Wednesday, 28 November 2012

2-14 Back Up & Recovery

A Backup is simply an extra copy of data.

If data become Corrupted or Stolen, it can be restored from the back up copy.

A Backup and Recovery stratergy is needed to plan how data is backed up and how it will be recovered

"Of all Companies that had a major loss of computerised records, 43% never re-open, 51% close within two years and only 6% will survive long-term."


Back up media, is the storage device used to store the back up
 - Examples would be:

  • CDR or DVDR Disk
  • Removable flash drive
  • Removeable hard disk (Store large amounts of data, can be kept away from the main computer)
  • RAID systems - instant backups in real time for large systems
  • DAT Tape - Large capacity, used by business
  • The Cloud - Remote backup services can be used for online back ups
Stratergy's for protecting  Data 
Back up Stratergy
•What files should be backed up?
•Who is responsible?
•When will the backups be done and which type?
•Where will the backups be stored?
•Which backup media will be used?

Recovery Stratergy
 •What files, OS & Applications need to be recovered?
 •Who is responsible?
 •When will the deadlines for recovery be?
 •Where are recovery offices and computer equipment?
 •How will we ensure continuity of service?

Types of Backup


Friday, 9 November 2012

Computer Misuse Act Homework

Level 1 - Unauthorised access to computer material
  • Case: NHS Primary Care Trust Manage Accessed confidential female NHS patients records for personal use.
  • Sentence: 6months imprisonment and suspension from work for two years.
  • Summary: This person used sensitive information for his personal gain, therefore his sentence was fairly light for what he was using it for.
Level 2 - Unauthorised access to computer material with intent to commit a crime
  • Case: Computer Operator at Henderson Financial Investment Services accused of hacking into the company's computer system with the intend to defraud her employer of 1 million pounds. 
  • Sentence: 5 Years imprisonment & 1 million pound fine.
  • Summary: This person attempted to steal large sums of money from her employer for her personal gain, her sentence is fairly moderate for what she did.
Level 3 - Unauthorised modification of computer material
  • Case: Franchise manager aka warpigs virus writer used malware attached to spam to spy on victims using their webcams and steal their personall information.
  • Sentence Eighteen month imprisonment.
  • Summary: This person used his skills to his personall gain and took away people personal information, he only recieved eighteen months imprisonment for his actions.
Source of information: http://computerevidence.co.uk/Cases/CMA.htm

Tuesday, 6 November 2012

2-13 - Threats to ICT Systems


Five Threats to ICT Systems:

- Disgruntled Employees
- After an employee has been made redundant, once they find this out they could go back to their desk and make changes to the computer system, copy files or even delete them.
- An example would be deleting client details from a computer system after an employee has been fired.
- A way to guard against this would be to either remove the employee straight away from the company or to restrict the access to the system such as only being able to access file as read only. 
- Untrained Staff
- An untrained employee could make errors to the system or even go against company policy.
- An example could be an employee leaving a computer logged on when they are away from their desk, meaning anyone could access the information.
 - A way to prevent against this would be to give staff adequate training and make sure they are aware of the company’s policies. 
- Viruses
- Viruses don't always have to be a damaging to a computer system. However the normally are used to delete files or make significant changes to an IT system.
- An example of this would be a virus attached to an email that once opened starts deleting the files around it until the whole system has been infected.
- Ways to prevent this is to use virus checkers that are continually updated so all the known viruses can be prevented 
- Spyware
- This is where data stored on internal systems is sent to and external source
- For example someones key strokes are sent to an external source, which they then use to access data with passwords etc
- To prevent this would be to use spyware checkers, frequently change your passwords or turn your Internet on and off which would change your IP address.

- Hackers
- This is where a person accesses a computer system unauthorised and could try to commit a further offence such as stealing data.
- An example of this would be obtaining credit card details of a computer system and then buying goods with the details.
-  To prevent the possibilities of hacks the ICT system should have measures in place such as encryption of data, passwords that are changed regularly.

2-13 Computer Misuse Act


Computer Misuse Act (1990)

Three offences of the Computer Misuse Act:
- Unauthorised Access to computer material
   - Example: Bank Account access
   - Results in 6month imprisonment and/ or £5000 
- Unauthorised access with intent to commit further offences:
   - Examples: Credit card details stolen
             - Results in 5 years imprisonment and/ or unlimited fine
- Unauthorised modification of data
             - Examples: Changing grades on a school system, other examples could be viruses such                as Trojans

             - Results in 5 years imprisonment and/  or Unlimited fine