23-Ind-B4 Design of Information Systems · December 2013
Question 6 of 13: Internal and External Threats to Information Systems
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
Notes on this paper
National Exams — December 2013 — 98-Ind-B4, Design of Information Systems. 3 hours; closed book, no calculator permitted. The exam comprises four parts: Part A (select 20 of 40 terms and explain each in a sentence or two, 2 marks each = 40 marks), Parts B and C (select 2 of 5 questions in each part, 11 marks each = 22 marks per part), and Part D (select 1 of 2 questions, 16 marks). Complete answers to every term and every question in all four parts follow below, not only the minimum selection a candidate would submit on exam day.
Reference texts: Laudon & Laudon, Management Information Systems: Managing the Digital Firm, 15th ed.; Schwalbe, Information Technology Project Management, 9th ed.
Question 6 (Part B.5): Internal and External Threats to Information Systems (11 marks)
Hackers and malware (viruses, worms, trojans, ransomware, term 28) — unauthorized outsiders and malicious code seeking to steal, damage, or hold data hostage. Countered with firewalls, anti-malware software, timely patch management, and network segmentation to limit how far an intrusion can spread.
Denial-of-service attacks (term 19) — flooding a system to deny legitimate access. Countered with traffic filtering, rate limiting, redundant/geographically distributed infrastructure, and a specialist DDoS-mitigation service for internet-facing systems.
Phishing and spoofing (term 40) — social engineering that impersonates a trusted source to obtain credentials or induce a harmful action. Countered with user security-awareness training, email authentication standards, and multi-factor authentication so a stolen password alone is insufficient to gain access.
Natural and infrastructure disasters (fire, flood, power failure, carrier outage) — external events outside the organization's control that can destroy or disconnect IT infrastructure. Countered with off-site/cloud backup, a documented disaster-recovery plan, and geographically redundant facilities.
Internal Threats
Malicious insiders (current or disgruntled former employees with legitimate access) — the hardest threat category to detect because the activity uses valid credentials. Countered with least-privilege access control (term 1), behaviour monitoring (term 5) of sensitive systems, segregation of duties, and prompt access revocation on termination.
Negligent or untrained users (weak passwords, mishandled data, falling for phishing) — unintentional harm caused by a lack of awareness rather than intent. Countered with mandatory security training, clear acceptable-use policy, and technical controls (password policy, data-loss-prevention software) that reduce reliance on individual judgement alone.
Software vulnerabilities and hardware failure — defects in the organization's own systems that can be exploited or that simply fail. Countered with a formal change-control process (term 11) and testing regime before deployment, regular patching, and redundant hardware/failover for critical systems.
Poor access-control administration (over-privileged accounts, orphaned accounts left active after a role change) — a governance failure rather than a technical one. Countered with periodic access reviews/audits and IT governance (term 24) that assigns clear ownership for granting and revoking access.
The Common Thread
Effective defence against both categories rests on the same core disciplines applied consistently: layered technical controls (defence in depth, so no single control's failure is catastrophic), least-privilege access control, continuous monitoring, and, critically, an organizational security culture and governance structure — because the internal category above shows that technology alone cannot address threats that arise from how people, not systems, behave.