Information Culture and Security for Schoolchildren and Employees, Risk Assessment

Lecture



The Concept of "Information Culture" and Information Security

Information culture is the ability to work purposefully with information and to use computer information technology, modern technical means and methods to obtain, process and transmit it. To find one's way freely in the flow of information, a person must possess information culture as one of the components of general culture.
Information culture is not a set of elementary applied knowledge that everyone needs in order not to get lost in the world of information. The task of information culture is to give an understanding of the dialogic nature, variability and openness of knowledge.
Information culture is connected with the social nature of the human being.

Information culture is

  1. in the broad sense, a set of principles and real mechanisms that ensure positive interaction between ethnic and national cultures, as well as their connectedness in the common experience of humanity.
  2. in the narrow sense, a set of knowledge and skills for effective information activity that achieves its intended goal.

It should also be regarded as algorithms of human behavior and symbolic structures in the infosphere that give this behavior meaning and significance from the human point of view.

Information culture can be regarded as an integral part of general culture, oriented toward the information support of human activity. Information culture reflects the levels achieved in the organization of information processes and in the effectiveness of creating, collecting, storing, processing, presenting and using information, which ensure a holistic view of the world, its modeling, and the anticipation of the results of decisions made by a person.

Information Culture and Security for Schoolchildren and Employees, Risk Assessment
Our time is called the "age of information." Every day an ever-increasing flow of it reaches us. It is not easy to find one's bearings in this truly boundless sea. Which of this information is important and which is not, how should one work with it, how should it be evaluated? Many questions arise.
In the sociocultural context, such phenomena as information resources, informatization and the information society are considered. According to specialists, the time frame of the renewal cycle of not only production but also social technologies is rapidly shrinking and in the
future will amount to six to eight years, outpacing the rate at which generations change. Consequently, for all members of society the need grows for constant professional development, updating of knowledge and mastering of new kinds of activity. A person must be able to use all the information
resources that society has accumulated. "Information resources are understood as the available stocks of information recorded on some medium and suitable for storage and use"1. Information resources are a product of the intellectual activity
of society and are currently regarded as a strategic resource for the development of any country, one that is not inferior in importance to others: financial, raw material and material-technical resources. Another concept related to information is the information space. "The information
space is a certain space (a territory such as a country or region, a scientific and technical information center, a library, a branch of knowledge, an area of science or professional activity) where the most diverse information 'circulates'."
Information Culture and Security for Schoolchildren and Employees, Risk Assessment
The main purpose of creating a comfortable information space is obvious: to give the user access to the documents he or she needs,
regardless of the form in which they are presented and the place where they are stored. A modern person must be able to use information resources and find their way around the information space. To do so, he or she must have search knowledge. And no one can do without it
today: neither the teacher, nor the student, nor the pupil, nor the librarian, who must not only possess this knowledge personally but also pass it on to users of information.
Under the conditions of the informatization of modern society, the formation of the information culture of the individual acquires particular relevance, since broad prospects open up for the individual for the effective use of the information resources accumulated by humanity. The main thing about information today
is that it is no longer regarded as something secondary. There is a growing realization that the quality of life depends more and more on information and its use. In modern society the fate of each individual person depends to a large extent on his or her
information culture, and in the future this dependence will increase.

The difficulty stems from the ambiguity of the very concept of "information culture." There are many concepts that are close but not identical in meaning: "library and bibliographic culture," "reading culture," "computer literacy." Library and bibliographic culture is a set of knowledge, abilities and skills of the reader that ensure effective use of the reference and bibliographic apparatus and the holdings of a library. It includes knowledge of the structure of the library collection, the composition of library catalogs, card files and bibliographic aids, and the rules for using libraries; and the ability to find the necessary sources of information in bibliographic aids, catalogs and card files. Reading culture is an integral part of the general culture of the individual, a set of skills for working with books that includes the conscious choice of subjects, systematic and consistent reading, the ability to apply rational reading techniques, to absorb and deeply comprehend what has been read to the maximum extent, and to handle printed works with care. Computer literacy is the knowledge, abilities and skills in the field of informatics that every person needs in order to use computer technologies effectively in his or her activity. In addition, the structure of information culture includes elements of the following cultures: communicative (culture of communication); lexical (language, the culture of writing and of preparing business documentation); intellectual (the culture of scientific research and mental work); information-legal; worldview-related and moral. All components of information culture are interconnected and interdependent.

There are many definitions of the concept of "information culture." A. Kudrina, Candidate of Pedagogical Sciences, Associate Professor and Head of the Department of Automated Information Processing Technology at KemGAKIT, characterizes it as "a set of knowledge, value orientations, convictions and attitudes that determine the actions and, in general, the activity of a person"; N. B. Zinovieva, Doctor of Pedagogical Sciences and Associate Professor at KGUKI, considers the main subject of forming the information culture of the individual to be "the process of harmonizing a person's inner world in the course of mastering the entire body of socially significant information"6; V. A. Minkina, Doctor of Pedagogical Sciences and Professor at SPbGUKI, holds that "the formation of a person's information culture takes place in his or her everyday activity under the influence of acquired everyday knowledge and skills, information from the mass media, in the course of self-education, and through learning in the family and at work." According to the interpretation of Yu. S. Zubov, Doctor of Pedagogical Sciences and Professor at MGUKI, "information culture is a systematized set of knowledge, abilities, skills

INFORMATION CULTURE OF THE TEACHER

  • the ability to monitor the web space and to search remote databases; to create and update problem-oriented databases and electronic educational publications;
  • the ability to transform information from one form into another, verbal information into tabular or graphic form, ensuring the visualization of knowledge; the ability to verbalize graphic information, and so on;
  • command of the culture and technology of business e-mail;
  • an understanding of the teacher's increased responsibility in the transition from traditional oral to written electronic ways of transmitting information. This applies, for example, to the formation of special requirements for the reliability of recommended information resources, in particular web resources, and for the quality of the texts of electronic consultations, electronic lectures and the like, which may be subject to evaluation and analysis by any third parties.

INFORMATION CULTURE OF THE LEARNER

  • •students' mastery of the skills needed to organize their own information activity, and the development of skills in applying ICT tools in everyday life, in learning activity, and in the further mastery of professions in demand on the labor market.
  • •Acquiring the knowledge that forms the basis of scientific ideas about information, information processes, systems, technologies and models;
  • •Mastering the skills of working with various kinds of information using a computer and other information and communication technology (ICT) tools, organizing one's own information activity and planning its results;
  • •Developing cognitive interests and intellectual and creative abilities by means of ICT;
  • •Fostering a responsible attitude toward information, taking into account the legal and ethical aspects of its dissemination, and a selective attitude toward the information received;
  • •Developing skills in applying ICT tools in everyday life, in carrying out individual and collective projects, in learning activity, and in the further mastery of professions in demand on the labor market

Information security (English: Information Security, also InfoSec) is the practice of preventing unauthorized access, use, disclosure, distortion, alteration, examination, recording or destruction of information. This universal concept applies regardless of the form the data may take (electronic or, for example, physical). The main task of information security is the balanced protection of the confidentiality, integrity and availability of data , with due regard to practicality of application and without any damage to the productivity of the organization . This is achieved mainly through a multi-stage risk management process that makes it possible to identify key assets and intangible assets, sources of threats, vulnerabilities, the potential degree of impact and the possibilities for managing risks. This process is accompanied by an assessment of the effectiveness of the risk management plan .

Information Culture and Security for Schoolchildren and Employees, Risk Assessment

Fig. 1. Diagram of cause-and-effect relationships

It should be noted that information culture also has both an objective and a subjective nature, and the individual is at the same time both the subject and the object of information culture. Noting the ambiguity of all three concepts, O. A. Panchenko and L. V. Panchenko present a complex structure of their cause-and-effect relationships (Fig. 1).

In order to standardize this activity, the scientific and professional communities are in constant cooperation aimed at developing a basic methodology, policies and industry standards in the field of technical measures for information protection, legal liability, and standards for training users and administrators. This standardization is developed to a considerable extent under the influence of a wide range of laws and regulations that govern the ways data is accessed, processed, stored and transmitted. However, the implementation of any standards and methodologies in an organization can have only a superficial effect if a culture of continuous improvement has not been properly instilled

Introduction


The main problem discussed in this article is the specific features of the socialization of modern children and adolescents amid rapidly
growing information flows, above all in the electronic space. The Internet, which has become a natural communication
environment for the younger generation, unquestionably influences the worldview and behavior of schoolchildren. This environment is full of useful information and at the same time serves as a channel for transmitting the risks of socialization. Current risks include, for example, the "death communities" that have become widespread in social networks and actively provoke suicidal acts; thematic groups that encourage various kinds of addictions; and the harmful content widely available on the Internet, which can damage the psycho-emotional health and the moral and intellectual development of children and adolescents. These risks become more real against the background of relatively low parental and pedagogical control, whose exercise, like the prevention of risks, is made harder by the fact that modern children and adolescents far surpass adults in digital competence. In this situation it is important to find productive approaches that ensure favorable socialization of schoolchildren and, where possible, neutralize the risks of the information environment that threaten personal development.
To achieve the stated goals and to clarify the factors that determine the safety of schoolchildren's socialization in the information
environment, we analyzed current domestic and foreign studies relevant to the topic and attempted to determine the relationship between the restrictive and the personality-developing approaches to the problem of ensuring the information security of
students.

The importance of forming the information culture of the individual is fully recognized, as shown by various conferences and the increased number of publications. Having recognized this problem as interdisciplinary, representatives of many fields of knowledge have joined in studying it: librarians, computer scientists, culture scholars, sociologists and philosophers. However, although united by common interests, they consider different phenomena. "Librarians customarily put reader skills and abilities into the concept of the information culture of the individual. Computer scientists link it with computer literacy and the ability to work in electronic networks. Sociologists believe that the manifestation of information culture is a person's orientation in rapidly changing social conditions and the ability to adapt to them by evaluating incoming information critically and independently. Culture scholars and philosophers approach the problem most broadly: they see information culture as a way of human life in the information society and as a component of the process of forming the culture of humanity"3. And all these points of view are valid.

According to the interpretation of Yu. S. Zubov, Doctor of Pedagogical Sciences and Professor at MGUKI, "information culture is a systematized set of knowledge, abilities and skills that ensures the optimal performance of individual information activity aimed at satisfying both professional and non-professional needs"8. According to the definition of E. P. Semenyuk, one of the leading domestic specialists in the field of informatization, information culture is "the information component of human culture as a whole, objectively characterizing the level of all the information processes existing in society and the existing information relations"9. Leading specialists of the Kemerovo State Academy of Culture and Arts N. I. Gendina, N. I. Kolkova, I. L. Skipor and G. A. Starodubova, who have studied this problem in depth, offer the following interpretation of the concept of "information culture of the individual": "The information culture of the individual is one of the components of a person's general culture; a set of an information worldview and a system of knowledge and abilities that ensure purposeful, independent activity for the optimal satisfaction of individual information needs using both traditional and new information technologies. It is the most important factor of successful professional and non-professional activity, as well as of the social protection of the individual in the information society"10. Summarizing all these definitions, we can say that information culture is a systematized set of knowledge, abilities and skills aimed at satisfying information needs that arise in the course of educational, scientific-cognitive and other kinds of activity. The criteria of a person's information culture can be considered his or her ability to formulate an information need adequately, to search effectively for the necessary information across the whole set of information resources, to process information and create qualitatively new information, to maintain individual information retrieval systems, as well as the capacity for information communication and computer literacy. The information culture of society and of the individual must make possible continuous education of the person and greater responsibility for the decisions he or she makes. In the first case, information culture serves as a means of social protection for an individual who is capable of independently building up knowledge, changing the sphere of activity, and regulating his or her own behavior on the basis of a comprehensive analysis of the situation. In the second, information culture is a means of protecting society from ill-considered actions by a person, a guarantee that fundamental decisions in any sphere, whether social, economic or technological, are made only after a thorough analysis of all the available information

General information

Information security is built on the activity of protecting information: ensuring its confidentiality, availability and integrity, and preventing any compromise of it in a critical situation . Such situations include natural, man-made and social disasters, computer failures, physical theft and similar events. While the record keeping of most organizations in the world is still based on paper documents , which require appropriate information security measures, there is a steady rise in the number of initiatives to introduce digital technologies in enterprises , which entails bringing in information technology (IT) security specialists to protect information. These specialists ensure the information security of the technology (in most cases, some kind of computer system). A computer in this context means not only an ordinary household personal computer, but digital devices of any complexity and purpose, ranging from primitive and isolated ones, such as electronic calculators and household appliances, up to industrial control systems and supercomputers connected by computer networks. The largest enterprises and organizations, because of the vital importance and value of information to their business, hire information security specialists, as a rule, onto their own staff. Their tasks include protecting all technologies from malicious cyberattacks, which are often aimed at stealing important confidential information or at taking over control of the organization's internal systems.

Information security, as a field of employment, has developed and grown significantly in recent years. It has given rise to many professional specializations, for example, network and related infrastructure security, software and database protection, information systems auditing, business continuity planning, electronic records discovery and computer forensics[en]. Information security professionals enjoy very stable employment and high demand in the labor market. Large-scale research conducted by the organization (ISC)² showed that as of 2017, 66% of information security managers acknowledged an acute shortage of workforce in their departments, and it is forecast that by 2022 the shortage of specialists in this field will amount to 1,800,000 people worldwide .

Threats and countermeasures

Information security threats can take very diverse forms. As of 2018, the most serious are considered to be threats related to "crime as a service" (Crime-as-a-Service), the Internet of Things, supply chains and the growing complexity of regulatory requirements[10]. "Crime as a service" is a model in which mature criminal communities offer packages of criminal services on the darknet market at affordable prices to novice cybercriminals . This allows the latter to carry out hacker attacks that were previously out of reach because of their high technical complexity or cost, making cybercrime a mass phenomenon . Organizations are actively adopting the Internet of Things, whose devices are often designed without regard for security requirements, which opens up additional opportunities for attack. Moreover, the rapid development and growing complexity of the Internet of Things reduce its transparency, which, combined with vaguely defined legal norms and terms, allows organizations to use the personal data of their customers collected by the devices at their own discretion, without the customers' knowledge. In addition, it is problematic for the organizations themselves to track which of the data collected by Internet of Things devices is transmitted outside. The supply chain threat is that organizations, as a rule, hand over various valuable and confidential information to their suppliers, and as a result lose direct control over it. Thus, the risk of a breach of the confidentiality, integrity or availability of this information increases significantly. More and more new regulatory requirements greatly complicate the management of organizations' vital information assets. For example, the General Data Protection Regulation (GDPR), which came into force in the European Union in 2018, requires any organization, at any time, in any part of its own activity or supply chain, to demonstrate what personal data is held there and for what purposes, how it is processed, stored and protected. Moreover, this information must be provided not only during inspections by authorized bodies, but also at the first request of a private individual who owns that data. Complying with such requirements demands diverting significant budget funds and resources from the organization's other information security tasks. And although putting the processing of personal data in order implies an improvement in information security in the long term, in the short term the organization's risks increase noticeably.

