Matua Doc

Matua Doc

What is computer security?

Learning intentions

You will learn:

  1. What the term “computer security” means
  2. The different types of computer security
  3. What kinds of data need protecting and why they are valuable
  4. How security needs differ between individuals and organisations
  5. The three pillars of cybersecurity: people, processes, and technology

What does “computer security” mean?

“Computer security”

“Computer security” (also called ‘cybersecurity’ or ‘IT security’) is the protection of information systems from theft or damage.

This includes:

🖥️ Hardware

  • computers, servers
  • disk drives

🎛️ Software

  • programs
  • viruses and malware

📄 Data

  • private information, databases
  • personal photos, videos

Protecting computer systems from theft or damage means defending on many different fronts:

🛜 Network

  • Unauthorised connection (hacking, penetration)
  • Stolen network credentials (log-in details)

🎛️ Software

  • Code injection (making programs perform code they weren’t originally intended to run)
  • Exploiting vulnerabilities (taking advantage of bugs in programs)

🖥️ Physical

  • Stealing hardware
  • Damaging hardware and data storage

Why study computer security?

We know that computer security is about protecting digital resources, but why is it worth studying as a subject on its own? Because it will always be relevant, anywhere, everywhere!

Computer security, under the name of ‘cybersecurity’ is its own profession and field of study.

Computer security and data

What is data?

Data is information that we create, use, or store when interacting with electronic devices, apps, and websites.

We create some data intentionally, such as writing a message or uploading a photo. Other data, such as a record of how long we watch a video, may be collected without us noticing.

Data does not have to be shared publicly to be valuable or need protection.

Personal information

Personal information is information about an individual.

Examples include:

  • Bank details
  • Identification documents, such as a driver’s licence
  • Contact details, such as a phone number or email address

We often share this information to prove who we are or access a service. If someone else obtains it, they may be able to misuse it or impersonate us.

User-generated content

Content is material that people create, consume, and share.

This includes:

  • Social media posts, photos, and videos
  • Private messages
  • Work files and school assignments
  • Personal documents stored on a device or private network

A document saved only on your laptop is still data, even if you have never posted it online.

User behaviour

User behaviour data records how we interact with devices and services.

Examples include:

  • Our browsing history
  • The time of day we search for something
  • How long we spend on a website or watching a video

The content of a video and the record of you watching it are different kinds of data. Both can be valuable.

Data about other people

We also hold data about other people, such as their contact details, messages, or photos.

Information about who we know and how we are connected is sometimes called a social graph.

Protecting your account can therefore protect other people too. Someone who accesses your messages may also gain access to information that friends shared with you privately.

Why is data valuable?

Data has value to others

Our data is valuable to us, but it can also be valuable to companies.

Companies can use data to:

  • Improve their services
  • Personalise the content or products they show us
  • Target advertising to our interests
  • Increase their chances of making a sale

For example, browsing information about clothing could help a company decide which clothes to advertise to you.

Buying and selling data

The data economy involves collecting, buying, selling, and trading valuable data, sometimes without the user’s knowledge.

Data brokers are companies that collect and sell customer data.

For example, a business might want to buy phone numbers so it can contact potential customers about its products.

This helps explain why information can have value even when it does not seem particularly private or important to us.

Stolen data

There is also an underground trade in stolen data, including login details, bank details, and contact information.

Someone could use this information to:

  • Access your accounts
  • Steal your money
  • Impersonate you

Even a detail such as your first pet’s name could help someone guess a password or answer a security question.

Protecting data

Deliberate and accidental harm

Cybersecurity includes protecting data from theft, corruption, and breaches.

  • Theft: someone obtains data without permission
  • Corruption: data is damaged or changed so that it is no longer reliable or usable
  • A breach: data is exposed or accessed without authorisation

Harm can result from a deliberate attack or an accident. For example, sending a private document to the wrong person can expose data without anyone breaking into a system.

Different situations, different needs

Individuals and organisations have different security requirements, resources, and costs.

Small businesses

A limited budget may mean relying on basic protections such as firewalls and antivirus software.

Large organisations

More resources can support dedicated security teams and more advanced systems.

Different industries

The data and services being protected affect the priorities. For example, keeping patient information private and detecting fraudulent financial activity involve different security needs.

The three pillars of cybersecurity

Three pillars working together

The PDF describes three pillars of cybersecurity:

🙂 People

Knowledgeable, motivated people who can follow good security practices.

📈 Processes

Clear procedures that explain what people are expected to do.

💻 Technology

The tools and systems that allow people to follow those procedures.

Good cybersecurity requires all three to work together.

Example: protecting a shared school document

Imagine a teacher needs to share a document containing private student information.

  • People: the teacher understands why the information is private and checks who should receive it
  • Processes: the school has a procedure for checking recipients and setting access permissions before sharing
  • Technology: the document service provides account sign-in and controls for restricting access

Access controls only help if people know how to use them and follow a clear process. A process is also difficult to follow if the necessary tools are unavailable.

Discussion

Which of the three pillars do you think has the biggest impact on security? Explain why, using an example.

Then consider:

  1. What could go wrong if either of the other two pillars were missing?
  2. What kinds of data would be at risk?
  3. Why might that data be valuable to someone else?

Task

In the placemat, fill out another section or edit a previous answer incorporating your understanding of:

  1. types of data
  2. the data economy
  3. the three pillars of cybersecurity (people, processes, technology)

At the bottom of the placemat, start a glossary with all the subject-specific terms.