Evaluate organization security policies and risk management

Assignment Help Management Information Sys
Reference no: EM131127627

It is common knowledge that Web server application attacks have become common in today's digital information sharing age. Understanding the implications and vulnerabilities of such attacks, as well as the manner in which we may safeguard against them is paramount, because our demands on e-Commerce and the Internet have increased exponentially. In this assignment, you will examine the response of both the U.S. government and non-government entities to such attacks.

To complete this assignment, use the document titled "Guidelines on Securing Public Web Servers", located at https://csrc.nist.gov/publications/nistpubs/800-44-ver2/SP800-44v2.pdf, to complete the assignment. Read the Network World article, "40% of U.S. government Web sites fail security test" also, located at https://www.networkworld.com/article/2186860/data-center/40--of-u-s--government-web-sites-fail-security-test.html.

Write a three to five (3-5) page paper in which you:

1. Examine three (3) common Web application vulnerabilities and attacks, and recommend corresponding mitigation strategies for each. Provide a rationale for your response.

2. Using Microsoft Visio or an open source alternative such as Dia, outline an architectural design geared toward protecting Web servers from a commonly known Denial of Service (DOS) attack. Note: The graphically depicted solution is not included in the required page length.

3. Based on your research from the Network World article, examine the potential reasons why the security risks facing U.S. government Websites were not always dealt with once they were identified and recognized as such.

4. Suggest what you believe to be the best mitigation or defense mechanisms that would help to combat the Domain Name System Security

Extensions (DNSSEC) concerns to which the article refers. Propose a plan that the U.S. government could use in order to ensure that such mitigation takes place. The plan should include, at a minimum, two (2) mitigation or defense mechanisms.

5. Use at least three (3) quality resources outside of the suggested resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources.

Your assignment must follow these formatting requirements:

· Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; citations and references must follow APA or school-specific format. Check with your professor for any additional instructions.

· Include a cover page containing the title of the assignment, the student's name, the professor's name, the course title, and the date. The cover page and the reference page are not included in the required assignment page length.

· Include charts or diagrams created in Visio or an open source alternative such as Dia. The completed diagrams / charts must be imported into the Word document before the paper is submitted.

The specific course learning outcomes associated with this assignment are:

· Define common and emerging security issues and management responsibilities.

· Evaluate an organization's security policies and risk management procedures, and its ability to provide security countermeasures.

· Use technology and information resources to research issues in security management.

· Write clearly and concisely about the theories of security management using proper writing mechanics and technical style conventions.

Article: Guidelines on Securing Public Web Servers Recommendations of the National Institute of Standards and Technology by Miles Tracy, Wayne Jansen, Karen Scarfone and Theodore Winograd.

Reference no: EM131127627

Questions Cloud

Net income for the year ended 28 february 2009 : For the year ending February 28, 2009, Samaritan Medical Co. mistakenly omitted adjusting entries for .
What is the maximum deceleration possible : The car of Prob. 3/59 is traveling at 25 mi/hr when the driver applies the brakes, and the car continues to move along the circular path. What is the maximum deceleration possible if the tires are limited to a total horizontal friction force of 24..
Total quality management addresses organizational quality : Total Quality Management (TQM) addresses organizational quality from managerial and philosophical viewpoints. It focuses on customer-driven quality standards, managerial leadership, continuous improvement, quality built into product and process desig..
Best step response while attaining a high : A robot tennis player is shown in Figure DP9.4 (a), and a simplified control system for θ2(t) is shown in Figure DP9.4(b).The goal of the control system is to attain the best step response while attaining a high Kv for the system.
Evaluate organization security policies and risk management : Define common and emerging security issues and management responsibilities. Evaluate an organization's security policies and risk management procedures, and its ability to provide security countermeasures.
How can you earn a riskless profit from this situation : Assume the debt in the previous question is trading at $1,035. How can you earn a riskless profit from this situation (arbitrage)?
What are at least five new product ideas : What are at least five new product ideas that could really increase new revenue for Olive Garden? Out of the ideas you list which one do you think would really have the best chance of succeeding in generating additional revenue and not just cannibali..
Dna double helix : When the base pair A=T in the middle of a short (20 nucleotide) synthetic duplex DNA strand was replaced with a. Z F base pair (shown below) the duplex was destabilized by about 13.4 kJ/mol.
How many addresses total does the dram have : How many addresses, total, does the DRAM have?

Reviews

Write a Review

Management Information Sys Questions & Answers

  Various types of information systems

Investment in IT has the potential to give your organization a competitive edge. Discuss this statement in the light of what you learned in chapters 1,2&3?

  The appropriate erp

The appropriate ERP - What enterprise resource planning (ERP) systems do your organization rely on

  What action the organization should take

Mark works for the Wonder Mattress Company in the IS department. He is in charge of looking at new technologies that come on the market and determining if they can be used for the company. An explanation of what the organization's responsibility sh..

  Hired developer to focus on improving his coding skills

Imagine you are the manager of a medium-sized IT department. While walking through the hall one day, you overhear a senior-level software developer telling a newly hired developer to focus on improving his coding skills rather than learning about ..

  Business intelligence users at colgate-palmolive

Describe the different types of business intelligence users at Colgate-Palmolive. Describe the "people" issues that were affecting Colgate's ability to use business intelligence

  Ethical issues related to information technology

Locate a news article based on a recent event on ethical issues related to information technology. For example, Wikileaks, Snowden, etc.

  Mechanisms used to help increase collaboration

Mechanisms Used to Help Increase Collaboration -  Describes the mechanisms that can be used to help increase collaboration across business and IS leaders

  How will he communicate with his customers

He wants to have a website that will facilitate e-business for his golf course. He wants online scheduling of tee times (including coordination of group play), online shopping, and social network integration. One difficulty of moving a small busin..

  Risk management of a large pharmaceutical company

ERP and the 9-step model as VP of a pharmaceutical company - I need your opinion on this: You are the Vice President of Enterprise Risk Management of a large pharmaceutical company. You are in Bermuda on vacation.

  Locate an information security policy

Locate an information security policy which governs employee and company responsibilities.  Do what is required to mask the identity of the organization.

  Discuss challenges they feel they face in collecting data

Identify an acute care facility and a non-acute health care facility in your area. Arrange to speak to the health information management professional at each facility and discuss the challenges they feel they face in collecting data, the type of d..

  Research a company that uses cross-functional systems

Select and research a company that uses cross-functional systems. Note any obvious advantages and disadvantages you might find within the company selected

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd