Information Technology

onyango2013
IT409-Assignment3-questions.docx

Pg. 01

Assignment 3

Assignment 3

Deadline: Day 30/03/2018 @ 23:59

[Total Mark for this Assignment is 4]

IT Security and Policies

IT409

https://www.seu.edu.sa/sites/ar/SitePages/images/logo.png

College of Computing and Informatics

Physical and Environmental Security

01 Marks

Learning Outcome(s):

LO 4: Write security policies and put in place an effective security architecture that comprises modern hardware and software technologies and protocols.

Q1)

a) What control policy is required in order to prevent unauthorized access and damage to facilities?

There are many policies which can be implemented to ensure security for the computing facilities. One of the available policies which could be adopted is ensuring that the data center is physically away from the company. The facility could be located in the underground floor. Data center also needs to be protected from entry by unauthorized persons. This can be done through having physical barriers and having cards to help in accessing the barriers. All sensitive information should also be kept and must be placed in areas which are secured and be protected against any physical threat and damage. Activities such as public tours and conferences should not be placed in public places as well. The communication center should also be protected against drainage, fire and be located in safe locations. The should be ni signs indicating the location for data center and the facilities used should resist fire for at least one hour.

b) Write 2 example controls that are required for securing Offices, Rooms, and Facilities.

The server room should be locked.

All servers should be locked down, before the server is turned down for the first time, the server room should be locked up. There should be policies showing that the room should be locked when there is no one in the occupancy. The policy should also show who is authorized to enter the facility. The server room should be at the center of the company, routers and switches which their protection should be maximized to avoid damage to the whole network. The surveillance should be made so that should someone make attempt at entering the server room, they are recorded. Another solution should be having automated logbook and have authentication system incorporated. A video to avail the surveillance scans. The scans should made a call notifications if any detected.

Protecting equipment

01 Marks

Learning Outcome(s):

LO 4: Write security policies and put in place an effective security architecture that comprises modern hardware and software technologies and protocols.

Q2) Give two examples for protecting the equipment in an organization.

The following are the ways in which the equipment can be protected in an organization. Lock the server room, the server rom should be guaranteed to be blocked. The major aim of the lock is to bar the people from entering the server room whenever the server room is unoccupied. A constant observation is a requirement for a server room. A log book will be required to have an entry to the server room. A video observation is very important element in ensuring that the people entering the rooms can be discovered easily.

Secure messaging

01 Marks

Learning Outcome(s):

LO 5: Use effective, proper and state of the art security tools and technologies

Q3) Email is the most preferred way of communication in many sectors currently. Apart from its advantages in communication, emails are also prone to cause various threats to the information technology framework. Explain in the various threats (at least 2) of emails being sent over the internet or a network, and the techniques (at least 2) to protect the messages sent over emails.

There are many threats that come with emails, one example is someone asking for an email, send to you in order to ascertain the original address. Most scammers do not care if they are swindling because what is required is your money. Another feature in the email box is the auto-download, the business purpose for the email addresses and the junk emails that populate email address. Junk email will help in protecting the person from the sample email. Another feature of emails is that they can be hacked. The messages sent via email should be encrypted for there are hackers who can participate in intercepting emails. One tool that could be used is windows Desktop Standard, the software is a paraphrase-based encryption. Hushmail can also be used in sending secure emails.

Log management

01 Marks

Learning Outcome(s):

LO 5: Use effective, proper and state of the art security tools and technologies

Q4) Describe the activities involved in log management. How to select the appropriate data to log.

The following activities would be used in managing the logs..

· Check the event logs

· Check for the Instant messaging, IRC and transaction logs to analyse

· Message Logs

· Evaluates the results of the latest risk assessments.

· Check for the transaction logs

The activities are important in understanding the system designs and devising the system architecture.