COMPUTER(2210) HANOUTS
GCE OLEVELS
DATA SECURITY & ETHICS
8.1 Data Security
Definition
“Computer security means protecting computer hardware, software and information stored on computer
from threats.”
Importance
Data security is about keeping data safe. Many individuals, small businesses and major companies rely
heavily on their computer systems. If the data on these computer systems is damaged, lost, or stolen, it
can lead to disaster.
8.2 Key threats to data security
Following are the key threats to data security
i) Lost or damaged during a system crash - especially one affecting the hard disk
ii) Corrupted as a result of faulty disks, disk drives, or power failures
iii) Lost by accidentally deleting or overwriting files
iv) Lost or become corrupted by computer viruses
v) Hacked into by unauthorized users and deleted or altered
vi) Destroyed by natural disasters, acts of terrorism, or war
vii) Deleted or altered by employees wishing to make money or take revenge on their employer
8.3 Keeping data secure
Steps/measures that can be taken to keep data secure include:
i) Making regular backups of files (backup copies should be stored in fire proof safes or in another
building)
ii) Protecting the data against viruses by running anti-virus software.
iii) Using passwords so that access to data is restricted
iv) Allowing only authorized staff into certain computer areas, e.g. by controlling entry to these areas by
means of ID cards or magnetic swipe cards
v) Always logging off or turning terminals off and if possible locking them
vi) Avoiding accidental deletion of files by write-protecting disks
vii) Using data encryption techniques to code data so that it makes no apparent sense
8.4 Security Risks
8.4.1 Hacking
A. Definition
“The act of gaining illegal access to computer system”
B. Possible Effects
This can lead to identity threat or gaining personal information.
Data can be changed, deleted or corrupted.
C. Methods to Remove Security Risk
Firewalls
Use of strong password and User ID
Use of anti-hacking software
8.4.2 Viruses
A. Definition
“Program or program code that can replicate/ copy itself with the intention of deleting or corrupting files,
or cause the computer to malfunction”
B. Possible Effects
Can cause the computer to crash, stop functioning normally or become unresponsive.
Can delete files/ data
Can corrupt files/ data
C. Methods to remove security Risk
Install anti-virus software
Don’t use software from unknown sources
Be careful when opening emails/ attachments from unknown senders.
8.4.3 Phishing
A. Definition
, B. Possible Effects
The creator of email can gain personal data such as bank account numbers from users when they visit
the fake website. This can lead to a fraud or identity theft.
C. Methods to remove security Risk
Many ISPs filter out phishing emails.
The user should always be cautious when opening emails or attachments.
8.4.4 Pharming
A. Definition
“Malicious code installed on a user’s hard drive or on the web server, the code will redirect the user to a
fake/ bogus website without their knowledge.”
B. Possible Effects
The creator of malicious code can gain personal data such as bank account numbers from users when
they visit the fake website. This can lead to a fraud or identity theft.
C. Methods to remove security Risk
Some anti-spyware can identify and remove the pharming code from the hard drive.
The user should always be alert and look out for the clues that they are being redirected to other
websites.
8.4.5 War driving
A. Definition
“The act of locating and using wireless internet connections illegally; it requires a portable device, a
wireless network card and an antenna to pick up wireless signals.”
B. Possible Effects
It is possible to steal a user's internet time/ allocation by downloading large files (e.g. movie files)
It is possible to hack into the wireless network and steal a user's password and other personal details
C. Methods to remove security Risk
Use of wired equivalent privacy (WEP) encryption
Protect use of the wireless device by having complex passwords before the internet can be accessed
Use of firewalls to prevent outside users from gaining access
The user needs to protect their password from other users; if any unusual activity is seen, then the
password should be changed
8.4.6 Spyware/ Key-logging Software
A. Definition
“Software that gathers information by monitoring key presses on a user’s keyboard; the information is
then sent back to the person who sent the software.”
B. Possible Effects
Give the originator access to all the data entered using a keyboard on the user’s computer.
The software is able to install other spyware, read cookie data and also change a user’s default
browser.
C. Methods to remove security Risk
Use of anti-spyware software
The user should always be alert and look out for clues that their keyboard activity is being monitored.
Use a mouse to select characters from password etc.
8.5 Cookies
Definition
“A COOKIE is a packet of information sent by a web server to a web browser.”
Description
Cookies are generated each time the user visits the website.
Every time a user visits the website, cookies will collect some key information about the user.
They are able to carry out user tracking and also maintain user preferences
Cookies aren’t programs but are simply pieces of data. They can’t actually perform any operations.
They only allow the detection of web pages viewed by a user on a particular website and store user
preferences
The information gathered by cookies forms an ANONYMOUS USER PROFILE and doesn’t contain
personal information (such as credit card numbers or passwords).
Cookies are subject to privacy and security concerns.
