ISSC499 final

deweese3
ISSC499week5assignment.docx

Organizational Strategic Security Plan

Cristian DeWeese

ISSC499

American Military University

07/07/2024

ABC Corp is a medium scale computer firm that operates in the technology niche with specialty in software, cloud solutions. It has around 500 employees and manages a central office in New York City, USA (Walsh, 2023). Hybrid cloud, local data center in which physical infrastructure is a crucial component supported by managed as well as endpoint devices consists of laptops, desktops, and mobiles.

IT Architecture Overview:

1. Hybrid Cloud Environment: Infrastructure of both private and public cloud resources.

1. Local Data Center: It has targeted on-premises servers and networking equipment.

1. Endpoint Devices: Notebooks, PCs, portable, stationary, pocket, hand, and palm computers.

Purpose of the Strategic Security Plan: The objective of this Strategic Security Plan is to design an effective security over the company’s computer network systems against cyber criminals. This plan specifies approaches, measures and courses of action aimed at the identification of network penetration and the development of adequate countermeasures against the threats of cyber security.

Organizational Strategic Security Plan

1. Security Awareness and Training Program

Objectives:

1. Raise awareness of potential risks in the workplace among the personnel.

1. Minimize one’s interaction with the outside world and greatly diminish the probability of falling for phishing schemes.

1. This is why security has to be proactively promoted in the organization and be viewed as an essential part of the organizational culture.

Methods of Delivery:

1. Workshops: These are presented in the form of face-to-face sessions every three months on the chosen themes related to cybersecurity.

1. Online Courses: For example, all employees are required to take the annual online training.

1. Newsletters: Current cyber threats and protection tips are in the monthly newsletters.

Content:

1. Cybersecurity fundamentals and social engineering and phishing.

1. Clare Beckett pointed out some general preventive safety measures, including practicing safe internet and email usage.

1. Incident reporting procedures.

In this case, a Security Awareness & Training Program remains paramount for ensuring that the security deficiency of the organization is corrected (Dash & Ansari, 2022). To achieve this, workshops, online courses, and newsletters will be used to ensure that the employees are informed and aware of the latest threats and standards in cybersecurity.

2. Policy and Compliance

Security Policies:

1. Acceptable Use Policy: Policies that specify appropriate behavior in relation to the company’s resources.

1. Data Protection Policy: Some of its functions are to address measures for the proper protection of sensitive data.

1. Incident Response Policy: Security program countermeasures.

Compliance Requirements:

1. GDPR: Preserving freedom, security and justice for EU citizens as well as data protection and privacy issues.

1. HIPAA: Securing clients' health information in the healthcare sector.

1. ISO/IEC 27001: Ensuring compliance with international standards for information security management.

Enforcement:

1. There should also be a Systematic process of review and examination to check compliance with the set procedures. Consequences of failure to adhere to the company’s policies.

1. There should always be a check and balance on whatever policies are implemented, and new policies should always be adopted.

Now, policies and compliance are essential elements of an organization's security management. Thus, by providing specific guidelines, ABC Corp avoids getting into legal and operational issues that may be relevant, according to Edwards (2024). Thus, these policies should be audited and reviewed periodically to ensure that they remain useful and relevant.

3. Tools and Techniques of Intrusion Detection and Prevention

Tools and Techniques:

1. Firewalls: Network firewalls to screen incoming and outgoing traffic.

1. IDS/IPS: Intrusion Detection Systems and Intrusion Prevention Systems are used to control and prevent violations.

1. SIEM: Security Information and Event Management systems used to gather, process and provide security incidents.

1. Endpoint Protection: Security programs that fight against viruses and malware on all the nodes of the computer network.

Implementation:

1. Periodic upgrades and efficient management of patches along with continuous monitoring and alerting.

1. An incident response team is responsible for managing the intrusions that have been detected.

Intrusion detection and prevention systems (IDPS) are used to analyze this flow and search for suspicious activities (Garbis et al., 2021). Firewalls, IDS/IPS, SIEM, and endpoint protection tools shall be implemented as multiple layers of protection for the organization. Due to the dynamics of threats, these tools need to be constantly monitored and updated to remain effective.

4. Procedures of the Vulnerability Assessment and Penetration Testing

Procedures:

1. Vulnerability Assessments: Scammon or biannual scans to define the problem and find a solution.

1. Penetration Testing: Semi-annual tests that would mimic possible cyber-attacks on the targets in an attempt to find their vulnerabilities.

Tools:

1. Nessus: For vulnerability scanning.

1. Metasploit: For penetration testing.

Documentation and Response:

1. Detailed reports of findings. Critical vulnerability assessment and its correlation with the priority of the issue and the work on its solution.

1. To make sure that any discovered vulnerability has been fixed, a retest is done.

Scanning and ethical hacking are preventive techniques of out mapping the loopholes within the network security system before the outsider exploiter does that. Periodical update, and scanning for the tests and assessment will enable ABC Corp to fortify its system and protect it from possible threats (Zahid et al., 2023).

5. Disaster Recovery Program

Data Backup and Recovery:

1. Back-up of data that are sensitive and/or have high value with a frequency of at least once a week.

1. Backup data storage is at a different location from the main operation or in a different room within the facility. Backup and recovery are also the testing processes.

Incident Response:

1. Natural Disasters: Planning procedures for the data centers and business contenuity.

1. Cyber-Attacks: Measures that need to be taken to prevent the attacks, as well as measures that need to be taken in the process of mitigating the attacks.

Testing and Maintenance:

1. Regular disaster recovery drills.

1. The actions are as follows: continuous improvement of the disaster recovery plan.

Disaster Recovery Program guarantees that ABC Corp can regain normalcy irrespective of the event’s type, such as natural disasters and cyber-attacks (Fikri et al., 2021). The objective of backing up the data frequently and storing it off-site will enhance its safety, whereas the frequent testing and refining of the plan will guarantee readiness for any occurrence.

6. Defense in Depth Principles

Layered Security Measures:

1. Physical Security: Access control and security in the physical space of the building and its environs.

1. Network Security: Deploying firewalls, IDS/IPS, and network segmentation.

1. Application Security: Code owners need to have proper and secure ways of developing the code and constant checking on the code.

1. Data Security: In this case, the protection of data by applying security at the two main levels- data at rest and data in transit.

Implementation:

1. Duplicate mechanisms can be used to minimize risks that are associated with security as a specialty.

1. Continuous monitoring and improvement and continuing education for personnel and especially students as a reminder of the firm’s security measures.

ABC Corp should use two sets of security measures that have been duplicated so that in case one is compromised, the other will be useful (Arogundade, 2023). Through constant evaluation of the implemented procedures and training of the company employees, these measures will be effective.

In conclusion, this Organizational Strategic Security Plan of ABC Corp includes multifaceted approaches that will help to counteract the threats and protect the information within the corporation. Implementing a Security Awareness & Training Program, creating clear policies and making sure that they are being followed, utilizing high-end Intrusion Detection/Prevention systems, having regular Vulnerability Assessment & Penetration Testing, building a strong Disaster Recovery Program and adhering to DoD secure principles will greatly help ABC Corp in improving the company's security.

References

Arogundade, O. R. (2023). Network security concepts, dangers, and defense are best practical. Computer Engineering and Intelligent Systems14(2). https://core.ac.uk/download/pdf/564354439.pdf

Dash, B., & Ansari, M. F. (2022). An effective cybersecurity awareness training model: first defense of an organizational security strategy. https://d1wqtxts1xzle7.cloudfront.net/89862930/IRJET_V9I401-libre.pdf?1660813617=&response-content-disposition=inline%3B+filename%3DAn_Effective_Cybersecurity_Awareness_Tra.pdf&Expires=1720097134&Signature=NOgKHkQMalUbIhlvXGjWNsV2OglJ19oaZjqErQulGaMFzH6Cr6Po2uXbC4d72bKwuBKuB0eBEKxnvMkhaov5WA3xcp5r9JYGZcXdIretXw4czP3Jwn9y-4wnl74JU6ZwAXLpPsD~jDicBndASo~OzAtsAKACipUpQ-pD6NVZ5vC9At7x4DLYwhiStQUZAA-gDR0zdGA6fC5ASsDASH2lmvZDjXO8-LThPcLGU12TlnWhyok25IZqxV6sQsgWaWPRAqYS0L3qBBGgqOnSwv0agXjicJmPDUyLOSHu79uW-2iL6nkaNU~Po7-nt1IJ0nhGfP8RjauZtMmTPH1Jie9E9g__&Key-Pair-Id=APKAJLOHF5GGSLRBV4ZA

Edwards, D. J. (2024). Security Policies and Procedures. In  Mastering Cybersecurity: Strategies, Technologies, and Best Practices (pp. 413-434). Berkeley, CA: Apress. https://link.springer.com/chapter/10.1007/979-8-8688-0297-3_12

Fikri, A. M., Fachrureza, F., Octaraisya, N., Agustyana, N. A., Putra, M. G. L., & Amalia, D. N. JBTI: Jurnal Bisnis: Teori dan Implementasi. https://d1wqtxts1xzle7.cloudfront.net/76248504/6712-libre.pdf?1639471558=&response-content-disposition=inline%3B+filename%3DImplementation_of_Business_Continuity_Pl.pdf&Expires=1720097380&Signature=WMZf8XEyCjaMNEK5Gia9bXfO~mMwAu4y70n2CynXY1Dml1HPPfp7CZs2l05ay7CAiYmthnMweN22sKHlTdqNWBwJWTGyKUPgOaIhnsMcO3okRzY1kgmaE4NtzXZ9~nkxe56gpiQl6t0seKMl487uBKLCFHhyVjpKg1SLSRH8wEwGgDpQNgl5w99xWTeHTYt9haXlSgJVQtAROOFQk5~cTsYEcyvzi-2HTB-1LVZ2UtHSNOsvZFMzmI3D~IOrC1xt2HGU921RloY6zIqlGD4IZgxkeb0u5B7lrzF5qVuPoVl-gQAs1Dj1gkDTZQNlIRkOGBM218CxJX4gUAYIvmn7YQ__&Key-Pair-Id=APKAJLOHF5GGSLRBV4ZA

Garbis, J., Chapman, J. W., Garbis, J., & Chapman, J. W. (2021). Intrusion Detection and Prevention Systems.  Zero Trust Security: An Enterprise Guide, 117-126. https://link.springer.com/chapter/10.1007/978-1-4842-6702-8_8

Walsh, K. (2023).  Security-first Compliance for Small Businesses. CRC Press. https://www.taylorfrancis.com/books/mono/10.1201/9781003128588/security-first-compliance-small-businesses-karen-walsh

Zahid, S., Mazhar, M. S., Abbas, S. G., Hanif, Z., Hina, S., & Shah, G. A. (2023). Threat modeling in smart firefighting systems: Aligning MITRE ATT&CK matrix and NIST security controls.  Internet of Things22, 100766. https://www.sciencedirect.com/science/article/pii/S2542660523000896