Protecting Information Assets
David L. Cannon · CISA · 2016
This chapter discusses the implementation of access controls by using administrative, physical, and technical method for protecting information assets. Sabotage is defined as willful and malicious destruction of an employer's property, often during a labor dispute or to cause malicious interference with normal operations. The intention is to steal any perceived advancements in position or technology. Telecommunications traveling through each country are subject to legal eavesdropping by governments. Additional care must be taken to keep secrets out of the hands of a competitor. The mishandling of information can result in the loss of trade secrets. Valuable information concerning system designs, future marketing plans, and corporate formulas could be released without any method of recovering the data. Once a secret is out, there is no way to make the information secret again. Security must cover the entire sequence of manual and automated steps regardless of the department and the system used. Attackers will always attack between the work steps. Depending on the data classification in the RMS, different levels of access may be provided with or without authentication. The marketing website frequently allows unauthenticated users access to the data contained on the system. Employees and clients will have their own login with weak authentication or strong authentication.