Posts

Showing posts from July, 2017

INFOSEC - Learning Log #4

Image
Last week (July 25, 2017 - July 28, 2017), Asia Pacific College celebrated SoCIT Techfest. Usually, SoCIT students are excused from class in order to participate in activities or seminars planned by various organizations. INFOSEC was no exception. Sadly, it was raining hard and the wind was very strong last Thursday morning. I was already in corporate attire by 8am so that I could attend my 9:30 INFOSEC class. However, I couldn't leave the house because it was raining hard. I tried to go out and got soaked by the rain. Thus I had to wait an hour before the rain relented and had a hard time commuting because some areas were starting to flood. I got to school at 10:15. I headed straight for the auditorium because we were asked to participate in the VR (Virtual Reality) Seminar. There we learned the difference between virtual reality and augmented reality (AR). We also learned how VR and AR can be applied in different industries. Ex: Medical students use VR to learn about hu

INFOSEC - Learning Log #3

For the past 2 weeks, we discussed about Legal Issues and Privacy. The lesson about legal issues made me more aware of what and what not to do online and on computers. There are apparently several laws on the proper use of computers, internet and information security. For example, the E-Commerce Act of 2001 and Cybercrime Prevention Act of 2012 are existing laws in the Philippines. These laws can be classified as Statutory, Administrative and Common law. Statutory Law is written law by the legislative body of the government. Meanwhile, Administrative Laws are laws enacted by the executive body of the government. Lastly, Common Laws are judicial rulings.  Meanwhile last week, we discussed about privacy. I was asked by the professor, "What is privacy for you?". I was caught off guard and answered nonsense. Yes, it was very embarrassing. I said that privacy is for example, what's mine is mine therefore I dictate who can view it or know about it. I openly admit that my

INFOSEC - Learning Log #2

This period in INFOSEC, we've focused on Operational Organizational Security. We learned the difference between policies, standards, guidelines and procedures. We learned about Access Controls, Group Policy and Password Policy. I used to think that password were simple. I'd only change it when I was prompted to do so, but then I learned about minimum password age and maximum password age. Like how minimum password age is meant to protect from users. There are some users who are lazy when it comes to memorizing passwords. For example, a student can have a password of student1 and password history of 2 passwords. Without min password age, the student can change his password to student2, then student3, and then back to student1 in the same day - having exceeded the password history count of 2. This defeats the purpose of actually maximum password change and changing the password so that it won't be compromised. I felt sort of guilty while listening to the lecture about