Disaster Recovery and Business Continuity Plan
CMGT/400 Intro to Information Assurance & Security
Financial Service Security Engagement
The financial services company has just completed the migration of the Customer Relationship Management (CRM) System to the cloud platform environment. This move supports on-site investing and account management for our high net-worth customers. The business objective of and our decision to move the CRM application to the cloud environment is based on the need to generate more leads, increase sales while reducing the cost of sales, generate additional revenue, and improve relationships with our customers. With that in mind, the following Security Analysis will address security concerns regarding the integration of the new CRM System with current systems; including, the use of employee mobile devices in the workplace, physical and environmental security controls, and access management and identity policies. Comment by Author: Introduction is focused on requirements.
In a data center physical and environmental controls should be used to ensure security of IT and networks infrastructure. A data center is protected from internal and external threats by use of technologies. The physical and environmental controls will help to restrict and manage access to the system's infrastructure. Only people who are authorized will be able to have access to the IT systems and critical infrastructure. The security controls are to ensure that the security system is secured against the environmental and physical threats. Comment by Author: Sound approach. Remember geographic risks,
Physical Security
Video Surveillance
Closed-circuit television cameras (CCTVs) will be very useful in monitoring the entry and exit access points. The video surveillance will be used to record camera footage of all the activities at all the access points. All live recordings should be archived in the offsite storage area for future retrieval when needed. The CCTVs used should have full pan, zoom and tilt features to ensure high recording performance (Yau, & Cheng, 2014).
Secure Access Points
The most sensitive areas such as data floor are to be secured by several control systems. For example, a locked door and a mantrap to be used at the access points to prevent access to the data center by unauthorized visitors. The checkpoints can also be manned by security guards who should cross-check the visitors credential before allowing them to proceed to the next level.
All-Time Security
Security cameras, checkpoints and alarms should be used together with on-site security staffs to help relay better security in the data center. This will help to respond to illegal activities and potential threats on time. Routine patrols should also be conducted on the data center by the security personnel. In case any potential security threat is spotted on site then it will be dealing with on time.
Background Checks Comment by Author: Excellent consideration of personnel security.
Since many people are moving in and out of the data center then the background check is necessary. Staffs entering the data center include technicians and security staffs. A thorough background check should be done on the new employees to avoid allowing people with a bad reputation to access sensitive areas (Yau, & Cheng, 2014). Vetting should also be done on third party contractors. Only trustworthy people should be allowed to manage and access IT assets.
Exit Procedures
After staffs that are authorized to access data center leaves the organization then their accounts should be deleted or removed. This will prevent them from being able to access the organization's system in future. This should also apply to the contractors. Their biometric data should be deleted from the system to completely lock them out from accessing any information.
Multi-Factor Authentication Comment by Author: Excellent application of relevant technologies.
Installing a multi-factor authentication system will greatly help in controlling access to the data center. The multi-factor authentication system should be installed on the access points. A two or more authentication factor system will be used in the identification and authorization of system users.
Biometric Technology
Biometric technology is the latest innovation used in security standards. The technology uses the physical characteristics of human beings which are unique for identification. Some of the unique characteristics used in biometric access controls include voice pattern, thumbprint and retina shape. The technology is usually used in the two-factor authentication system.
Environmental Controls Comment by Author: Appropriate focus on environmental controls.
Heating, Ventilating, Air conditioning system
Environmental controls should be applied in the working environment to help make the place safe and friendly for employees. In the data center a system should be installed to help in heating, ventilation and air conditioning. The system will make the data center to have a constant temperature. Overheating is a common phenomenon data centers and may trigger a fire. The VAC system can be integrated with the fire system to help suppress fire in case of overheating (Hernández, et al., 2017).
Electromagnetic Interference (EMI) Shielding
Electromagnetic interference occurs in a situation where there are many computers put close to each other. The interference affects the performance of computers. Modern computers are shielded against electromagnetic interference by metal shielding on the cases. These metals should not be removed as they guard against radiated signals in the environment.
