Cataloging threats and vulnerabilities

Assignment Help Basic Computer Science
Reference no: EM133029847

You have been hired as an information security analyst at a small company called Astounding Appliances. The company sells appliances online. Astounding Appliances owns and hosts all of its IT assets and forward-facing web applications on site. The assets are about 5 years old. The company is seeking to expand its operations in the next 5 years.

Your manager asks you to help her document the threats and vulnerabilities to the company's IT operations. In addition to what you already know about the company, you learn the following during your interviews and inspections for this project.

The Astounding Appliances company and all of its IT operations are located in New Orleans, Louisiana. The data center is located on the ground floor of the company's building. There is no basement. No one can come into the data center without a smart card scan. However, there is a physical key system that can override the smart card scanner and access. There is no inventory of who has keys to the data center, although the company's vice president for operations doesn't think that too many people have keys.

Because New Orleans is vulnerable to hurricanes, all of the equipment in the data center is stored in elevated racks that sit on a raised floor. Pumps have also been installed to remove water. The pumps are attached to a generator, which has not been inspected in several years. You learn that it has not been inspected in a timely manner because making sure the generator is functional is not on the organization's disaster recovery checklist.

From the director of human resources, you learn that any Astounding Appliances employee with a valid smart card can enter the data center; access is not granted based on a need to enter the data center. You also learn that smart card access is not always terminated promptly when employees leave Astounding Appliances. The director of human resources tries to audit smart card validity regularly, but this is a low-priority task for her. You also learn that it is not part of the regular employment process for new employees to complete information security training or to sign the company's IT acceptable use policy.

Question 1. Identify 6-10 vulnerabilities to Astounding Appliances information systems and data. Be sure to include the asset that is affected by the vulnerability.

Question 2. For each vulnerability that you have already identified, document potential threats associated with it. Be sure to list the relevant information security concern (i.e., confidentiality, integrity, or availability) for the vulnerability-threat pair.

Question 3. For each vulnerability-threat pair, identify the relevant information security concern(s) (i.e., confidentiality, integrity, or availability).

Question 4. For each vulnerability-threat pair, identify the vulnerability category.

Question 5. For each vulnerability-threat pair, identify the threat category.

Reference no: EM133029847

Questions Cloud

Deciding the appropriate arrangements of first aid : What are the criteria that employers must take into account in deciding the appropriate arrangements of first aid?
Explain instance of personification : Explain this instance of personification. What is being spokenof as though it were human? Paraphrase it
How can the environment affect areas of growth : How can the environment affect areas of growth: physical, cognitive, social, and personality? Provide a specific example of each.
Summarize the function of patient records : In at least 550 words, explain how the use of HIM systems can benefit both patients and healthcare organizations within the United States.
Cataloging threats and vulnerabilities : Identify 6-10 vulnerabilities to Astounding Appliances information systems and data. Be sure to include the asset that is affected by the vulnerability.
Example of visualization or infographic : Start by identifying all the annotation features deployed, listing them under the headers of either project or chart annotation
Essential elements of employment law contract : List and explain the essential elements of employment law contract (maximum 300 words COUNT)
What are the financial options available to assist : What are the financial options available to assist the elderly and their families in your state?
Gramm-leach-bliley act : Conduct an internet or library search on the Gramm-Leach-Bliley Act (GLBA). Explain the main security and privacy requirements of HIPAA.

Reviews

Write a Review

Basic Computer Science Questions & Answers

  Maintaining executive support for programs

Acquisition strategy statements are important documents for gaining and maintaining executive support for programs and projects.

  Use the language of economics

How do the people making the pencil for me know that I want one? Be precise, specific, and use the language of economics.

  What is wrong with this policy compliance clause

1. What is wrong with this policy compliance clause? Show how you could fix it. People who violate this policy are subject to sanctions.

  Current or target place of employment

Create a 2- to the 3 page outline of a proposed security policy for your current or target place of employment.

  Identify one or few visualisations and infographics

Identify one or a few visualisations/infographics you think are especially effective.

  Determine the fat percentage and fat calories

Change the fi le name in the first comment. Modify the program so that it uses two value-returning functions: one to determine the fat calories and the other to determine the fat percentage. Save and then run the program. Test the program appropri..

  Define the term solvable

What does the term solvable mean to you? What does it mean to say that "you solved a problem"? Find examples of problems for which you believe there are no solutions.

  What constitutes union compatibility

What is the purpose of the Union, Intersection, and Difference operations?

  To what extent do UC benefits experienced by Boeing mirror

To what extent do the UC benefits experienced by Boeing mirror those of other firms that have deployed UC capabilities over converged IP networks?

  Plot the multiple views on a single sheet

Using viewports in paper space, create the top, front, right side, and SE isometric view of the security clip shown in Fig. 26-6. Create a border and title block, and plot the multiple views on a single sheet.

  Develop the website and online admission application

Discuss whether you will use a traditional or web-based development strategy to develop the website and online admission application

  Create a microsoft excel workbook with four worksheets

Create a Microsoft Excel workbook with four worksheets that provides extensive use of Excel capabilities including charting and written analysis

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd