Basis of the scenario and the threat model

Assignment Help Other Subject
Reference no: EM132970393

This assessment will require you to use open source intelligence frameworks, sources of information (e.g. NIST vulnerabilities database) ir order to produce a threat model for a given scenario. On the basis of the scenario and the threat model you have produced you will be required to present a report that contains the following:

1. An overview of the intelligence sources you chose to utilise and why they were chosen (500 words)

2. A fully formed threat model using an open source framework such such as OWAPs Threat Dragon. You can download a free copy of OWASP Threat Dragon this will work on Linux, mac and Windows. You can take screen short of your developed threat model

3. On the basis of the threat model, the intelligence and vulnerability you should provide a summary (upto 1000 words) outlining the basis of the threat model you have used, and how the sources that you collected information from helped you to develop your threat model.

4. You should outline the key threats to the systems in your chosen scenario, and present these in the form of a risk table, identifying the likelihood of the threat (high, medium, low) and the likely impact that the threat could have on the business in monetary terms (business failure, business interruption or business as usual). You should then suggest mitigation actions that should be put in place to reduce the impact of the threat (1500 words).

5. A separate section should be dedicated for the developed threat model

Scenario

MoneyTransfer4U is an organisation that has over fifteen years of experience providing money transfer services on the UK High Street. The organisation has stores across the UK, including in London, Birmingham, Leeds, York, Liverpool, Manchester and Edinburgh.

The organisation has a set of 50 UK wide stores, and they are all currently connected via a Metropolitan Area Network. Daily transactions are sent using FTP to the Headquarters in London from each of the other stores across the UK on a daily basis. Each local store also maintains a MYSQL database of daily transactions and customer details. To make things easier the IT team created a single database for each region/city, and customer details, tables, financial transaction table, staff log-on credentials and an annual financial reporting data store are all located in this single database.

In terms of transactions, customers can either vii a store in person, in which case a member of staff performs the transaction, or else customers can log- on and create an account. All they need to do is enter their personal details, bank account details and address to get started. As the organisation has a small staff base of 200 across the UK, there is no verification service in house, so the transactions are set to an-off site service via email for verification before a transaction can take place.

The organisation has set up Windows 10 accounts for all in-store and back- house staff. As well as this, all data is stored on physical servers installed with Windows 2012 Server. The IT has five members of staff and they have to travel across the UK to personally apply patches in each location. Given the geographical spread of stores and offices, this can only take place once a month.

As some staff want to work remotely, then a virtual image has been created and staff can log in using a standard browser.

Staff are asked to create their own passwords, but there is no official password policy in place regarding the correct formation of strong passwords. You have been employed as a consultant as over the past month they have suffered XSS attacks on their website, a major personal data breach and a Distributed Denial of Service (DDoS) attack

Possible sources of open source intelligence frameworks for Cyber Threat Intelligence and known vulnerabilities
Cyber Threat Intelligence reports
National Cyber Security Centre (UK)

Reference no: EM132970393

Questions Cloud

Prepare journal entries to record the sale of one model : Prepare journal entries to record the sale of one model A forklift truck plus service contract for $180,000 assuming a comparable service contract is sold
How the canadian source income would be taxed : How the Canadian source income would be taxed under Canadian tax legislation. Hebert Haman is a resident of a country that does not have a tax treaty
Give the entries in the accounts of cosmo : Give the items and amounts that would be reported in 20X0 earnings and all amounts on the statement of financial position. Give the entries in the accounts
What is the impairment loss for cosmo : Is the machine impaired? If so, what is the impairment loss? Cosmo has a large piece of machinery, and management has determined there is potential impairment
Basis of the scenario and the threat model : Overview of the intelligence sources you chose to utilise and why they were chosen - separate section should be dedicated for the developed threat model
What cash are required to pay for the property value : What cash are you required to pay for the property value not covered by the mortgage, the tax due and the legal and other costs?
What implications can draw from findings : What implications can you draw from your findings? Direct quote between the U.S. dollar and another currency, where the United States is designated as the home
What is the revised earnings after correction of erros : What is the revised 20X0 earnings after correction of these errors? Company Ltd prepared its draft 20X0 financial statements in Feb 20X1.
Which of the portfolios would be the market portfolio : The risk-free rate is 3%. Which of the portfolios would be the market portfolio? Portfolio A: expected profitability: 6%, standard deviation 3%

Reviews

Write a Review

Other Subject Questions & Answers

  Review case-nurses as change agents in the community

The discussion assignment provides a forum for discussing relevant topics for this week on the basis of the course competencies covered.

  Describe one personal real-life example of an occurrence

Consider the events from the past week of your life. How does expertise, or the perception of it, affect our behaviors, actions, and knowledge development?

  Explain how your topic is used in global financing

choose one of the following topics. prepare a 1050- to 1750-word paper in which you analyze one of the following global

  Task - Design of a system using OOP

DSAA204/ BIT 204 Data Structures and Algorithms - Individual Report Assignment. The assessment is about a design of a system using OOP

  Explain how this storage space works where it is located in

ram is a temporary storage space that is used to store program instructions and data. but accessing ram is inefficient

  Explain common good differ from the concept of private gain

Define common good. Either quote a source or create your own. List five of the things that could be considered as elements or aspects of the common good.

  Describe one argument that supports the death penalty

To support the death penalty, some try to use the topic of crime deterrence. Some are under the thought process that if people know.

  How might this reading be used to broach conversation

Provides a 2019 connection: how might this reading be used to broach a conversation?

  Evaluate three pros and three cons of e-prescribing

Evaluate three pros and three cons of e-prescribing. Summarize the e-prescription standards as described by the National Council for Prescription Drug Programs. Evaluate the projected cost and time savings as estimated by the United States Department..

  God distributes divine rewards

The books of __JOB__ and ____ proposed that God distributes divine rewards and punishments in an afterlife rather than in the present world (as the Egyptians, Persians, and Greeks had proposed long before).

  Identify how the organization can provide audit trails

Identify how the organization can provide audit trails, endpoint anomaly detection and a forensic security capability to ensure a stable security posture.

  Alternative affect family relationships and child behavior

How does this alternative affect family relationships and child behavior/development? How do parenting styles impact this alternative? What impact does culture play on family dynamics, family structure, and family values in this alternative?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd