情報セキュリティ
- 情報セキュリティの3要素(CIA):機密性(権限者のみアクセス可)・完全性(改ざんされていない)・可用性(必要時に利用可能)
- 主な脅威:マルウェア(ウイルス・ランサムウェア)・フィッシング・DoS攻撃・SQLインジェクション
- リスクマネジメント:リスクを特定・評価し、対策(回避・低減・転嫁・受容)を選択する
The three goals of information security are remembered as CIA:
- Confidentiality — only authorised people can see the data. (Your medical records are not public.)
- Integrity — data hasn't been changed without permission. (Your bank balance is the correct number.)
- Availability — the system works when you need it. (ATMs are available 24/7.)
- Ransomware — malware that encrypts your files and demands payment for the key. Phishing — fake emails pretending to be a bank or trusted company to steal credentials.
သတင်းအချက်အလက်လုံခြုံရေး ၃ ရည်မှန်းချက်ကို CIA ဟု မှတ်သားသည်:
- Confidentiality (လျှို့ဝှက်မှု) — ခွင့်ပြုချက်ရသောသူများသာ ဒေတာဖတ်ရနိုင်သည်。
- Integrity (ပြည့်စုံမှု) — ဒေတာ ခွင့်မပြုဘဲ ပြောင်းလဲမည်မဟုတ်。
- Availability (ရရှိနိုင်မှု) — လိုအပ်သောအခါ system အသုံးပြုနိုင်သည်。
- Ransomware — ဖိုင်များ ကုဒ်ဝှက်ပြီး ပြန်ရလိုပါက ပိုက်ဆံပေးဆောင်ရမည်ဟု တောင်းဆိုသော malware。
Related Practice Questions
ဆက်စပ် လေ့ကျင့်ခန်းမေးခွန်းများ
အောက်ပါဒေတာ၏ ကိုးကား (mean) နှင့် အလယ်တန်ဖိုး (median) တို့၏ ပေါင်းစပ်မှုသည် အဘယ်နည်း? [ဒေတာ] 10, 20, 20, 20, 40, 50, 100, 440, 2000
In PKI, there is a CRL — a public list of digital certificates meeting certain conditions. Which condition is appropriate for certificates listed in a CRL?
PKI တွင် CRL (Certificate Revocation List) ဟုခေါ်သော ရည်ညွှန်းချက်တစ်ခုနှင့်ကိုက်ညီသော digital certificate သတင်းအချက်အလက်ကို အများသိရှိနိုင်ရေး ထုတ်ပြန်ထားသော စာရင်းတစ်ခုရှိသည်။ ဤစာရင်းတွင် ဖော်ပြသင့်သည့် condition မှာ သင့်လျော်သည်မှာ အဘယ်နည်း?
Person A received four types of messages from Person B. Which message could only have been received by A, given that A and B share a common secret key?
A သည် B ထံမှ မက်ဆေ့ချ် လေးမျိုး လက်ခံရရှိသည်။ A နှင့် B တို့ ဘုံ secret key ရှိသောအခါ A သာ လက်ခံနိုင်သည့် မက်ဆေ့ချ်မှာ အဘယ်နည်း?
Which is an appropriate description of security measures for wireless LAN?
Wireless LAN ၏ လုံခြုံရေး ကာကွယ်ကွပ်ကဲမှုနှင့်ပတ်သက်သော ဖော်ပြချက်အဖြစ် သင့်လျော်သည်မှာ အောက်ပါတို့အနက် အဘယ်နည်း?
Of the following, which includes ONLY cases where availability in information security has been compromised? a A failure in an electronic payment system prevented transaction completion for a certain period. b Personal information in a customer management system was leaked to an external organization. c A company server was illegally accessed and used as a stepping stone to attack external organizations.
အောက်ပါတို့အနက် သတင်းအချက်အလက်လုံခြုံရေးတွင် availability (ရရှိနိုင်မှု) ကျော်လွန်ဆုံးရှုံးသည့် ကိစ္စရပ်များကိုသာ ရွေးချယ်ပါ။ a Electronic ငွေပေးချေမှု system တွင် ချို့ယွင်းမှုဖြစ်၍ တစ်ချိန်တစ်ကာလ ငွေပေးချေမှု ပြီးစီးနိုင်ခြင်း မရှိပေ။ b ဖောက်သည်စီမံခန့်ခွဲမှု system ရှိ ကိုယ်ရေးကိုယ်တာ သတင်းအချက်အလက်များ ပြင်ပအဖွဲ့အစည်းသို့ ပေါက်ကြားသည်။ c ကုမ္ပဏီ server ကို တရားမဝင် ဝင်ရောက်ပြီး ပြင်ပအဖွဲ့အစည်းများကို တိုက်ခိုက်ရာ ကြားခံအဖြစ် အသုံးချခဲ့သည်။