#11 (04/05/2024)
The overlaps between the fields or criminal justice and cyber crime are many. They lie within the committed use of computers, digital technology, networks and their applications of legal principles, law enforcements strategies, and investigative techniques. Criminal justice itself is not just about law enforcement. It is about the law themselves, rules and agencies of accountability, and their structures. It also focuses on how to help the victims of crimes. Cybercrimes are crimes committed with the use of technology sech as computers, networks, and malware. There must be an associated legal framework for the contingency of these occurrences and enforcement of laws. The FBI (Federal Bureau of Investigation) is a leading agency when it comes to investigating these different cyber attacks. There are also specialized crime units who implement specialized techniques of investigation and digital forensics for cases related to cybercriminals. Another overlap happens in court, since these cases need to be handled when it comes to prosecution. This involves all the regular parts of the court like lawyers, judges, police, etc.
Cybercrime and criminal justice overlap when it comes to psychology and sociology. It is important in both fields to understand the motives for certain actions and behaviors. It is also important to recognize the social factors associated. This helps to determine who is more likely to commit a certain crime. This also helps to develop prevention strategies and rehabilitation. Business and economics also overlap in these fields. Criminal justice plays an important roles in protecting citizens and businesses from cybercriminals. All the while, cybercrime itself has had its fair share of impact on the economy. The prevention of cybercrime has been the focus of many business. There is also overlap when it comes to developing and implementing policies and regulations related to cybersecurity and the prevention/prosecution of cybercrimes. There must be collaboration between policy makes, some stakeholders, and the criminal justice system.
#10 (03/24/2024)
There are many techniques and strategies that engineers use for making cyber networks safe. One of these approaches is through network security protocols. A network security protocol encrypts data, ensures its integrity, and authenticates data origins. There are many different network security protocols that engineers implement. Another method is security awareness and training. While they themselves must be properly educated and trained, engineers can formulate and provide training to users on the best practices for personal or business-related cybersecurity (i.e. the manner of online behaviors, recognizing possible attacks, password health). Engineers may also compose firewalls. Firewalls are systems that monitor, and control incoming and outgoing data traffic based on a set of predetermined rules to minimize potential threats.
Engineers must also continuously monitor and improve the effectiveness of a network’s security posture. Analyzing trends is a part of the monitoring and improvement process. They are also part of the team responsible for incident responses and disaster recovery plans. Incident response covers the organization’s process for identifying and responding to cybersecurity incidents. A disaster recovery plan is a document an organization creates with detailed instructions on how to respond to unplanned incidents that may occur. The incidents the organization should plan for contingency can range from natural disasters to cyber-attacks. This process ensures a network can properly respond to a cybersecurity event and recover from any incidents.
Penetration testing and vulnerability assessments are strategies engineers can use to secure cyber networks. These activities are done normally within an organization to identify areas of weakness within the network that need to be addressed. Penetration testing is when experts try to identify and exploit vulnerabilities, while vulnerability assessments are reviews of security weaknesses found in the system. Engineers are also responsible for implementing strategies of access control and authentication, for example, using different methods of authentication and role-based controls.
#9 (03/24/2024)
One-way computers have made the world safer is improved communication. Digital communication systems have allowed for faster and more efficient communication. Information can travel faster in comparison to old methods of communication (ex. Mail delivery system). Easier and faster communication has helped emergency response systems as well. The development of telecommunication paired with location services serves us daily all around the world, especially in the aspect of medical emergency response systems. This leads to the advancements of healthcare due to computers/technology. Medical diagnosis, treatments and research have all been positively impacted and dramatically transformed by computers. Computer-aided surgeries have helped improve trust and the quality of medical procedures. Computers have added to the level of organization that could be had in medical offices with the use of electrical health records and documentation. Another way computers have made the world safer is through automation in industrial settings. Many jobs that were once described as strenuous and hazardous to the human body as well as the environment have been taken over by computer-based systems and machinery. This helped to minimize mistakes and the risk of accidents that could occur due to human error.
While that which is mentioned about as well as many others can be attributed as benefits of the development of computers, there are downfalls that leave society less safe. One of these is the concerns of privacy and surveillance. Personal information is often exploited for different purposes. The automation of workplace systems has left many without jobs and means to provide for themselves and their families. The advancement of technology has also led to the advancements of weapons for malicious purposes. Those weapons include cyber warfare, misinformation and propaganda. Another very considerable factor is the way humanity has become highly dependent on technology. We have turned to computers for education, entertainment, comfort, as well as income.
#8 (03/16/2024)
From what I have learned so far, there is no way to ensure that my computer is 100% safe. There are several ways, however, to get as close to 100% as possible. Even with the implementation of multiple security methods, the safety of my computer could be easily compromised by just one wrong decision made on my end. This means that most of the possibility for insecurity of my device comes from my own actions. This is also true for the level of security my computer can have.
One way I ensure the security of my personal laptop is the sort of passcode that I use. I do not have a set password for my laptop, rather, I use biometrics in the form of a fingerprint. I only used one fingerprint. Even this can be compromised, as biometrics can be falsified. When my siblings and I were younger, we would use my mother’s photos to get into her Apple FaceID secured devices. Another way I incorporate safety on my personal laptop is in the lock settings. If my laptop is physically closed then reopened, the device will be locked, and my designated fingerprint will be required for reentry. If my laptop is idle for a certain time, the system will automatically lock itself and require the designated biometric.
I am very cautious of the type of email messages I trust as well. I have been scammed before in multiple ways and have experienced loss of finances as well as the hacking of personal social media accounts. The has led me to be weary of not only suspicious looking emails, but instant messaging and direct messaging I might receive via various social media platforms. This is all I do personally for my laptop, however, there are additional steps that can be taken to better ensure the security and safety of your device. One of these methods is installing anti-virus and anti-malware software onto the system for protection.
#7 (03/03/2024)
The costs of developing cybersecurity programs in business vary on multiple factors. These factors include the starting monthly charges of the cybersecurity vender providing the services, what products or combinations of products they are offering, and what changes may be needed to implement these services. An example brought to us in module 8 of this course was Cyber Revolution, Inc, whose service is known as the Serenity Plan (depending on the size of the company) starting at $175/month for a business. This plan provides 24/7 emergency support, training to employees, a cyber security brief, and more. Developing cybersecurity programs benefits business because it helps them to stay secure, reach business goals, maintain good legal standings, uphold ethical standards, and ensure the ethical moral of their employees. Employee morale is one aspect that can be emphasized upon here, seeing as employees are responsible for a range of topics within the company: following and adapting policies, hiring processes, workplace culture, etc. The proper continuous training of a business’s employees is vital to its success. Tactics to ensure training is successful could include award/punishment systems.
The costs of developing and maintaining cybersecurity programs are way less than the potential losses that can be had if programs are not properly maintained. The United States has been reported to have the highest levels of loss as far as cyber-attacks are concerned, with those numbers being well above $7.7 million annually. That is far more loss than the costs of our considered Serenity Plan with Cyber Revolution, which may be $3,000 for a very small company. It is known that breaches are bound to occur, even with the proper protection in place. Insurance-like cyber liability programs could cover the losses that could occur in the event of a cyberattack, for example containment and recovering costs, revenue loss, business disruption and much more.
#6 (02/16/2024)
Workplace deviance can be defined as intentional actions made with the desire to cause harm to a company (or even for self-gain). This most often happens from the inside, as in employees or in some cases old employees that were recently let go who still have a certain access within the company. In my criminology class we were taught that the terms criminal and deviance are not interchangeable. Something that is criminal has been determined unacceptable by laws, for which there are established consequences. A deviant action is not necessarily deemed illegal; however, it is still unacceptable to societal standards. In this module, workplace deviance is known also as elite deviance, white-collar crime, corporate crime, etc. Victims of white-collar crimes most likely will not immediately know they are victims, which brings out a big difference between it and street crimes, for which the victims usually know immediately if they have been made a victim or not.
It can be hard to determine what is a white-collar crime or not, which is why it can be easier to get away with than other cybercrimes. Chances are, those participating in these sorts of crimes have some sort of institutional higher education, making them smarter than the average criminal. One way that has allowed for workplace deviance is unauthorized access or abuse of access. This is when employees use the resources they have as a member of a member to gain access to systems or information/data without permission. Or they misuse the access that they may already have, for example, doctors overcharging Medicare for procedures. Embezzlement is the process and crime of stealing money from a business or employer. There are many more examples of white-collar crime and workplace deviance.
#5 (02/06/2024)
Cybersecurity Engineer – creates and executes network security solutions
Y – Digital Forensics Anal(Y)sts – examine data containing evidence of cybercrimes
Blockchain Developers – code the future of secure transactions
Ethical Hacker – search for & report vulnerabilities
Red Team Member – participate in real world cyberattack simulations
SOC Analyst – monitors networks for suspicious activities & potential attacks
Enterprise Architecture
Chief Information Security Officer – anticipates new threats & actively works against them
U – Security A(U)ditor – conduct audits of an organization’s information systems
R – Vi(R)us Technician – detect and Remediate computer virus & malware
Incidents Responders – respond to cybersecurity happenings
Technician – provide technical support
Y – Vulnerabilit(Y) Assessor – find exploits in systems & applications
#4 (02/04/2024)
Cybersecurity risks are present in any country where there are internet users, in some countries more than others. Cybercrime is a global risk, affecting all countries involved. According to our reading this week, Cyber Crime Nation Typologies, the countries, and nations where most cybercrimes originate out of tend to be the wealthiest. In these places, there are more citizens behind the screen, using the internet to make their living. These nations with higher levels of internet connectivity are the victims as well as the sources of different crimes such as fraud, phishing, malware, spam, and digital piracy. There have been different studies conducted on this information. Some aim to show which nations output cybercrime at the highest rates. Others seek to predict the rate of crime occurrence between nations. There is, however, a lack of studies showing how certain nations specialized in cybercrime, or how they can be profiled according to the type of crimes they produce. An index of cybercrime activity has been created by Symantec. The top five nations in this index shown to have the highest concentration of different cybercrime servers where the United States, China, Brazil, Germany, and India. “Some of the top spam sending countries include China, Brazil, the United States, and Russia (Project Honey Pot, 2016).” * Upwards of 72% of all emails received worldwide are spam emails and have contributed to the loss of $22 billion in the year of 2004. Another form of cybercrime that results in substantial loss in many countries is advance fee fraud.
To compare the cybersecurity risks of The United States to another country, one can view the overall cybersecurity score of each country. To get this number as well as its Global Cyber-Safety Index, SEON collected data from the National Cyber Security Index (NCSI), as well as the Global Cybersecurity Index and Cybersecurity Exposure Index (CEI). This was to measure the level of at-risk internets users in each country. Denmark scored the best overall for lowest risk at 8.91, while the United States ranked at number three with an 8.73 on the same scale.
*Quote and information from Cyber Crime nation Typologies: K-Means Clustering of Countries Based on Cyber Crime Rates reading by Alex Kigerl
Secondary Resource: Which countries are more (and least) at risk for cybercrime? CSO News Analysis Article by Shweta Sharma
#3 (01/23/2001)
The first issue I must consider is confidentiality. Details such as someone’s address, phone number, banking information, etc., being comprised can have detrimental effects. An attacker could look to gain unauthorized access to this information for financial gain and to steal identifying information, or sometimes maybe just to out someone publicly over a private disagreement. Certain information is protected by law. This is why it is important that, if an organization must gather it, they follow all guidelines and regulations legally required of them. They also must store it properly. This leads to the next issue, availability, which is a second part of the Cybersecurity triad. Availability in this aspect makes sure that only those who are authorized to access and make changes to data are allowed to do so. For example, a doctor would have access to review and make changes to a patient’s medical records. The patient themselves and say, the parents of a minor, would be able to view but not make changes. A well-meaning pastor who wants the patient to be healed of their afflictions, however, should not have access to change medical records, and would be allowed to view them maybe if given expressed consent by the patient or if said patient is the one showing them.
The third issue I would like to address is one of accuracy. This can also be referred to as integrity and is the third and final aspect of the cybersecurity triad. Integrity is making sure that the data stays true and unaltered by anyone unauthorized. Data’s accuracy can be affected if data is put in incorrectly, or say, if a certain bias is used. Documents must be regularly maintained, and their sources checked. The last issue I would like to bring up is one of risk or security. While it is assumed that security measures will be in place to protect information, the risk of attack is always there so it should always be considered. During our learning for the past two weeks, I ‘ve only seen someone say once that 100% security can be attained. In all other cases, it is said that there is no way that 100% security can be attained and that is important to consider.
#2 (01/20/2024)
Computer Science is a degree path that relates very closely to Cybersecurity. It focuses on teaching students to use multiple subjects such as science, math, programming, and theory, to solve problems with computer software. Both have focuses on computer systems and communication networks. It is easy to say that a Computer Science degree can lay the foundation for a career in Cybersecurity, as degree in this path can lead to positions with titles like ones that can be gained with a Cybersecurity named degree, for example, Security Analyst and Intelligence Analyst. Computer Engineering is another education path offered at ODU (Old Dominion University) that relates to Cybersecurity. This is because while there are focuses on hardware as well as some software aspects. A degree in Computer Engineering could lead to a position in Software Development, whose experience combined with further education could introduce one to a position in, say, Information Systems Security Development. Criminology is another discipline offered that finds relations with Cybersecurity. Prevention of and protection against cybercrime, understanding who commits these crimes and why is a large part of the defensive side of Cybersecurity. So, Criminology is related to Cyber Security because here students learn about theory, criminal justice, and policy as well as research methods. Research is an important key in all these disciplines alike for anyone who wants to be a part of the field because it is important to inform oneself on all the developments, changes, and history of said discipline. Digital Forensics is a certification, rather than a degree, that can be attained at Old Dominion University. Its process includes collecting and analyzing data stored on computers while maintaining its integrity. The discipline is related to Cybersecurity because both involve storing and preserving the integrity and availability of data. There is a term called Cryptology that further research reveals in interchangeable between the two. The discipline also implements risk analysis, which is a key part of Cybersecurity framework and policy development.
#1 (01/11/2024)
My mother and biological father both held IT positions during their time serving in the United States military. I grew up with my mother and stepfather. My mother only stayed in the military for about eight years. After discharge, she would self-contract her technology skills to different organizations. My siblings and I were homeschooled. Not only would we tag along with her during her jobs, but often she would take the time to introduce us to very entry level technology skills. I remember cutting wires, attempting to remember color combinations, and neatly arranging wires along walls and baseboards using zip ties and such. It was always fun when she brought out her IT toolbox. I thought it was so interesting, especially since everything in her toolbox was a miniature size to fit computers and small hardware. I always liked technology when I was using it. Honorably, I’m glad to believe I am following in my parents’ footsteps choosing this major. I always wanted the new iPhone, the fancy laptop, and the newest game systems. When my mother bought me a helicopter with video compatibility I was in love. I tried to learn coding languages here and there, however, I never kept at it long enough. My language interest was held more in foreign languages like Spanish, French, and Arabic, all of which I enjoy studying. I’m excited to say that there is a Python language section in one of my classes this semester. Another reason I’m interested in cybersecurity is the pay, as well as the range of positions available. My mother always told me I have “expensive taste.” I figure having a degree in a field where the entry level salary is better than McDonald’s would be good for me. I see my career allowing me to increase myself financially through funding my businesses, real estate, and investments, as well as allowing me to travel and live a good life that others can be inspired by.