Table of Contents
Information Security1
What is a computer network?1
Network Technologies2
| Wired Network Technologies | 2 |
| Wireless Network Technologies | 4 |
| IEEE 802.11 | 4 |
| IEEE 802.11b | 4 |
| IEEE 802.11g | 4 |
| IEEE 802.11n | 5 |
| IEEE 802.11ac | 5 |
| IEEE 802.11ax | 5 |
Network Components5
| Network hubs | 6 |
| Network Switches / Bridges | 6 |
| Network Switching | 8 |
| Network Routers | 8 |
| Hybrid Devices | 9 |
| What is Routing? | 9 |
| Routing Data Packets | 9 |
| Identifying Reachable Networks | 9 |
| Routing Metrics | 9 |
| Network Protocols | 11 |
| Wireless access points | 11 |
| Access Point Modes | 12 |
| Multiple Access Points | 13 |
| Wireless Routers | 13 |
Internet13
Information Security14
| Application security | 15 |
| Incident response | 17 |
| Vulnerability management | 18 |
Why Worry about Network Security?18
Information Security Risk Management19
Risk Control21
Security Concepts22
| Confidentiality | 22 |
| Integrity | 23 |
| Availability | 23 |
People Accessing Information24
| Authentication | 24 |
| Authorization | 24 |
| Nonrepudiation | 25 |
Unsecured Computers and Networks25
Types of Network Security26
| Access Control/Network Access Control (NAC) | 27 |
| Antivirus and/or Antimalware Software | 28 |
| Application Security | 28 |
| Behavioral Analytics | 29 |
| Data Loss Prevention | 30 |
| Email Security | 32 |
| Email Security - Best Practices for Companies | 34 |
| Email Security - Best Practices Best Practices for Individual Users | 38 |
| Firewalls | 41 |
| Intrusion Prevention Systems (IPS) | 42 |
| Mobile Device Security | 43 |
| Network Segmentation | 43 |
| Physical Security | 44 |
| Virtual Private Network (VPN) | 44 |
| Web Security | 45 |
| Web Application Security | 46 |
| Wireless Security | 47 |
Disposing of Equipment Securely47
Techniques for Removing Information48
| Deleting information | 48 |
| Overwriting information | 49 |
| Secure Erasure | 49 |
| Physical destruction | 49 |
Disposing of Mobile Phones and Tablets50
Network Threats51
Review Questions52
Review Questions Answers55
Phishing60
| Spear Phishing | 61 |
| Clone Phishing | 62 |
| Whale Phishing | 62 |
| Social Media Phishing | 62 |
| Phishing Evolution | 63 |
| Phishing Opportunities | 63 |
| Criminals are Learning and Evolving | 64 |
Phishing Tools64
| Bots/Botnets | 64 |
| Phishing Kits | 64 |
| URL Obfuscation | 64 |
| Simple HTML redirection | 65 |
| Use of JPEG images | 65 |
| Use of alternate IP addresses | 65 |
| Registration of similar domain names | 65 |
| Web Browser Vulnerabilities used for Phishing | 66 |
| Session Hijacking | 66 |
| Domain Name Resolving Attacks | 67 |
| Global DNS Hijacking Campaign | 67 |
| Cross-Site Scripting Attacks | 68 |
| Domain Name Typos | 68 |
| Man-in-the-Middle Attacks | 69 |
| Phishing-Related Malware Examples | 69 |
| Bancos | 69 |
| Bankash | 69 |
| W32/Grams | 70 |
| CoreFloo | 70 |
| Dyre Banking Malware | 70 |
Phishing Mitigations71
Phishing Solutions71
Prevent Phishing Attacks:71
| Two-factor authentication | 72 |
Identify Theft72
| Identify Theft Methods | 73 |
| Trash Sifting/Dumpster Diving | 73 |
| Mail Theft | 74 |
| Address Manipulation: | 75 |
| Skimming | 75 |
| Scanning | 76 |
| Straightforward Theft: | 76 |
| Conning | 77 |
Identify Theft Crimes77
| Yahoo Data Breach | 77 |
| Equifax breach | 77 |
| Target Data Breach | 78 |
Malware79
| Viruses and Worms | 80 |
| Virus | 80 |
| Worm | 80 |
| Trojans | 81 |
| Backdoor / Remote Access Trojan (RAT) | 81 |
