Information Risk Management Paper

Posted: Mar 01, 2010 |Comments: 0 | Views: 382 |

Introduction

Businesses have now realized that the security of their information could make or break their organization. For this particular paper, the discussion will be limited to the security threats and risk factors associated with baby products production

Vulnerabilities of the system

Potential of external and internal threats

Information systems have become highly complicated. Consequently, there is a need to establish a comprehensive approach to deal with external threats. One of the most common yet dangerous external threats is the issue of hacking. Since the company places considerable information about its clients and itself in its information system, then chances are unauthorized persons may gain access to these pieces of information. (Borodzicz, 2005)

External threats may occur in the form of domestic or foreign competitors to the baby products company who may be interested in finding out trade secrets that would enable them to get ahead of the baby products company. In other circumstances, information brokers who operate on a freelance level may do this kind of thing in order to benefit financially from the endeavor. In other circumstances, it may be that there are hackers who engage in unauthorized entry of computer system for fun. In certain incidences, this may be out of malice from persons with some psychological problems. Common thieves may also break into the company's information systems to as to steal laptops or computers and sell them for profit.

External threats require a lot of attention owing to the fact that the internet brings with it a lot of opportunities for hacking. In this regard, the internet was created in such a manner that it did not consider the issue of security. There are intricate networks that are connected and there are numerous ways in which these systems can be interjected. Matters are also made worse by the fact that intruders can remain anonymous while doing some of the things that are related to information systems. It should also be noted that due to automation of systems, it is now possible for hackers to get into the baby products system without possessing serious knowledge about it. Consequently, care should be taken by this company to guard against unauthorized entry because it provides hackers with low cost and low risk activities that have the potential to provide high gains to the affected person. The Baby products company should therefore watch out for this type of risk. (Gorrod, 2004)

While internal threats receive little if any attention, research has shown that their occurrence has the potential to create greater losses to companies owing to the position of the offenders. Consequently, the same thing can happen to this particular company. Internal threats to security may emanate from disgruntled employees who may want to get back to leaders of the organization. In other circumstances, employees may simply be dishonest and may be interested in advancing their financial or career positions through unscrupulous means. It should be noted that this kind of security threat to information systems may be done through authorized access. The baby products company is in danger of dealing with any of the following forms of internal attacks

  • Financial fraud
  • Sabotage of networks
  • Denial of service to clients
  • Theft of proprietary data and information

Insider threats in this regard may be seen through any of the following routes and they may include the compartmented unauthorized entry of computer systems. In other scenarios, this could be seen through the process of surfing in classified libraries. The latter may apply to the baby products company through the browsing supplier related websites. Additionally, it may apply to processing and storing classified information on systems that have not yet been approved by the authorities.

Natural or unintended events that can jeopardize the system

There are a number of occurrences that can ruin the information system for the baby products company. The first could lie in the type of software being used by the company. In this regard, a problem may arise out of the design of the software being used. This usually means that the system is not protected from vulnerabilities associated with the system and this may prove to be difficult for the company.  Such a scenario may be an intended consequence of choosing an operating system that is low on security. Because the use of high proof security software could prove to cause slow progress within the company, then it would be advisable for one to consider another mechanism for handling this scenario.

It should also be noted that there are certain circumstances in which the coding information can be messed up. For instance, in the case that a language such as C++  or C is being used, then the baby products company could experience integer overflow, buffer overflows, code injection among other issues. (Gasser, 2005)

In certain circumstances, system malfunctions can occur at any one time. This usually means that the main server within the company may malfunction and chances of these occurrences are quite unpredictable. Besides this, there may be instances in which hackers may choose to enter into the computer system of the baby product companies especially when there are flaws within the system's encryption system.

Levels of security that are appropriate to secure the information system while allowing maximum amount of uninterrupted work flow

The company under consideration is one in which production continues on a twenty four hour basis. Consequently, the use of certain extreme security measures may slow down work. The company should begin by implementing some of the basis forms of risk management for information systems. First of all, passwords should be  protected because passwords allow users the ability to either change, destroy or merely use the company's information. Consequently, the company under consideration must do any of the following; it could attempt to protect the accounts of the administrator and the people using it so that no one can engage in unauthorized entry by using rare passwords. This system should also be backed up by frequent changes to the passwords. Employees should also be prevented from sharing passwords or information about it with one another.

The next step in implementing security within this company is through the use of proper software. Software can be vulnerable to attack when there are no mechanisms for installing new versions. In certain circumstances, this can occur automatically. However, in cases where this is not the cases, then the software vendors of that respective company need to be checked from time to time to ensure that they adhere to those operations. (Scheier, 2006)

Antivirus software is another way in which threats can be minimized and this could be done through the installation, operation and update of the antivirus. In relation to the latter approach is the minimized use of the root or the administrator account which could lead to vulnerability to all the systems.

Lastly, the company should also look for ways in which it can minimize phishing through user education. Employees should know that no reputable company would require the passage of confidential information such as security numbers though email and this signifies phishing.

Conclusion

Given the circumstances under which the latter company is operating under. Installation of certain stringent safety measures may disrupt workflows. Consequently, in order to deal with some of the risk factors, then the company should instate basic safety measures such as the use of and update of good software, password protection, installation of good antivirus and protecting the company against phishing.

References

Borodzicz, E. (2005): Crisis, Risk and Security Management, Wiley Publishers

Gorrod, M. (2004): Risk Management Systems; Palgrave Publishers

Scheier, B. (2006): Digital security in a networked world; Pocket Books

Gasser, M. (2005): Building a secure computer system; Cambridge University Press

Questions and Answers

Ask
200 Characters left
Rate this Article
  • 1
  • 2
  • 3
  • 4
  • 5
  • 0 vote(s)
    Feedback
    Print
    Re-Publish
    Source:  http://www.articlesbase.com/business-articles/information-risk-management-paper-1924847.html

    Article Tags:

    custom essays

    ,

    custom research papers

    ,

    term paper help

    ,

    quality research papers

    ,

    quality essays

    ,

    college essays

    ,

    customized research papers

    ,

    buy essays

    ,

    buys research papers

    ,

    term papers for sale

    ,

    custom papers

    ,

    essay writing

    ,

    custom writing

    ,

    non plagiari

    The Education system in the United States has undergone numerous changes over the past years. Some of the policies passed centered on the need to increase transparency in the education system, others focused on standardization of tests while others aimed at improving the performance disparities between various categories of students.

    By: Carolyn Smithl Educationl Feb 28, 2010 lViews: 218

    Research conducted by Skogan (1986) found that the fear of crime creates negative psychological effects in a community. Consequently, stakeholders in the crime prevention sector need to equip themselves with knowledge surrounding this topic. They need to know factors linked to the fear of crime and the magnitude or relative importance of each.

    By: Carolyn Smithl Law> Criminall Feb 25, 2010 lViews: 2,649

    The Indian aviation industry is one of the most talked about aviation industries in the world. The major reason behind this interest is its liberalisation. After the latter move, India's airline passengers began enjoying the benefit of choice because Indian carriers quadrupled in number. As if that was not enough, the country recorded a twenty two percent increase in passenger traffic. (Gramaticas, 2007)

    By: Carolyn Smithl Travel> Flightsl Mar 01, 2010 lViews: 694

    Many individual argue that fluctuations in prices of commodities may be a short term reaction to the goings on in the global arena. However, others argue that these effects may be so large that they may cause long term repercussions. There is a need to look at both sides of the argument in order to come up with a critical conclusion on the matter.

    By: Carolyn Smithl Finance> Creditl Mar 01, 2010

    Tesco PLC is a Retail Company based in the United Kingdom. It is the most recognised retailer of groceries in the region; this was backed up by the fact that last year it was responsible for supplying thirty percent of all the groceries in the UK. The Company was started in the 1920s and has since grown both regionally and globally.

    By: Carolyn Smithl Businessl Feb 23, 2010 lViews: 4,015

    In USA, one of the leading brands that offer diverse and high quality products promoting proper hygiene is Difresh USA. If you are looking for the best opportunity to grow and have the opportunity for a new business Difresh USA can help you for they are looking for Exclusive Local Distributors

    By: danieltorrisl Businessl May 31, 2012

    Getting clean and refresh doesn't sacrifice the place where you are for it should be a habit. Having a healthy body will allow you to do things right and good. And no matter where you are you should practice a healthy and proper hygiene even in little things you do.

    By: danieltorrisl Businessl May 31, 2012

    Maintaining a healthy and proper hygiene badly needs products that are truly effective and could truly answer our need for this. No matter where we are and at anytime we want to get clean we basically need these products right away and only Difresh USA can supply these in a very easy way

    By: danieltorrisl Businessl May 31, 2012

    The key reason why some firms thrive while some implode during an financial recession is still a puzzle to many people business-owning business owners. Some wrongly assume that all businesses should suffer via recessionary cycles. But the truth is that some companies are usually essentially recession-proof, and it is not necessarily because they are much larger, better known, or a lot more generously capitalized.

    By: danhoh75rel Businessl May 31, 2012

    Companies like Arch Coal (ACI) and Massey Energy (MEE) watched his or her stock climbed.

    By: pennystockegghead49l Businessl May 30, 2012

    Warner (1995) explains that the UN peacekeeping operations have been placed under increased scrutiny over the past few years. This has come against the introduction of relatively new players in peace keeping efforts such as Germany and Japan. Additionally, continuous scrutiny has been propagated by heightened religious, ethnic and local conflicts among several nations of the world.

    By: Carolyn Smithl Business> Non Profit Organizationsl Mar 01, 2010 lViews: 452

    An organization is said to have outsourced their jobs when they delegate certain duties and functions to an external party. (Gilley et al, 2004)This is usually necessary in instances where a specific company has no skills for performing the task within the organization. Additionally, it can be done in order to minimize workload.

    By: Carolyn Smithl Writing> Article Marketingl Mar 01, 2010 lViews: 1,524

    The working title will be " Contemporary feminism: Performing queer identity through culture, gender, differential consciousness, embodied knowledge and phenomology" This title was chosen owing to the fact that the queer theory has gained some leverage on gender studies. Consequently, it would be necessary to look into its methods of performance.

    By: Carolyn Smithl News and Society> Women's Issuesl Mar 01, 2010 lViews: 203

    Rutter and Rutter (1992) define lifespan development as "the systematic, intra-individual change that is clearly associated with generally expectable age related progressions and which is carried forward in the same way that has implications for a person's pattern or level of functioning at some time later.

    By: Carolyn Smithl Writingl Mar 01, 2010 lViews: 1,100

    Discuss this Article

    Author Box
    Articles Categories
    All Categories
    Quantcast