Hot and Cold Aisles
This refers to how the data centers have been designed and developed. The design involves the direction and the rack where the servers have been put. The racks should be made in such a way that there should be good aeration of air to help in cooling the servers. During system design, there should be both cold and hot aisles (Hernández, et al., 2017). Hot air is to be released freely into the environment while cool air is to be pulled in to the air condition system.
Cryptography and Public Key Infrastructure (PKI) Comment by Author: Applied PKI and encryption correctly.
Here are some recommended uses of the PKI that we suggest using to secure the system.
PKI certificates should be extended to the new system. These should also be stored on cards (CAC) for use in various other locations. This would allow positive control over not only network access but also use of facilities. An example of this would be CAC enabled printers. These not only allow you to authorize the release of printing documents, but allow the user more flexibility on where to send their scans.
Issued PKI certifications should also be used in securing tunnels and the user’s session. PKIs offer two major benefits traceability for the controlling authority, and the user’s traffic is encrypted. This allows for verification of work and service integrity.
This all leads to the main reason to implement this with the company switching to cloud based CRM verification of the information and encryption of the information is imperative. The main reason is since we will no longer have direct control over the data that is on the cloud, for both storage and processing.
To implement this we will need a certificate authority and an offline root certificate authority. After that we will want to separate the certificate authorities by region or major division of the company. This will prevent possible root authority compromise. The end idea is that we need to secure and guarantee nonrepudiation of a user’s actions on the network.
Mobile Device’s Security
Mobile device security is important in many ways to the company. Internal and external employees might be different in terms of what they do, but each have similar security risk. Either the type of device they will have is a bring your own device type or a company trusted device, each can be vulnerable to a cyber-attack. With bringing your own device more popular currently(Lord, 2018), it is a perfect situation to call out what challenges it may face. The threats like malware, phishing, spyware, spear phishing, trojans, and more can affect mobile devices just as much as computers. Comment by Author: Considered BYOD risks.
Internal or external employees can also share the same risk. Just because they might Knowing what to do to address these risks will reduce our minimize impact of an attack. Internal employee and external employees can be easily fooled by trojans, phishing and/or spear phishing techniques hackers use every day. To combat this, we must have a strong filtering tool of company emails and our business partner’s ways of contacting us to be thoroughly checked while bad traffic is sent before reaching the companies network. Also having audit logs so each mobile device can be tracked and recorded as well for any kind of suspicious activity as going to websites not permitted or using a large amount of bandwidth. Comment by Author: Good start on mobile device management (MDM)
Another thing to look at is the whole bring your own device marketecture. While bringing your own device is convenient and easy, the security issues with it are alarming. With BYOB being popular in a large amount of companies, it also has its issues such as not properly clearing data from devices when an employee leaves, employees using the device for other things than work, losing the device, etc., can all have repercussions against the company. To fix these issues, assuring that the company can remotely clear any data relating to the company when ever they want could reduce risk of the laptop being stolen or a disgruntled ex-employee giving information. Another way to stop from harmful devices entering is making sure each mobile device is running with a security scan such as an anti-virus that checks from the root of the mobile device to the whole operating system of malware. Comment by Author: ?? BYOD??
If BYOB is monitored and secure, mobile devices can thrive in the workplace just as much as desktop computers. Ensuring the IT manager and even the regular employee practices computer safety on their mobile devices can go a long way.
Backup Protection/Cloud Protection Comment by Author: Applied BCP/DR concepts!
Data backups are an integral part of the IT spectrum. Being able to retrieve and store data on an electronic device comes in handy. When accidents occur, often data gets lost, deleted or corrupted. Backing said data up prevents these permanent losses.
