Top Banner
ENHANCING INFORMATION SECURITY & STRENGTHENING USER EDUCATION 提升 學校資訊保安 加強 用戶教育 黃健威老師( A lbert W ong 資訊科技教育領袖協會( A i TLE )主席 英華書院( YWC )資訊科技統籌及電腦科老師 手提 / W hatsapp 9028 9443 / 電郵: [email protected]
58

ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

Dec 25, 2021

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

ENHANCING INFORMATION SECURITY

& STRENGTHENING USER EDUCATION

提升學校資訊保安及加強用戶教育黃健威老師(Albert Wong)

資訊科技教育領袖協會(AiTLE)主席

英華書院(YWC)資訊科技統籌及電腦科老師

手提 / Whatsapp:9028 9443 / 電郵:[email protected]

Page 2: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 3: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 4: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 5: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 6: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 7: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 8: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 9: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

https://www.edb.gov.hk/tc/edu-system/primary-secondary/applicable-to-primary-secondary/it-in-

edu/Information-Security/information-security-in-school.html

Page 10: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 11: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

https://www.ogcio.gov.hk/en/our_work

/information_cyber_security/governme

nt/doc/G3.pdf

Page 12: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 13: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 14: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 15: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

ENHANCING INFORMATION SECURITY

& STRENGTHENING USER EDUCATION

提升學校資訊保安及加強用戶教育黃健威老師(Albert Wong)

資訊科技教育領袖協會(AiTLE)主席

英華書院(YWC)資訊科技統籌及電腦科老師

手提 / Whatsapp:9028 9443 / 電郵:[email protected]

Page 16: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

EXPERIENCE SHARING BASED ON

• SECaaS

• School IT Management

• School ICT / CL Teaching

Page 17: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS

• “Security as a Service” pilot project

• user training

• security check and audit

Page 18: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS

• “Security as a Service” pilot project

• user training

• security check and audit

Page 19: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Website Security Check

• Critical

• The unauthorized disclosure of information could be expected to have

a severe or catastrophic adverse effect on organizational operations,

organizational assets, or individuals. Exploit is trivial and/or readily

available. Probability of exploit is high.

• High

• The unauthorized disclosure of information could be expected to have

a severe or catastrophic adverse effect on organizational operations,

organizational assets, or individuals.

Page 20: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Website Security Check•Medium

• The unauthorized disclosure of information could be expected

to have a serious adverse effect on organizational

operations, organizational assets, or individuals.

• Low

• The unauthorized disclosure of information could be expected

to have a limited adverse effect on organizational

operations, organizational assets, or individuals.

Page 21: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Website Security Check

• CMS for Website

• Using cookie to store username and password

• especially for CMS admin page

• allows attackers do unlimited brute-force attack

Page 22: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Website Security Check

• CMS for Website

• some non-school-related news

• exists in the website's database

• or even accessible webpages

Page 23: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Security Risk Assessment

• IT Security Policy

• Access Control

• Security Incident Management

• Vulnerability Scan

• Web Penetration Test

Page 24: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Security Risk Assessment

• IT Security Policy

• Access Control

• Security Incident Management

• Vulnerability Scan

• Web Penetration Test

Page 25: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 26: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

學校資訊容易因

網頁伺服器未進

行加密及有效認

在傳輸過程中被

駭客截取

令學生或家長個

人資料外泄。

Page 27: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

USER EDUCATION : PASSWORD HANDLING

Teaching ICT :

social implication

Page 28: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 29: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 30: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 31: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 32: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

CONTENT

•Who are we ?

• Where are we ?

• IT in education vs computer subject

• Systems managed by IT in education

• Not related to IT in education

• Your first system in YWC : eClass

• Your first system login

Page 33: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

CONTENT

•Who are we ?

• Where are we ?

• IT in education vs computer subject

• Systems managed by IT in education

• Not related to IT in education

• Your first system in YWC : eClass

• Your first system login

Page 34: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 35: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 36: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 37: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 38: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

STOP

Page 39: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 40: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 41: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 42: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 43: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 44: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 45: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 46: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 47: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 48: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Security Risk Assessment

• IT Security Policy

• Access Control

• Security Incident Management

• Vulnerability Scan

• Web Penetration Test

Page 49: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 50: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Security Risk Assessment

• Communications Security

• System acquisition, development &

maintenance

Page 51: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Security Risk Assessment

• Communications Security

• Cleartext submission of password

• System acquisition, development &

maintenance

• Password field submitted using GET method

Page 52: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Security Risk Assessment

• Password field submitted using GET method

• This page contains a form with a password field

• This form submits user data using the GET method

• Contents of the password field will appear in the URL

• Even HTTPS is applied to the server

• Password will not completely safe from others

• GET request will be logged in browser history or log

files

Page 53: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

SECaaS : Security Risk Assessment

• The effect is

• Get one, hack many

Page 54: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …
Page 55: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

https://www.aitle.org.hk/?p=5983

Page 56: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

Other coming AiTLE events

• STUDENT TRAINING PACKAGES (IT INNOVATION LAB) SOLUTIONS

SHOW

• https://www.aitle.org.hk/?p=5916

• EDMODOCON HONG KONG 2019

• https://www.aitle.org.hk/?p=5849

• “IMPORTANCE OF COMPUTER SCIENCE OUR NEXT GENERATION”

• https://www.aitle.org.hk/?p=5953

Page 57: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

Other coming AiTLE events

• SAMSUNG SOLVE FOR TOMORROW 2019 全港學界科技比賽

• https://www.aitle.org.hk/?p=5887

• 1 MILLION HKD SCHOLARSHIP COMPUTER SCIENCE

COMPETITION FOR HIGH SCHOOL STUDENTS

• https://www.aitle.org.hk/?p=5936

Page 58: ENHANCING INFORMATION SECURITY STRENGTHENING 提升 …

Mr. Albert WongIT Manager & Teacher, Ying Wa College (YWC)

Chairman, Association of IT Leaders in Education (AiTLE)Email : 9028 9443 / [email protected]

Website: https://www.aitle.org.hk