Information Risk Management Paper

Introductionby the company. In this regard, a problem may arise
Businesses have now realized that the security ofout of the design of the software being used. This
their information could make or break theirusually means that the system is not protected from
organization. For this particular paper, the discussionvulnerabilities associated with the system and this
will be limited to the security threats and risk factorsmay prove to be difficult for the company.  Such a
associated with baby products productionscenario may be an intended consequence of
Vulnerabilities of the systemchoosing an operating system that is low on security.
Potential of external and internal threatsBecause the use of high proof security software
Information systems have become highlycould prove to cause slow progress within the
complicated. Consequently, there is a need tocompany, then it would be advisable for one to
establish a comprehensive approach to deal withconsider another mechanism for handling this scenario.
external threats. One of the most common yetIt should also be noted that there are certain
dangerous external threats is the issue of hacking.circumstances in which the coding information can be
Since the company places considerable informationmessed up. For instance, in the case that a language
about its clients and itself in its information system,such as C++  or C is being used, then the baby
then chances are unauthorized persons may gainproducts company could experience integer overflow,
access to these pieces of information. (Borodzicz,buffer overflows, code injection among other issues.
2005)(Gasser, 2005)
External threats may occur in the form of domesticIn certain circumstances, system malfunctions can
or foreign competitors to the baby productsoccur at any one time. This usually means that the
company who may be interested in finding out trademain server within the company may malfunction and
secrets that would enable them to get ahead of thechances of these occurrences are quite unpredictable.
baby products company. In other circumstances,Besides this, there may be instances in which hackers
information brokers who operate on a freelance levelmay choose to enter into the computer system of
may do this kind of thing in order to benefit financiallythe baby product companies especially when there
from the endeavor. In other circumstances, it mayare flaws within the system's encryption system.
be that there are hackers who engage inLevels of security that are appropriate to secure the
unauthorized entry of computer system for fun. Ininformation system while allowing maximum amount
certain incidences, this may be out of malice fromof uninterrupted work flow
persons with some psychological problems. CommonThe company under consideration is one in which
thieves may also break into the company'sproduction continues on a twenty four hour basis.
information systems to as to steal laptops orConsequently, the use of certain extreme security
computers and sell them for profit.measures may slow down work. The company
External threats require a lot of attention owing toshould begin by implementing some of the basis
the fact that the internet brings with it a lot offorms of risk management for information systems.
opportunities for hacking. In this regard, the internetFirst of all, passwords should be  protected because
was created in such a manner that it did not considerpasswords allow users the ability to either change,
the issue of security. There are intricate networksdestroy or merely use the company's information.
that are connected and there are numerous ways inConsequently, the company under consideration must
which these systems can be interjected. Matters aredo any of the following; it could attempt to protect
also made worse by the fact that intruders canthe accounts of the administrator and the people
remain anonymous while doing some of the thingsusing it so that no one can engage in unauthorized
that are related to information systems. It should alsoentry by using rare passwords. This system should
be noted that due to automation of systems, it isalso be backed up by frequent changes to the
now possible for hackers to get into the babypasswords. Employees should also be prevented
products system without possessing seriousfrom sharing passwords or information about it with
knowledge about it. Consequently, care should beone another.
taken by this company to guard against unauthorizedThe next step in implementing security within this
entry because it provides hackers with low cost andcompany is through the use of proper software.
low risk activities that have the potential to provideSoftware can be vulnerable to attack when there
high gains to the affected person. The Baby productsare no mechanisms for installing new versions. In
company should therefore watch out for this type ofcertain circumstances, this can occur automatically.
risk. (Gorrod, 2004)However, in cases where this is not the cases, then
While internal threats receive little if any attention,the software vendors of that respective company
research has shown that their occurrence has theneed to be checked from time to time to ensure
potential to create greater losses to companiesthat they adhere to those operations. (Scheier, 2006)
owing to the position of the offenders. Consequently,Antivirus software is another way in which threats
the same thing can happen to this particular company.can be minimized and this could be done through the
Internal threats to security may emanate frominstallation, operation and update of the antivirus. In
disgruntled employees who may want to get back torelation to the latter approach is the minimized use of
leaders of the organization. In other circumstances,the root or the administrator account which could
employees may simply be dishonest and may belead to vulnerability to all the systems.
interested in advancing their financial or careerLastly, the company should also look for ways in
positions through unscrupulous means. It should bewhich it can minimize phishing through user education.
noted that this kind of security threat to informationEmployees should know that no reputable company
systems may be done through authorized access.would require the passage of confidential information
The baby products company is in danger of dealingsuch as security numbers though email and this
with any of the following forms of internal attackssignifies phishing.
- Financial fraudConclusion
- Sabotage of networksGiven the circumstances under which the latter
- Denial of service to clientscompany is operating under. Installation of certain
- Theft of proprietary data and informationstringent safety measures may disrupt workflows.
Insider threats in this regard may be seen throughConsequently, in order to deal with some of the risk
any of the following routes and they may include thefactors, then the company should instate basic
compartmented unauthorized entry of computersafety measures such as the use of and update of
systems. In other scenarios, this could be seengood software, password protection, installation of
through the process of surfing in classified libraries.good antivirus and protecting the company against
The latter may apply to the baby products companyphishing.
through the browsing supplier related websites.References
Additionally, it may apply to processing and storingBorodzicz, E. (2005): Crisis, Risk and Security
classified information on systems that have not yetManagement, Wiley Publishers
been approved by the authorities.Gorrod, M. (2004): Risk Management Systems;
Natural or unintended events that can jeopardize thePalgrave Publishers
systemScheier, B. (2006): Digital security in a networked
There are a number of occurrences that can ruin theworld; Pocket Books
information system for the baby products company.Gasser, M.
The first could lie in the type of software being used