☰ Contents · Computing

Methods of protecting information

Lessons 28 · 1 lessons · N. I. Taylaqov (general editor), A. B. Akhmedov, M. D. Pardayeva, A. A. Abdug‘aniyev, U. M. Mirsanov. Informatics and Information Technologies, Grade 11, 1st edition. “Extremum-press”, Tashkent, 2018
28

Information security problems. Components and methods of protecting information

Textbook: pp. 96–101
GoalLists the kinds of threat to information, tells organizational, technical and software means of protection apart, and protects a personal device with passwords, archiving, backups and updates.
New words
organizational protection: rules, instructions, access orders and legal measures · tashkiliy himoyabackup: a copy of data kept separately so it can be restored after a loss · zaxira nusxaaccess control: allowing each user only the actions that their rights permit · kirish nazoratiencryption: turning data into a form that is unreadable without the key · shifrlash
Explanation

Means of protecting information fall into three groups. Organizational means are rules, instructions, access procedures and legal measures (for example, an employee signs a promise not to disclose data). Technical means are locks, video surveillance, alarms, an uninterruptible power supply (UPS), filters and other devices. Software means are programs for identifying the user and controlling access, antivirus, firewall, encryption and backup programs. The main steps in protecting a personal computer or phone: (1) lock the screen with a password, PIN or biometrics and switch on automatic locking after a short time; (2) create a separate account for each person and use an ordinary account, not an administrator, in daily work; (3) keep the operating system and programs updated, because updates close the weaknesses that were found; (4) keep a backup of important files by the “3-2-1” rule: 3 copies, on 2 kinds of media (for example the computer and an external disk), 1 of them in another place (for example in the cloud); (5) switch on disk encryption so that the files cannot be read even if the device is lost. Archiving gathers files into one file and reduces its size; most archivers can put a password on the archive and use strong encryption (AES-256). Be careful: if you forget the password, the data cannot be recovered, so keep the password in a safe place. Some methods are not real protection: setting the “hidden” mark on a file only hides it from view, and anyone can show it with one click; “protecting” a spreadsheet sheet makes changes harder but does not hide the data. Also check your backup from time to time: a backup that cannot be restored is useless.

Worked examples
The “3-2-1” rule: a school project is 15 GB. If one copy is on the computer, a second on an external disk and a third in the cloud, 3·15 = 45 GB of space is needed in total. Even if one copy is lost, the other two remain.
Archiving: if an 800 MB file becomes 200 MB after archiving, the compression ratio is 800 : 200 = 4 times, the size became 4 times smaller. (Pictures and videos are already compressed, so their archives hardly shrink.)
Class activity

“Security audit”: in pairs check your own phone (or a school computer) against 8 points: screen lock, automatic locking, updates, backup, two-step verification, antivirus/protection, app permissions, device encryption. Write the result in a table and fix the weaknesses. Look at someone else's device only with their permission.

Practice
1
Name the three groups of protection means and give an example for each.
2
How much space (GB) do all the copies of 12 GB of data take under the 3-2-1 rule?
3
Why is setting the “hidden” mark on a file not protection?
4
A 1200 MB file became 300 MB after archiving. By how many times was it compressed?