M4 Assignment 2 Capstone
Running head: INFORMATION SECURITY 1
INFORMATION SECURITY 6
Information Security
Trevor Henry
Argosy University
11/22/17
Over the past century there has been a rise in technology use in many organizations. With the major upgrade and changes in technology, many organizations have resulted in the integration of normal business process to technology solutions. The change has positively impacted many institutions such as banks, hospitals and industries. Due to these changes in normal operations, there has been an increase in efficiency, in service delivery and increased profit margins. These system solutions are used to automate many processes that were initially time consuming and repetitive. They have also made their business operations to be available over the internet and through cloud technology solutions, business and work are possible from different locations over the world. Also, they have made complex network connections over the world to the various business partners and clients making their accessibility to be effective and consistent (Kostopoulos 2013).
Through technology implementations, a lot of the organization's assets are made available accessible from different locations, either internally or externally. This advancement in technology has resulted to the to the growth of the economy as more and more businesses are improving their productivity levels and efficiency resulting in the high profits. When these businesses are succeeding, they also impact the economy positively and more development for the society.
However, with these advancements, it is important to note that there are many security threats that are associated with the use of this technology. These results to the questioning of whether the advancements and implementation of such technology result to more exposure to the security threats or not? The huge advancements and use of the technology systems to be the core of the business processes can heavily impact these business threats which would otherwise not be possible to be executed if these systems were not put in place (Subramanian 2008).
The more the technology systems are implemented, the more the risk to be attacked and hacked is increased. This is because the malicious attackers can able to use advanced hacking techniques which can take advantage of the new systems which are implemented in the business environments. Some of these threats are not identified during the production and testing phase of these systems. They are commonly referred to as zero-day threats where the malicious attackers can exploit previously unidentified threats to carry out their malicious attacks.
Do these technology systems increase the attack surface for attack? The technology systems are always being improved and integrated with other systems that are already in use to carry out the business processes. However, when these technology systems are used and combined with the other technology systems already put in place, they increase the attack surface which is identified by the malicious attackers to attack the systems. At the same time, an attack on one system in place can be used to advance more attacks to the other systems that are integrated with the systems to cause more damage.
The more the technology systems are implemented, the more the attack surface is increased. With a big attack surface, the attackers cannot lack a vulnerability in one of these systems. This is because they can use very sophisticated software scanners that can automate the vulnerability identification process. These scanners are developed to identify more than one vulnerability in the systems using different plugins and scripts which are reported by the same software in order of their severity. This information can be very important for the internal audit teams that can use this information to fix some of the issues that they identify with these systems.
Further, can this technology be fully secure when they are implemented together with security systems? Can the security systems be a solution for the security attacks? Can the security systems be a 100% proof for the technology systems used in the businesses? It has been identified that the security companies have developed security solutions aimed at protecting the business assets. However, these security systems can be very expensive to implement. They are also very complex and require that they are managed and installed by well-trained security experts that have experience with the security systems. Some of this security software have been identified to be effective solutions and have reduced the security threats by a huge percent.
The security software can be active scanners that are installed on the networks to identify any malicious behaviour of files that are shared over the networks. The security software can scan for vulnerabilities in the same level as the software used by the malicious attackers. This software can identify vulnerabilities on the business infrastructure. They provide crucial information for the internal security teams that can fix these security threats before they can be manipulated and attacked by the malicious attackers. However, these security solutions are not able to offer full protection to the whole infrastructure. Therefore, there is still a chance of malicious attackers finding and exploiting the loopholes that these security solutions are unable to fix or identify (Kadrich 2007).
In conclusion, securing the technology systems becomes a great challenge that can be fully fixed at one specific time. Security of the systems should be a continuous process to keep identifying and updating the systems to fix these security threats once and as they are identified. It also requires having a vigilant security team that can carry out research on modern attack vectors and exploit that is being developed by the malicious attackers. They should be able to be ready to respond to any security attacks that are bound to face the systems. They should also have backup mechanisms to ensure that the business solutions have alternative solutions to ensure that they continue to operate even in the case that there are security attacks.
References
Kadrich, M. (2007). Endpoint security. Indianapolis: Addison Wesley Professional.
Kostopoulos, G. (2013). Cyberspace and cybersecurity. Boca Raton, Fl: CRC Press.
Subramanian, R. (2008). Computer security, privacy, and politics: current issues, challenges and solutions. Hershey PA: IRM Press.