a...

Question 1 a) What is a NMS? Question 2 Explain about Structure of Management Information Question 3 A)In which UDP port number does a protocol entity receive message?

Enterprise information security policy (eisp), Enterprise Information Secur...

Enterprise Information Security Policy (EISP) EISP also known as security policy directly supports the mission of the organization and sets the strategic direction, scope, and t

Broadband Technology, In 10 or more pages, address the following topics (be...

In 10 or more pages, address the following topics (be sure to use diagrams as well as references). 1) Define broadband and baseband transmission technology. 2) Describe broadban

Write Your Message!

Captcha
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd