The common criteria address these four problems of tcse

Assignment Help Computer Networking
Reference no: EM13855656 , Length: 2000 words

Question 1: The Trusted Computer System Evaluation Criteria (TCSEC) had several drawbacks. They include: 


(1) It only addressed confidentiality aspects and not integrity and availability of security; 
(2) It focused on operating system products; 
(3) Its evaluation process was too slow; and 
(4) It suffered from Criteria Creep. 

Recall that criteria creep is the process of refining evaluation requirements as the industry gains experience with them, making the evaluation criteria something of a moving target. (See Section 21.2.4.2 of Bishop) 

How well did the Common Criteria (CC) address these four problems of TCSEC? 

Question 2: This question is on Vulnerability Analysis as discussed in INFA670 Session 4. The vulnerability analysis, in practical terms, is to find what software and services are running in your enterprise, whether various systems and applications in your enterprise are properly patched, and whether they are configured correctly and, as the name indicates, what vulnerabilities exist in various infrastructure components and applications and the significance of the vulnerabilities discovered. 

For this exercise, assume that you are a security officer for a large networked enterprise consisting of thousands of IP addresses (hosts, servers and devices) running thousands of services and applications on those machines. 

Discuss in detail one vulnerability analysis tool that is suitable for this (deployment) environment. Justify to your CTO or CIO why the tool you have selected is appropriate for this environment from the perspectives of: 

  • Mapping: Determining what is running where

• Ability to identify versions and patches (or lack of them) of software 
• Vulnerability Analysis (both false positive and false negative aspects should be considered) 

  • Usability

• Performance (Is it taking a whole day to run? Or is it bringing down a system?) 

  • Cost

You may consider one of the tools discussed in the Section 4 Discussion Forum such as SAINT (Security Administrator's Integrated Network Tool), beyondtrust Retina suite of products, and Tenable Network Security Nessus (and their derivatives). You have the liberty to consider open source or free products such as OpenVAS. You may also consider products not discussed in the class. (You may decide you need a suite of tools. That is fine too.) 

State your assumptions/restrictions about the tool clearly. For example, the tool could not be employed beyond the firewall. Another example is the type of privilege the tool needs to have in order to be successful. 

Question 3 :The CMMI® Model for Development has several process areas (PAs), 22 in Version 1.3 to be exact. For this exercise, we will consider the following 4 PAs: (1) Configuration Management, (2) Organizational Training, (3) Requirement Management, and (4) Risk Management. These 4 PAs are also applicable for CMMI for Services and CMMI for Acquisition. Let us suppose you are interested in achieving a higher "Capability Level" in these process areas in one project or several projects in your enterprise. (If your enterprise does not develop any software, consider improving the services you offer or acquisitions you make.) For each of these four PAs, 
1. Briefly describe what the process area is and why it is needed. Enumerate improvements you expect to see for these process areas in your enterprise. 
2. Describe specific goals for the process area. 
3. List resources/tools you may use to assist or automating the process area. 

Provide all above three answers in saparate document along with references. Write your response in 2000 words count total including all three answers

Verified Expert

Reference no: EM13855656

Questions Cloud

Principles of marketing : Principles of Marketing
Target marketing and swot analysis : Target Marketing and SWOT Analysis
Estimate survival in patients : A study is conducted to estimate survival in patients following kidney transplant. Key factors that adversely affect success of the transplant include advanced age and diabetes. This study involves 25 participants who are 65 years of age and older..
Product and competitive advantage : Product and Competitive Advantage
The common criteria address these four problems of tcse : Recall that criteria creep is the process of refining evaluation requirements as the industry gains experience with them, making the evaluation criteria something of a moving target. (See Section 21.2.4.2 of Bishop) How well did the Common Criteria (..
Identify a theory or idea from a non-business course : Identify a theory or idea from a non-business/non-MIS course that relates to concepts in IT. Explain where it came from, what it is, and how it relates to MIS/IT.
Steps in maintaining chain of custody for digital evidence : List the steps in maintaining chain of custody for digital evidence? Why is important to follow the chain of custody when gathering evidence
Wrote using ethical scholarship visual aesthetics proper : Wrote using ethical scholarship, visual aesthetics, proper grammar, and mechanics.
Discuss the differences between gaap and ifrs : Discuss the differences between GAAP and IFRS: What are implications of the differences in financial reporting? What are two advantages and two issues with each?

Reviews

Write a Review

Computer Networking Questions & Answers

  Explain most memorable experience with salesperson which

prepare a three-page paper in apa style that describes explains addresses and answers the following. many people shy

  Developing the network design

The Fiction CEO has informed you that the capital budget cannot exceed $500,000 and must not interrupt business operations. What follows is a brief overview that will serve as your foundation in developing the network design.

  Define the vpn implementation

explain the differences in attributes you would choose for a pharmaceutical company creating the latest groundbreaking drugs for the consumer market as opposed to the VPN implementation at a private college.

  Porpose to verify that you can login into the strayer unix

The purpose of this lab assignment is to verify that you can login into the Strayer UNIX / Linux server. You must submit evidence of your login session via a screenshot.

  Considering changing cell phone plan

considering changing her cell phone plan

  Describe the network management software components

Describe the network management software components. Side server components, middleware components and northbound interface.

  What type of security issues need to be considered

What are some of the reasons an organization might consider using a Wireless LAN? What type of security issues need to be considered when implementing a Wireless LAN

  Question 1a medical clinic recently conducted a patient

question 1a medical clinic recently conducted a patient satisfactory survey of a 100 patients. using the lickert scale

  Evolution of the telecommunications industry

The World Wide Web the best know example of a WAN that's why once a WAN is in place, WAN security must be implemented. Some methods for securing WANs include firewalls, routers with access control lists, and intrusion detection systems

  Explain transit systems for both avl and tsp

Outcome of this process must then be incorporated into ITS regional architecture. Are there plans to give ems vehicles with signal priority/pre-emption?

  What is a client-server system

What is a client-server system? What are the main features of a client-server system? Describe the architecture of a client-server system. Adhere to MLA formatting and reference guidelines Deliverable length 3-5 pages

  Assignment on social media and networking presentation

Social Media and Networking Presentation, Imagine that you have been hired as a consultant for a university that wants to leverage social media and networking technologies to encourage the collaboration of students, and improve their overall sense ..

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd