Security, Authentication and Data Management
Every defence answers a threat, so you defend by matching a control to how the attacker gets in. Learn the two kinds of threat, the controls that block each, and why a backup beats even a successful attack.
Get the method right under pressure
Free interactive practice on the steps that lose marks under exam pressure.
Start revising freeWhat you'll cover
Every defence answers a threat
Security looks like a long list of words to memorise: malware, phishing, firewalls, encryption, and the rest. It is far easier than a list, because every defence exists to answer a particular THREAT. Learn the pairs, not the list. ⭐⭐ There are really two kinds of threat, and they get in by different routes. Some TRICK A PERSON: phishing sends fake messages, and social engineering manipulates someone into breaking the rules. Others ATTACK THE SYSTEM directly: malware is malicious software that damages, steals or locks data. ⭐ The defences pair up with the route. To stop the person-tricks you train people to be wary and you use strong authentication, so a stolen password alone is not enough. To stop the system attacks you use firewalls, which filter network traffic, and anti-malware, which finds and removes malicious software. ⭐⭐ And encryption is the BACKSTOP behind all of it. Encryption scrambles data so that only someone with the key can read it, which means that even if an attacker gets past everything and steals the data, what they take is unreadable. Data management is the last piece: keeping data SAFE, ACCURATE and AVAILABLE, through access rights that limit who can see it and backups that let it be restored. A backup is what beats even a successful attack such as ransomware. ⚠️ Carry one question through the whole module: what is the threat, and which control blocks THAT route in?
Threats, defences, and the law
Read the first column as ways in, the second as the controls that block them, and the third as keeping data safe and the wider rules that apply.
Tap the two that trick a person
Tap the TWO threats that work by TRICKING A PERSON, rather than by attacking the system directly.
- A fake email that pretends to be your bank and asks you to confirm your details.
- A caller who pretends to be from IT support to get you to reveal a password.
- A virus that spreads through a network and corrupts files.
- Software that locks a computer files until money is paid.
Stolen but unreadable
A laptop is stolen and the thief copies all the files off it. The files had been encrypted. Why does this limit the damage?
- Encryption scrambles the data, so without the key the thief cannot read what they have taken
- Encryption deletes the files as soon as the laptop is stolen
- Encryption acts as a firewall around the laptop
- Encryption means the laptop had no password
Words for staying secure
Six terms this topic turns on. The first three are threats or the trick; the last three are defences.
Match each threat or tool to what it does
- Malware
- Phishing
- A firewall
- Encryption
- A backup
- Malicious software that damages, steals or locks data
- A fake message that tricks a person into giving details
- Filters network traffic to block unwanted connections
- Scrambles data so only a key holder can read it
- A spare copy that lets data be restored after loss or an attack
Two that stop the person being tricked
Select the TWO controls that best defend against a PERSON being tricked, rather than against a system attack.
- Training people to spot and question fake messages and callers
- Two-factor authentication, so a stolen password alone is not enough to get in
- A firewall on the network
- Anti-virus software
Match the control to the threat
Security questions almost always give you a threat and ask for a defence, or the other way round. A few habits earn the marks. ⭐⭐ PAIR THE CONTROL TO THE ROUTE. Ask first whether the threat tricks a PERSON or attacks the SYSTEM. A person-trick is answered by awareness and by strong authentication; a system attack is answered by a firewall and anti-malware. Naming a defence that does not match the route, a firewall against a phishing email, for instance, scores nothing. ⭐ REMEMBER ENCRYPTION IS THE BACKSTOP. It does not stop an attack, but it means that data stolen despite everything is unreadable. So it is the answer whenever the worry is data being intercepted or a device being lost. ⭐⭐ AND REMEMBER BACKUPS BEAT A SUCCESSFUL ATTACK. If ransomware locks the files, no clever defence undoes it, but a recent backup means the data can simply be restored. Data management, access rights and backups, is about keeping data safe, accurate and available even when something goes wrong. Know the wider rules too. A data-protection law requires personal data to be kept safe and used fairly; a computer-misuse law makes unauthorised access illegal; and there are ethical questions of privacy and environmental ones such as the energy that data centres use and the waste from discarded devices. ⚠️ One matter of tone. Explain how a threat works only far enough to defend against it. This subject is about protecting people and data, not about how to carry out an attack. Keep the one-line test to hand: what is the threat, and which control blocks that route in?
Order the response to a suspect message
A message arrives that might be phishing. Put the sensible response into a safe order.
- Notice that it asks for details or urges you to act at once
- Do not click any link in it or reply with any details
- Check the sender against a contact you already know to be genuine
- Report it to the organisation it claims to be from
- Delete the message so it cannot catch you later
Build the case for a backup
A company is worried about ransomware, which locks files until a payment is made. Assemble the advice.
The security run
Five quick decisions about security and data. Three lives.
Protecting a house
Leave computers aside for a screen. Think about how a family keeps its home safe, and notice that different dangers need different answers. ⭐ The first danger is a break-in, someone forcing the door or a window. The answer is physical: strong locks, bolts, maybe an alarm. No amount of good advice to the family stops a crowbar; you need the locks. ⭐⭐ The second danger is quite different: a stranger at the door who talks their way in, pretending to be from the gas company. Locks are useless here, because the family opens the door themselves. The only defence is to have warned everyone in advance not to let a stranger in without checking who they really are. So the two dangers need two kinds of defence, and using the wrong one fails completely. Locks against the smooth talker, or warnings against the crowbar, protect nothing. ⭐ And there is a third, quieter precaution that assumes something will go wrong anyway: keeping a spare set of keys at a trusted relative house. If the family is ever locked out, or a key is lost, they are not stranded, because there is another copy elsewhere. ⚠️ Hold that picture. Keeping data safe is exactly this: some dangers force the system and need a technical lock, some fool the person and need a wary, well-warned user, and a copy kept safely elsewhere rescues you when something gets through anyway.
Complete the security facts
Malicious software that damages, steals or locks data is _____. A fake message that pretends to be from a trusted source to trick you into giving details is _____. Scrambling data so that only someone with the key can read it is _____. Proving that you are who you say you are, using a password or a fingerprint, is _____. A spare copy of data, kept so it can be restored after loss or an attack, is a _____.
Handle three security incidents
Three things happen in one week at a small company. For each, choose the control that answers the actual threat.
- A staff member receives an email that looks like it is from the bank and asks them to confirm the company login details on a linked page.
- A laptop holding customer data is left on a train and never recovered.
- Ransomware locks the company files and demands a payment to unlock them.
Explain how to keep data safe
Explain how a business can protect itself and its data, using the idea that each control answers a particular threat. Cover at least one person-trick and one system attack, and explain why backups matter.
- Explain the difference between a threat that tricks a person and one that attacks the system
- Give one control that defends against a person being tricked, and say why it fits
- Give one control that defends against a system attack, and say why it fits
- Explain what encryption protects, even when data is stolen
- Explain why a backup matters, using an attack such as ransomware as your example