Chapter 8 – Safety and Security

← Chapter 7All chaptersChapter 9 →
Cambridge IGCSE ICT

Safety and Security

This chapter looks at physical safety when using computer equipment, e-safety and data security. It also covers common threats such as hacking, phishing and malware, together with ways of protecting data.

Physical safetyE-safetyData protectionCyber threatsMalwareData protection methods

Jump to a subtopic

Use these links to move directly to each part of Chapter 8.

8.1 Physical safety

Physical safety is concerned with dangers from computer equipment that could cause serious injury or even loss of life. This is different from the health problems covered in Chapter 5.

The main safety risks

Safety riskPossible causeWays to reduce the risk
ElectrocutionDamaged wires, liquids near electrical equipmentCheck cables regularly, keep drinks away, use safe electrical equipment
FireOverloaded sockets, overheating, short circuitsAvoid overloaded sockets, keep ventilation holes clear, ensure good ventilation
TrippingLoose/trailing cablesUse cable ducts, keep cables away from walkways
Personal injuryHeavy equipment falling from desksUse strong, suitable desks and keep equipment away from edges

Safety vs health

Students should not confuse the two:

Safety risk

Tripping over a cable, electrocution, fire.

Health risk

RSI, eyestrain, headaches, back/neck strain.

8.2 E-Safety

E-safety means the safe and responsible use of technology. It involves both electronic security and the way users behave when using ICT.

using the internetsending and receiving emailsocial mediaonline gaming

Data protection

Most countries have some form of Data Protection Act (DPA).

Data protection legislation is designed to:

protect individuals
prevent personal data being misused
help ensure stored data is accurate
control how data is collected, stored, processed and disclosed

It applies to both computerised and paper records.

Main data protection principles

Important principles include:

data should be processed fairly and lawfully
data should only be used for its stated purpose
data should be accurate
unnecessary data should not be collected
data should not be kept longer than necessary
data should be kept secure

Protecting stored personal data

Simple precautions include:

do not leave personal documents unattended
lock filing cabinets
log out when leaving a computer
use secure user IDs and passwords
avoid sending sensitive information unnecessarily

Personal and sensitive data

Personal data

Personal data is information that can be used to identify a living person.

name
home or email address
passport/ID number
IP address
date of birth
banking details
photograph

Sensitive personal data

Sensitive personal data requires extra protection.

race or ethnicity
political views
religion
medical history
criminal record
genetic/DNA data
biometric data
Sensitive and personal data should be kept confidential and protected against both deliberate and accidental disclosure.

Staying safe when using the internet

Important precautions include:

use trusted websites
look for https and the padlock symbol when appropriate
use secure websites for online purchases
use safe-search settings
be careful when downloading files
keep anti-virus/anti-malware software up to date
log out after using important websites

Email safety

When using email:

only open emails and attachments from known sources
be suspicious of unexpected messages
do not give personal information in replies
avoid clicking suspicious hyperlinks
use strong passwords
be aware of phishing and pharming
use Bcc when appropriate when sending messages to groups so recipients' addresses are not revealed

Social media safety

When using social networking sites:

do not publicly reveal personal information
use privacy settings
only accept people you know
avoid posting photographs that reveal where you live or study
block/report suspicious users
do not arrange to meet an online contact alone
do not reveal your real name or private details in chat rooms

Online gaming safety

Online gaming can expose users to:

cyberbullying
online predators
misuse of webcams
people disguising their identity/voice
viruses and spyware
phishing attacks
Users should not reveal their real name or other personal information while gaming.

8.3 Security of data

Data stored on computers or transmitted over networks can face several security threats.

The main threats covered are:

hackingphishingsmishingvishingpharmingvirusesother malwarecard fraud

Hacking

Hacking is gaining unauthorised or illegal access to a computer system.

Possible effects

personal data may be stolen
identity theft may occur
data may be changed, deleted or corrupted

Protection includes

firewalls
strong user IDs and passwords
anti-hacking/security software
Encryption does not stop hacking, but it can make stolen data unreadable.

Phishing

Phishing uses fake but legitimate-looking emails to trick users into giving away personal information.

A phishing email may:

appear to come from a trusted organisation
contain a link to a fake website
ask the user to enter banking, credit-card or login details

This can lead to fraud or identity theft.

Protection

be suspicious of unexpected emails
avoid unknown attachments
do not click suspicious links
check the sender carefully

Smishing and vishing

Smishing

Smishing = SMS phishing.

Fake text messages are sent to a mobile phone asking the user to:

visit a website
call a number
provide passwords or banking details

Vishing

Vishing = voicemail/voice phishing.

A user receives a voice message or call designed to trick them into giving personal information while believing they are communicating with a genuine organisation.

Easy comparison

ThreatMethod
PhishingEmail
SmishingSMS/text message
VishingVoice/telephone

Pharming

Pharming uses malicious code to redirect a user to a fake website without their knowledge.

Unlike phishing, the user does not necessarily need to click a fraudulent email link.

Possible results

banking/card details stolen
identity theft
fraud

Protection includes

anti-spyware software
checking the website address
looking for https and security indicators

Phishing vs pharming

PhishingPharming
Usually uses a fake email/messageUses malicious code
User is persuaded to follow a link or give dataUser is automatically redirected
Relies heavily on tricking the userCan happen without the user knowingly taking action

Malware

Malware means malicious software designed to damage a system, steal information or interfere with computer operation.

viruseswormsTrojan horsesspyware/key loggersadwareransomware

Virus

A virus is program code that can copy itself and is intended to damage files or cause a computer to malfunction.

A virus needs an active host/program or trigger to run.

Possible effects

computer crashes
files deleted
files corrupted
computer becomes slow or unresponsive

Protection

use updated anti-virus software
avoid unknown software
avoid suspicious email attachments

Worm

A worm can copy itself and spread across networks.

Unlike a virus, it does not need a user to run an infected host program before it can spread.

Worms can therefore spread quickly between computers and may infect an entire network.

Trojan horse

A Trojan horse is malicious software disguised as legitimate software. The user is tricked into running it.

Once installed, it may:

steal personal information
install spyware
install ransomware
give criminals access to the system

Key logger / spyware

Key logging software records the keys a user presses.

It may capture:

passwords
bank account details
card numbers
PINs

The recorded data can then be sent to a cybercriminal. Anti-spyware software can help detect and remove key loggers.

Adware

Adware floods users with unwanted advertisements.

It may:

display pop-ups
redirect browsers
change default searches

Ransomware

Ransomware encrypts or locks a user's data and demands payment to restore access.

Infect computer → encrypt files → demand ransom → offer decryption key after payment

Regular backups are particularly important because they can reduce the need to pay a ransom if files become inaccessible.

Virus vs worm

VirusWorm
Needs a host/triggerStand-alone
User action may be requiredCan spread automatically
Can damage filesCan spread rapidly across networks

Card fraud

Card fraud is the illegal use of a credit or debit card.

Methods covered include:

shoulder surfingcard cloningkey logging

Shoulder surfing

This involves obtaining information by watching or listening while someone enters or gives sensitive details.

For example, someone may:

watch a user enter their PIN
use a hidden camera
listen while card details are given over the phone

Protection

cover the keypad when entering a PIN
avoid entering sensitive data in public places
use biometric authentication where suitable

Card cloning

Card cloning involves copying data from a payment card.

A skimmer can copy information from a magnetic stripe.

Criminals may combine this with shoulder surfing to obtain the PIN and create a fake card.

Protecting data

The chapter covers several methods:

biometricsdigital certificatesSSLencryptionfirewallstwo-factor authenticationuser IDs and passwords

Biometrics

Biometric authentication identifies a person using unique physical characteristics.

fingerprintfaceirisretinavoicesignature

Fingerprint recognition

The scanned fingerprint is compared with one stored in a database.

Advantages

fingerprints are unique
cannot easily be lost or stolen like an ID card
provides strong identification

Disadvantages

equipment can be expensive
damaged fingers may cause scanning problems

Face recognition

Software measures facial features such as:

distance between the eyes
shape of the nose
cheekbones
jawline

These measurements are compared with stored values. Changes in appearance or lighting can reduce accuracy.

Digital certificates

A digital certificate helps prove that data or a message comes from a trusted source.

It uses:

a public key
a private key

Information in a certificate can include:

owner's name
email address
serial number
expiry date
public key
certificate authority's digital signature

Secure Sockets Layer (SSL)

SSL (Secure Sockets Layer) is a protocol that allows information to be transmitted securely over the internet.

SSL encrypts data being transferred between the user's computer and the web server.

Signs of a secure connection include

https
a padlock symbol

Uses include

online banking
online shopping
email
cloud storage
VoIP and messaging

Encryption

Encryption converts readable data into a form that cannot easily be understood without the correct key.

Plain text → Encryption key/process → Cypher text → Decryption key/process → Plain text
Plain text = original readable message
Cypher text/script = encrypted unreadable version
Encryption key = used to encode the data
Decryption key = used to decode it
Important point: Encryption does not prevent hackers accessing data. Instead, it means that if data is stolen, the hacker should not be able to understand it without the decryption key.

Encryption is useful for:

stored files
email
cloud storage
data transmitted over networks

Firewalls

A firewall can be hardware or software placed between a computer/network and an external network such as the internet.

Internet ↔ Firewall ↔ Computer/network

The firewall monitors incoming and outgoing traffic. It can:

check traffic against security rules
block suspicious traffic
warn the user/network manager
prevent access to certain websites
log network activity
help prevent unauthorised access

Two-factor authentication

Authentication means proving who a user is.

Authentication can be based on:

something you know – password/PIN
something you have – smartphone
something unique to you – fingerprint/other biometric

Two-factor authentication (2FA) uses two different authentication methods.

Username + password → one-time code sent to phone → code entered → access granted

User IDs and passwords

A user ID identifies the user, while the password helps prove that they are authorised to access the system.

A strong password should be difficult to guess. The book recommends including:

capital letters
numbers
other keyboard characters

Passwords should also:

not be based on obvious personal information
be kept private
be changed regularly
only be allowed a limited number of incorrect attempts

Important Chapter 8 comparisons

Phishing, smishing, vishing and pharming

ThreatWhat happens
PhishingFake email tries to obtain data
SmishingFake SMS/text message tries to obtain data
VishingFake voice/telephone message tries to obtain data
PharmingUser is redirected to a fake website

Main malware types

MalwareMain idea
VirusCopies itself and damages files; needs a host/trigger
WormSpreads automatically across networks
Trojan horseMalicious program disguised as legitimate software
Spyware/key loggerSecretly collects user information
AdwareDisplays unwanted advertising
RansomwareEncrypts/locks data and demands payment

This summary follows the malware distinctions given in the chapter.

Chapter 8 revision checklist

Students should be able to:

distinguish between health and safety risks
explain electrocution, fire, tripping and personal-injury risks
explain the purpose of data protection legislation
distinguish between personal and sensitive data
describe safe behaviour when using the internet, email and social media
explain hacking
distinguish between phishing, smishing, vishing and pharming
distinguish between viruses, worms, Trojan horses, spyware, adware and ransomware
explain shoulder surfing and card cloning
explain how biometric authentication works
explain the purpose of digital certificates
explain SSL
explain the encryption/decryption process
explain what a firewall does
explain two-factor authentication
describe how strong passwords improve security
← Chapter 7All chaptersChapter 9 →