Explain access control methods and attacks

Assignment Help Management Information Sys
Reference no: EM131194101

Global Finance, Inc. Network Diagram

Above is the Global Finance, Inc. (GFI) network diagram. A hypothetical company, GFI has grown rapidly this past year and implemented a number of network devices as displayed in the diagram. The company invested in the network and designed it to be fault tolerant and resilient from any network failures. However, although the company's financial status has matured and its network has expanded at a rapid pace, its overall network security posture has not kept up with the company growth.

GFI's network has historically been fairly stable, and the company has not experienced many full scale network outages. GFI has hired three (3) network engineers to keep up with the network growth, as well as the bandwidth demand by the company employees and the clients. However, the company has not hired any security personnel who can take care of the operational security responsibility.

The trusted computing base (TCB) internal network within the Global Finance, Inc. Network Diagram hosts the company's mission critical systems that are vital to the company's operations that also affect the overall financial situation. The Oracle database and email systems are among the most intensively used application servers in the company. GFI cannot afford system or network outages, as its cash flow and financial systems heavily depend on the network stability and availability. GFI has experienced DoS network attacks twice this year, and its Oracle database and email servers had been down for a total of one (1) week as a result. The recovery process required GFI to utilize $25,000 to restore its operations to the normal operating baseline. GFI estimated the loss from these network attacks at more than $1,000,000, as well as lost customer confidence.

Write an eight to ten (8-10) page formal risk assessment proposal in which you:

Describe the company network, interconnection, and communication environment.

Assess risk based on the GFI, Inc. network diagram scenario. Note:Your risk assessment should cover all the necessary details for your client, GFI Inc., to understand the risk factors of the organization and risk posture of the current environment. The company management will utilize this risk assessment to determine what actions to take; therefore, it must be comprehensive for the business leaders to make data-driven decisions.

Defend your assumptions where pertinent information from the scenario isn't available.

Ascertain apparent security vulnerabilities, and analyze at least three (3) such vulnerabilities. Such analysis should entertain the possibility of faulty network design. Recommend mitigation processes and procedures for each of the identified vulnerabilities.

Justify your cryptography recommendations, based on security concerns and requirements, data-driven decision-making, and objective opinions.

Examine whether your risk assessment methodology is quantitative, qualitative, or a combination of these, and discuss the main reasons why you believe that the methodology that you utilized was the most appropriate.

Explain the way in which you would present your findings and assessment to the company's management and thus facilitate security buy-in and concentration.

Using Microsoft Visio or its open source equivalent, redraw the CFI diagram, depicted as a secure and risk-mitigating model. Note: The graphically depicted solution is not included in the required page length.

Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources.

Your assignment must follow these formatting requirements:

Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; citations and references must follow APA or school-specific format. Check with your professor for any additional instructions.

Include a cover page containing the title of the assignment, the student's name, the professor's name, the course title, and the date. The cover page and the reference page are not included in the required assignment page length.

Include charts or diagrams created in Visio or an open source alternative such as Dia. The completed diagrams / charts must be imported into the Word document before the paper is submitted.

The specific course learning outcomes associated with this assignment are:

Evaluate an organization's security policies and risk management procedures, and its ability to provide security countermeasures.

Analyze the methods of managing, controlling, and mitigating security risks and vulnerabilities.

Explain access control methods and attacks.

Describe the details and the importance of application security models and their implementation from a management perspective.

Evaluate and explain from a management perspective the industry-standard equipment, tools, and technologies organizations can employ to mitigate risks and thwart both internal and external attacks.

Use technology and information resources to research issues in security management.

Write clearly and concisely about the theories of security management using proper writing mechanics and technical style conventions.

Reference no: EM131194101

Questions Cloud

Global ventures have gone smoothly : Censorship, enforced written and unwritten laws, red tape and language hurdles not to mention having and keeping the rights to your own patents and products. Give examples of 2 U.S companies who may have faced some or all of these issues. Give exam..
Random diffusion - provide all relevant equations : Random Diffusion - Provide all relevant equations The stability of the numerical method (ex: if you change the delta or delta x, does your result change.) Change something and see the effect it has.
Calculate the current density in each material : Assuming that each material has the same coefficient of expansion and the same power dissipating capability which way will the bimetal device bend? Explain.
Write a handout on parenting and parent-child relationship : Write a handout on parenting and parent-child relationship. Define the topic and Consider relevant developmental processes and outcomes
Explain access control methods and attacks : Examine whether your risk assessment methodology is quantitative, qualitative, or a combination of these, and discuss the main reasons why you believe that the methodology that you utilized was the most appropriate.
Attribute these negative and positive results : To what do you attribute these negative and positive results? Country? Multi-national company (MNC) preparedness? Luck of the draw? Support your answers with appropriate theory.
Calculate the total charge at the interface : Two perfectly conducting cylinders are connected to the two ends for the purpose of connecting to the source. Calculate the total charge at the interface between each two materials (see arrows in Figure 7.45).
Review the articles john locke and jean jacques rousseau : Review the articles "John Locke" and "Jean Jacques Rousseau" in this week's Learning Resources. Think about how social contract theory is related to contemporary democratic theory.
Emotional content in the workplace : What are the ethical implications of reading faces for emotional content in the workplace?

Reviews

Write a Review

Management Information Sys Questions & Answers

  Case study - supporting mobile health clinics

What minimum information should you obtain from the user to start troubleshooting the problem? Research, find and list sources that give insight into performance problems.

  Show the impact of information for an organization

The impact of information for an organization - experience related to best practices and capability

  How should change be managed for successful implementation

How should change be managed for successful implementation of different forms of knowledge management initiative? Discuss how information systems are used to support different forms of incremental change and discontinuous change?

  Addresses why the smartphone is attractive

This post addresses why the Smartphone is attractive and describe the condition that makes it attractive.

  Describe the purpose of initiatives and organizations

Integration of new technology - Describe the purpose of initiatives and organizations

  Describe the privacy concerns with internet service provider

From the first e-Activity, describe the privacy concerns with Internet service provider (ISP) packet detection. Decide whether or not you believe the government should demand ISPs to take more of a proactive approach in detecting and protecting ag..

  Simulate five years of activity using random numbers

Simulate five years of activity using random numbers from Appendix B.  - Discuss some questions of experimental design that this problem poses.

  Calculate the total annual compensation of a salesperson

Write a Java application using NetBeans Integrated Development Environment (IDE) that calculates the total annual compensation of a salesperson. Consider the following factors: A salesperson will earn a fixed salary of

  Discusses rfp and its role in the purchasing process

What is an RFP, and what critical tasks does it facilitate in the purchasing process? and Discusses RFP and its role in the purchasing process.

  How should adel decide whom to take to the negotiation

What factors should Adel consider in deciding whether to use a team for the negotiation and what additional information would you desire before making your final decision on whether to take a team to Washington?

  List and explain the key participants in an ach e-payment

List and explain the key participants in an ACH e-payment. Identify and analyze at least four digital payment concerns Centervale Apparel might want to consider in light of what you have learned from NACHA

  What factors behind huawei decision to enter canadian market

What were the factors behind Huawei's decision to enter the Canadian market? Use the PESTEL (political, economic, social, technological, environmental and legal) framework to analyze the external environment pertinent to Huawei's entry into Canada..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd