Information security problems. Components and methods of protecting information
Means of protecting information fall into three groups. Organizational means are rules, instructions, access procedures and legal measures (for example, an employee signs a promise not to disclose data). Technical means are locks, video surveillance, alarms, an uninterruptible power supply (UPS), filters and other devices. Software means are programs for identifying the user and controlling access, antivirus, firewall, encryption and backup programs. The main steps in protecting a personal computer or phone: (1) lock the screen with a password, PIN or biometrics and switch on automatic locking after a short time; (2) create a separate account for each person and use an ordinary account, not an administrator, in daily work; (3) keep the operating system and programs updated, because updates close the weaknesses that were found; (4) keep a backup of important files by the “3-2-1” rule: 3 copies, on 2 kinds of media (for example the computer and an external disk), 1 of them in another place (for example in the cloud); (5) switch on disk encryption so that the files cannot be read even if the device is lost. Archiving gathers files into one file and reduces its size; most archivers can put a password on the archive and use strong encryption (AES-256). Be careful: if you forget the password, the data cannot be recovered, so keep the password in a safe place. Some methods are not real protection: setting the “hidden” mark on a file only hides it from view, and anyone can show it with one click; “protecting” a spreadsheet sheet makes changes harder but does not hide the data. Also check your backup from time to time: a backup that cannot be restored is useless.
“Security audit”: in pairs check your own phone (or a school computer) against 8 points: screen lock, automatic locking, updates, backup, two-step verification, antivirus/protection, app permissions, device encryption. Write the result in a table and fix the weaknesses. Look at someone else's device only with their permission.