How the selected product could be used by sifers-graysonto

Assignment Help Management Information Sys
Reference no: EM131842194

Case Study : Technology & Product Review for Application Lifecycle Management Tools

Case Scenario:

As a Nofsinger consultant, you have been tasked with researching and recommending an Application Lifecycle Management (ALM) tool. Your deliverable for this task will be used to help obtain buy-in from the company's program managersfor increased security investments.

An Application Lifecycle Management tool (product) is used to help manage and protect digital assets which are part of or contribute to the management of software applications (especially source code and design documents) throughout theSoftware & Systems Development Life Cycle (SDLC).

The digital assets for each software application must be protected from initiation of a development or acquisition project through to disposal of equipment at the end of its useful lifespan.

Multiple Sifers-Grayson managershave responsibility for making sure that Sifers-Grayson products are developed and delivered on-time and in compliance with the contractual requirements for functionality ("quality").

For the current set of customers this means that Sifers-Grayson must implement security focused configuration management. Configuration management is a first-line defense against attacks intended to compromise the security and integrity of software applications. This business process is part of a larger, more complex process known as application lifecycle management.

During initial interviews, the engineering managers and program managers provided the following information to your team.

1. Software and Systems Development are the lifeblood of the client company, Sifers-Grayson. From robots to drones to industrial control systems for advanced manufacturing, every product or system sold by the company depends upon software.

Some system functions depend upon tiny control programs that capture data from a sensor or command an actuator to move.

Other system functions depend upon sophisticated software algorithms to receive and analyze data to make sense out of the surrounding environment.

2. Sifers-Grayson's engineers are responsible for writing and testing this software. But, they've never had to worry about cybersecurity ... especially not internal security over software development activities in their own facilities.

3. The engineers feel ownership over their files and folders of source code.

4. There are occasional pranks between engineers working in the labs but software is "sacred" and "off limits."

5. The engineers believe that "No one would dare mess with a file containing source code for an operational system or a system that has moved into the integration and test phase of the software lifecycle."

The Nofsinger Engagement Leader (your boss), has provided the following advance notice information as part of your background briefing for this task.

1. Within the next 60 days, a Nofsinger Red Team will conduct penetration tests for the enterprise.

2. The Red Teamtest plan includes attacks designed to demonstrate to the engineers and managers (through penetration testing)that there is a need to protect digital assets, especially software designs, source code, and related artifacts from both insider and external threats.

Research:

1. Review the weeklyreadings.

2. Using Google or another search engine, identify anApplication Life Cycle Management product which could meet the needs of Sifers-Grayson.Then, research your chosen product using the vendor's website and product information brochures.

3. Find three or more additional sources which provide reviews for (a) your chosen product or (b) information about Application Life Cycle Management.

Write:

Write a 3 page summary of your research. At a minimum, your summary must include the following:

1. An introduction or overview for the security technology category (Application Lifecycle Management)

2. A review of the features, capabilities, and deficiencies for your selected vendor and product

3. Discussion of how the selected product could be used by Sifers-Graysonto support its cybersecurity objectives by reducing risk, increasing resistance to threats/attacks, decreasing vulnerabilities, etc.

4. A closing section in which you restate your recommendation for a product (include the three most important benefits).

As you write your review, make sure that you address security issues using standard cybersecurity terminology (e.g. protection, detection, prevention, "governance," confidentiality, integrity, availability, nonrepudiation, assurance, etc.).

Reference no: EM131842194

Questions Cloud

What is the value of the company equity : What is the value of the company’s equity? What is the total value of Icarus?
Influence on our morality as human beings : Freewill has key influence on our morality as human beings. Every action that we take (whether good or bad) demonstrates our morality
Ethics of the chinese concerned opinion : The Ethics of the Chinese concerned opinion should we ONLY concern ourselves with the Matters of this world? Discuss your opinion in depth.
Rate of return and annualized nominal yield : Bonds of similar risk are currently earning a 6.13% rate of return (annualized nominal yield).
How the selected product could be used by sifers-graysonto : Discussion of how the selected product could be used by Sifers-Graysonto support its cybersecurity objectives by reducing risk
Same way in empirical statements : Is the word "know" used in the same way in empirical statements, such as "I know the sun will rise tomorrow," and 2 + 2 = 4?
What the business produces or sells of BLAZE international : Produce a business study report. Make report on BLAZE international limited. What the business produces or sells; Where most of the customers are located
Analyze how would you describe ambush marketing : Analyze how would you describe ambush marketing? What are the advantages and disadvantages (risks and consequences) of ambush marketing?
What defenses will the bank assert : Assume that the jurisdiction does not recognize assumption of risk or contributory negligence. The jurisdiction does recognize the defense of comparative.

Reviews

Write a Review

Management Information Sys Questions & Answers

  Sdlv versus agile explained in detail

SDLV versus Agile Explained in Detail - The SDLC methodology uses a cascading flow in the process phases of conception, feasibility and analysis, design and development, implementation, testing, release and maintenance.

  What is an entity relationship diagram

What is an Entity Relationship Diagram? In your answer please describe the terms Entity, Attribute, Primary Key, Relationship and Cardinality. At least 500 words.

  Analyze the multi-national and global aspects of the article

Analyze the multi-national and global aspects of the article - what is the impact or what is the importance of the information in the article?

  This posting addresses fraudulent behavior in a software

this posting addresses fraudulent behavior in a software co.jason works at a new software development company. the

  Determine your native conflict response behavior

Provide one (1) example that supports your conclusion. Note: This is a safe environment for everyone to share his / her personal experience.

  Show where you believe both small and large companies

show where you believe both small and large companies havdiscuss where you believe both small and large companies have

  What does the encarta versus wikipedia story tell you

MGMT 515:According to Motivation Crowding Theory, contingent extrinsic rewards crowd out intrinsic motivation. Do you concur? Defend.

  What is the purpose of a disaster recovery plan

What is the purpose of a disaster recovery plan (DRP)? What is the difference between a DRP and business continuity planning?

  Which are the key risk areas for the project

Which approach will you use to estimate the overall cost of the project? Why? Justify your choice. Why do you think that other approaches will be less appropriate?

  What are the different types of malware

What are the different types of malware that may attack the devices in your home.

  Explain why it projects fail

Why IT Projects Fail - What do you envision are the primary contributors to this dismal record of performance?

  Read the danforth manufacturing company case study

The first thing the architect, Vince Albright, did with the group was to document the current business services and associated IT resources that might be replaced or modified by Kate's and Jim's proposals. Why do you believe this was a necessary ..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd