A1 Internal threats
- What does it mean by an internal threat in IT/Computing?
- Give an example for each point below (first one has been done for you)
- Accidental threats:
- accidental damage to physical equipment caused by employee/user
Example: Laptop accidently dropped on the floor and cracking screen
- accidental loss of data/power, unintentional disclosure of data, authorised user action
Example:
- risk of bring your own device (BYOD)
Example:
Example:
- the use of external storage devices/media
Example:
- visiting untrusted websites
Example:
- downloading/uploading files to/from the internet
Example:
- file-sharing applications.
Example:
- Malicious threats:
- malicious damage caused by employee/unauthorised user action
Example:
- intentional deletion/editing of data and intentional disclosure of data
Example:
- dumpster diving and shoulder surfing
Example:
- theft of equipment or data
Example:
- malicious damage to equipment or data
Example:
- unauthorised access by employees to secure areas in a building
Example:
- unauthorised access to administration functions, security levels and protocols,
Example:
- users overriding security controls
Example:
Example:
A2 – External Threats
- What does it mean by an external threat in IT/Computing?
External threats to computer systems and data:
- Briefly describe what is malicious software (malware) used to obtain secure information, viruses.
- For each one write a sentence to describe it (Use only 8 words)
| Worms |
|
| Trojans |
|
| Ransomware |
|
| Spyware |
|
| Adware |
|
| Rootkits |
|
| Backdoors |
|
| Botnets |
|
- What are zero-day attacks?
- What does it mean by unauthorised access by (10 words)
| individuals |
|
| commercial organisations |
|
| Governments |
|
- How is social engineering used for (max 10 words)
| obtaining secure information by deception |
|
| to include collection of passwords |
|
| data theft |
|
| scams |
|
| Phishing |
|
| pharming |
|
- What is the difference between
| Dumpster diving |
|
| Shoulder surfing |
|
- In your own words give an example of malicious damage to equipment or data. (12 words)
A3 – Changing and evolving threats Learners will need to have an awareness that:
Complete the table below in 15 words max for each
| Threat |
Give an example of what this means |
| Existing threats evolve over time |
|
| New threats are constantly being developed |
|
| Regular updates should be available and the importance of organisations/ users applying these updates either automatically or manually |
|
| Where is information available for organisations/user on known hardware and software vulnerabilities |
|
A4 – Vulnerabilities Factors that affect the vulnerability of computer systems and data and how each factor impacts on the vulnerability.
- Describe the different types of system below in 12 words max
| |
Description |
| Individual devices, including PCs, laptops, mobile devices |
|
| Portable storage devices |
|
| Networks, including local area network (LAN), wireless local area network (WLAN) |
|
| File servers |
|
| Cloud computing systems, online storage, remote server, online software. |
|
- Describe the connectivity methods below (10 words max)
- Describe the different connection methods (8 words max)
| |
Wired |
Wireless (Wi-Fi, Bluetooth®, cellular) |
| Description |
|
|
| Advantage |
|
|
| Disadvantage |
|
|
- Describe the issues with the terms below in relation to operating systems:
| Unsupported versions |
|
| Updates not installed |
|
| Mobile devices’ reliance on original equipment manufacturers (OEM) to update system software |
|
| Legacy systems |
|
- Describe the issues with the terms below in relation with software:
| Zero-day vulnerability |
|
| Downloads |
|
| Untrusted sources |
|
| Illegal copies |
|
- Describe the issues with the terms below in relation with users:
| Limitations of understanding |
|
| Training |
|
| Keeping up to date |
|