Access control plan and security policy

Assignment Help Basic Computer Science
Reference no: EM133086451

A. Access control plan

Access controls provide the ability to allow or deny access to critical information and devices on a network. Access controls can be physical or logical.

Develop a plan for implementing access control models in an enterprise level network based on the principle of least privilege. Make sure to address the following:

1. Which of the elements of access control would you use in your plan? Would you use them all? Why or why not?

2. What are some of the best practices concerning access control? For example, multi-factor authentication, biometrics, or minimizing secrets.

3. Defend the strategy for your plan using the principles of cybersecurity.

B. Security Policy

A well-written security policy will clearly define the limits of computing infrastructure to the end users. Security policies should be simple, explicit, and avoid hidden implicit elements that are controlled by the system, which users may misunderstand.

1. Research any computer security threat or a recent attack. Select one element of the threat or attack (e.g., "Complex Passwords").

2. Write a security policy for your selected element and explain the basic security implications of a specified security threat or a recent attack, as well as how the implementation of the policy will protect the system.

3. Your policy, at a minimum, should include a title, purpose of the policy, scope, details of the policy, compliance, author, and review date.

4. Your policy should be written using an industry-standard policy format.

5. Your policy should explain how any user interface issues could affect the implementation and perception of security mechanisms, as well as the behavioral impacts of the policy.

6. Your policy should explore the tension between user security and convenience, which results in user behaviors that undermine system security. How can you develop the right balance?

Reference no: EM133086451

Questions Cloud

Implications of health economic concepts for health care : Assess the value of health care professionals and decision makers understanding the discipline of health economics.
Your state current competitive market model in health care : Analyze your state's current competitive market model in health care. Compare and contrast the market power of monopolistic and monopsony markets in health care
Evaluate the mobile strategies of each firm : Why is mobile computing so important to these three firms? Evaluate the mobile strategies of each firm.
Discuss reasons organization should not jump into hybrid : Discuss reasons an organization should not jump into a hybrid method if they are new to Agile approaches.
Access control plan and security policy : What are some of the best practices concerning access control? For example, multi-factor authentication, biometrics, or minimizing secrets.
Leverage self-analysis work : Create a LinkedIn account and create a profile that will leverage the self-analysis work and some of the deliverables completed for this course.
Create listing of assets and their vulnerabilities : Create listing of assets and their vulnerabilities. Assign a risk-rating value to each of these assets according to importance of these assets to organization.
Important aspect of risk management components : Conducting risk assessment is an important aspect of risk management components. It allows organization to identify, assess and prioritize organizational risks.
Scada worm-nation state search-and-destroy weapon : Describe the impact and the vulnerability of the SCADA/Stuxnet worm on the critical infrastructure of the United States.

Reviews

Write a Review

Basic Computer Science Questions & Answers

  Describe the definition of the predicate name

Add rules to extend the definition of the predicate Name(s7 c) so that a string such as "laptop computer" matches against the appropriate category names.

  Research how erp systems impact business process

We focus on business process. Research how ERP systems impact business process.

  Particular infrastructure service

What command line tools could be used to figure out if a particular infrastructure service is running

  How strings are concatenated in the output

Input the following in JES to see the how strings are concatenated in the output:

  Web services project

What software is needed and compare this with other common approaches for Mobile development. Argue the need for cross-platform Mobile development frameworks.

  Annoted bibliography on enterprise risk management

Annoted Bibliography on Enterprise Risk Management on about 20 research articles each contains a summary of 150 to 200 words

  What will be the baud rate using this modem

If the transmitted bit rate is 9600 b/s, what will be the baud rate using this modem?

  What factors are involved in selecting architecture

Under what architecture would you classify technologies such as virtualization, cloud computing, and Web-based applications? Last, what factors are involved in selecting the architecture that is right for your organization?

  Selectivity and sensitivity compared

The superheterodyne radio receiver offers improved selectivity and sensitivity compared to the simple radio receiver.

  Price level in the united states

Would the following event cause pressure on the Canadian dollar to Appreciate or Depreciate?

  Determine the number of gates that can be enclosed

TTL SSI come mostly in 14-pin packages. Two pins are reserved for power and the other 12 pins are used for input and output terminals.

  Retrieve e-mail from a server

Which e-mail protocol is used to send and receive e-mail messages between e-mail servers and used by e-mail client software to send messages to the server, but never used to retrieve e-mail from a server?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd