What is computer security?
Learning intentions
You will learn:
- What the term “computer security” means
- The different types of computer security
- What kinds of data need protecting and why they are valuable
- How security needs differ between individuals and organisations
- The three pillars of cybersecurity: people, processes, and technology
What does “computer security” mean?
“Computer security”
“Computer security” (also called ‘cybersecurity’ or ‘IT security’) is the protection of information systems from theft or damage.
This includes:
🖥️ Hardware
- computers, servers
- disk drives
🎛️ Software
- programs
- viruses and malware
📄 Data
- private information, databases
- personal photos, videos
Protecting computer systems from theft or damage means defending on many different fronts:
🛜 Network
- Unauthorised connection (hacking, penetration)
- Stolen network credentials (log-in details)
🎛️ Software
- Code injection (making programs perform code they weren’t originally intended to run)
- Exploiting vulnerabilities (taking advantage of bugs in programs)
🖥️ Physical
- Stealing hardware
- Damaging hardware and data storage
Why study computer security?
We know that computer security is about protecting digital resources, but why is it worth studying as a subject on its own? Because it will always be relevant, anywhere, everywhere!
Computer security, under the name of ‘cybersecurity’ is its own profession and field of study.
Computer security and data
What is data?
Data is information that we create, use, or store when interacting with electronic devices, apps, and websites.
We create some data intentionally, such as writing a message or uploading a photo. Other data, such as a record of how long we watch a video, may be collected without us noticing.
Data does not have to be shared publicly to be valuable or need protection.
Personal information
Personal information is information about an individual.
Examples include:
- Bank details
- Identification documents, such as a driver’s licence
- Contact details, such as a phone number or email address
We often share this information to prove who we are or access a service. If someone else obtains it, they may be able to misuse it or impersonate us.
User-generated content
Content is material that people create, consume, and share.
This includes:
- Social media posts, photos, and videos
- Private messages
- Work files and school assignments
- Personal documents stored on a device or private network
A document saved only on your laptop is still data, even if you have never posted it online.
User behaviour
User behaviour data records how we interact with devices and services.
Examples include:
- Our browsing history
- The time of day we search for something
- How long we spend on a website or watching a video
The content of a video and the record of you watching it are different kinds of data. Both can be valuable.
Data about other people
We also hold data about other people, such as their contact details, messages, or photos.
Information about who we know and how we are connected is sometimes called a social graph.
Protecting your account can therefore protect other people too. Someone who accesses your messages may also gain access to information that friends shared with you privately.
Why is data valuable?
Data has value to others
Our data is valuable to us, but it can also be valuable to companies.
Companies can use data to:
- Improve their services
- Personalise the content or products they show us
- Target advertising to our interests
- Increase their chances of making a sale
For example, browsing information about clothing could help a company decide which clothes to advertise to you.
Buying and selling data
The data economy involves collecting, buying, selling, and trading valuable data, sometimes without the user’s knowledge.
Data brokers are companies that collect and sell customer data.
For example, a business might want to buy phone numbers so it can contact potential customers about its products.
This helps explain why information can have value even when it does not seem particularly private or important to us.
Stolen data
There is also an underground trade in stolen data, including login details, bank details, and contact information.
Someone could use this information to:
- Access your accounts
- Steal your money
- Impersonate you
Even a detail such as your first pet’s name could help someone guess a password or answer a security question.
Protecting data
Deliberate and accidental harm
Cybersecurity includes protecting data from theft, corruption, and breaches.
- Theft: someone obtains data without permission
- Corruption: data is damaged or changed so that it is no longer reliable or usable
- A breach: data is exposed or accessed without authorisation
Harm can result from a deliberate attack or an accident. For example, sending a private document to the wrong person can expose data without anyone breaking into a system.
Different situations, different needs
Individuals and organisations have different security requirements, resources, and costs.
Small businesses
A limited budget may mean relying on basic protections such as firewalls and antivirus software.
Large organisations
More resources can support dedicated security teams and more advanced systems.
Different industries
The data and services being protected affect the priorities. For example, keeping patient information private and detecting fraudulent financial activity involve different security needs.
The three pillars of cybersecurity
Three pillars working together
The PDF describes three pillars of cybersecurity:
🙂 People
Knowledgeable, motivated people who can follow good security practices.
📈 Processes
Clear procedures that explain what people are expected to do.
💻 Technology
The tools and systems that allow people to follow those procedures.
Good cybersecurity requires all three to work together.
Example: protecting a shared school document
Imagine a teacher needs to share a document containing private student information.
- People: the teacher understands why the information is private and checks who should receive it
- Processes: the school has a procedure for checking recipients and setting access permissions before sharing
- Technology: the document service provides account sign-in and controls for restricting access
Access controls only help if people know how to use them and follow a clear process. A process is also difficult to follow if the necessary tools are unavailable.
Discussion
Which of the three pillars do you think has the biggest impact on security? Explain why, using an example.
Then consider:
- What could go wrong if either of the other two pillars were missing?
- What kinds of data would be at risk?
- Why might that data be valuable to someone else?
Task
In the placemat, fill out another section or edit a previous answer incorporating your understanding of:
- types of data
- the data economy
- the three pillars of cybersecurity (people, processes, technology)
At the bottom of the placemat, start a glossary with all the subject-specific terms.