1. Provide an IT example that relates to the ethical issues for the ideas of privacy, accuracy, property, and accessibility.
Privacy – issues involving collecting, storing, and disseminating information about individuals.
Accuracy – issues involving the authenticity, fidelity, and accuracy of information that is collected and processed.
Property – issues involving the ownership and value of information.
Accessibility – issues involving around who should have access to information and whether they should have to pay for this access
2. What are the 5 general types of IT threats? Provide an example for each one
Human error
Natural disaster
Malicious behaviour
Malicious code: virus, spam, phishing
Management security negligence – through incorrect procedure and recovery established within workplace
3. Describe/discuss three types of software attack and a problem that may result from them
A denial of service: when front end of company’s internet is flooded with ping of death, and site can be flooded until ransom is payed
Virus: malicious code not done anymore to cause harm but to steal information
Spam: junk mail which users high numbers to gain profits
Phishing: using fake identification through emails to gain information of other.

http://www.hyperlearn.com/images/ComputerChainedDown.jpg
4. Describe the four major types of security controls in relation to protecting information systems.
Authentication: system knowing exactly who the user is, done by entering passwords, security bar-coded card or biometric scanning of fingerprints, eye detection etc.
Physical security: entering server rooms are highly secure and limited to access. Other procedures such as locking computers when leaving terminals. Administration limitation on access is also a manipulated control.
Authorisation: determines which actions, rights, or privileges the person has, based on the verified identity.
5. What is information system auditing?
Process of evaluating the suitability and validity of an organization's information systems, practices and operations to ensure people who view or access the files should be viewing the files (that is authorised)
6. What is the difference between authentication and authorization and why are they important to e-Commerce/give an example of their relevance to e-Commerce
Authentication and authorization are important to e-Commerce because once users have been properly authenticated then their rights and privileges that they have on the organisation systems are established. For example, this allows a companies system to be better secured whilst granting access to employees for activities where there is justifiable need to grant authorization.










