The security systems development life cycle (secsdlc), Computer Network Security

Assignment Help:

The Security Systems Development Life Cycle (SecSDLC)

The same phases which is used in traditional SDLC can be adapted to support specialized implementation of IS project,At its center, implementing information security includes Identifying of specific threats and creating special controls to counter them.

 Investigation

The investigation phase of SecSDLC starts with a directive from upper management, dictating or Identifies the process, goals, outcomes, budget and constraints of project. This phase begins with the enterprise information security policy that outlines the implementation of a security program within organization. Organizational feasibility analysis can be performed to determine whether the organization has resources and commitment required to conduct a successful security analysis and design.

Analysis

In analysis phase, the documents from investigation phase are studied properly. The development team conducts a preliminary analyzes existing security policies or programs, along with the documented current threats and connected controls. This phase includes analysis of relevant legal issues also which could impact design of the security solution. The risk management task begins from this stage.

 Logical Design

The logical design phase creates and develops blueprints for information security and examines and implements key policies which influence the decisions. The team plans the incident response actions to be taken in the event of the partial or catastrophic loss. The planning answers following questions:

•    Continuity planning – How will business they continue in the event of loss?
•    Incident response - What steps should be taken when the attack is observed?
•    Disaster recovery – What should be done to recover information and vital systems immediately when the disastrous event has occured?

 Physical Design


In physical design phase, the information security technology required to support the blueprint outlined in the logical design can be evaluated, alternative solutions generated, feasibility study and final design agree upon.

 Implementation

In implementation phase in of SecSDLC is similar to that of the traditional SDLC. The security solutions are acquired, tested, implemented, and tested again. Personal issues are evolved, and specific training and education programs are conducted. Finally, the whole tested package is presented to upper management for the final approval.

Maintenance and Change

In this phase, given the current ever changing threat environment. Reparation and restoration of information is a constant duel with the unseen adversary. Information security profile of the organization requires constant adaptation as new threats emerge and old threats expand.


Related Discussions:- The security systems development life cycle (secsdlc)

Arrangement of self-learning switches, QUESTION a) Consider the speed ...

QUESTION a) Consider the speed of propagation of an electrical signal is same to 2x10 8 m/s, evaluate the ratio of the propagation delay to the transmit time for the given typ

Hypothetical reliable data transfer protocol, Hypothetical reliable data tr...

Hypothetical reliable data transfer protocol: A jumping window based Go-back-N  ARQ protocol for file transfer using UDP as the transport protocol: In this protocol, a window o

Produce a pcap file from a wireshark capture, Question requires you to prod...

Question requires you to produce a pcap file from a Wireshark capture.  In addition, you must include a screen capture of Wireshark and some specific information regarding the fram

What do you understand by the concept web of trust, Question: a) Name ...

Question: a) Name a method to allow a person to send a confidential email to another person, without risks of a third-party reading the email. Describe briefly the operations

encrypt and decryption using rsa with the prime numbers, Problem (1) -...

Problem (1) - Alice, Bob and Charlie have a secret key a=3, b=4, c=5, respectively. - They want to find a common secret key using Diffie-Hellan key exchange protocol (with g

Arp message format, ARP MESSAGE FORMAT Although the ARP data packet fo...

ARP MESSAGE FORMAT Although the ARP data packet format is sufficiently general to allow hardware addresses and arbitrary protocol. ARP is almost usually used to bind a 32-bit

Caralouer case study: analysis and design techniques, CarALouer provides re...

CarALouer provides rental of cars to its customer on a regional basis i.e. a car is attached to a regional home-base which also houses a regional office of the company. Each regi

Estimate the average throughput, Question (a) Estimate the average thr...

Question (a) Estimate the average throughput between two hosts given that the RTT for a 100 bytes ICMP request-reply is 1 millisecond and that for a 1500 bytes is 2 millisecon

Attacks on wireless network, Q. Attacks on wireless network WSN are vul...

Q. Attacks on wireless network WSN are vulnerable to attacks which compromise the integrity of the WSN nodes by decreasing the nodes' fault tolerance capabilities, data distrib

Imap and pop functions, How does the POP functions? What are the advantages...

How does the POP functions? What are the advantages/benefits of IMAP over POP? POP stands for Post Office Protocol, version 3 (POP3) is one of the easiest message access protoc

Write Your Message!

Captcha
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd