Write Up: CIA Triad
What is CIA Triad
What is the CIA Triad?
The CIA Triad is a model that consists of Confidentiality, integrity and availability, which
help companies guide their policies toward secured data. This model plays a huge role in
information security.
The Three foundation principles
Confidentiality is a process of protecting information by using measures to authenticate
their right to access it. Integrity is the process of making sure that the data one is accessing
is accurate and reliable. Availability is making sure that data is accessible during events of
outage or other circumstances.
What is Authentication & Authorization?
Authentication is the process of making sure that the person accessing this data is who
they are, so by providing the necessary information they can access this need-to-know
information. Like when you sign into a website, which most likely needs a username and
password. This allows you to access the website and its data. The difference that is
authorization is something that it can ask to further verify that’s it’s you by sending you a
code, message, or calling you to make sure that you are accessing that website or
information at that time. This is an example of a Multi-Factor Authentication.
In conclusion
The CIA Triad is important to information security and the privacy of all data. They are used
together to make sure that the data is secure, accurate, and easily accessible to those who
are authorized.
References
(Wesley Chai: “What is the CIA Triad? Definition, Explanation, Examples”)
(Victor Cervantes: “Confidentiality, Integrity and Authentication (CIA) triad”)
Write Up : Hacking Humans
Hacking humans in Cybersecurity
DNA digitization has its advantage and disadvantage, for there to be a benefit from digitization is to have a backup plan to ensure this process is protected from malicious data breach. But due to the fact that DNA is unique there must be a way to control that information, because any breach can be permanent and cause huge losses. In my opinion there should be another system or a device specifically just for DNA testing that doesn’t involve with the digital world, so we can exclude this lifelong security risk. This can also cause many new ways that people can access data that they shouldn’t or changed something that can benefits them. DNA should never be a factor in someone employment, as this doesn’t determine someone abilities to do that job successfully. Also, organization should be prevented from using this type of data even if its was made known to them. With traditional digital password, they are not permanent which means thy can be fixed, but with biological data its permanent meaning that there has to be zero errors with the human factor. Or a solution to prevent missuses of these data to prevent permanent damage. Human factor will always be a security issues as everything is controlled by us, but with biological data being a factor that can help someone access data while being that person. In conclusion, if these type of data is being used, then they will be a more concern for unauthorized to privilege data as these type data cannot be changed afterwards or recognizable yet.
Write Up : SCADA Systems
SCADA Systems
What are SCADA Systems?
Supervisory Control and Data Acquisition refers to the Industrial Control System or ICS
which is used to control various infrastructure processes like water treatment, wastewater
treatment, gas pipelines, wind farms, and many more. It tracks data in real time and
uploads it to a centralized environment for analysis.
Vulnerabilities associated with critical infrastructure
every system ever made, nothing is perfect and that comes with vulnerabilities, so
with SCADA they are more targeted as this system controls multiple infrastructures. It also
consists of an older system and processes that are outpaced by newer technology which
allows hackers to easier get through its defensive. With SCADA being at one centralized
source, it’s easier for attackers to brute force through the system and even causing the
whole system to go down instantly which can cause vast amounts of damage since SCADA
system are to be monitored in real time.
Mitigating these risks
SCADA systems risk can be mitigated through many measures but to ensure these
measure works is to start with the basic which is the people. They need to be properly
trained on this system and how they work to ensure that it’s properly monitored for
infractions. Then we start by implementing measures to ensure during an outage that it’s
secured or backup in other sources to reduce loss. Also, this system could be updated or
replaced with a more advanced system to increase their security against advanced cyber-
attacks.
In conclusion
SCADA systems are essential for control and analysis of critical infrastructure because
they need real time monitoring since these infrastructures affect every human dally life.
Which means they are highly targeted by hackers since this system is connected to many
organizations and people which they can use against them for personal gains.
References
SCADA System Vulnerabilities to Cyber Attack
https://electricenergyonline.com/energy/magazine/181/article/SCADA-System-
Vulnerabilities-to-Cyber-Attack.htm
CYSE-200T Analytical Paper
The importance of CIA Triad and SCADA systems
Introduction
CIA Triad and SCADA systems are few of the important ways to ensure data is protected in their own way that are critical to organizations and infrastructure. CIA Triad provides organizations with the basic framework on how data should be protected and utilized. While the SCADA system is used for a centralized control and analysis of critical infrastructure to ensure its properly monitored and working correctly daily. Using them can ensure data is protected from accessed from the wrong user and is processed through the right channels to ensure it goes to the right people. Without these systems or frameworks, critical information is at risk of being improperly used for personal gains that can affect every life.
What is the CIA Triad?
The CIA Triad is a model that consists of Confidentiality, integrity and availability, which help companies guide their policies toward secured data. This model plays a vital role in Information security by ensuring that data is secured, accurate, and reliable for those who have the right to utilize it. The three principles of the CIA Triad help organizations secure their data through proper processes and is reliable through basic security protocols.
The Three foundation principles
Confidentiality is a process of protecting information by using measures to authenticate their right to access it. This helps people feel relieved knowing that their personal data or organization data is properly secured from unauthorized access. Integrity is the process of making sure that the data one is accessing is accurate and reliable. This ensures that the data is accurate for customers trying to access it with proper authorization and gives them confidence that the data is properly authenticated when it is accessed. Availability is making sure that data is accessible during events of outage or other circumstances. This
helps organizations give customer reliable satisfaction that their data is accessible during almost any circumstances that prevents them from accessing their data.
What is Authentication & Authorization?
Authentication is the process of making sure that the person accessing this data is who they are, so by providing the necessary information they can access this need-to-know information. Like when you sign into a website, which most likely needs a username and password. This allows you to access the website and its data. The difference that is authorization is something that it can ask to further verify by sending you a code, message, or calling you to make sure that you are accessing that website or information at that time. This is an example of a Multi-Factor Authentication, which is a good way to ensure that data is being accessed from the right person and at the right time by using their information to authenticate themselves.
What are SCADA Systems?
Supervisory Control and Data Acquisition refers to the Industrial Control System or ICS which is used to control various infrastructure processes like water treatment, wastewater treatment, gas pipelines, wind farms, and many more. It tracks data in real time and uploads it to a centralized environment for analysis. It is a centralized hub that obtains information from all these infrastructure processes and analysis them to ensure accurate data. Without this system to control these processes, these can improperly manage and can cause failures that can lead to failures of these processes causing panic in daily life. It’s also a way to analysis complex processes in a centralized environment to reduce spillage and lost data in separate places that can cause inaccurate data.
Vulnerabilities associated with critical infrastructure
With every system ever made, nothing is perfect and that comes with vulnerabilities, so with SCADA they are more targeted as this system controls multiple infrastructures. It also consists of an older system and processes that are outpaced by newer technology which allows hackers to easier get through its defensive. With SCADA being at one centralized source, it’s easier for attackers to brute force through the system and even causing the whole system to go down instantly which can cause vast amounts of damage since SCADA system are to be monitored in real time. This also creates attention to attackers that need a perfect target for their personal gains, and this system is a perfect target since it controls most infrastructure in one system, making it easier to control most systems through one system. It can also be used to access other information that is linked to the system that can be crucial to many other infrastructure and organizations that can cause catastrophic results.
Mitigating these risks
SCADA systems risk can be mitigated through many measures but to ensure these measure works is to start with the basic which is the people. They need to be properly trained on this system and how they work to ensure that it’s properly monitored for infractions. Then we start by implementing measures to ensure during an outage that it’s secured or backup in other sources to reduce loss. Also, this system could be updated or replaced with a more advanced system to increase their security against advanced cyber-attacks. Mitigating these risks is important since this system is not 100 percent secured, so these risks must properly manage and reduce by using a security framework that ensures these risks are not happening.
CIA Triad and SCADA system
The CIA Triad is one of the most important basic frameworks for cybersecurity and crucial to protecting data in critical infrastructure from malicious threats. SCADA system is an important system that has its risks, but it can manage and properly protected by using the CIA triad to ensure it is secured, accurate, and reliable. These two are important in today’s economy that they are used in most critical infrastructure and organization today to ensure data is secured from attacks. CIA Triad is crucial to ensuring SCADA systems is secured through its three core principles Confidentiality, integrity and availability without them the SCADA systems are at risks of attacks can cause outage on critical infrastructure that affects daily life. Without each other, it would render our infrastructure vulnerable to many cybersecurity attacks.
In conclusion
The CIA Triad is important to information security and the privacy of all data. They are used together to make sure that the data is secure, accurate, and easily accessible to those who are authorized. SCADA systems are essential for control and analysis of critical infrastructure because they need real time monitoring since these infrastructures affect every human dally life. Which means they are highly targeted by hackers since this system is connected to many organizations and people which they can use against them for personal gain. Cybersecurity as a hole needs many options to ensure that the data is properly secured and giving people an option to see how their data should be stored without having the thought of it being used against them. By using the CIA Triad and SCADA system we can ensure that these important data are secured in their own way to ensure that its safety from malicious attacks that threaten our critical infrastructure that can affect every person’s daily normal life. So, to ensure that data is correctly secured, we must apply basic protocols like CIA triad and SCADA systems that are being used properly by starting with the basics to reduce cyber or physical threats to various infrastructures.
References
SCADA System Vulnerabilities to Cyber Attack
https://electricenergyonline.com/energy/magazine/181/article/SCADA-System-
Vulnerabilities-to-Cyber-Attack.htm
(Wesley Chai: )
(Victor Cervantes: Confidentiality, Integrity and Authentication (CIA) triad )