Security Authentication Process
Discuss how this and other information security considerations will affect the design and development process for new information systems.
Authentication refers to the process of validating the identity of information intruder which might be an individual or an object (Stallings, 2006). The process of authentication requires the provision or presentation of relevant credentials and value items in the process of validating who you actually are in trying to access documentation or networking system. The value items focuses on specific characteristics such as concepts you know, what you have, and the status of an individual. Authentication process takes three critical forms in the adoption and implementation. These forms include challenge-response, centralized authentication, and basic authentication. Basic authentication is mainly associated with the server through the application of the concepts of the username and relevant passwords. Challenge-response entails the generation of a challenge to the individual or host requesting for the aspect of authentication thus expectation of the response from the host. Centralized authentication focuses on the validation of authenticity of the hosts or users at a central aspect within the server and network.
Information security considerations such as authentication, authority, and accounting have considerable influence in relation to the development of new designs of the information systems. The development of the new information system must incorporate or implement the concept of the security considerations thus essential for the enhancement of the credibility, availability, and integrity of the information. Authority aspect of the security consideration is essential in the promotion of credibility or validity of the information. Information systems should aim at ensuring the aspect of credibility in order to maximize the application of the information or documentation in addressing the relevant needs and objectives (Stallings, 2006). Authority, therefore, transforms the development of the new information systems towards the achievement of credibility through incorporation of universal applied concepts and aspects. This relates to the accomplishment of the goals and objectives of the security considerations in relation to the development and design of new information systems.
Authentication is essential in enhancing credibility, confidentiality, and integrity of the information (Stallings, 2006). Information systems, communication, and networking aspects should focus on the promotion of the needs of the three security considerations. The development of the new information systems will integrate the authentication needs or considerations thus essential directive towards the achievement of secure networking systems. Type of authentication also plays a critical role in the process of designing new information systems within the technological fields. This is essential because of the need to prevent external and internal intrusion to the private or confidential information and networking systems. It is the role of authentication to protect the networking systems and relevant information from attackers or malware programs through installation by unauthorized users or hosts.
Accounting also ensures that information systems are transparent towards the achievement of the goals of confidentiality, integrity, and availability of the information within the networking system. Accounting will ensure that the development of the new information systems concurs with the universal perspectives. This indicates that the new information systems must adhere to the three security considerations in relation to the networking systems and server or communication systems. This also illustrates the need for the new designs to prevent external and internal intrusion of the confidential information thus affecting the integrity and availability of information for future references (Stallings, 2006).
Include a brief discussion of how to include preventative measures for securing data, such as (but not limited to) backups and remote or redundant storage
There are several ways through which an organization or individuals can integrate preventive measures in relation to the enhancement of the security of the data. In the discussion of this section, the focus will be on various ways through which the organization or individual entities can incorporate protection mechanisms for the security of the data or information.
Implementation of strong password
This is the easiest aspect in relation to the enhancement of security of the networking system and data. In the development or establishment of strong password for the enhancement of security of the data, it is advisable for the users and organizations to avoid application of personal data or information and backward spelling of the common words. These are elements of weak password development thus offering cheap path for the intruders. It is also essential to incorporate the essence of the convenient password checker with the aim of determining how strong the password is in relation to the improvement of security of the data and networking system.
Firewall
In the prevention against security threats to the communication systems and networking concepts, it is essential to adopt and apply strong firewalls (Canavan, 2001). This is vital in controlling the aspects of internet traffic within the networking systems. This is one of the most effective preventive approaches against security threats thus essential for individual or organization entities.
Installation of antivirus protection
Integration of the antivirus and anti-malware programs is essential towards the prevention of the security threats in relation to the networking concepts. These components should be the last line of defense in case of the essence on unwanted attack through the networking systems.
Updating Regularly
In the prevention of the security threats to the server and the networking systems, it is essential for organizations and individual entity to ensure that the systems are fully patched and updated effectively and regularly (Canavan, 2001). This is because it is of minimal importance to install programs then fail to update them regularly. Updating the programs ensures that the tools are safe for the application in the networking systems and servers by the users.
Regular Backup
This is another easier and essential aspect towards the prevention of security threats to the networking systems and computer gargets (Canavan, 2001). This involves storing information to external hard disk or drive. This is a preventive measure in case of loss of the data in the networking system, crash of the computer system, or infection of the files by viruses or malware programs.
Diligent Monitoring
In the management of security threats in relation to networking and computer systems, it is essential to monitor the components and traffics effectively and efficiently (Canavan, 2001). This is application of effective monitoring system to evaluate vulnerability of the systems in relation to the concept of security threats. This will also ensure improvement in performance of the computer systems through implementation of preventive measures.
Education
It is also critical for users to have valuable information on the roles and need for the security of the data (Canavan, 2001). This is essential especially in organizations. Business entities should develop and implement protective policies in relation to the needs of security of the data. Training enhances the knowledge of the employees in relation to accurate measures relevant for the prevention of the security threats to the new designs of the information systems.
Implementation of disk redundancy
This is now of the methods for the prevention of security threats to numerous database servers in the modern society. Components of this method such as redundant array of independent disks (RAID) are essential in the provision of improved security system to the networks and servers. The organization has the opportunity to choose favorable level in the case of disk redundancy thus effective protection to the information within the networking systems and computer servers (Canavan, 2001).
Note what role this will play in the other areas covered in the paper
Prevention of the security system is essential in the promotion of the goals of information systems and security considerations such as authentication, authority, and accounting (Stallings, 2006). Authentication refers to the process of identification and validation of the user with reference to evaluation of the identity. Preventive measures of the security system ensure that achievement of the goals and objectives of the authentication process. This is through implementation of the authentication process in tow distinct processes. Authentication involves identification and validation processes thus determination of the opportunity to access various information. This is essential for the enhancement of confidentiality of information.
Authorization offers users the opportunity to access the information they have the authenticity to view thus limiting accessibility. This enables the prevention of the security threats through restricting users from the information they have no authority to access. Accounting, on the other hand, offers the opportunity for users to audit the application of information. Preventive measures are essential for the achievement of the goals and objectives of the three security considerations thus effective in the enhancement of security of the computer systems and networking aspects (Stallings, 2006).
Provide an overview of several systems and devices that can provide security services to meet the needs raised by the other areas covered in the paper
The achievement of the network security is possible through the incorporation of software and hardware programs. Network security systems are essential in the minimization of the security threats facing the communication systems and networking components. The discussion in this section of the research paper focuses on the illustration of the common network security systems at the disposal of individual or organizational users.
Anti-virus & Anti-spyware
These are software programs that protect the computer systems from intrusion by viruses and other related malware practices or programs (Canavan, 2001). It is the duty of the anti-virus program to act as the last line of defense in enhancing the security of the networking systems. Examples of common anti-virus programs include Norton, Avira, AVG, ESET, and AVAST.
Firewall
Firewall as network security systems can take the form of software or hardware in the prevention of intrusion by the external attacks to the networking systems (Canavan, 2001). It is one of the easiest and convenient systems towards the enhancement of security of the information systems and contents. Firewall refers to the group of programs within the gateway of the network server with the aim of offering protection to the resources of the private networks.
Intrusion Prevention Systems
These systems are also known as the Intrusion detection and prevention systems (IDPS). Their main role in the enhancement of the network security is critical monitoring of the networking system with the aim of identifying malicious traffic or intrusion (Canavan, 2001). The systems operate towards minimization of the threats through identification, blocking, and reporting malicious activities.
Virtual Private Networks
This refers to network system with the ability to incorporate public infrastructures or telecommunication in the provision of secure access to the networking systems of the relevant organizations. The systems operate through the maintenance of privacy, confidentiality, and provision of secure network by implementation of security procedures for the information systems (Canavan, 2001).
References
Stallings, W. (2006). Network security essentials: Applications and standards. Harlow: Prentice Hall.
Canavan, J. E. (2001). Fundamentals of network security. Boston [u.a.: Artech House.