Data loss can occur for many different reasons. Many threats and vulnerabilities exist; many of which can be created by the own user. Deleting information, software failing or crashing, viruses, hardware theft, and pure accidents can affect data loss. In order to maintain secure backups, they need to be organized. Scheduling backups regularly is an example of how to ensure security when backing up data. Here are a few different steps to ensuring secure data recoveries:
· Use incremental and differential backups to reserve space and time as needed
· Use weekly backups especially on BYODs so that all important information is accessible
· Using advanced settings on each device to setup manual backups on things such as File History and saved personal information
· Use Cloud storage such as DropBox or OneDrive to store e-mails and passwords
· On Mac computers, complete backups through programs like Time Machine. Time Machine keeps hourly, daily and weekly backups as well as giving you the options which encrypted files are accessible
Bot Protection
Robot networks or botnets for short are a type of malware that attach themselves and infect networks of multiple computers and are typically controlled by an individual attacking party. Each computer system controlled by the single attacking party or bot-herder controls bots or each computer. Said controlled computer system can then commence organized attacks on other computers at the same time. Since most botnets are composed of millions of other bots, the bot-herder can orchestrate large scale attacks that weren't previously available by malware.
Botnets can also update their behaviors and maintain their threat level at will. Succinctly, bot-herders are also able to borrow parts of a botnet on the black market for quick and good money. The attack vectors for the botnets are: “
· Email spam– though email is seen today as an older vector for attack, spam botnets are some of the largest in size. They are primarily used for sending out spam messages, often including malware, in towering numbers from each bot. The Cutwail botnet for example, can send up to 74 billion messages per day. They are also used to spread bots to recruit more computers to the botnet.
· DDoS attacks– leverages the massive scale of the botnet to overload a target network or server with requests, rendering it inaccessible to its intended users. DDoS attacks target organizations for personal or political motives or to extort payment in exchange for ceasing the attack.
· Financial breach– includes botnets specifically designed for the direct theft of funds from enterprises and credit card information. Financial botnets, like the ZeuS botnet, have been responsible for attacks involving millions of dollars stolen directly from multiple enterprises over very short periods of time.
· Targeted intrusions– smaller botnets designed to compromise specific high-value systems of organizations from which attackers can penetrate and intrude further into the network. These intrusions are extremely dangerous to organizations as attackers specifically target their most valuable assets, including financial data, research and development, intellectual property, and customer information.” (1)
Dealing with botnets is a task that must be done properly and efficiently. If maintained with the right process, botnets can be destroyed. Three ways botnets can be detected and removed are:
1. Using network and host-based botnet detection programs. They won't find them all the time but they’re worth the try.
2. Making sure that the Anti-malware program being used can detect endpoint signs of infections and updated with the newest Command & Control data. Ensuring the obvious infections aren't neglected by the program.
3. Administering a honeypot server which is an illusioned computer system that’s used as hack trap in order to protect vital information.
IAM Access controls Comment by Author: Demonstrated understanding of IAM,
The task of developing Identity and Access Management controls and policies for both on-prem and cloud hosted applications can be a complex and difficult task. Each system may have its own requirements and intricacies. However, a general framework for effective security controls can be defined using standard security practices. IAM covers the creation and maintenance of user identities or user lifecycle, the granting and revocation of user rights and privileges, and eventually the deletion of the account. There are many different controls that be implemented to help secure access to both the on-prem environment and cloud hosted applications like a CRM such as Role-Based Access, AAA, Policy driven access controls, SSO, and MFA.
User Lifecycle
The user lifecycle starts when the new employee is entered into the HR system and is then populated in the Source of Record for identity provisioning. The Source of Record is the primary system where all user account information is stored, maintained, and modified for consumption by other systems on and off the network. The system administration team usually manages this system and processes requests for account creation, modification, and deletion. They will have their own change management controls in place to verify requests and validate that the requests have been completed. The user account will go through changes that need to be tracked such as when an employee changes roles within the company, goes on leave, and when they leave the company and are no longer employed there.
Role-Based Access Control (RBAC)
Role-based access control is the security concept of defining what access rights and privileges a particular job role requires and assigning those rights to the users in that role. According to Rouse, “RBAC lets employees have access rights only to the information they need to do their jobs and prevents them from accessing information that doesn't pertain to them.” In terms of how this applies to our scenario, a general user may be able to look up accounts in the CRM and add notes to accounts that they own however they would not be able to delete accounts or view financial data for customers. Where a financial analyst would be able to see and edit the secured financial data but not be able to edit the sales notes.
