3Q.docx

3.1 Assignment: Devotional

1. Review the material in the Getting Started section, including the specific Bible passage.

2. Be sure to address to the following prompts in your paper:

a. How do you see this verse applying to the attackers’ attempts at social engineering?

b. How would you apply the principles of these verses in your workplace?

3. Your paper should be at least 250 words in length.

3.2 Discussion: Textbook Reading

Resources

· Textbook: Principles of Computer Security: CompTIA Security and Beyond

1. Read Chapters 9–13 in your textbook.

2. Using the discussion link below, respond to the following questions:

a. What was the most useful takeaway for you from this workshop’s reading?

b. What concept from the reading is the most applicable to you now in your profession, and how might you implement it?

3.3 Discussion: Protecting System Infrastructure

Resources

· Textbook: Principles of Computer Security: CompTIA Security and Beyond

1. Read Chapters 9–13 in your textbook.

2. Using the discussion link below, respond to the following prompts and questions:

a. Identify the security components necessary to protect the information systems infrastructure. What key hardware components should be implemented?

b. Why are authentication methods important in assuring that only authorized users are accessing the system? Classify the levels of access controls.

c. Explain the use of an intrusion detection system (IDSs). How does such a system identify an intrusion? Differentiate between network level and host-based IDSs.

3. Your initial post should be at least 300 words and supported with at least three references.

2.3 Discussion: Cryptographic Functions

Read and respond in at least 150 words to at least two of your classmates’ postings. Include citations to at least one credible information source in your replies.

Peer Review 1:

Classify the types of cryptographic methods that are currently in use and describe their functionality.

Cryptography is used to code messages such that no one can read it or make out any use full information out of it. They include encryption methods that are best suited for processing large data streams. Cryptography can be broken down into three different types:

· Secret Key Cryptography

· Public Key Cryptography

· Hash Functions

Secret key cryptography, or symmetric cryptography, uses a single key to encrypt data (both encryption and decryption). this is the easiest type.

Public key cryptography uses two keys to encrypt data. One is used for encryption, while the other key can decrypt the message.

Hash functions are irreversible, one-way functions which protect the data, at the cost of not being able to recover the original message

Examples of methods that use symmetric encryption include:

Advanced Encryption Standard (AES)

Data Encryption Standard (DES)

International Data Encryption Method (IDEA)

Camelia

Misty 1

Skipjack

Two Fish

Public Key Cryptography

ECC

Diffie-Hellman

DSS

 

Asymmetric cryptography (public key cryptography) encryption methods are best used for key exchange, user authentication and digital signatures. In public key cryptography a pair of keys is used to encrypt and decrypt a message so that it arrives securely.

Cryptographic methods that are currently used in most cases are the Triple Data Encryption Standards,  Twofish is another method that refers to a method of encryption. 

 

b. What function does PKI play in secure transactions? Discuss any issues with the use of PKI.

Public Key Infrastructure PKI is a system designed to manage the creation, distribution, identification, and revocation of public keys. The system consists of a set of entrusted user roles, policies, procedures, hardware and software. The core idea behind this system is to ensure that a public key is used only by its owner and no one else. Information can be encrypted and securely transmitted even without PKI, but in that case, there won’t be any method to ensure the identity of the sender. Additionally, it helps in ensuring that the individual systems exchange takes place over the networks which are potentially insecure (Epstein, 2016). It is useful, therefore, since it helps in authentication as well as verification of identity when communicating. Using KPI, however, has issues such as side key mishandling as well as the insufficient client.

 

c. Discuss why physical security is important. Select several physical security measures and provide reasoning for their implementation.

Physical security is basically the protection of personnel, hardware, software, networks and data from physical actions and events that could cause serious loss or damage to any organization. It does include protection from fire, flood, natural disasters, burglary, theft, vandalism, and terrorism.

Physical security ensures safety to prominent buildings, resources, equipment, information, personnel, and property also deny unlawful access to the commodity of public interest.

Some examples of physical security are, Locks. Walls, Doors, Chains, Bolts, Gates, Shutters, Padlocks, Alarm systems, Security camera’s, Vehicles, Vaults, Small arms, Bullet proof glass, Blast doors, there are many more that we can add to this list.

 Peer Review 2:

Types of Cryptographic methods:

Public key cryptography:  It involves the use of the two keys to ensure that information and data which is shared between the sender and receiver is secure. Public key encryption involves using a public key when encrypting information while the receiver decrypts it using the private key. Everyone who needs to decrypts distributed information should own a private key.

Key escrow Cryptography: key escrow cryptography encryption is strong, and decryption keys are split into different parts and are granted different authorities. For one to be able to decrypt data, he /she need all the decryption keys.

Symmetric key cryptography: This is cryptography in which the key used for encoding is supposed to match the key used for decoding. The person who encrypts information is supposed to share an encryption key to allow decryption of the information.

Translucent cryptography: The cryptography method in which the decryption key allows access to only a certain percentage of information. The encryption key cannot decrypt the remaining percentage of the information entered, ensuring the security of the information.

Public critical infrastructure ensures the security of electronic transactions by providing authentication of all communication that happens during electronic transfers. PKI ensures data integrity and ensures there is enough proof through digital signatures, for example, to enable transactions from taking place. PKI digital certificates, for example, public and private keys, ensures transaction security.

One of the issues with PKI is that once one gets the public key, he gets access to all the information which has been encrypted. There is a risk of the critical landing to an unintended person, making data insecure since it can facilitate all the transactions.

Physical security is essential as it helps in the protection of the assets which the organization owns. Having physical security protects unauthorized access to the assets which an organization owns.

Locking the servers’ room ensures that security servers and organizations are protected and are not interfered with by anyone.

Installation of CCTV surveillance: It helps to identify those who access the information room and cause a threat to the information security.

Backing-up information: It helps safeguard information from loss if the intruder tries to interfere with it.