1. Virtually every company with a computer is vulnerable to computer abuse, crime and accident. Security of the computer and of the information and assets contained within it are therefore of paramount importance to management. Skilled computer criminals can break into a computer system far more easily than an armed robber can gain access to a bank vault, and usually with far less risk of apprehension and punishment. A slight change in a complex program can bring about the misappropriation f thousands of pounds. Accidental erasure of crucial data can paralyse company’s operations. Anyone familiar with the necessary procedure can gain access to information stored in the computer, no matter how confidential, and use it for his own purposes.
实际上,每个有电脑的公司都会因电脑滥用、电脑犯罪和电脑事故而蒙受损失,因而,电脑及内存信息和财产的安全对管理来说至关重要。熟练的电脑罪犯进入电脑系统比武装劫匪闯入银行金库要容易得多,而其被捕和受惩罚的风险却很小。复杂程序的稍许改动会带来数千英镑的损失。无意中消除一些重要资料会使整个公司的动作陷于瘫痪状态。无论保密程度有多么高,任何熟悉必要程序的人都可获取贮存于电脑中的信息并利用它达到自己的目的。
2. Although the actual extent of computer crime is difficult to measure, most experts agree that it is one of the fastest growing areas of illegal activity. The principal reason for both the growth and the lack of accurate measurement is the difficulty in detecting a well-executed theft. Losses per incident thus tend to be higher than in other types of theft. Once the computer criminal has compromised the system, it is just as easy to steal a great sum as it is to steal a little, and to continue stealing long after the initial theft. Indeed, the computer criminal may find it more difficult to stop his illicit activity than to start it.
尽管电脑犯罪的范围很难测定,但是大多数专家认为它是非法活动增加最快的领域之一。非法活动增加和缺乏精确测定的主要原因是很难侦查精心实施的偷窃行为,因而每次损失比其他类型的偷窃损失要高。一旦电脑罪犯危及软件系统,那么盗取巨款与偷窃一小笔钱是一样的容易;而且一次得逞,能轻而易举地在间隔相当长的时间后继续作案。事实上,电脑罪犯会发现停止犯罪比开始犯罪更难。
3. Computer criminals are, for the most part, well-educated and highly intelligent, and have the analytical skills that make them valued employees. The fact that computer criminals do not fit criminal stereotypes helps them to obtain the positions they require to carry out crimes. Being intelligent, they have fertile imaginations, and the variety of ways in which they use equipment to their advantage is constantly being extended. In addition to direct theft of funds, the theft of data (“program-napping”) for corporate espionage or extortion is becoming widespread, and can obviously have a substantial effect on a company’s finances. Another lucrative scheme, often difficult to detect, involves accumulating fractions pence from individual payroll accounts, with electronic transfer of the accumulated amount to the criminal’s payroll. Employers are hardly concerned with pence; much less fractions of pence. In addition, of course, the company’s total payroll is unaffected. But the cumulative value of fractions of pence per employee in a company with a substantial payroll can add up to a useful gain.
大体说来,电脑罪犯都受过良好教育,智商高并有分析能力而使他们成为受重视的雇员。电脑犯罪不同于常规犯罪这样的一个事实有助于他们获得他们想要得到的地位,以便于犯罪。因为他们智商高、想象力丰富,他们利用设备作案的方式也不断增多。除了直接盗窃金钱,为社团从事间谍活动而偷窃资料的犯罪活动也日益猖獗,并且它们很明显对公司的财务会产生极坏的影响。另一个盗窃金钱的方式是将个人工资单上的几便士聚集起来,用电脑将这笔钱转到罪犯本人的工资单上。这种犯罪方式很难侦查出来。雇主们对几便士不太注意。另外,整个公司的工资单当然不会受到影响。但是,如果一个公司的雇员很多,工资名单很长,那么雇员的几便士加起来就会构成一笔不小的收入。
4. Sabotage is also an increasingly common type of computer crime. This can involve disabling the hardware, but is more likely to affect the software. Everyone in the computer business has heard of cases of a “time-bomb” being placed in a program. Typically, the programmer inserts an instruction that causes the computer to destroy an entire personnel data bank, for example, if the programmer’s employment is terminated. As soon as the termination data is fed into the system, it automatically erases the entire program.
蓄意破坏也是日益增加的普遍的电脑犯罪。它包括破坏硬盘,但更可能影响软盘。每个电脑从业人员都听说过在程序中设置“定时炸弹”的事例。通常,程序员输入一道指令,这项指令能使电脑毁灭整套人事资料库。比如,如果这个程序员被解雇,只要将解雇资料输入系统中,它就会自动删除整个程序。
5. Such acts of sabotage are particularly difficult to prevent because they do not become evident until the trigger is activated — by remote control. But, of course, not all computer losses are attributable to theft or abuse. Simple human error is by far the largest cause of system failure. Data stored on disks or tapes may be accidentally erased, or improper entry of information may introduce errors into the database. This is partly why every newly-created program must undergo extensive debugging.
这种蓄意破坏特别难以防备,因为直到通过间接控制被激活这种破坏程序才显现出来。但是,当然并不是所有的电脑损失都是由偷窃和滥用造成的。单纯的人为失误是系统故障的最主要原因。储存于软盘的资料可能被偶然删除或者输入不当的信息时将错误输入资料库中。新编制的程序一定要除去其中的错误,这就是其原因之一。
6. Guarding against computer abuse — whether deliberate or accidental — involves attention to the following areas: (1) Protection of hardware from physical damage; (2) Protection of software and data.
防止电脑滥用 — 无论是故意还是无意— 包括注意以下两方面:(1)保护硬盘以免机体损害。(2)保护软盘和资料。
7. The protection of hardware from accidental or intentional damage is a function of the environment in which the equipment is kept. The computer must be isolated from other company facilities, and access should be strictly controlled. No unauthorized person should ever be admitted to the computer area. Many insurance companies and security firms offer free evaluation of the physical protection of computer installations.
保护硬盘以免无意或故意损害是设备存放的环境条件。电脑必须与公司的其他设备分开,应该严格控制人员进入。未经批准,任何人不得进入电脑室。很多保险公司和安全公司对电脑设施的机体保护提供免费鉴定。
8. The protection of software is a more difficult problem. Some risks are reduced by controlling physical access by unauthorized personnel, but most damage to software, accidental and intentional, is caused by those whose jobs require at least some access to the computer. The writer of the program is often the one responsible for its misuse. Programs devised exclusively for a particular company are therefore far more vulnerable to abuse and accident than standard software packages produced by external suppliers.
保护软盘是一个较为困难的问题。通过控制未经批准的人员的进入,减少了一些危险,但是,大多对软盘的损害,包括无意损害和故意破坏,是由工作需要而至少必须接触电脑的人造成的。程序的编制者通常要对电脑误用负责。专门为某公司设计的软件程序较之公司外设计者提供的标准软件包更易于被滥用和受到意外损害。
9. A unique program is both difficult and expensive to replace. Accidental erasure, sabotage, or physical removal of a single disk or tape could mean that a whole system has to be rebuilt, followed by a lengthy testing process. The creators of a custom-made program are almost always company employees, who may or may not have a vested interest in the program’s function, and who, in the course of programming, can include virtually any instruction or routine with very little risk of detection. Moreover, they can alter the program at will, and there is little management that one can do to make sure that alternations in a unique program are always legitimate.
独一无二的软件程序更换起来既困难又昂贵。偶然删除,蓄意破坏,或者去掉某一个软盘就意味着必须重建整个系统,及随之而来的漫长的测试。为定制的软件而编程的人几乎都是公司职员,而软件运行成功与否,和他们的既得利益也许有关系,也许没有关系;在编制过程中,他们事实上可以编进任何指令、任何程序而不被发觉。另外,他们可以随意更改程序,并且几乎没有管理来确保一个独一无二的程序的更改必须是合法的。
10. Systems controlling cash management, financial operations, and personnel and payroll functions offer the greatest potential fro individual gain, and are therefore the most common targets for computer crime and sabotage. However, well-proven standard applications software is available for these functions, which are essentially the same fro all companies. The programs are written, tested, documented and maintained independently by organizations which have no vested interest in the operation of the computer, and are unaffected by management’s policy decisions. Internal programmers have little need to become thoroughly familiar with a software package, since it is delivered and installed complete. Further, a duplicate program can easily be obtained if the company has any reason to suspect that the software has been compromised.
现金管理,财务管理以及人事和工资管理系统为个人获取利益提供潜在的可能性,因而成为电脑犯罪和蓄意破坏最常见的目标。然而这些管理中,已有行之有效的软件应用标准,这在所有的公司中基本上是一样的。程序的编制、检测、验收及维修是由与电脑运行没有利害关系的机构来完成的,因而它不受管理决策的影响。公司内部的程序制定人员不需要全部熟悉软件包,因为它是完整地交付和安装的。还有,如果公司有理由怀疑软件已受损坏,可以很容易购买到相同的软件。
11. Controls incorporated in software packages are almost always stricter than those built into internally developed systems, because the former must function in a variety of environments. In addition, software packages may provide for different levels and types of access. One user may gain access, via a particular set of codes, just to view the data in the system; but another set of codes altogether may be roquired to alter data. A means of logging and identifying the source of every access, or change to the system, can also be provided. Each inquiry and update will then be identified by operator and/or terminal, so preventing anonymous access. This both discourages abuse and encourages operators to be conscientious. Because authorized operators are guided in their procedures, errors should be minimized.
软件包的社团控制几乎总是比内部开发建立的系统严格得多,因为前者必须能在不同的环境操作。另外,软件包可以提供不同水平、不同类型的使用方式。一个用户可以通过特殊的密码使用软件包来查阅系统中的资料,但是改变资料却要用另一套密码。它也能提供使用中的记录和辨别系统或者改变系统。每次的询问和修改,都要得到操作员和(或)终端的确认,因而防止不明身份的人进入计算机系统。这两方面都既避免电脑混用又使操作员谨慎认真。因为操作员在程序指导下操作,所以就减少了失误。
12. But even in a controlled physical environment, and with uniform software, security procedures are only effective if they are strictly followed by everyone in the company. It is not unusual to walk into a computer room and find the instructions for gaining access taped to a terminal. Concern fro security must permeate the organization if it is to be effective, and that concern needs to be generated from the top.
在控制的外部环境中,即使软件内部相同,只有公司的每个人都严格遵守安全程序,才会起到安全保护的作用。电脑室里,在屏幕上看到使用方法指令并不奇怪。只有安全意识深入整个单位的人们心中,才会有效果,而且这种安全意识需要从上层产生。