AAA
The acronym AAA stands for Authentication, Authorization, and Accounting. This applies to the access controls for both internal and external resources. The first part, Authentication, is the process by which users identify themselves to the system. This is typically done with username and password, but as modern security requirements improve, this can also be done with smart cards, biometrics, One-Time Passcodes, or a combination thereof. Authorization is the process by which the system defines what rights the user has on the system they are authenticating to. In older systems this typically done by group membership and newer systems this could be done by attributes assigned to the user or the system they are accessing. Accounting in IT terms is the audit trail of activity performed by a user from the time they log in to the time they log out. The use of a AAA system to control access on the network is critical to improving security and providing logs of each access attempt and the commands entered by a user. Comment by Author: Assignment considers audit but think about CRM audit in a cloud environment,. Remember standards such as ISO27001. The shift to the cloud poses challenges for managing security and for conducting audits. According to Ryoo, Rizor, Aiken, and Kissell (2015), cloud security auditing requires changes from pre-cloud IT security auditing practices. Cloud security auditing standards are evolving. In the past audit was separated into internal and external views but the cloud complicates and blurs this view. Check out the following article for insight into auditing in the cloud environment. Reference Ryoo, J. Rizor, S., Aiken, W. & Kissell, J. (2015, March 8). Cloud Security Auditing: Challenges and Emerging Approaches. InfoQ. Retrieved from Cloud Security Audit
Policy driven access controls
There are ways to define specific policies for being able to access the protected application. There are a number of policy controls that can be implemented such as geolocation, time of day, which network a user is coming from, if they are using a personal device or a corporate owned one. These policy controls can limit the field from which an attacker can try to attack from. By excluding specific geographic locations from access, you can, to a degree, limit access to only the countries that the company has employees in. By limiting access based on known network ranges you can ensure that a user is either at their desk or securely connected to the corporate network through a VPN connection. There are also ways to determine if the device being used to access the protected resource if corporate owned and managed or a personal device. This is typically done with MDM software or a device-based certificate only issued to corp owned devices. Blocking access based on the absence of the MDM software or device-based certificate can severely narrow the number of devices capable of being used for access. Comment by Author: Yes!
SSO
SSO or Single Sign-on, is a way to provide access to many different applications and resources using a single identity. Strong IAM offerings will generally include a heavily featured SSO platform. This makes it easier to manage a user’s access rights from a single source of record for user identities. Implementing SSO also has the drawback, that if a user’s password and account information is compromised, an attacker has full access to the network with a single credential. If
MFA
There are three different things that can be used to authenticate a user. Something you know such as a password, something you have such as a smartcard, and something you are such a fingerprint. Multi-factor authentication, or MFA, occurs when you require more than one of those three things to securely verify the identity of a user. The use of MFA is required by many different authoritative audit and compliance security frameworks such as PCI-DSS, HIPPA, DFARS, NIST, NERC, EPCS, and many more. It is increasingly becoming standard practice to use MFA even outside the confines of IT security such as with customer facing access to websites and services like social media and mobile banking. The inclusion of MFA as part of the access requirements for both internal and external resources is one step on the path to a full zero trust implementation and a part on any solid IAM plan.
References
Rouse, M. (n.d.). role-based access control (RBAC). Retrieved from https://searchsecurity.techtarget.com/definition/role-based-access-control-RBAC
Hernández, L., Calderon, Y., Martinez, H., Pranolo, A., & Riyanto, I. (2017, October). Design of a system for detection of environmental variables applied in data centers. In 2017 3rd International Conference on Science in Information Technology (ICSITech) (pp. 389-395). IEEE.
Yau, H. K., & Cheng, A. L. F. (2014). Improving the Physical and Environmental Security of a Data Centre: Case Study of a Hong Kong Wines and Spirits Distribution Company. In Proceedings of the International MultiConference of Engineers and Computer Scientists (Vol. 2).
(1) What is a Botnet?(). Retrieved from https://www.paloaltonetworks.com/cyberpedia/what-is-botnet
(2) Gross, G. (2015). Botnet Detection and Removal: Methods & Best Practices. Retrieved from https://www.alienvault.com/blogs/security-essentials/botnet-detection-and-removal-methods-best-practices
Lord, N. (2018) THE ULTIMATE GUIDE TO BYOD SECURITY: OVERCOMING CHALLENGES, CREATING EFFECTIVE POLICIES, AND MITIGATING RISKS TO MAXIMIZE BENEFITS Retrieved from : https://digitalguardian.com/blog/ultimate-guide-byod-security-overcoming-challenges-creating-effective-policies-and-mitigating Comment by Author: One reference included and used in text., Add at least one more professional reference to meet research depth requirement. See grading rubric on the next page.
CMGT 400 Grading Rubric Learning Team – Week 2 Financial Service Security Engagement |
|||
|
|
MEETS CRITERIA? |
||
|
Week 2 Financial Service Security Engagement |
PTs |
Grade |
COMMENTS |
|
Content (75.0 points) |
|
|
|
|
Your Learning Team is a cybersecurity engineering team for a financial services company that sells investments to, and manages investment portfolios for, high net-worth individuals.
|
|
|
|
|
Your organization just completed the migration of the account managers to a cloud-based, customer relationship management (CRM) software application. Your organization has integrated the cloud-based CRM with on-site investing and account management systems to improve the sales of investment products to customers and potential customers and for managing customer accounts and investment portfolios. The Chief Information Security Officer (CISO) of your organization is concerned about the security of this new system and its integration to existing systems and has requested that your team complete the following 6- to 8-page security analysis:
Create a plan that addresses the secure use of mobile devices by internal employees and external employees as they use mobile devices to access these applications. (15pt) Recommend physical security and environmental controls to protect the data center which runs the on-site applications. (15pt) Propose audit assessment and processes that will be used to ensure that the cloud-based CRM software provider uses appropriate physical security and environmental controls to protect their data centers which run your cloud-based CRM software. (15pt) Develop identity and access management policies for both the on-site systems and the cloud-based CRM. (15pt) Recommend cryptography and public key infrastructure (PKI) uses which could be used to increase security for these systems. (15pt) |
75.0 |
73 |
Learning team assignment met most requirements. The team developed a comprehensive plan to address the secure use of mobile devices by internal employees and external employees. Applied the mobile device management (MDM) concept and considered BYOD risks. Consider the role of risk assessment when developing security plans. The team made valid recommendations for physical security and environmental controls. Included several aspect of audit but think a little more about audit in a cloud environment. Applied appropriate controls for data center security were included. The team demonstrated understanding of identity and access management policies for on-site and cloud-based systems. Cryptography and PKI were included. The team included appropriate rationale to justify recommendations. |
|
|
73 out of 75.0 |
||
|
Research |
|
|
|
|
Assignment has research depth including at least two outside relevant peer reviewed references from course material and/or the library. |
7 |
4 |
The assignment content demonstrated your team did research. Include at least two references to meet research depth requirement. One reference included and used in text., Add at least one more professional reference to meet research depth requirement.
|
|
Organization |
|
|
|
|
Assignment is organized appropriately covering all required topics in a logical sequence. Title, introduction, body, conclusion and references are included in required sequence. |
4 |
4 |
Assignment is organized, flowed logically covering all required topics. Assignment is structured to meet most APA requirements. Add section header for reference section
|
|
Mechanics, Quality and APA: |
|
|
|
|
Assignment projects professional, quality image, meets academic integrity requirements. Meets APA format. Include title page and reference section. References in APA format. No spelling errors - the paper has obviously been proofread. Title and reference pages do not count toward the length requirement. |
4 |
4 |
Met most APA. Included the names or participating team members on the title page. Included a reference section. Assignment has in text reference to support APA and academic integrity requirements. Add section header for reference section |
|
TOTAL POINTS FOR RESEARCH, ORGANIZATION, QUALITY, AND APA REQUIREMENTS |
12 out of 15 |
||
|
|
|||
|
TOTAL POINTS |
(85 out of 90 possible points) 04-29-19 rpg |