PACS 5

profileHansbke17
CaseStudyGAPAnalysis.docx

Case Study GAP Analysis

Kenneth Hansberry

University of Maryland University College

Professor: Kenice Middleton

November 3, 2017

Risks that the bank system is most vulnerable to and that might be easily exploitable to overcome the system are as follows:

1. The use of an outdated system as well as an outdated DRBCP that were last updated in 2009

2. An insecure system vulnerable to exploits last tested in 2010

3. A backup of the systems Disaster Recovery and continuity policy is stored on the same system.

4. The admin has write access to the event logs in the system

5. Failure to identify issues as they arise for example the reason for failed backups

6. Physical backups are stored in the same geographic locality with the main system

7. No encryption of data and screenshots of the configurations are carelessly handled

8. Some of the key personnel have not been trained on which actions to toke in accordance to the DRBCP

The following list identifies the solutions that could be implemented to mitigate or prevent all of the exploitable risks or issues that have been identified above.

1. Acquire an already updated system from the software vendor or update the system with the latest upgrades.

2. Test the current system for vulnerabilities after updating it to ensure that no backdoors or exploitable threats that the system is vulnerable to.

3. Deny the power users full control and ownership rights on the system.

4. Create a secure cloud or offsite backup that ensure all of the data from all of the data centers the bank owns is secured from all form of risks.

5. Identify the reasons why a scheduled automatic backup failed.

6. Advice the staff within the company to refrain from storing the financial data back up in their personal residential. This prevents hostage situations in case a physical attack is conducted on the bank and its employees.

7. Encrypt the data as well as the transmission of the data from every item processing facility to the data centers.

8. Train the personnel to be able to handle disasters according to the DRBCP

Each of the proposed solutions mentioned above serves a purpose to the overall security of the financial institution. The institution is at a risk of various cyber security threats since it is connected to the internet. Without the proper handling of these threats, the system and data within the bank may be at a risk of theft, destruction or being lost forever.

1. An outdated system last updated in 2009 according to the Disaster Recovery Backup and business continuity policy. The use of an old system ensures that the same DRBC policy is still applicable. Upgrading the system by applying updates not only improves the security of the system but also ensures that the new system runs more efficiently and able to perform better than the previous system ("10 reasons to upgrade your office systems | Avopress", 2017). This will also realize the development of a new DRBC policy in the company

2. An insecure system vulnerable to exploits last tested in 2010 as defined by the DRBC policy. The disaster recovery and business continuity policy should be regularly tested in order to identify any flaws that might exist in the current policy. In cases where the policy has not been revised to meet or cover all of the new technology implemented, then the business might suffer from loss of data or other valuable information in case of a security breach into the institution

3. A backup of the DRBCP is stored on the same network as reported by Douglas. This is a classical error as described in the study. Should the attackers invading or over run the security of the system, they should not have any clue or details of how the company is going to protect itself from loss of business or other risks that are brought by the attack. Once they have this information the financial institution will face difficulties trying to recover to their normal business policy.

4. The power user has write access to the event logs in the system. The system’s power users should not have ownership writes over the system as this gives them the permission and access to view event logs as well as modify their contents. Ownership right give the user total or full control over the system (Bernstein-Sierra & Kezar, n.d.). This means that power users can view and delete the system logs after the implementation of any privileged activities.

5. Identify the reasons why a scheduled automatic backup failed and educate the information Technology officer of the necessity and need for ensuring a regularly back up of the system is made regularly (Drake, 2017).

6. Advice the staff within the company to refrain from storing the financial data back up in their personal residential. This prevents hostage situations in case a physical attack is conducted on the bank and its employees.

7. The bank can ensure that all of their data on their database and also on the backup drives is securely encrypted using cryptographic technology. The bank should also ensure that all the transmission of data from every item processing facility to the data centers is also encrypted using SSL encryption (Chernin, Guerrino & Nelson, 2016). SSL encryption ensure that there is end to end encryption from the item processing facility to the data center.

8. Develop a training program that ensures that all of the personnel working in various branches of the financial institution are trained (Truitt, 2011). Training the personnel to be able to handle disasters according to the DRBCP ensures that the business is best capable of implementing its own recoverability program because everyone is knowledgeable of the policy.

Issue NO.

Estimated time

Recommended strategy

1. An outdated system last updated in 2009

12 – 24 hrs

Upgrade the system

2. An insecure system vulnerable to exploits last tested in 2010

12 – 24 hrs

Test the system regularly

3. A backup of the system’s DRBCP is stored on the same network

2 – 6 hrs

Encrypt the folder or documents that contain all of the data about disaster recovery and continuity policy of the company. This will help in securing that information from unauthorized access.

4. The admin has write access to the event logs in the system

1 – 2 hrs

Generate a new user who will have full control on the system.

This includes access to the event logs.

5. Identify the reasons why a scheduled automatic backup failed.

24 hrs – 1 week

The IT officer should ensure that a backup has completed since the backup is used to restore the system in case of any issues in the system. In cases where the backup never completed, the IT department is responsible for resolving the issue.

6. Configuration data handled carelessly

12 – 24 hrs

With the use of an encryption software, all of the data including the configurations and screenshots of the system are meant to be encrypted to ensure confidentiality of the information

7. Untrained personnel

3 – 6 days

This can only be resolved when the business develops a

Recommendation

Advanced information systems are needed to ensure the rapid, accurate exchange of vital information related to the banking industry. To provide a safe operating environment for these systems, upgrades are required to enable the system to fully prevent exploitable vulnerabilities from manifesting and endangering the business operations.

References

Chernin, M. A., Clancy, M., Eiken, D., Guerrino, E., & Nelson, W. (2016). U.S. Patent Application No. 15/098,977.

Drake, J. Data Backup and Recovery Options.

Damiani, E., Di Vimercati, S., Foresti, S., Jajodia, S., Paraboschi, S., & Samarati, P. (2005, November). Key management for multi-user encrypted databases. In Proceedings of the 2005 ACM workshop on Storage security and survivability (pp. 74-83). ACM.

Truitt, D. L. (2011). The effect of training and development on employee attitude as it relates to training and work proficiency. Sage Open, 1(3), 2158244011433338.

10 reasons to upgrade your office systems | Avopress. (2017). Avopress.com. Retrieved 25 October 2017, from http://www.avopress.com/blog/2014/10-reasons-upgrade-your-office-systems

Bernstein-Sierra, S., & Kezar, A. Intellectual property, faculty rights and the public good.

Zhou, Y., Brumbaugh, L., Yurcik, B., Samarati, P., & Atluri, V. (2005). Proceedings of the 2005 ACM workshop on Storage security and survivability. New York, N.Y.: Association for Computing Machinery.

Copyright © 2015 by University of Maryland University College. All rights reserved.