Example: tourism industry

Intrusion Detection and Information Security Audits

Intrusion Detection and Information Security I. Audits Terry T. Kidd University of Texas Health Science Center, USA. Robert K. Hiltbrand University of Houston, USA. INTRODUCTION also Information on popular Intrusion Detection and Security auditing software used in industry. The rapid expansion and dramatic advances in informa- tion technology in recent years have without question generated tremendous benefits to business and organi- BACKGROUND. zations. At the same time, this expansion has created significant, unprecedented risks to organization opera- Advances in Information systems and the technology tions. Computer Security has, in turn, become much used to support those systems have produced great more important as organizations utilize Information results for organizations, businesses, and other agen- systems and Security measures to avoid data tampering, cies in terms of work productivity, Information storage, fraud, disruptions in critical operations, and inappr

Intrusion Detection and Information Security Audits areas, such as the firewall, host, or network. However, a security audit will address issues with your systems,

Tags:

  Information, Security, Detection, Intrusion, Intrusion detection and information security

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Intrusion Detection and Information Security Audits

1 Intrusion Detection and Information Security I. Audits Terry T. Kidd University of Texas Health Science Center, USA. Robert K. Hiltbrand University of Houston, USA. INTRODUCTION also Information on popular Intrusion Detection and Security auditing software used in industry. The rapid expansion and dramatic advances in informa- tion technology in recent years have without question generated tremendous benefits to business and organi- BACKGROUND. zations. At the same time, this expansion has created significant, unprecedented risks to organization opera- Advances in Information systems and the technology tions. Computer Security has, in turn, become much used to support those systems have produced great more important as organizations utilize Information results for organizations, businesses, and other agen- systems and Security measures to avoid data tampering, cies in terms of work productivity, Information storage, fraud, disruptions in critical operations, and inappro- management, and in opportunities for the competitive priate disclosure of sensitive Information .

2 Such use of advantage. While the promise and offerings of infor- computer Security is essential in minimizing the risk mation systems have tremendous benefits, Information of malicious attacks from individuals and groups. To systems have also created significant and unprecedented be effective in ensuring accountability, management levels of risks to organizational operations. Businesses, and Information technology Security personnel must hospitals, schools, universities, governmental agencies, be able to evaluate Information systems Security and and banks depend heavily on Information systems, thus offer recommendations for reducing Security risks to increasing the need for Information Security .

3 With this an acceptable level. To do so, they must possess the newfound dilemma, organizations are beginning to appropriate resources, skills, and knowledge. use Information Security measures to ensure that the With the growing perverseness of Information integrity of other data is held at an optimal level. systems and the technologies used to support such As discussed previously, the aim of Information tools, the growing need to keep the integrity of both Security used by an organization is to avoid data tam- the data and the system used to manage that data will pering, fraud, inappropriate access to and disclosure become a major priority. Therefore, it is important for of sensitive Information , and disruptions in critical Security personnel and management to keep abreast operations (Umar, 2003).

4 Unfortunately, these risks are of the issues and trends in Information systems and expected to escalate as wireless communication tech- Security , and the tools and techniques used to secure nologies emerge and become ubiquitous. If Information systems and data. systems personnel are to be effective instruments of In order to keep Information safe and systems se- accountability and assessment, they need to be able to cured from outside attacks from computer criminals, evaluate Information systems and Security measures to Information systems Security and network vulner- offer recommendations for reducing the Security risk ability assessment must be conducted on a regular and to an acceptably low level (Umar, 2003).

5 Ongoing basis to insure system Security integrity. The Further, the growing importance of Information aim of this article is to introduce to the Information systems in performing daily operational activities, technology community, the conceptual overview of along with the elimination of paper-based evidence and Information Security Audits . Not only will this article audit trails, demands that these professionals consider present an overview of Information Security Audits , but the effectiveness of Information technology Security Copyright 2007, IGI Global, distributing in print or electronic forms without written permission of IGI Global is prohibited.

6 Intrusion Detection and Information Security Audits controls during the course of financial and performance These risks include the fraudulent loss or misuse of Audits . To do so, Information Security personnel must organization resources, unauthorized access to release acquire and maintain appropriate resources and skill of sensitive Information such as tax and medical records, sets to help prevent computing Security threats, vulner- disruption of critical operations through viruses or abilities, or attacks. This can be a daunting challenge hacker attacks, and modification or destruction of data. in an era of rapid evolution and deployment of new According to the National State Auditing Association Information technology.

7 Likewise, management within and the General Accounting Office (NSS & GAO, organizations needs to take stock of their Information 2001), the risk that Information attacks will threaten systems Security audit and its capabilities, to ensure vital organization interests increases with the following that strategies exist for their continued development developments in Information technology: and enhancement, for an organization's Security is only as strong as its policy. Monies are increasingly transferred electroni- When it comes to articulating or writing the orga- cally between and among governmental agen- nization Security policy, the discussion should be more cies, commercial enterprises, businesses, and than Information systems and the technologies used to individuals.

8 Support those systems, the conversation should move Organizations and businesses are rapidly expand- past a discussion of infrastructure ( , hardware and ing their use of electronic commerce. software), but to a discussion of Security and methods Business, government, and national/domestic for securing the organization's systems and most valu- Security communities increasingly rely on the able assets its Information . available Information technology. According to Holden (2004), Information is essential Public utilities and telecommunications increas- to the achievement of any business or organizational. ingly rely on computer systems to manage every- Its reliability, integrity, and availability are significant day operations.

9 Concerns in most organizations. The use of comput- More and more sensitive economic and commer- ing and system networks, particularly the Internet, is cial Information is exchanged electronically. revolutionizing the way organizations conduct their Computer systems are rapidly increasing in business and their day-to-day operations. While the complexity and interconnectivity. benefits of such tools have been enormous and have Easy-to-use hacker tools are readily available, allowed vast amounts of Information to be available and hacker activity is increasing. at our fingertips, these interconnections also pose Paper supporting documents are being reduced significant risks to computer systems, Information , or eliminated.

10 And to the critical operations and infrastructures they Each of these factors significantly increases the support. Infrastructure elements such as telecommu- need for ensuring the privacy, Security , and avail- nications, power distribution, financial data, research ability of state and local government, business, and development Information , as well as personnel and public education systems. data are subject to these risks. The same factors that benefit operations speed and accessibility if not Although as many as 80% of Security breaches are properly controlled, can leave them vulnerable to fraud, probably never reported, the number of reported inci- sabotage, and malicious or mischievous acts (NSAA dents are growing dramatically with relative intensity & GAO, 2001).


Related search queries