Cyber-security and legislation

Cambridge National IT revision notes, key terms and practice questions.

Threats

  • Malware (viruses, worms, trojans, spyware and ransomware), hacking (gaining unauthorised access to a system), social engineering (phishing, blagging and shoulder surfing), denial of service attacks, and data theft or interception.
  • Human error is a big risk too, such as losing a laptop or sending data to the wrong person.
  • Attackers' motives include money, stealing data, causing disruption, spying, revenge, or just the challenge.

Impacts

  • Loss or theft of data, financial loss (fines, compensation and lost sales), damage to reputation, disruption to services, and identity theft for individuals.

Prevention

  • Physical measures: locks, biometric access, CCTV and security staff.
  • Logical measures: strong passwords and two-factor authentication, firewalls, anti-malware, encryption, user access levels, software updates and backups.
  • Policies and training: acceptable use policies, staff training on spotting phishing, and disaster recovery plans.

Legislation

  • Data Protection Act 2018 and the UK GDPR: rules for handling personal data, and rights for people (to see, correct and erase their data). Organisations can be fined for breaking them. In Guernsey, the Data Protection (Bailiwick of Guernsey) Law, 2017 does the same job.
  • Computer Misuse Act 1990: makes unauthorised access, unauthorised access to commit further crimes, and unauthorised changes to data (such as spreading malware) illegal.
  • Copyright, Designs and Patents Act 1988: protects original work, including software, images and music, from being copied without permission.
  • Freedom of Information Act 2000: gives people the right to ask public bodies, such as councils and schools, for the information they hold.

Key terms

Hacking
Gaining unauthorised access to a computer system.
Malware
Malicious software, such as viruses and ransomware.
Phishing
Fake messages designed to trick people into giving away their details.
Encryption
Scrambling data so it can only be read with the right key.
Firewall
Hardware or software that blocks unauthorised network traffic.
Biometrics
Using body features, such as fingerprints, to identify a person.
Data Protection Act 2018
The UK law that controls how personal data is used.
Computer Misuse Act 1990
The UK law that makes hacking and spreading malware illegal.
Freedom of Information Act 2000
The UK law that lets people request information held by public bodies.

Practise Cyber-security and legislation: 12 questions