Most people are affected in one way or another by information security threats. For example, they become victims of malicious software (viruses and worms, Trojan programs, ransomware), phishing or identity theft. Phishing is a fraudulent attempt to obtain confidential information (for example, an account name, password or credit card data). Usually an Internet user is lured to a fraudulent website that is indistinguishable from the original website of some organization (a bank, an online store, a social network, etc.) . As a rule, such attempts are made by means of mass mailings of forged e-mails supposedly sent on behalf of the organization itself , containing links to fraudulent sites. After opening such a link in a browser, the unsuspecting user enters their credentials, which fall into the hands of the fraudsters. The term Identity Theft appeared in the English language in 1964 to denote actions in which someone's personal data (for example, a name, a bank account or a credit card number, often obtained by means of phishing) is used for fraud and to commit other crimes. The person in whose name criminals obtain illegal financial advantages and loans or commit other crimes often becomes the accused himself, which can have far-reaching and severe financial and legal consequences for him. Information security has a direct impact on privacy , the definition of which can differ greatly in different cultures .

Government bodies, armed forces, corporations, financial institutions, medical institutions and private entrepreneurs constantly accumulate large amounts of confidential information about their employees, customers, products, scientific research and financial results. If such information falls into the hands of competitors or cybercriminals, it can entail far-reaching legal consequences and irreparable financial and reputational losses for the organization and its customers. From a business point of view, information security must be balanced against costs; the Gordon-Loeb economic model describes a mathematical apparatus for solving this problem[24]. The main ways of countering information security threats, or information risks, are:

  • mitigation — implementing security and countermeasures to eliminate vulnerabilities and prevent threats;
  • transfer — shifting the costs associated with the realization of threats to third parties: insurance or outsourcing companies;
  • acceptance — building financial reserves in case the cost of implementing security measures exceeds the potential damage from the realization of the threat;
  • avoidance — abandoning excessively risky activity.

History of information security

With the appearance of the earliest means of communication, diplomats and military leaders realized the need to develop mechanisms for protecting confidential correspondence and ways of detecting attempts to falsify it . For example, Julius Caesar is credited with inventing, around 50 BC, the Caesar cipher, which was designed to prevent his secret messages from being read by those for whom they were not intended[26]. However, for the most part, protection was provided by controlling the very procedure of handling secret correspondence. Confidential messages were marked so that they would be protected and transmitted only with trusted persons under guard, and kept in secured rooms or strong boxes .

With the development of the postal service, government organizations began to emerge for intercepting, decrypting, reading and resealing letters. Thus in England the Secret Office appeared for these purposes in 1653 . In Russia, the interception of mail was carried out at least since the time of Peter I: from 1690 in Smolensk all letters going abroad were opened. The practice of secretly copying the correspondence of almost all foreign diplomats, so that the addressee would have no suspicions, became systematic in the middle of the 18th century, when the so-called "black chambers" appeared. After a letter was opened, cryptanalysis of the message was required, for which the leading mathematicians of the time were brought into the work of the black chambers. The most outstanding results were achieved by Christian Goldbach, who managed to decrypt 61 letters of Prussian and French ministers in half a year of work. In some cases, after a letter was successfully decrypted, its contents were replaced, a kind of forerunner of the man-in-the-middle attack .

At the beginning of the 19th century in Russia, with the accession of Alexander I, all cryptographic activity came under the authority of the Chancellery of the Ministry of Foreign Affairs. From 1803 the eminent Russian scientist Pavel Lvovich Schilling served in this department. One of the most significant achievements of the Chancellery was the decryption of the orders and correspondence of Napoleon I during the Patriotic War of 1812 . In the middle of the 19th century more complex systems for classifying secret information appeared, allowing governments to manage information depending on its degree of confidentiality. For example, in 1889 the British government to some extent legitimized such a classification by publishing the Official Secrets Act[en][33].

During the First World War, multilevel classification and encryption systems were used by all the belligerents to transmit information, which contributed to the emergence and intensive use of encryption and cryptanalysis units. Thus by the end of 1914 one of the sections of the British Admiralty was formed, "Room 40", which became the leading cryptographic body of Great Britain. On 26 August 1914 the light German cruiser Magdeburg ran aground on the rocks near the island of Odensholm at the mouth of the Gulf of Finland, which then belonged to the Russian Empire. The Germans destroyed all the documents and blew up the ship, but Russian divers, examining the seabed, found two copies of the signal book, one of which was handed over to the British. Having soon obtained the code books for auxiliary vessels, as well as those for communication between ships in distant seas and the enemy vessels accompanying them, the British managed to decrypt the German naval codes. Breaking the code made it possible to read intercepted enemy radio messages. From the end of November 1914, "Room 40" began regular decryption of the radio messages of the German fleet, which carried practically all orders and instructions[34]. The decrypted data was first attempted to be used during the sortie of the German fleet to the British coast on 16 December 1914[35].

