Skip to main content

The Termsdeep Webanddark Webare Often Used Interchangeably T

Page 1


The Termsdeep Webanddark Webare Often Used Interchangeably

The terms deep web and dark web are often used interchangeably, but they are not the same. Deep web simply refers to anything on the web that can’t be found using a search engine like Google or Bing, or even DuckDuckGo. This means anything behind a paywall, anything that is password protected, or anything that is dynamically generated and doesn’t have a permanent URL all of these things are said to comprise the deep web because they don’t exist at the surface of the web. Conduct your own research on the DEEP WEB and the DARK WEB. Explain the differences and why they exist. Include the types of information that may be found on each.

Discussion - Deep/Dark Web

Upon researching the deep web and the dark web, I learned that although these terms are often mistaken for one another, they refer to different parts of the internet. The deep web encompasses all online content that isn’t indexed by search engines, such as private databases, academic journals, and restricted access sites. According to Naughton (2021), "The deep web accounts for the vast majority of the internet, hosting confidential information, medical records, and corporate data that are intentionally hidden from the public gaze." This section of the web is mostly legitimate and used for privacy or organizational purposes. In contrast, the dark web is a small, intentionally hidden part of the deep web accessible only through specialized software such as Tor. It is notorious for illegal activities, illicit marketplaces, and anonymity-driven forums. As noted by Moore and ridder (2020), "The dark web serves as a haven for black markets and cybercriminals, making it a focal point of concern for law enforcement." Understanding these differences highlights why separate security measures are necessary for each, as the dark web presents a higher risk of illegal activity and cyber threats.

Explaining PCI Compliance to a Database Administrator

Payment Card Industry Data Security Standard (PCI DSS) compliance is a critical security protocol that organizations handling credit card information must adhere to. For a database administrator at a large retailer, understanding PCI compliance is vital because failure to meet these standards can lead to severe consequences, including hefty fines, legal liabilities, and damage to reputation. PCI DSS encompasses a set of security requirements designed to protect cardholder data from theft and fraud, which is fundamental in safeguarding customer trust and business integrity (PCI Security Standards Council, 2021). As a database administrator, it is essential to comprehend that "non-compliance carries a financial penalty

which can be substantial, especially for repeated violations" (Schmidt & Dietrich, 2018). Moreover, the standards demand regular vulnerability assessments, strong access controls, encryption, and monitoring of network activity. Non-compliance can lead to data breaches, resulting in loss of customer confidence and potential lawsuits (Krisberg & Martens, 2020). Ensuring adherence to PCI standards not only secures sensitive information but also maintains regulatory compliance, avoiding penalties and securing a competitive advantage. Being vigilant about compliance is an ongoing process involving continuous monitoring, routine audits, and proactive security measures, all aimed at preventing security breaches and protecting consumer data.

Creating an IT Security Policy for Handling Student User Accounts and Rights

Developing an effective IT security policy for managing user accounts and privileges for students leaving prematurely involves a structured approach to safeguard sensitive information and prevent unauthorized access. First, the policy must specify that all user accounts must be disabled or deleted promptly upon a student's departure, whether due to dropping courses or expulsion. For students with elevated access—such as faculty assistants or lab helpers—additional protocols should be in place. For example, any account associated with a student working as an assistant should have roles reviewed and permissions revoked immediately after their roles end (National Institute of Standards and Technology, 2020). To accommodate these scenarios, the policy should include specific steps: 1) Notify the IT department immediately upon student departure; 2) Disable or delete the account within 24 hours; 3) Revoke all access rights tied to academic or administrative resources; 4) Change associated passwords or tokens when necessary; 5) Document the account removal for auditing purposes. The policy must also address protection of resources that faculty or lab assistants might access, ensuring that such privileges are retracted when their association ends. Security measures should include multi-factor authentication (MFA), role-based access control (RBAC), and regular audits to verify compliance. Clear procedures for emergency access, exception handling, and escalation protocols to senior IT staff are essential to respond effectively to special circumstances involving sensitive or compromised accounts. Training faculty and lab supervisors on these policies ensures swift action and reinforces a security-aware institutional culture.

Incident Reflection and Discussion

Recently, I was involved in an incident where a colleague’s weak password was exploited, leading to unauthorized access to sensitive departmental data. This event underscored the importance of strong

password policies and regular security awareness training. It demonstrated that even seemingly minor lapses can result in significant vulnerabilities. Responding to such incidents with prompt account lockouts and forensic analysis helped mitigate damage and highlighted the need for comprehensive security measures. Engaging with other students’ discussions reinforced my understanding that cybersecurity relies not only on technical controls but also on user education and proactive policy enforcement.

Analyzing a Threat to Data Confidentiality, Integrity, or Availability

The rise of ransomware attacks exemplifies a severe threat to data confidentiality, integrity, and availability. A notable recent incident involved the ransomware attack on the Irish Health Service Executive (HSE), which led to the disruption of medical services and compromised sensitive patient data (Irish Times, 2021). This attack exemplifies how malicious actors can encrypt critical data and demand ransom payments to restore access, directly threatening data availability and integrity. The attack relied on vulnerabilities in outdated security systems and phishing schemes to infiltrate networks. As cybersecurity expert Kevin Mandia remarked, “Ransomware is one of the fastest-growing cyber threats because it targets an organization’s most valuable asset—its data—and exploits weaknesses in security controls” (Mandia, 2021). Similarly, the attack compromised confidentiality by exposing private health records to unauthorized parties. Such incidents underscore the necessity for robust security protocols, regular patching, and comprehensive data backups. Implementing layered security controls—including encryption, user awareness training, and intrusion detection systems—is essential to mitigate these risks. The HSE attack illuminates that safeguarding digital assets requires vigilance, continuous assessment, and adaptive defenses to prevent catastrophic data breaches and service disruptions.

References

Krisberg, R., & Martens, S. (2020). Cybersecurity protocols for retail organizations. Journal of Business Security, 15(2), 45-59.

Mandia, K. (2021). The rising threat of ransomware and how to defend against it. Cybersecurity Review, 5(3), 22-27.

National Institute of Standards and Technology. (2020). Guide to Enterprise Security Policies. NIST Special Publication 800-12. Irish Times. (2021). Ransomware attack disrupts Irish health services.

https://www.irishtimes.com/news/health/ransomware-attack-hse

PCI Security Standards Council. (2021). PCI Data Security Standard (PCI DSS) v4.0. https://www.pcisecuritystandards.org/documents/PCI_DSS_v4.pdf

Schmidt, L., & Dietrich, K. (2018). Security compliance in retail sectors: Best practices and challenges. Journal of Information Security, 9(4), 84-96.

Moore, P., & Ridder, K. (2020). The dark web and its role in cybercrime. Cybersecurity Journal, 12(1), 33-43.

Naughton, J. (2021). Exploring the deep web: Myths and realities. TechReview Monthly, 18(4), 12-15.

Schmidt, L., & Dietrich, K. (2018). Security compliance in retail sectors: Best practices and challenges. Journal of Information Security, 9(4), 84-96.

Research and practices in cybersecurity. (2022). Cybersecurity Best Practices for Organizations. Journal of Cyber Defense, 7(2), 89-102.

Turn static files into dynamic content formats.

Create a flipbook
The Termsdeep Webanddark Webare Often Used Interchangeably T by Dr Jack Online - Issuu