Comments on: Midterm Exam https://sayedkenawy.com/2019/03/04/midterm-exam/ Sat, 02 Jan 2021 18:50:28 +0000 hourly 1 By: محمد سامى قاسم سلطان مكاوى https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4575 Sat, 02 Jan 2021 18:50:28 +0000 http://www.sayedkenawy.com/?p=680#comment-4575 Question (1)
What is information security? And Why information security is important?
Is the collection of technologies standards policies and management practices that are applied to information to keep it secure.
Or
The practice of protecting both physical and digital information from destruction or unauthorized access.
Its important:
1- To protect data from any attacks.
2- Protect it from accidental risks.
3- Prevent unauthorized people to access it
4- Easy recovery
what is information security management system required?
Describes controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. ISM includes information risk management, a process which involves the assessment of the risks an organization must deal with in the management and protection of assets.

Question (2)
1- false: Acq[@RNs is one of best password
2- false: money not important after is done for Maintance and development
3-True
4- false: information discussion musn’t be in an open work area , because information is the backbone of system security.
5- True

Question (3)
First plan:
1-. develop stronger passwords throughout organization
2- reqularly backup data
3-develop a data security policy
4- manage who has access
5- know and protect your important data
second plan:
1- Ensuring that security policy has teeth and enforced.
2- Establishing and maintaining a meaningful and relevant security policy.
3- Providing tools to help it staff implement security policy.
4- Plugging security holes in cohosting situations.
5- Closing an increasingly popular network back door.

]]>
By: محمد محمد على الوكيل https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4554 Thu, 31 Dec 2020 21:18:36 +0000 http://www.sayedkenawy.com/?p=680#comment-4554 Q1)
( A) – The practice of protecting both physical and digital information from destruction or unauthorized access.
– Important because :
1- To protect data from any attacks.
2- Protect it from accidental risks.
3- Prevent unauthorized people to access it.
4- Easy recovery.
(B)… Describes controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. ISM includes information risk management, a process which involves the assessment of the risks an organization must deal with in the management and protection of assets.

Q2)
(A)
1- false: Acq[@RNs is one of best password
2- false: money not important after is done for Maintance and development
3-True
4- false: information discussion musn’t be in an open work area , because information is the backbone of system
security.
5- True

Q3)
The First plan:
1-manage who has access.
2-know and protect your important data
3-develop a data security policy
4-develop stronger passwords throughout organization
5-reqularly backup data
The second plan:
1- Establishing and maintaining a meaningful and relevant security policy.
2- Ensuring that security policy has teeth and enforced.
3- Providing tools to help it staff implement security policy.
4- Closing an increasingly popular network back door.
5- Plugging security holes in cohosting situations

]]>
By: احمد خالد عبدالونيس https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4531 Mon, 28 Dec 2020 21:32:25 +0000 http://www.sayedkenawy.com/?p=680#comment-4531 Q1.
1-Information security is a set of strategies for managing the process , tools and polices necessary to prevent , detect document and counter threats to digital and non-digital information. its importance relies in As we store and access information in various devices such as laptops , mobiles and verbal documents . We handle various types of valuable information like customer data , financial information and business data .
Information is the asset that powers and enables our business and Any loss of information can affect the organization in terms of :
– time – reputation – Money .

2 – Business Obligations: Security commitments to the business. For example, security has a responsibility to ensure that information in the business is kept secure and is available when needed.

Regulatory Obligations: Legal, compliance, or contractual obligations that security must fulfil. For example, organizations in the healthcare industry must be HIPAA compliant.

Customer Obligations: Security commitments that the customer expects the organization to keep. For example, the customer of a manufacturer may require all their blueprint files to be encrypted.

Q2 ;

1- (false) the best password should contain letters which are capitalized and small ones , symbols and numbers .
2- (false) money is important all the time during the life time of the project as we might need maintenance works after we finish the IS .
3- (true ) .
4- (false) you do not know whether these information you share could be important for your rivals or not .
5- (true) .

Q3;
1 – you should encrypt your data :
Data encryption isn’t just for technology geeks; modern tools make it possible for anyone to encrypt emails and other information.

2- backup your data :-
One of the most basic, yet often overlooked, data protection tips is backing up your data. Basically, this creates a duplicate copy of your data so that if a device is lost, stolen, or compromised, you don’t also lose your important information. It’s best to create a backup on a different device, such as an external hard drive, so that you can easily recover your information when the original device becomes compromised.

3-The cloud provides a viable backup option:-
While you should use sound security practices when you’re making use of the cloud, it can provide an ideal solution for backing up your data. Since data is not stored on a local device, it’s easily accessible even when your hardware becomes compromised. “Cloud storage, where data is kept offsite by a provider, is a guarantee of adequate disaster recovery.

]]>
By: Omar Mohamed Abd Elraouf https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4521 Sun, 27 Dec 2020 13:35:14 +0000 http://www.sayedkenawy.com/?p=680#comment-4521 What is information security? And Why information security is important?
policies and management practices that are applied to information to keep it secure or
The practice of protecting both physical and digital information from destruction or unauthorized access.

Why information security is important?
(1) Easy recovery
(2) Prevent unauthorized people to access it
(3)Protect it from accidental risks.
(4) To protect data from any attacks.

what is information security management system required?
ISM includes information risk management, a process which involves the assessment of the risks an organization must deal with in the management and protection of assets. Describes controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities.

Question2:

(1) ( false) Acq[@RNs is one of best password
(2) (false) money not important after is done for Maintance and development
(3) (True)
(4) (false) information discussion musn’t be in an open work area , because information is the backbone of system security.
(5) (True)

Question 3:

The First plan:
(1) develop a data security policy
(2) develop stronger passwords throughout organization
(3) manage who has access.
(4) know and protect your important data
(5) reqularly backup data
The second plan:
(1) Providing tools to help it staff implement security policy.
(2) Ensuring that security policy has teeth and enforced.
(3) Establishing and maintaining a meaningful and relevant security policy.
(4) Plugging security holes in cohosting situations.
(5) Closing an increasingly popular network back door.

]]>
By: Ahmed Sobhy Abdu Algendy https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4518 Sun, 27 Dec 2020 13:21:28 +0000 http://www.sayedkenawy.com/?p=680#comment-4518 Q1) A)
– The practice of protecting both physical and digital information from destruction or unauthorized access.
– Important because :
1- To protect data from any attacks.
2- Protect it from accidental risks.
3- Prevent unauthorized people to access it.
4- Easy recovery.
B)
Describes controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. ISM includes information risk management, a process which involves the assessment of the risks an organization must deal with in the management and protection of assets.

Q2) A)
1- false: Acq[@RNs is one of best password
2- false: money not important after is done for Maintance and development
3-True
4- false: information discussion musn’t be in an open work area , because information is the backbone of system security.
5- True

Q3)
First plan:
1-manage who has access.
2-know and protect your important data
3-develop a data security policy
4-develop stronger passwords throughout organization
5-reqularly backup data
second plan:
1- Establishing and maintaining a meaningful and relevant security policy.
2- Ensuring that security policy has teeth and enforced.
3- Providing tools to help it staff implement security policy.
4- Closing an increasingly popular network back door.
5- Plugging security holes in cohosting situations.

]]>
By: Osama Amer https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4510 Sat, 26 Dec 2020 23:19:17 +0000 http://www.sayedkenawy.com/?p=680#comment-4510 Q1
What is information security? And Why information security is important?
Is the collection of technologies standards policies and management practices that are applied to information to keep it secure.
Or
The practice of protecting both physical and digital information from destruction or unauthorized access.
Its important:
1- To protect data from any attacks.
2- Protect it from accidental risks.
3- Prevent unauthorized people to access it
4- Easy recovery
what is information security management system required?
Describes controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. ISM includes information risk management, a process which involves the assessment of the risks an organization must deal with in the management and protection of assets.

Q2
1- false: Acq[@RNs is one of best password
2- false: money not important after is done for Maintance and development
3-True
4- false: information discussion musn’t be in an open work area , because information is the backbone of system security.
5- True

Q3
First plan:
1-manage who has access.
2-know and protect your important data
3-develop a data security policy
4-develop stronger passwords throughout organization
5-reqularly backup data
second plan:
1- Establishing and maintaining a meaningful and relevant security policy.
2- Ensuring that security policy has teeth and enforced.
3- Providing tools to help it staff implement security policy.
4- Closing an increasingly popular network back door.
5- Plugging security holes in cohosting situations.

]]>
By: Nour Adel https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4507 Sat, 26 Dec 2020 18:02:16 +0000 http://www.sayedkenawy.com/?p=680#comment-4507 Q1
What is information security? And Why information security is important?
Is the collection of technologies standards policies and management practices that are applied to information to keep it secure.
Or
The practice of protecting both physical and digital information from destruction or unauthorized access.
Its important:
1- To protect data from any attacks.
2- Protect it from accidental risks.
3- Prevent unauthorized people to access it
4- Easy recovery
what is information security management system required?
Describes controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. ISM includes information risk management, a process which involves the assessment of the risks an organization must deal with in the management and protection of assets.

