The common criteria address these four problems of tcse

Assignment Help Computer Networking
Reference no: EM13855656 , Length: 2000 words

Question 1: The Trusted Computer System Evaluation Criteria (TCSEC) had several drawbacks. They include: 


(1) It only addressed confidentiality aspects and not integrity and availability of security; 
(2) It focused on operating system products; 
(3) Its evaluation process was too slow; and 
(4) It suffered from Criteria Creep. 

Recall that criteria creep is the process of refining evaluation requirements as the industry gains experience with them, making the evaluation criteria something of a moving target. (See Section 21.2.4.2 of Bishop) 

How well did the Common Criteria (CC) address these four problems of TCSEC? 

Question 2: This question is on Vulnerability Analysis as discussed in INFA670 Session 4. The vulnerability analysis, in practical terms, is to find what software and services are running in your enterprise, whether various systems and applications in your enterprise are properly patched, and whether they are configured correctly and, as the name indicates, what vulnerabilities exist in various infrastructure components and applications and the significance of the vulnerabilities discovered. 

For this exercise, assume that you are a security officer for a large networked enterprise consisting of thousands of IP addresses (hosts, servers and devices) running thousands of services and applications on those machines. 

Discuss in detail one vulnerability analysis tool that is suitable for this (deployment) environment. Justify to your CTO or CIO why the tool you have selected is appropriate for this environment from the perspectives of: 

  • Mapping: Determining what is running where

• Ability to identify versions and patches (or lack of them) of software 
• Vulnerability Analysis (both false positive and false negative aspects should be considered) 

  • Usability

• Performance (Is it taking a whole day to run? Or is it bringing down a system?) 

  • Cost

You may consider one of the tools discussed in the Section 4 Discussion Forum such as SAINT (Security Administrator's Integrated Network Tool), beyondtrust Retina suite of products, and Tenable Network Security Nessus (and their derivatives). You have the liberty to consider open source or free products such as OpenVAS. You may also consider products not discussed in the class. (You may decide you need a suite of tools. That is fine too.) 

State your assumptions/restrictions about the tool clearly. For example, the tool could not be employed beyond the firewall. Another example is the type of privilege the tool needs to have in order to be successful. 

Question 3 :The CMMI® Model for Development has several process areas (PAs), 22 in Version 1.3 to be exact. For this exercise, we will consider the following 4 PAs: (1) Configuration Management, (2) Organizational Training, (3) Requirement Management, and (4) Risk Management. These 4 PAs are also applicable for CMMI for Services and CMMI for Acquisition. Let us suppose you are interested in achieving a higher "Capability Level" in these process areas in one project or several projects in your enterprise. (If your enterprise does not develop any software, consider improving the services you offer or acquisitions you make.) For each of these four PAs, 
1. Briefly describe what the process area is and why it is needed. Enumerate improvements you expect to see for these process areas in your enterprise. 
2. Describe specific goals for the process area. 
3. List resources/tools you may use to assist or automating the process area. 

Provide all above three answers in saparate document along with references. Write your response in 2000 words count total including all three answers

Verified Expert

Reference no: EM13855656

Questions Cloud

Principles of marketing : Principles of Marketing
Target marketing and swot analysis : Target Marketing and SWOT Analysis
Estimate survival in patients : A study is conducted to estimate survival in patients following kidney transplant. Key factors that adversely affect success of the transplant include advanced age and diabetes. This study involves 25 participants who are 65 years of age and older..
Product and competitive advantage : Product and Competitive Advantage
The common criteria address these four problems of tcse : Recall that criteria creep is the process of refining evaluation requirements as the industry gains experience with them, making the evaluation criteria something of a moving target. (See Section 21.2.4.2 of Bishop) How well did the Common Criteria (..
Identify a theory or idea from a non-business course : Identify a theory or idea from a non-business/non-MIS course that relates to concepts in IT. Explain where it came from, what it is, and how it relates to MIS/IT.
Steps in maintaining chain of custody for digital evidence : List the steps in maintaining chain of custody for digital evidence? Why is important to follow the chain of custody when gathering evidence
Wrote using ethical scholarship visual aesthetics proper : Wrote using ethical scholarship, visual aesthetics, proper grammar, and mechanics.
Discuss the differences between gaap and ifrs : Discuss the differences between GAAP and IFRS: What are implications of the differences in financial reporting? What are two advantages and two issues with each?

Reviews

Write a Review

Computer Networking Questions & Answers

  Networking and types of networking

This assignment explains the networking features, different kinds of networks and also how they are arranged.

  National and Global economic environment and ICICI Bank

While working in an economy, it has a separate identity but cannot operate insolently.

  Ssh or openssh server services

Write about SSH or OpenSSH server services discussion questions

  Network simulation

Network simulation on Hierarchical Network Rerouting against wormhole attacks

  Small internet works

Prepare a network simulation

  Solidify the concepts of client/server computing

One-way to solidify the concepts of client/server computing and interprocess communication is to develop the requirements for a computer game which plays "Rock, Paper, Scissors" using these techniques.

  Identify the various costs associated with the deployment

Identify the various costs associated with the deployment, operation and maintenance of a mobile-access system. Identify the benefits to the various categories of user, arising from the addition of a mobile-access facility.

  Describe how the modern view of customer service

Describe how the greater reach of telecommunication networks today affects the security of resources which an organisation provides for its employees and customers.

  Technology in improving the relationship building process

Discuss the role of Technology in improving the relationship building process Do you think that the setting of a PR department may be helpful for the ISP provider? Why?

  Remote access networks and vpns

safekeeping posture of enterprise (venture) wired and wireless LANs (WLANs), steps listed in OWASP, Securing User Services, IPV4 ip address, IPV6 address format, V4 address, VPN, Deploying Voice over IP, Remote Management of Applications and Ser..

  Dns

problems of IPV, DNS server software, TCP SYN attack, Ping of Death, Land attack, Teardrop attack, Smurf attack, Fraggle attack

  Outline the difference between an intranet and an extranet

Outline the difference between an intranet and an extranet A programmer is trying to produce an applet with the display shown in Figure 1 below such that whenever one of the checkboxes is selected the label changes to indicate correctly what has..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd