Principles of Information Security Kris Rosenberg, Chief Technology Officer Oregon State University College of Business Kris Rosenberg, Chief Technology Officer Oregon State University College of Business
What is “Information Security” “ The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorized acquisition, damage, disclosure, manipulation, modification, loss, or use ”. - McDaniel, George, ed. IBM Dictionary of Computing. New York, NY: McGraw-Hill, Inc., “ The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorized acquisition, damage, disclosure, manipulation, modification, loss, or use ”. - McDaniel, George, ed. IBM Dictionary of Computing. New York, NY: McGraw-Hill, Inc., 1994.
Why is Information Security Important? Moving towards an “Information based economy”. Increasingly hostile public networks. Moving towards an “Information based economy”. Increasingly hostile public networks.
Who is Responsible for Information Security? EVERYONE Information Security is a business issue, not just an IT issue, and needs to be addressed as such. EVERYONE Information Security is a business issue, not just an IT issue, and needs to be addressed as such.
Information Security Across the Enterprise
Human Resources Information Classification Privacy Issues Information Classification Privacy Issues
Accounting The 3 A’s of Information Security: Authentication Authorization Auditing / Accounting The 3 A’s of Information Security: Authentication Authorization Auditing / Accounting
B2B Firewalls VPN Firewalls VPN
Marketing & E-Commerce Denial of Service Attacks (DoS)
Operations Viruses Patches Viruses Patches
Q&A