In the interwar period encryption systems became more and more complex, so that special machines came to be used for encrypting and decrypting secret messages, of which the best known is the Enigma, created by German engineers in the 1920s. Already in 1932 the Cipher Bureau of Polish intelligence managed to break the Enigma cipher by the method of reverse engineering[36].

The volume of information exchanged by the countries of the anti-Hitler coalition during the Second World War required formal harmonization of national classification systems and of control and management procedures. A set of security classifications, accessible only to the initiated, took shape, defining who may handle documents (as a rule, officers rather than rank-and-file soldiers) and where they should be stored, given the appearance of ever more sophisticated safes and vaults. The belligerents developed procedures for the guaranteed destruction of secret documents. Some violations of such procedures led to the most significant intelligence achievements of the entire war. For example, the crew of the German submarine U-570 failed to properly destroy many secret documents, which fell into the hands of the British who captured it . A vivid example of the use of information security tools is the Enigma mentioned above, a more complex version of which appeared in 1938 and was widely used by the Wehrmacht and other services of the Third Reich. In Great Britain, cryptanalysis of enemy messages encrypted with the Enigma was successfully carried out by a group led by Alan Turing. The decryption machine they developed, the "Turing Bombe", gave considerable help to the anti-Hitler coalition, and is sometimes credited with a decisive role in the Allied victory . In the USA, for encrypting radio communications in the Pacific theater of war, signalmen were recruited from the Navajo Indian tribe, whose language was known to no one outside the USA . The Japanese never managed to find the key to this exotic method of protecting information[40]. In the USSR, from the 1930s, the so-called VCh communication (high-frequency communication) was used to protect the telephone conversations of the country's highest governing bodies (including the Stavka of the Supreme High Command) from eavesdropping; it was based on voice modulation of high-frequency signals and their subsequent scrambling. However, the lack of cryptographic protection made it possible, using a spectrometer, to recover messages from the intercepted signal .

The second half of the 20th century and the beginning of the 21st were marked by the rapid development of telecommunications, computer hardware and software, and data encryption. The appearance of compact, powerful and inexpensive computer equipment made electronic data processing accessible to small businesses and home users. Very quickly computers were connected by the Internet, which led to explosive growth of electronic business. All this, combined with the emergence of cybercrime and numerous cases of international terrorism, created a need for better methods of protecting computers and the information they store, process and transmit. Scientific disciplines such as "Computer Security" and "Information Protection Methods" arose, along with many professional organizations pursuing the common goals of ensuring the security and reliability of information systems .

Definitions of information security

Below are definitions of the term "information security" from various sources:

  • Preservation of the confidentiality, integrity and availability of information. Note: other properties, such as authenticity, accountability, non-repudiation and reliability, may also be included .
  • Protection of information and information systems from unauthorized access, use, disclosure, distortion, modification or destruction in order to ensure confidentiality, integrity and availability .
  • Ensuring the protection of information in an enterprise from disclosure to unauthorized users (confidentiality), unlawful modification (integrity) and unavailability when it is needed (availability) .
  • The process of protecting an organization's intellectual property .
  • One of the risk management disciplines, whose task is to manage the cost of information risks to the business[47].
  • Reasonable assurance that information risks are balanced by appropriate control and management measures[48].
  • Protection of information that minimizes the risk of its disclosure to unauthorized persons .
  • A multidisciplinary area of study and professional activity focused on developing and implementing all kinds of security mechanisms (technical, organizational, human-oriented, legal) in order to protect information from threats wherever it is located (both inside the organization's perimeter and outside it) and, accordingly, the information systems in which the information is created, processed, stored, transmitted and destroyed. The list of security objectives may include confidentiality, integrity, availability, privacy, authenticity and reliability, non-repudiation, accountability and auditability[50].
  • The process of balancing emerging, acting threats against the success of countering those threats by the government bodies responsible for the security of the state

Key Principles of Information Security

Information Culture and Security for Schoolchildren and Employees, Risk Assessment
The CIA triad.

In 1975, Jerome Saltzer and Michael Schroeder, in their paper "The Protection of Information in Computer Systems", were the first to propose dividing security violations into three main categories: unauthorized information release, unauthorized information modification and unauthorized denial of use of information. These categories were later given short names and standardized definitions:

Confidentiality is the property of information being unavailable or closed to unauthorized persons, entities or processes;

Integrity is the property of safeguarding the accuracy and completeness of assets[54];

Availability is the property of information being accessible and ready for use on demand by an authorized subject entitled to it.

Taken together, these three key principles of information security are called the CIA triad.

In 1992, the OECD published its own information security model consisting of nine principles: awareness, responsibility, response, ethics, democracy, risk assessment, security design and implementation, security management and reassessment. In 1996, building on the 1992 OECD publication, the American National Institute of Standards and Technology (NIST) formulated eight basic principles, which state that computer security "supports the mission of the organization", "is an integral element of sound management", "should be cost-effective", "requires a comprehensive and integrated approach", "is constrained by societal factors", "should be periodically reassessed", that "responsibilities and accountability for computer security should be made explicit", and that "system owners have security responsibilities outside their own organizations". On the basis of this model, in 2004 NIST published 33 principles for the engineering design of information security systems, for each of which practical guidelines and recommendations were developed, and these continue to be developed and kept up to date to this day.

In 1998, Donn Parker supplemented the classic CIA triad with three more aspects: possession or control, authenticity and utility. The merits of this model, known as the Parkerian hexad[en] (from hexad, meaning "a group of six items"), are a subject of debate among information security specialists[61].

In 2009, the US Department of Defense published the "Three Fundamental Principles of Computer Security": system susceptibility, access to the flaw and capability to exploit the flaw.

In 2011, the international consortium The Open Group published the information security management standard O-ISM3, in which it abandoned the conceptual definition of the components of the classic CIA triad in favor of an operational definition of them. According to O-ISM3, an individual set of security objectives can be identified for each organization, belonging to one of five categories that correspond to one component of the triad or another: prioritized security objectives (confidentiality), long-term security objectives (integrity), information quality objectives (integrity), access control objectives (availability) and technical security objectives.

Of all the information security models mentioned above, the classic CIA triad remains the most widely recognized and widespread in the international professional community. It is enshrined in national and international standards and has been included in the main educational and certification programs in information security, such as CISSP. Some Russian authors use a calque of it, the "KTsD triad" (the Russian abbreviation for confidentiality, integrity, availability). In the literature, all three of its components, confidentiality, integrity and availability, are synonymously referred to as principles, security attributes, properties, fundamental aspects, information criteria, critical characteristics or basic building blocks .

Meanwhile, debates continue in the professional community about whether the CIA triad keeps pace with rapidly developing technologies and business requirements. As a result of these discussions, recommendations appear on the need to establish a link between security and privacy, as well as proposals for additional principles . Some of them have already been included in the standards of the International Organization for Standardization (ISO):

  • authenticity — the property ensuring that a subject or resource is what it claims to be;
  • accountability — the responsibility of a subject for its actions and decisions;
  • non-repudiation — the ability to prove that an event or action took place, and who was involved, so that the event or action and the subjects related to it cannot later be called into question;
  • reliability — the property of consistency with intended behavior and results.

Confidentiality

The confidentiality of information is achieved by granting access to it with the least privileges, on the basis of the need-to-know[en] principle. In other words, an authorized person should have access only to the information that he or she needs to perform official duties. The privacy-related crimes mentioned above, such as identity theft, are violations of confidentiality. One of the most important measures for ensuring confidentiality is the classification of information, which makes it possible to designate it as strictly confidential, or intended for public or internal use. Encryption of information is a typical example of a means of ensuring confidentiality.

Integrity Information integrity

Precise execution of operations or the making of correct decisions in an organization is possible only on the basis of reliable data stored in files, databases or systems, or transmitted over computer networks. In other words, information must be protected against deliberate, unauthorized or accidental modification relative to its original state, as well as against any distortion during storage, transmission or processing. However, its integrity is threatened by computer viruses and logic bombs, programming errors and malicious changes to program code, data substitution, unauthorized access, backdoors and the like. Besides deliberate actions, in many cases unauthorized changes to important information result from technical failures or human errors, made through carelessness or because of insufficient professional training. For example, integrity is violated by accidental deletion of files, entry of erroneous values, changes to settings and execution of incorrect commands, and this applies to ordinary users and system administrators alike.

Protecting the integrity of information requires a wide variety of controls and change-management measures for the information and the systems that process it. A typical example of such measures is limiting the group of people with change rights to only those who need such access to perform their official duties. In doing so, the principle of separation of duties[en] should be observed, according to which changes to data or to an information system are made by one person and are approved or rejected by another. In addition, any changes during the life cycle of information systems must be coordinated, tested for the preservation of information integrity, and introduced into the system only through correctly formed transactions. Software updates must be carried out in compliance with security measures. Any actions that entail changes must be logged.

Availability Information availability

According to this principle, information must be available to authorized persons when it is needed. The main factors affecting the availability of information systems are DoS attacks (an abbreviation of Denial of Service), ransomware attacks and sabotage. In addition, sources of threats to availability include unintentional human errors made through carelessness or insufficient professional training: accidental deletion of files or database records and erroneous system settings; denial of service resulting from exceeding permissible capacity or a shortage of hardware resources, or from communication network failures; an unsuccessful hardware or software update; and systems shutting down because of power supply failures. Natural disasters also play a significant role in disrupting availability: earthquakes, tornadoes, hurricanes, fires, floods and similar phenomena. In all cases the end user loses access to the information needed for his or her work, and forced downtime results. The criticality of the system to the user and its importance for the survival of the organization as a whole determine how much downtime affects it. Insufficient security measures increase the risk of malware infection, data destruction, outside intrusion or DoS attacks. Such incidents can make systems unavailable to ordinary users.

Non-repudiation

The term "non-repudiation" (sometimes written as one word, Nonrepudiation) first appeared in 1988 in the international standard "Security Architecture for Open Systems Interconnection" (ISO 7498-2). It is usually understood as the opposite of the Anglo-Saxon legal term repudiation, meaning "rejection, denial", which has two main interpretations. On the one hand, it means the fundamental right of a party to refuse, on lawful grounds, to perform obligations under a transaction if, for example, a signature on a paper document was forged, or the original signature was obtained unlawfully (as a result of fraud). In that case the burden of proving the authenticity of the signature lies with the party relying on it. The other interpretation is wrongful refusal to honor obligations. In the context of computer security, this may be, for example, one party's denial of the fact of sending, receiving, authorship or content of an electronic message. In the context of information security, "non-repudiation" is understood as confirmation of the integrity and original origin of data, excluding the possibility of forgery, which can be verified by third parties at any time, or as the establishment of identity (of a person, document or object) that can be considered authentic with a high degree of certainty and cannot be refuted.

Scope (Implementation) of the Concept of "Information Security"

A systems approach to describing information security proposes distinguishing the following components of information security:

  1. Legislative, regulatory and scientific base.
  2. Structure and tasks of the bodies (units) ensuring IT security.
  3. Organizational, technical and regime measures and methods (Information Security Policy).
  4. Software and technical methods and means of ensuring information security.

Each of the components of information security will be examined in detail below in this section.

The goal of implementing information security for any object is to build an information security assurance system (ISAS) for that object. To build and effectively operate an ISAS, it is necessary to:

  • identify the information protection requirements specific to the given object of protection;
  • take into account the requirements of national and international legislation;
  • use established practices (standards, methodologies) for building similar ISASs;
  • determine the units responsible for implementing and supporting the ISAS;
  • distribute among the units the areas of responsibility for fulfilling the ISAS requirements;
  • on the basis of information security risk management, define the general provisions and the technical and organizational requirements that make up the Information Security Policy of the object of protection;
  • implement the requirements of the Information Security Policy by deploying the appropriate software and hardware, engineering and technical, and other methods and means of information protection;
  • implement an Information Security Management System (ISMS);
  • using the ISMS, organize regular monitoring of the effectiveness of the ISAS and, when necessary, review and adjust the ISAS and ISMS.

As the last stage of work shows, the process of implementing an ISAS is continuous and cyclically returns (after each review) to the first stage, repeating all the others in sequence. In this way the ISAS is adjusted to perform information protection tasks effectively and to meet the new requirements of a constantly updated information system.

Regulatory Documents in the Field of Information Security

In the Russian Federation, the regulatory legal acts in the field of information security include[74]:

Acts of federal legislation:

  • International treaties of the Russian Federation;
  • The Constitution of the Russian Federation;
  • Federal-level laws (including federal constitutional laws and codes);
  • Decrees of the President of the Russian Federation;
  • Resolutions of the Government of the Russian Federation;
  • Regulatory legal acts of federal ministries and agencies;
  • Regulatory legal acts of the constituent entities of the Russian Federation, local self-government bodies, etc.

The lists and content of these regulatory documents in the field of information security are discussed in more detail in the section on Information Law.

The regulatory and methodological documents include

  • Methodological documents of Russian state bodies:
    • The Information Security Doctrine of the Russian Federation;
    • Guidance documents of the FSTEC (the State Technical Commission of Russia);
    • Orders of the FSB;
  • Information security standards, among which are distinguished:
    • International standards;
    • State (national) standards of the Russian Federation;
    • Recommendations on standardization;
    • Methodological guidelines.

Bodies (Units) Ensuring Information Security

Depending on the field of application of information protection activities (within state authorities or commercial organizations), the activity itself is organized by special state bodies (units) or by departments (services) of an enterprise.

State bodies of the Russian Federation that oversee activity in the field of information protection:

  • The State Duma Committee on Security;
  • The Security Council of Russia;
  • The Federal Service for Technical and Export Control (FSTEC of Russia);
  • The Federal Security Service of the Russian Federation (FSB of Russia);
  • The Federal Protective Service of the Russian Federation (FSO of Russia);
  • The Foreign Intelligence Service of the Russian Federation (SVR of Russia);
  • The Ministry of Defense of the Russian Federation (Russian Ministry of Defense);
  • The Ministry of Internal Affairs of the Russian Federation (Russian Ministry of Internal Affairs);
  • The Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor);
  • The Central Bank of the Russian Federation (Bank of Russia).

Services organizing information protection at the enterprise level

  • Economic security service;
  • Personnel security service (Security regime department);
  • Human resources service;
  • Information security service.

Organizational, Technical and Regime Measures and Methods

To describe the information protection technology of a specific information system, a so-called Information Security Policy, or Security Policy of the information system in question, is usually built.

Security policy (of information in an organization) (Organizational security policy) is a set of documented rules, procedures, practices or guidelines in the field of information security that an organization follows in its activities.

Security policy of information and communication technologies (ICT security policy) consists of rules, directives and established practices that determine how, within an organization and its information and communication technologies, assets, including critical information, are managed, protected and distributed.

To build an Information Security Policy, it is recommended to consider separately the following areas of protection of the information system:

  • Protection of the objects of the information system;
  • Protection of the processes, procedures and programs for processing information;
  • Protection of communication channels (acoustic, infrared, wired, radio channels, etc.), including protection of information in local networks;
  • Suppression of spurious electromagnetic emissions;
  • Management of the protection system.

For each of the areas listed above, the Information Security Policy must describe the following stages in creating information protection means:

  1. Identification of the information and technical resources subject to protection;
  2. Identification of the full set of potential threats and channels of information leakage;
  3. Assessment of the vulnerability and risks of information given the existing set of threats and leakage channels;
  4. Definition of the requirements for the protection system;
  5. Selection of information protection means and their characteristics;
  6. Implementation and organization of the use of the selected protection measures, methods and means;
  7. Monitoring of integrity and management of the protection system.

The Information Security Policy is formalized as documented requirements for the information system. Documents are usually divided by the level of description (detail) of the protection process.

Top-level documents of the Information Security Policy reflect the organization's position on information protection activities and its aspiration to comply with state and international requirements and standards in this area. Such documents may be called "IS Concept", "IS Management Regulations", "IS Policy", "IS Technical Standard", etc. The distribution of top-level documents is usually not restricted, although such documents may also be issued in two editions, for external and for internal use.

According to GOST R ISO/IEC 17799—2005, the following documents must be drawn up at the top level of the Information Security Policy: the "IS Assurance Concept", the "Rules for Acceptable Use of Information System Resources" and the "Business Continuity Plan".

The middle level includes documents concerning individual aspects of information security. These are requirements for the creation and operation of information protection means and for the organization of the organization's information and business processes in a specific area of information protection. For example: Data Security, Communications Security, Use of Cryptographic Protection Means, Content Filtering, etc. Such documents are usually issued in the form of internal technical and organizational policies (standards) of the organization. All middle-level documents of the information security policy are confidential.

The lower-level information security policy includes work regulations, administration manuals and operating instructions for individual information security services.

Software and Hardware Means of the Information Security Assurance System

The literature proposes the following classification of information protection means.[73]

  • Means of protection against unauthorized access:
    • Authorization tools;
    • Mandatory access control[75];
    • Discretionary access control;
    • Role-based access control;
    • Logging (also called Auditing).
  • Systems for analyzing and modeling information flows (CASE systems).
  • Network monitoring systems:
    • Intrusion detection and prevention systems (IDS/IPS).
    • Data loss prevention systems for confidential information (DLP systems).
  • Protocol analyzers.
  • Antivirus tools.
  • Firewalls.
  • Cryptographic tools:
    • Encryption;
    • Digital signature.
  • Backup systems.
  • Uninterruptible power systems:
    • Uninterruptible power supplies;
    • Load redundancy;
    • Voltage generators.
  • Authentication systems:
    • Password;
    • Access key (physical or electronic);
    • Certificate;
    • Biometrics.
  • Means of preventing tampering with equipment enclosures and theft of equipment.
  • Means of controlling access to premises.
  • Instrumental tools for analyzing protection systems:
    • Antivirus.

Organizational Protection of Informatization Objects

Organizational protection is the regulation of production activity and of the relationships among performers on a legal and regulatory basis that excludes or substantially hinders the unlawful acquisition of confidential information and the manifestation of internal and external threats. Organizational protection provides for:

  • organization of guarding, of the security regime, and of work with personnel and with documents;
  • use of technical security means and of information-analytical activity to identify internal and external threats to business activity[76].

The main organizational measures include:

  • organization of the security regime and guarding. Their purpose is to eliminate the possibility of covert entry by outsiders into the territory and premises;
  • organization of work with employees, which provides for the selection and placement of personnel, including getting to know employees, studying them, training them in the rules for working with confidential information, familiarizing them with the liability for violating information protection rules, etc.;
  • organization of work with documents and documented information, including the organization of the development and use of documents and media containing confidential information, and their registration, execution, return, storage and destruction;
  • organization of the use of technical means for collecting, processing, accumulating and storing confidential information;
  • organization of work on analyzing internal and external threats to confidential information and developing measures to ensure its protection;
  • organization of work on systematic monitoring of how personnel handle confidential information and of the procedure for registering, storing and destroying documents and technical media.

In each specific case, organizational measures take a form and content specific to the given organization, aimed at ensuring information security in particular conditions.

Risks in the Field of Information Security

Many small business managers underestimate the importance of information

продолжение следует...

Продолжение:


Часть 1 Information Culture and Security for Schoolchildren and Employees, Risk Assessment
Часть 2 Enterprise Information Security - Information Culture and Security for Schoolchildren
Часть 3 See also - Information Culture and Security for Schoolchildren and

Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "Theory of education. Organization and methods of educational work"

Terms: Theory of education. Organization and methods of educational work