Example
When a user buys a CD on a music website, the cookies will have remembered the user’s previous
buying habits and a message like this often follows: ‘Customers who bought items in your Recent
GCE OLEVELS
DATA SECURITY & ETHICS
8.1 Data Security
Definition
“Computer security means protecting computer hardware, software and information stored on computer
from threats.”
Importance
Data security is about keeping data safe. Many individuals, small businesses and major companies rely
heavily on their computer systems. If the data on these computer systems is damaged, lost, or stolen, it
can lead to disaster.
8.2 Key threats to data security
Following are the key threats to data security
i) Lost or damaged during a system crash - especially one affecting the hard disk
ii) Corrupted as a result of faulty disks, disk drives, or power failures
iii) Lost by accidentally deleting or overwriting files
iv) Lost or become corrupted by computer viruses
v) Hacked into by unauthorized users and deleted or altered
vi) Destroyed by natural disasters, acts of terrorism, or war
vii) Deleted or altered by employees wishing to make money or take revenge on their employer
8.3 Keeping data secure
Steps/measures that can be taken to keep data secure include:
i) Making regular backups of files (backup copies should be stored in fire proof safes or in another
building)
ii) Protecting the data against viruses by running anti-virus software.
iii) Using passwords so that access to data is restricted
iv) Allowing only authorized staff into certain computer areas, e.g. by controlling entry to these areas by
means of ID cards or magnetic swipe cards
v) Always logging off or turning terminals off and if possible locking them
vi) Avoiding accidental deletion of files by write-protecting disks
vii) Using data encryption techniques to code data so that it makes no apparent sense
8.4 Security Risks
8.4.1 Hacking
A. Definition
“The act of gaining illegal access to computer system”
B. Possible Effects
This can lead to identity threat or gaining personal information.
Data can be changed, deleted or corrupted.
C. Methods to Remove Security Risk
Firewalls
Use of strong password and User ID
Use of anti-hacking software
8.4.2 Viruses
A. Definition
“Program or program code that can replicate/ copy itself with the intention of deleting or corrupting files,
or cause the computer to malfunction”
B. Possible Effects
Can cause the computer to crash, stop functioning normally or become unresponsive.
Can delete files/ data
Can corrupt files/ data
C. Methods to remove security Risk
Install anti-virus software
Don’t use software from unknown sources
Be careful when opening emails/ attachments from unknown senders.
8.4.3 Phishing
A. Definition
, B. Possible Effects
The creator of email can gain personal data such as bank account numbers from users when they visit
the fake website. This can lead to a fraud or identity theft.
C. Methods to remove security Risk
Many ISPs filter out phishing emails.
The user should always be cautious when opening emails or attachments.
8.4.4 Pharming
A. Definition
“Malicious code installed on a user’s hard drive or on the web server, the code will redirect the user to a
fake/ bogus website without their knowledge.”
B. Possible Effects
The creator of malicious code can gain personal data such as bank account numbers from users when
they visit the fake website. This can lead to a fraud or identity theft.
C. Methods to remove security Risk
Some anti-spyware can identify and remove the pharming code from the hard drive.
The user should always be alert and look out for the clues that they are being redirected to other
websites.
8.4.5 War driving
A. Definition
“The act of locating and using wireless internet connections illegally; it requires a portable device, a
wireless network card and an antenna to pick up wireless signals.”
B. Possible Effects
It is possible to steal a user's internet time/ allocation by downloading large files (e.g. movie files)
It is possible to hack into the wireless network and steal a user's password and other personal details
C. Methods to remove security Risk
Use of wired equivalent privacy (WEP) encryption
Protect use of the wireless device by having complex passwords before the internet can be accessed
Use of firewalls to prevent outside users from gaining access
The user needs to protect their password from other users; if any unusual activity is seen, then the
password should be changed
8.4.6 Spyware/ Key-logging Software
A. Definition
“Software that gathers information by monitoring key presses on a user’s keyboard; the information is
then sent back to the person who sent the software.”
B. Possible Effects
Give the originator access to all the data entered using a keyboard on the user’s computer.
The software is able to install other spyware, read cookie data and also change a user’s default
browser.
C. Methods to remove security Risk
Use of anti-spyware software
The user should always be alert and look out for clues that their keyboard activity is being monitored.
Use a mouse to select characters from password etc.
8.5 Cookies
Definition
“A COOKIE is a packet of information sent by a web server to a web browser.”
Description
Cookies are generated each time the user visits the website.
Every time a user visits the website, cookies will collect some key information about the user.
They are able to carry out user tracking and also maintain user preferences
Cookies aren’t programs but are simply pieces of data. They can’t actually perform any operations.
They only allow the detection of web pages viewed by a user on a particular website and store user
preferences
The information gathered by cookies forms an ANONYMOUS USER PROFILE and doesn’t contain
personal information (such as credit card numbers or passwords).
Cookies are subject to privacy and security concerns.
Example
When a user buys a CD on a music website, the cookies will have remembered the user’s previous
buying habits and a message like this often follows: ‘Customers who bought items in your Recent