Information systems
Secure Socket Layer - SSL
Monday, 07 February 2011 19:01
Secure Sockets Layer (SSL) is predecessor of Transport Layer Security (TLS).
Cryptographic protocol that provides secure communications on the Internet for such things as web browsing, e-mail, Internet faxing, instant messaging and other data transfers. There are slight differences between SSL and TLS, but they are essentially the same.
ISAKMP (Internet Security Association and Key Management Protocol)
Monday, 07 February 2011 18:46
ISAKMP (Internet Security Association and Key Management Protocol) is a protocol for establishing Security Associations (SA) and cryptographic keys in an Internet environment. ISAKMP provides a framework for authentication and key exchange. It is designed to be key exchange independent. Authenticated keying material for use with ISAKMP are provided by protocols such as Internet Key Exchange and Kerberized Internet Negotiation of Keys.
Read more: ISAKMP (Internet Security Association and Key Management Protocol)
OAKLEY Key exchange protocol
Monday, 07 February 2011 16:49
The Oakley Key Determination Protocol is a key-agreement protocol that allows authenticated parties to exchange keying material across an insecure connection using the Diffie-Hellman key exchange algorithm.
Key management
Monday, 07 February 2011 11:22
Key management includes all of the provisions made in a crypto-system design, in cryptographic protocols in that design, in user procedures, and so on, which are related to generation, exchange, storage, safeguarding, use, vetting, and replacement of keys.
Security mechanisms
Sunday, 06 February 2011 21:10
Basic concepts of security mechanism such as pseudorandom number generator, hash functions, symmetric and asymmetric algorithms, steganography, watermarking etc.
Information technology standards overview
Sunday, 06 February 2011 20:23
Standard is an established norm or requirement vital to support and harmonize trading. It is usually a formal document that establishes uniform engineering or technical criteria, methods, processes and practices.
Information system security - threats
Sunday, 06 February 2011 19:36
If the assets identification is the first step of security then threats identification is a step number two.
Information system assets
Sunday, 06 February 2011 19:26
Asset is anything of a value to the organization.
Identification of assets is the first step of security. If we do not know what should be protected we cannot protect it.
Information system privacy concepts
Sunday, 06 February 2011 19:17
Privacy means someone's right to keep their personal matters and relationships secret.
Information system security
Friday, 04 February 2011 21:00
Security importance has been growing with the wider application and penetration of computer communications during last decades. Until recently the emphasis in the field of security and privacy has been on technology. Today the importance of the human factor became a major concern as human resources usually present the weakest link in the security. Security and privacy should become integral part of corporate culture.
Information vs data
Friday, 04 February 2011 20:20
Data
Data are plain (raw) facts representing events or physical environment..
Information
Information is data that have been shaped into a form that is meaningful and useful to human beings.
Data in themselves are fairly useless. But when these data are interpreted and processed to determine its true meaning, they become useful and can be called Information.
Protocols and communications - tcp/ip
Thursday, 03 July 2008 21:25
TCP/IP defines a set of rules to enable computers to communicate over a network. TCP/IP provides end to end connectivity specifying how data should be formatted, addressed, shipped, routed and delivered to the right destination. The specification defines protocols for different types of communication between computers and provides a framework for more detailed standards.
Network layer security - IPSec
Thursday, 03 July 2008 16:23
IPsec (IP security) is a suite of protocols for securing Internet Protocol (IP) communications by authenticating and/or encrypting each IP packet in a data stream.
It operates at the network layer (OSI layer 3). Other internet security protocols in widespread use (e.g. SSL, TLS, SSH), operate from the transport layer up (OSI layers 4 - 7). This makes IPsec more flexible, as it can be used for protecting layer 4 protocols, including both TCP and UDP, the most commonly used transport layer protocols. IPsec has an advantage over SSL and other methods that operate at higher layers: it is transparent to end user and applications.
Information system
Wednesday, 25 June 2008 20:56
An information system (IS) is a system, whether automated or manual, that comprises people, machines and/or methods organized to collect, process, transmit and disseminate data that represent user information.