Prepare a risk mitigation report and configure

Assignment Help Other Subject
Reference no: EM132982645 , Length: word count:2000

Assessment - Practical and Written Assessment

Purpose: The purpose of this assignment is to assess the students' understanding on identifying the risks, vulnerabilities and awareness of current industry and research trends in the field of information security. Students need to exercise operational, analytical, and critical skills to reduce the potential security risks involved in the given case study. Analyse and evaluate the organizational adoption of security controls. Design solutions for concrete security problems for distributed applications. This assessment contributes to learning outcomes a, b, c, d.

Reference sources must be cited in the text of the report and listed appropriately at the end in a reference list using Harvard Anglia referencing style. (More than 5 references)

Assessment topic: Port scanning, Security Planning

Task details: This Assignment requires you to perform a scan on the network, prepare a Risk Mitigation report and configure some of the firewall settings using Kali Linux to secure the network and the distributed applications.

The assignment requires 1 tool as listed below to complete the criteria of this assignment:

Use Nmap - a vulnerability scanning protocol in Kali Linux- Prepare a short Risk Mitigation plan to identify the threats for the assets.

Case Study for the Assignment: An educational institute suffers from very low information security in terms of maturity across many elements of infosec and information assurance, including cyber resilience and application of cybersecurity good practice. Data breaches could have the institute puts its reputation at risk, and students expect a high level of protection of their data. It is highly recommended that there is a need to impose a certain level of filtering for the network to be secure so as to sustain from threats and attacks. To add restrictions on a particular network it is necessary to identify the possible threats to the organization. For example, it is necessary to identify the important services that run on the network. In order to get this done, there is a need to perform scanning on the network to identify the services and ports of the applications. Furthermore, the firewall needs to be configured by adding rules to block and allow the services based on the requirements of the organization and the security perspectives of the network.

Part A: With respect to the given study, you need to:

- Run TCP scan will scan for TCP port like port 22, 21, 23, 445 and ensure for listening port (open) through 3-way handshake connection between the source and destination port. Analyse the ports' status.

- Run UDP Scan where it is sending a UDP packet to every destination port; it is a connectionless protocol.

Note: Use your computer or gateway IP address in Nmap commands!

Part B: The institute had no dedicated security team and therefore till now no security policy is in place. Recently, the governing body of this business forms a security team and makes following two goals that they would like to achieve in six months -

Assessing the current risk of the entire organization Treat the Risk as much as possible

Task I: Risk Identification

In achieving the above two goals, you will do the followings -

Find at least five assets Find at least two threats against each asset Identify vulnerabilities for the assets

Task II: Risk Assessment At the end of the risk identification process, you should have i) a prioritized list of assets and ii) a prioritized list of threats facing those assets and iii) Vulnerabilities of assets. At this point, create Threats Vulnerabilities-Assets (TVA) worksheet. Also, calculate the risk rating of each of the five triplets out of 25.

TASK III: Risk Treatment In terms of Risk Treatment, for each of the five identified risk, state what basic strategy you will take. Justify for each decision. Also, Advise all possible protection mechanism and corresponding place of application

Attachment:- Assessment cyber secruity.rar

Reference no: EM132982645

Questions Cloud

Major force in the generic pharmaceuticals industry : Why is rivalry not a major force in the generic pharmaceuticals industry? Give examples
Professional knowledge regarding working : Reflect on your own values and beliefs in relation to inclusiveness. How do you develop your own professional knowledge regarding working with children with add
Examples of recognition programs : -Discuss 3 examples of recognition programs that organizations can implement. What is the rationale for introducing the 3 recognition programs, and how can an o
Explain the factors external to any mne : Essay: Identify and explain the factors external to any MNE that in the 21st century affect the international management of human resources.
Prepare a risk mitigation report and configure : Prepare a Risk Mitigation report and configure some of the firewall settings using Kali Linux to secure the network and the distributed applications
What is the dsm : What is the DSM? Why is it important to mental health care? Please give reference
What are accountable care organizations : What are accountable care organizations? What value can they provide to the healthcare industry?
What is the experiential theory : What is the experiential theory? Why some people align with this theory.
Appropriate recruitment strategies for job position : Propose appropriate recruitment strategies for this job position (frontline manager)?

Reviews

Write a Review

Other Subject Questions & Answers

  Cross-cultural opportunities and conflicts in canada

Short Paper on Cross-cultural Opportunities and Conflicts in Canada.

  Sociology theory questions

Sociology are very fundamental in nature. Role strain and role constraint speak about the duties and responsibilities of the roles of people in society or in a group. A short theory about Darwin and Moths is also answered.

  A book review on unfaithful angels

This review will help the reader understand the social work profession through different concepts giving the glimpse of why the social work profession might have drifted away from its original purpose of serving the poor.

  Disorder paper: schizophrenia

Schizophrenia does not really have just one single cause. It is a possibility that this disorder could be inherited but not all doctors are sure.

  Individual assignment: two models handout and rubric

Individual Assignment : Two Models Handout and Rubric,    This paper will allow you to understand and evaluate two vastly different organizational models and to effectively communicate their differences.

  Developing strategic intent for toyota

The following report includes the description about the organization, its strategies, industry analysis in which it operates and its position in the industry.

  Gasoline powered passenger vehicles

In this study, we examine how gasoline price volatility and income of the consumers impacts consumer's demand for gasoline.

  An aspect of poverty in canada

Economics thesis undergrad 4th year paper to write. it should be about 22 pages in length, literature review, economic analysis and then data or cost benefit analysis.

  Ngn customer satisfaction qos indicator for 3g services

The paper aims to highlight the global trends in countries and regions where 3G has already been introduced and propose an implementation plan to the telecom operators of developing countries.

  Prepare a power point presentation

Prepare the power point presentation for the case: Santa Fe Independent School District

  Information literacy is important in this environment

Information literacy is critically important in this contemporary environment

  Associative property of multiplication

Write a definition for associative property of multiplication.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd