Home > Ask the Security Experts > Security Management Questions & Answers > Should computer exams be transmitted as PDF files or Word files?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Should computer exams be transmitted as PDF files or Word files?

Mike Rothman, past SearchSecurity.com expert EXPERT RESPONSE FROM: Mike Rothman, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 14 January 2008
If a university is planning on administering exams to students via computer, would be less risky to transmit PDFs rather than Word files?

>
There is no easy answer to this question because the inherent security of any system is based on more than just the file's form factor. To generalize, there is more security built into Acrobat than Word. Documents can be digitally signed more readily in Acrobat, but that doesn't mean the system will be more secure.

Let's think about how you would compromise either file type. Unless there is password protection and an encrypted file, anyone with access to the server where the files are stored (data at rest, not data in motion – since you are using SSL to protect the communications pipe) could edit the file and change the data. That person could even mess with the metadata in either PDF or a Word file, which would leave no trace of the edits.

As mentioned above, the only real difference in the process you described is that the students need to actually hand-write the answers on the PDF, which inherently adds a level of verification to the authenticity of the information. But if the students were to print out the Word file and hand-write it, and then scan it back in, the processes are roughly the same.

Ultimately, I think some measure of encryption and digital signature would be required whenever a file is submitted in order to feel good about the security of the documents and the integrity of the tests.

For more information:

  • Security pro Joel Dubin discusses the pros and cons of using PKI systems for laptop encryption.
  • Discover the best ways to compare PKI products and vendors for enterprise implementation.


  • BROWSE BY TAG
    Security Management,   PKI and Digital Certificates,   Enterprise Identity and Access Management,   User Authentication Services,   Enterprise Data Protection,   Disk Encryption and File Encryption,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Security Management
    How to prepare for a FERPA audit
    Why doesn't the CISSP cover information assurance and DIACAP?
    Data breach notification legislation: What info must be released?
    Risk management strategy for an information technology solution provider
    Are there guidelines to create a HIPAA-compliant data center?
    HHS HIPAA guidance on encryption requirements and data destruction
    Writing a patient identifier policy to prevent common HIPAA violations
    How to write technology outsourcing contracts
    The requirements for being a PCI DSS-compliant service provider
    The requirements needed to make an external penetration test legal

    PKI and Digital Certificates
    Best Authentication Products
    DoD urges less network anonymity, more PKI use
    Researchers to demonstrate new EV SSL man-in-the-middle hacks
    Portable security storage device could replace OTP devices
    What is most misunderstood about EV SSL certificates?
    VeriSign addresses MD5 flaw
    Rogue digital certificates strike blow to Internet security
    Can any firm or organization get a digital signature certificate?
    How to obtain a digital certificate for a server
    PKI and digital certificates: Security, authentication and implementation
    PKI and Digital Certificates Research

    Disk Encryption and File Encryption
    Heartland CIO is critical of First Data's credit card tokenization plan
    Heartland CIO on end-to-end encryption, credit card tokenization
    Should developers create libraries of common cryptographic algorithms?
    What is an encryption collision?
    Heartland CIO on PCI, E3 project
    Visa probes tokens, encryption for PCI card data protection
    Voltage, RSA spar over tokenization, data protection
    Truth, lies and fiction about encryption
    What are new and commonly used public-key cryptography algorithms?
    What are the export limitations for AES data encryption?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    authentication server  (SearchSecurity.com)
    Certificate Revocation List  (SearchSecurity.com)
    Digital Signature Standard  (SearchSecurity.com)
    HDCP  (SearchSecurity.com)
    MD2  (SearchSecurity.com)
    MD4  (SearchSecurity.com)
    MD5  (SearchSecurity.com)
    nonrepudiation  (SearchSecurity.com)
    PKI  (SearchSecurity.com)
    public key  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts