[
    {
        "heading": "Main Content",
        "content": "What is Cyber security and Information security  \nDefinition  \nInformation security:  Protecting information, regardless of its format, from unauthorized \naccess, use, disclosure, disruption, modification, or destruction.  \nBroader: Covers all forms of information, including physical and digital.  \nCybersecurity:  Protecting systems, networks, and data from cyber threats, focusing on \ntechnology and digital environments.  \nNarrower: Focuses specifically on protecting digital systems, networks, and data.  \nPrinciples of Cybersecurity  \nIn cybersecurity, the CIA Triad  is a foundational model representing the three core \nprinciples of information security. These principles ensure the effective protection of data \nand systems.  \nConfidentiality:  Ensures that information is accessible only to those authorized to access \nit. \nIntegrity:  Ensures that data is accurate, complete, and unaltered during storage or \ntransmission.  \nAvailability:  Ensures that information and resources are accessible to authorized users \nwhen needed.  \nDifferent types of cyber threats  \n• Social Engineering  \nSocial engineering is a manipulation technique that exploits human nature to gain private \ninformation, access, or valuables. In cybercrime, these “human hacking” scams tend to \nlure unsuspecting users into exposing data, spreading malware infections, or giving access \nto restricted systems. Attacks can happen online, in -person, a nd via other interactions.  \n• Malware  \nHarmful software that can access a system's data, such as viruses, spyware, ransomware, \nand worms   \n• Phishing  A deceptive attack where cybercriminals impersonate legitimate entities to trick victims \ninto revealing sensitive information   \n• Denial-of-Service (DoS) attack  \nA cyber attack that overwhelms a system's resources, making it unable to respond to \nlegitimate service requests   \n• Distributed denial -of-service (DDoS) attack  \nA similar attack to a DoS attack, but initiated by many malware-infected host machines   \n• SQL injection  \nAn attack that exploits vulnerabilities in databases by injecting malicious code into user \ninputs   \n• Cross-Site Scripting (XSS)  \nAn attack that involves injecting malicious code into a website, but the code only runs in \nthe user's browser   \n• Ransomware  \nA malicious form of software that encrypts a victim's files or locks them out of their \ncomputer system, demanding a ransom payment in exchange  \n \nSafe Internet and Device Usage  \nVerify Website Security  \n• Look for HTTPS in the URL.  \n• Avoid clicking on pop -ups or ads promising free products or rewards.  \nUse Strong Passwords  \n• Make passwords at least 8 characters long with a mix of letters, numbers, and \nsymbols.  \n• Avoid using common words or phrases.  \n• Use a password manager to store and generate secure passwords.  \nEnable Multi -Factor Authentication (MFA)  \n• Add an extra layer of protection to your accounts by requiring a second form of \nverification (e.g., a code sent to your phone).  \n \n Secure Browsing  \n• Keep Software Updated : Ensure your browser and plugins are up to date to patch \nvulnerabilities.  \n• Use a Secure Browser : Consider browsers with built -in security features.  \n• Avoid Clicking on Ads : Block or ignore pop -ups and ads to reduce risk.  \n• Use Private Browsing : Use incognito or private modes for sensitive activities.  \n• Limit Cookies : Manage browser settings to minimize cookie tracking.  \n• Avoid Public Wi -Fi: Use a VPN when browsing on unsecured networks.  \n• Log Out After Use : Always log out of accounts, especially on shared or public devices.  \n• Be cautious of typosquatting domains (e.g., goggle.com instead of google.com  \nTips for Public Wi -Fi Use  \n• Avoid Sensitive Transactions : Do not access banking or sensitive accounts on \npublic Wi -Fi. \n• Use a VPN : Encrypt your internet connection to protect your data from potential \neavesdroppers.  \n• Turn Off Sharing : Disable file and printer sharing while connected to public \nnetworks.  \n• Forget Networks After Use : Ensure your device does not automatically reconnect \nto public Wi -Fi. \n• Verify Network Authenticity : Confirm the network name with the provider to avoid \nconnecting to fake networks.  \n• Keep Software Updated : Regularly update your device’s operating system and \nsecurity software.  \n \nEmail Security Tips  \n• Think Before You Click : Avoid clicking on suspicious links or attachments in \nemails.  \n• Verify Senders: Check the sender’s email address carefully for signs of spoofing.  \n• Beware of Urgent Language: Scammers often use urgency to trick you into taking \naction.  \n• Enable Spam Filters: Use your email provider’s spam filtering features to reduce \nunwanted emails.  \n• Do Not Share Sensitive Information : Avoid sending passwords, financial details, or \npersonal information via email.  \n• Use Encryption: For highly sensitive communications, use email encryption tools.  • Update Email Passwords Regularly: Use strong, unique passwords and change \nthem periodically.  \n• Report Suspicious Emails : Notify your IT team or email provider about phishing \nattempts.  \n \n \nDos and Don’ts  \n• Do not change any hardware configuration, settings in the operating systems or any \napplications installed on their desktops.   \n• Do not install any software or applications on your desktops/ laptops that is not \nauthorized by the CMES’s IT team or is not essential to CMES’s business.   \n• USB ports, Compact Disk (CD)/ DVD, memory card access are disabled by default. If \nthe user needs to enable them, approval from the user’s manager and IT team shall \nbe required.   \n• Take appropriate measures for physical protection of laptops such as not leaving \nlaptops unattended in public places or while travelling.   \n• Do not connect r emovable media such as CD/ DVD, USB drives, and other portable \nstorage media from an unknown source to a CMES system.  \n• Removable media containing sensitive or confidential information shall be stored in \nencrypted format by using CMES approved tool.  \n• Removable media containing sensitive information must not be left out in the open \nor allowed to be vulnerable to opportunistic theft.  \n \nClear Desk and Clear Screen   \n• Ensure that desks and other work areas are kept clear of papers and any storage \nmedia when unattended.   \n• All workstations shall have password -locked screen savers enabled to activate after \n5 minutes of inactivity.   \n \nAnti-virus/ Anti -malware   \n• Users shall not disable the installed anti -virus agent or change its settings defined \nduring installation.  \n• Users shall report to the IT team for unpatched systems or  any virus that is detected \nin the system and not cleaned by the anti -virus software.  • If you suspect any non -adherence or suspicious activities or email, kindly inform IT \nteam at itsupport@cleanmax.com  \n \n \nHardware and Software   \n• To prevent the introduction of malicious code and protect the integrity of CMES \nassets, all hardware and software shall be obtained by raising request through the IT \nteam.   \n• CMES’s IT team shall ensure that an approved list of authorized software is \nmaintained.   \n• All employees shall abide by the software copyright law and shall not obtain, install, \nreplicate, transfer or use software except as permitted under the licensing \nagreements.   \n• Users shall ensure that personal software are not used on CMES owned assets to \nprotect the integrity of CMES’s assets and information.   \n \nIncident Reporting  \n \nBlogging and social media   \n• Access to social media, blogging/ micro -blogging, and video sharing websites such \nas Facebook, Twitter, LinkedIn, YouTube, etc. shall be restricted to ensure \nproductivity of the employees.   \n• No official matter, incidents and happenings that can align the name of CMES shall \nbe discussed/ posted on social media platform by employees. Reporting of such an \nevent may lead to sever consequences for the employees(s).   \n \n \n "
    }
]