| Botnets | 82 |
| Adware | 85 |
| Information stealers | 85 |
| Ransomware | 85 |
| Rootkits | 86 |
| Downloaders or Droppers | 86 |
| File Wipers | 87 |
| Spyware | 87 |
| Malware Summary | 88 |
Data security plan88
| Complying with the Safeguards Rule | 89 |
| Who Must Comply? | 89 |
| How To Comply | 90 |
| Securing Information | 90 |
| Employee Management and Training. | 91 |
| Information Systems. | 91 |
| Detecting and Managing System Failures. | 93 |
| Creating an Information Security Risk Management Plan | 94 |
| Identify Risks | 95 |
| Perform Risk Analysis | 97 |
| Plan Risk Responses | 99 |
| Implement Risk Responses | 101 |
| Monitor Risks | 101 |
| Basic Security Training | 102 |
| Use Security Software | 103 |
| Avoid Phishing and Malware | 103 |
| Protect Personal Information | 104 |
| Mobile Phone Security | 104 |
| Mobile Phone Theft | 105 |
| Securing Mobile Phones | 105 |
| Installing Apps with Malware | 106 |
| E-mail attachments | 106 |
| SMS links | 106 |
| Keeping Your Network and Information Safe | 106 |
| Install operating system updates regularly | 107 |
| Run Antivirus software on all computers and run regular scans | 108 |
| Keep Antivirus software updated | 108 |
| Practice safe online activities | 108 |
| Use both network firewalls and personal firewalls on all computers | 109 |
| Implement enhanced security features to better protect sensitive information | 109 |
| Encrypt Client Data | 110 |
| Back up all data regularly | 111 |
| Create Strong Passwords | 111 |
| Making Passwords More Secure | 112 |
| Password Managers | 113 |
| Making Online Accounts More Secure | 113 |
Review Questions115
Review Question Answers119
Glossary127
Course Details
Author: Andrew Clark, EA
Publication/Revision Date: 9/23/2025
Course Exam Questions (online): 40 (multiple-choice)
Program Delivery Method: Self-Study (NASBA QAS Self-Study)
Available Formats of Course Text: PDF or PDF plus printed copy sent in the mail
Course Level, Prerequisites, and Advance Preparation Requirements
| License | Course Level | Prerequisites | Advance Preparation Requirements |
|---|
| CPA | Overview | None | None |
| EA/OTRP | Intermediate | None | None |
* This program is appropriate for professionals at all organizational levels.
Sponsor ID Numbers
National Registry of CPE Sponsors ID: 107615
IRS Qualified Sponsor ID: FWWKO — Course ID: FWKKO-T-00794-26-S
State CPA Board Sponsor ID Numbers (where applicable)
Florida Division of Certified Public Accounting: 0004761
Hawaii Board of Public Accountancy: 14003
New York State Board for Public Accountancy: 002146
Ohio Accountancy Board: CPE .51 PSR
Pennsylvania State Board of Accountancy: PX178025
Texas State Board of Public Accountancy: 009349
Learning Objectives
As a result of studying the course material, you should be able to meet the objectives listed below:
- Identify the importance of network security for CPAs and Tax Practitioners.
- Identify what a network is along with the different components that make up a network.
- Identify the different types of network security that contribute to a comprehensive information security protocol.
- Define the term “identify theft” and recognize how identify theft most commonly occurs.
- Recognize why CPAs and Tax Professionals are being targeted by cybercriminals.
- Recognize the importance of encrypting client data.
- Identify the importance of creating internal controls and a security plan to protect client data.