CS Unit 4
CS Unit 4
UNIT-5
• Introduction
• IPR Issues
Organizational Implications-Introduction
In the global environment with continuous network connectivity, the possibilities for cyberattacks
can emanate from sources that are local, remote, domestic or foreign. They could be launched by an
individual or a group. They could be casual probes from hackers using personal computers (PCs) in their
homes, hand-held devices or intense scans from criminal groups.
PI is information that is, or can be, about or related to an identifiable individual. It includes any
information that can be linked to an individual or used to directly or indirectly identify an individual.
Most information the organization collects about an individual is likely to come under “PI”
category if it can be attributed to an individual. For an example, PI is an individual’s first name or
A case in point is the infamous “Heartland Payment System Fraud” that was uncovered
in January 2010. This incident brings out the glaring point about seriousness of “insider attacks.
In this case, the concerned organization suffered a serious blow through nearly 100 million
credit cards compromised from at least 650 financial services companies. When a card is used
to make a purchase, the card information is trans- mitted through a payment network.
Yet another incidence is the Blue Cross Blue Shield (BCBS) Data Breach in October
2009 the theft of 57 hard drives from a BlueCross BlueShield of Tennessee training facility
puts the private information of approximately 500,000 customers at risk in at least 32 states.
The two lessons to be learnt from this are:
1. Physical security is very important.
2. Insider threats cannot be ignored.
A key message from this discussion is that cybercrimes do not happen on their own or
in isolation. Cybercrimes take place due to weakness of cybersecurity practices and “privacy”
which may get impacted when cybercrimes happen.
The key challenges from emerging new information threats to organizations are as follows:
1. Industrial espionage: There are several tools available for web administrators to
monitor and track the various pages and objects that are accessed on their website.
2. IP-based blocking: This process is often used for blocking the access of specific IP
addresses and/or domain names.
3. IP-based “cloaking”: Businesses are global in nature and economies are interconnected.
4. Cyberterrorism: “Cyberterrorism” refers to the direct intervention of a threat source
toward your organization’s website.
Confidential information leakage: “Insider attacks” are the worst ones. Typically, an organization is
protected from external threats by your firewall and antivirus solutions
When a cybercrime incidence occurs, there are a number of internal costs associated
with it for organizations and there are organizational impacts as well.
Detection and recovery constitute a very large percentage of internal costs. This is
supported by a benchmark study conducted by Ponemon Institute USA carried out with the sample
of 45 organizations representing more than 10 sectors and each with a head count of at least 500
employees.
The internal costs typically involve people costs, overhead costs and productivity losses.
The internal costs, in order from largest to the lowest and that has been supported by the
benchmark study mentioned:
1. Detection costs.(25%)
2. Recovery costs.(21%)
3. Post response costs.(19%)
The most often quoted reasons by employees, for use of pirated software, are as follows:
There are tools to protect organization’s bandwidth by stopping unwanted traffic before
it even reaches your Internet connection.
Use of mobile handset devices in cybercrimes. Most mobile communication devices for
example, the personal digital assistants has raised security concerns with their use. Mobile
workers use those devices to connect with their company networks when they move. So the
organizations cannot protect the remote user system as a result workforce remains unprotected.
We need tools to extend web protection and filtering to remote users, including policy
enforcement
Cloud computing is one of the top 10 Cyber Threats to organizations. There are data privacy risks
through cloud computing. Organizations should think about privacy scenarios in terms of “user spheres”.
There are three kinds of spheres and their characteristics:
1. User sphere: Here data is stored on users’ desktops, PCs, laptops, mobile phones, Radio
Frequency Identification (RFID) chips, etc. Organization’s responsibility is to provide access to
users and monitor that access to ensure misuse does not happen.
2. Recipient sphere: Here, data lies with recipients: servers and databases of network providers,
service providers or other parties with whom data recipient shares data. Organizations
responsibility is to minimize users privacy risk by ensuring unwanted exposure of personal
data of users does not happen
Prepared by Mrs.K.Rajani, Dept. of CSE, Page 9 of 20
III- II SEM ECE, Cyber Security Unit - V
3. Joint sphere: Here data lies with web service provider’s servers and databases. This is the in
between sphere where it is not clear to whom does the data belong. Organization responsibility
is to provide users some control over access to themselves and to minimize users futures
privacy risk.
Following are the most typical reasons why organizations use social media marketing to promote
their products and services:
1. To be able to reach to a larger target audience in a more spontaneous and instantaneous
manner without paying large advertising fees.
2. To increase traffic to their website coming from other social media websites by using Blogs
5. To collect potential customer profiles. Social media sites have information such as user
profile data, which can be used to target a specific set of users for advertising
There are other tools too that organizations use; industry practices indicate the following:
1. Twitter is used with higher priority to reach out to maximum marketers in the technology
space and monitor the space.
2. Professional networking tool LinkedIn is used to connect with and create a community of
top executives from the Fortune 500.
3. Facebook as the social group or social community tool is used to drive more traffic to
Websense website and increase awareness about Websense.
4. YouTube (the video capability tool to run demonstrations of products/services, etc.) is used
to increase the brand awareness and create a presence for corporate videos.
5. Wikipedia is also used for brand building and driving traffic.
There are conflits views about social media marketing some people in IT say the expensive and
careless use of it.Some illustrate the advantages of it with proper control of Security risk