Home > Ask the Security Experts > Security Management Questions & Answers > Should computer exams be transmitted as PDF files or Word files?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Should computer exams be transmitted as PDF files or Word files?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 14 January 2008
If a university is planning on administering exams to students via computer, would be less risky to transmit PDFs rather than Word files?

>
EXPERT RESPONSE
There is no easy answer to this question because the inherent security of any system is based on more than just the file's form factor. To generalize, there is more security built into Acrobat than Word. Documents can be digitally signed more readily in Acrobat, but that doesn't mean the system will be more secure.

Let's think about how you would compromise either file type. Unless there is password protection and an encrypted file, anyone with access to the server where the files are stored (data at rest, not data in motion – since you are using SSL to protect the communications pipe) could edit the file and change the data. That person could even mess with the metadata in either PDF or a Word file, which would leave no trace of the edits.

As mentioned above, the only real difference in the process you described is that the students need to actually hand-write the answers on the PDF, which inherently adds a level of verification to the authenticity of the information. But if the students were to print out the Word file and hand-write it, and then scan it back in, the processes are roughly the same.

Ultimately, I think some measure of encryption and digital signature would be required whenever a file is submitted in order to feel good about the security of the documents and the integrity of the tests.

For more information:

  • Security pro Joel Dubin discusses the pros and cons of using PKI systems for laptop encryption.
  • Discover the best ways to compare PKI products and vendors for enterprise implementation.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    After a data breach, what are the legal implications of sharing the details?
    Boosting the morale of the information security staff after a data breach
    Does the DoD's ban of USB storage devices mean our enterprise should ban them too?
    Finding a security management job after an economic downturn
    Is a lack of employee privacy a HIPAA violation if the employee files Medicare claims?
    How to create a data security policy to avoid disgruntled employee data leaks
    How to set up a remote access security policy
    Ethical hacking techniques for standard penetration testing
    What are some best practices for handling a merger while getting our counterpart up to speed on PCI?
    What's the best strategy to catch up on HIPAA compliance quickly?

    PKI and Digital Certificates
    Rogue digital certificates strike blow to Internet security
    How to obtain a digital certificate for a server
    PKI and digital certificates: Security, authentication and implementation
    What is the best way to administer exams to students via computer?
    Should PKI systems be used for laptop encryption?
    Email authentication showdown: IP-based vs. signature-based
    VeriSign to shed businesses, return to security roots
    How do anonymous credentials and selective disclosure certificates affect enterprise IAM?
    Choosing from the top PKI products and vendors
    Can the symmetric encryption algorithm for S/MIME messages be changed?
    PKI and Digital Certificates Research

    Disk Encryption and File Encryption
    TrueCrypt an open source laptop encryption choice for SMBs
    Can DNS be used to support encryption?
    Seagate hardware-based disk encryption could gain traction
    Workstation hard drive encryption: Overdue or overkill?
    Encryption no longer an optional technology
    Oracle DBAs cite lack of security measures
    IBM offers hardware-based encryption for x servers
    Crypto landmark Bletchley Park in danger of closing
    What does the future of the endpoint encryption market look like?
    PCI DSS 1.2 clarifies wireless, antivirus use

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    authentication server  (SearchSecurity.com)
    Certificate Revocation List  (SearchSecurity.com)
    Digital Signature Standard  (SearchSecurity.com)
    HDCP  (SearchSecurity.com)
    MD2  (SearchSecurity.com)
    MD4  (SearchSecurity.com)
    MD5  (SearchSecurity.com)
    nonrepudiation  (SearchSecurity.com)
    PKI  (SearchSecurity.com)
    public key  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts