Cybersecurity: Techno-legal Domains
Keywords:
cybersecurity, security trends, risks, attacks, Botnet, Attack Vectors, threats, vulnerabilities, system hardening, layering security, security policy, processes, review, controls, digital forensics, digital assets, proprietary assets, role-players, responsibilities, mitigation, remediation, training, techno-legal solutions.Abstract
In the information age or the digital era, cybersecurity measures require the adoption of international standards by scrupulously complying the international protocols and norms since the digital assets of a corporate Company or organization and intangible property under the intellectual property regime have assumed money value as what William Gibson predicted three decades ago. The cybersecurity comprises of both physical and logical security, implying the system hardening and layering security measures in tune with the cybersecurity policy. Information processed by the corporate Company needs to be protected and secured by the top level management on a high priority basis by providing the required resources in a cost-effective manner. All the risk factors, threats and vulnerabilities should be analysed, processed and complied by affording technological and legal safeguards. The plans, approaches and strategies should be formulated by the top level management to mitigate and provide solutions to the challenges posed by the cyber attackers. Cybersecurity being the long-term strategy for high structured corporate Companies, the security 'programme document' is required to be prepared and reviewed periodically. The top security sleuths should exercise due diligence to confine to the 'business specific' needs than resorting to 'overstepping details' in the security document to avoid confusion. The latest trends of attacks should invariably be addressed in a copious manner towards achieving the goals and objectives of an organization. In order that the security plan to be successful, the responsibility should start with the top level management and made functional at every single level with the 'need to know and need to do basis
References
1. Abbreviated as 'Information Communication Technology' which gave rise to cyber crimes
2. Abbreviated as 'Internet Wireless Technology' resulting in the emergence of Voice Over Internet Protocol (VOIP) crimes
3. Abbreviated as Computer Systems Group, a global digital leader.
4. Abbreviated as Information System Security Association.
5. Vulnerabilities are of imminent danger to cybersecurity.
6. Abbreviated as M ulti-National Companies.
7. Abbreviated as Trans-National Companies
8. Abbreviated as Liberalization, Privatization and Globalization.
9. Abbreviated as Organization for Economic Cooperation & Development NJCSL (2018) 56-64 © Law Journals 2018. All Rights Reserved Page 64
10. The Shere Committee (1995), constituted under the chairmanship of Mrs. K.S Shere recommended for enactment of the Data Protection Act as a long-term measure, but in vain.
11. The data -related cyber attacks mainly include plagiarism or data theft, data diddling, masquer ading or shoulder surfing, phishing and criminal damage to data etc.
12. Software-related cyber attacks include software piracy, source code theft, packet sniffing, cloning of smart cards, online frauds etc.
13. Technology-related cyber attacks include hacking, cr acking, whacking, piggybacking, eavesdropping, spiking, distributed denial of services (DDOS), cyber terrorism etc.
14. Botnet is an automated robot distributed across the compromised computer network to launch Denial of Service attacks.
15. The pawn has no real power but controlled and used by others to achieve some result to their advantage.
16. Necurs is the largest Botnet with 6.1 Bots capable of causing loss of millions of dollars which was developed in July 2016.
17. Spewing implies ejecting large volumes of e-mail data by force.
18. AttackVectors could be ingress (intrusion) and egress (exfiltration) vectors, wherein the former launches the attack on moving data in the cyberspace and the latter circumvents the network controls to gain ingress into the computer system or the network.
19. This source code is a Trojan that surfaces at a later stage.
20. A website contains huge information which is of general nature, classified or unclassified data and the classified information comprises confidential or price sensitive data.
21. Stucknet was discovered in 2010.
22. A firewall includes packet filtering, application firewall systems, dynamic packet filtering tracks and next generation firewall.
23. Threats imply the potentially hostile activity by the cyber attackers in the internal or external environment.
24. Skywiper was discovered in 2012.25. A Authorization implies the 'need to know and need to do basis'.
25. Authorization implies the 'need to know and need to do basis'.
26. Standards imply the mandatory international norms or protocols which provide th e means to specific application and procedure; International Organization for Standardization (ISO) and International Electro -technical Commission (IEC) together with the Joint Technical Committee have developed international standards in the field of information technology.
27. http://appknox.com/aglance-at-medias- cybersecurity-laws/
28. The term 'resilient' is derived from the Latin word 'resilire', meaning 'to spring back to the shape' or able to quickly return to the good condition.
29. This Act was amended in 2008 with effect from 2009.
30. WLAN connects computers and other components to the network using an access point device called the "wireless networking hub" with a malafide intention of carrying out cyber attacks. Cite this Article M.K. Nagaraja . Cybersecurity: Techno - legal Domains. National Journal of Cyber Security Law. 2018; 1(1): 56-64p.
