Tuesday, February 24, 2009

Week 6

Group presentations
T.A.S.K: Security Information Alpha Team: Eyes Everywhere Lucky #7: Information Security and great Granola Inc. A company has to consider these criteria when going online: Insiders, hackers, social engineering, dumpster diving, viruses, identify thefts, phising, elevation of privilege, hoaxes, spyware, spoofing, sniffer, package tampering Hot Chocolate: Thinking Like the Enemy - People and technology are the two primary lines of security defence Yankees: Stealing SoftwareOur Group, the Bugs: Ethical issues in the working place. One must always talk to the people involved when it comes to ethical issues.

Ethics
Considering ethics in the working place always have to deal with human beings. Ethics are the principles and standards that guide out behavior towards other people. Information ethics considers how individual determine to use information and how information affects them.

All organizations should build a corporate culture based on ethical principles that employees can understand and implement. Furthermore, ePolicies should also be addressed as new technology is easy to abuse. An ethical computer use policy contains general principles to guide user behavior. e-mail privacy policy details the extent to which e-mail messages may be read by others. There is a need for managers to create a corporate culture based on trust. Moreover, the best path for an organization planning to engage in employee monitoring is open communication about the issue.
When an organization has considered the First Line of Defence: The people it can start to consider the Second Line of Defence: The technology.

Class Lecture - Chapter 5
Video: Understanding security and risks
Regulation:
HIPAA: Health Regulation
SOX: Corporate Regulation

GLBA: Banking/finance
You have to take risks to be in a business. Good money comes from taking risks
- Operation risk
- Managing risks
CIA: Confidentiality Information Availability
RSA token

To be a successful business person, use have to have a knowledge or understanding of the risks and threads

No comments:

Post a Comment