Q2
1- false: Acq[@RNs is one of best password
2- false: money not important after is done for Maintance and development
3-True
4- false: information discussion musn’t be in an open work area , because information is the backbone of system security.
5- True

Q3
First plan:
1-manage who has access.
2-know and protect your important data
3-develop a data security policy
4-develop stronger passwords throughout organization
5-reqularly backup data
second plan:
1- Establishing and maintaining a meaningful and relevant security policy.
2- Ensuring that security policy has teeth and enforced.
3- Providing tools to help it staff implement security policy.
4- Closing an increasingly popular network back door.
5- Plugging security holes in cohosting situations.

]]>
By: ايه احمد السيد العموشي https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4504 Thu, 24 Dec 2020 22:08:22 +0000 http://www.sayedkenawy.com/?p=680#comment-4504 Plan “B” // This plan will not cost you much money and you will not need more staff, It can be implemented anywhere in any country // Plan |B| While there can be no single answer that applies to every system and every business, you can make significant improvements in your overall security stance by taking some simple actions. Here are seven steps: 1- PERFORM REGULAR BACKUPS! Sorry about shouting, but I cannot stress this one enough. If you do nothing else, save your work, including contacts, accounting, and stored email. And keep your backups somewhere else, away from your office or place of business. 2- Scan for Viruses Effectively use your virus scanner on all desktop workstations and servers (you do have scanning software, right?). That means regular scans and regular updates. Most scanners will do this for you, but what if an employee disables this feature? (Maybe it slows down his web surfing experience or something). You need to be sure! 3- Use Firewalls No, firewalls are not going to save us all from all the evil hackers in the world, but they go a long way to making it more difficult for them. If you already have one, make sure it’s configured to allow nothing but the essential traffic. Consider using personal (software) firewalls on each workstation and server, too. A layered approach is best always! 4- Patch OS and Application Software Check for security advisories regularly. If your vendor says you should apply an important security patch, you really need to get it done. 5- Use Strong Passwords Do not use your favorite color. Do not use the name of your dog (or cat, parakeet, critter, …). Do not change letters to a clever number and punctuation replacements (c!3v3r, n0? No!). These all can be cracked in no time. Better yet, consider a stronger authentication mechanism. 6- Don’t open email attachments! Delete email from unknown and unexpected sources outright. But even email that appears to be coming from friends, relatives, and associates can be dangerous. Many worms have used personal address books to propagate themselves. 7-Develop a security policy Even creating a simple security policy will force you to think about what needs protection and the threats specific to your business. If you have employees, make sure they understand the importance of your policy. Educate them (and yourself, in the process!) //many software programs vary in price and some free ones can be used for (System protection) and determine the number of employees according to the available cost // ايه احمد السيد العموشي]]> // What is information security // —–> Information security, often referred to as InfoSec, refers to the processes and tools designed and deployed to protect sensitive business information from modification, disruption, destruction, and inspection.

// Importance of IS //——–> Today, you can order from any online stores and pay them online from your credit cards even better, make it EMI. You can pay your bills from home and book airline tickets from your mobile……All that just in a click.

Obviously, you love all this convenience and want to keep doing this, even you want the service providers to provide more such services. If you lose money from your bank account while doing a recharge, will you again try that? No. You are doing this conveniently because you know it is safe, your bank and vendors are convinced that it is secure and even if something bad happens, you know “some” people will make sure it won’t happen again. “Some” people are working to keep the system safe and improving it every day. This assurance is there due to these people and it is necessary.

B) What is information security management required?

Question (2) : –

1) False —-> because abc123 is an easily recognizable Password so any hacker can get it without any difficulty so ur Password must be more difficult for example a@b1*c2$3

2) False —–> In any business there are two terms Capex which refers to the amounts that companies use to purchase major physical goods or services that will be used in this example (build Security System) / and Opex which means Operating expenses represent the other day-to-day expenses necessary to keep the business running.in this example (System admin)

3) True.

4) False ——> because there are two types of attacks (External attack) Carried out by node that does not belong to the domain of the network. and (Internal attack) It is from compromised nodes, which are actually part of the network, So you have to be careful about confidentiality

5) True.

Question (3) : –

Plan |A|
The effort needed in achieving total computer system security seems overwhelming. There is always something else you could do to improve your security stance. You might be surprised, then, if I told you that just one step could accomplish this goal:

Eliminate all computer systems from your business and use paper instead!

Of course, for most businesses this is not a realistic solution, but then, achieving total computer system security is not a realistic goal. Like crossing the street, there is an element of risk no matter how careful you are. So what can you do to mitigate this risk reasonably, without consuming endless resources? 😀 Plan “B”

// This plan will not cost you much money and you will not need more staff, It can be implemented anywhere in any country //

Plan |B|
While there can be no single answer that applies to every system and every business, you can make significant improvements in your overall security stance by taking some simple actions. Here are seven steps:

1- PERFORM REGULAR BACKUPS!
Sorry about shouting, but I cannot stress this one enough. If you do nothing else, save your work, including contacts, accounting, and stored email. And keep your backups somewhere else, away from your office or place of business.

2- Scan for Viruses
Effectively use your virus scanner on all desktop workstations and servers (you do have scanning software, right?). That means regular scans and regular updates. Most scanners will do this for you, but what if an employee disables this feature? (Maybe it slows down his web surfing experience or something). You need to be sure!

3- Use Firewalls
No, firewalls are not going to save us all from all the evil hackers in the world, but they go a long way to making it more difficult for them. If you already have one, make sure it’s configured to allow nothing but the essential traffic. Consider using personal (software) firewalls on each workstation and server, too. A layered approach is best always!

4- Patch OS and Application Software
Check for security advisories regularly. If your vendor says you should apply an important security patch, you really need to get it done.

5- Use Strong Passwords
Do not use your favorite color. Do not use the name of your dog (or cat, parakeet, critter, …). Do not change letters to a clever number and punctuation replacements (c!3v3r, n0? No!). These all can be cracked in no time. Better yet, consider a stronger authentication mechanism.

6- Don’t open email attachments!
Delete email from unknown and unexpected sources outright. But even email that appears to be coming from friends, relatives, and associates can be dangerous. Many worms have used personal address books to propagate themselves.

7-Develop a security policy
Even creating a simple security policy will force you to think about what needs protection and the threats specific to your business. If you have employees, make sure they understand the importance of your policy. Educate them (and yourself, in the process!)

//many software programs vary in price and some free ones can be used for (System protection) and determine the number of employees according to the available cost //
ايه احمد السيد العموشي

]]>
By: osama shata https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4502 Thu, 24 Dec 2020 20:17:18 +0000 http://www.sayedkenawy.com/?p=680#comment-4502 Q1
What is information security? And Why information security is important?
Is the collection of technologies standards policies and management practices that are applied to information to keep it secure.
Or
The practice of protecting both physical and digital information from destruction or unauthorized access.
Its important:
1- To protect data from any attacks.
2- Protect it from accidental risks.
3- Prevent unauthorized people to access it
4- Easy recovery
what is information security management system required?
Describes controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. ISM includes information risk management, a process which involves the assessment of the risks an organization must deal with in the management and protection of assets.

Q2
1- false: Acq[@RNs is one of best password
2- false: money not important after is done for Maintance and development
3-True
4- false: information discussion musn’t be in an open work area , because information is the backbone of system security.
5- True

Q3
First plan:
1-manage who has access.
2-know and protect your important data
3-develop a data security policy
4-develop stronger passwords throughout organization
5-reqularly backup data
second plan:
1- Establishing and maintaining a meaningful and relevant security policy.
2- Ensuring that security policy has teeth and enforced.
3- Providing tools to help it staff implement security policy.
4- Closing an increasingly popular network back door.
5- Plugging security holes in cohosting situations.

]]>
By: Ahmed Gamal abd elmotelp https://sayedkenawy.com/2019/03/04/midterm-exam/#comment-4501 Thu, 24 Dec 2020 19:36:11 +0000 http://www.sayedkenawy.com/?p=680#comment-4501 Q1
What is information security? And Why information security is important?
Is the collection of technologies standards policies and management practices that are applied to information to keep it secure.
Or
The practice of protecting both physical and digital information from destruction or unauthorized access.
It’s important:
1- To protect data from any attacks.
2- Protect it from accidental risks.
3- Prevent unauthorized people to access it
4- Easy recovery
what is an information security management system required?
Describes controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. ISM includes information risk management, a process that involves the assessment of the risks an organization must deal with in the management and protection of assets.

Q2
1- false: Acq[@RNs is one of the best passwords
2- false: money not important after is done for Maintenance and development
3-True
4- false: information discussion musn’t be in an open work area because the information is the backbone of system security.
5- True

Q3
First plan:
1-manage who has access.
2-know and protect your important data
3-develop a data security policy
4-develop stronger passwords throughout an organization
5-regularly backup data
second plan:
1- Establishing and maintaining a meaningful and relevant security policy.
2- Ensuring that security policy has teeth and enforced.
3- Providing tools to help its staff implement a security policy.
4- Closing an increasingly popular network back door.
5- Plugging security holes in cohosting situations.

]]>