Step 15 Plan for the IRP Implementation
Mobile device management policy
Urie L. Reed
Itemize Critical Infrastructure Concerns
Dr. Roger Ward
CMP 640 Cyber Security Program Development
University of Maryland Global Campus
Mobile device management policy
Introduction
The policy will provide rules and regulations on how mobile devices are being used in the company in a secure manner that does not offer a threat to the performance and reputation of the organization (International law and cybersecurity background, 2017). When the guidelines are not put in place to protect the usage of mobile devices such as mobile phones and tablets that are connected to the operations of the company, then the company is at the risk of cyber security threat because hackers are always ready to steal confidential information of the company which might damage the reputation of the company to the public. The mobile devices policies will cover tablets, mobile phones, computers, notebooks, and laptops. The main aim of mobile devices management policy (MDM) is to control cyber security thefts by securing the usage of mobile devices within the company.
Scope of the policy
The formulation of the policy will entail the establishment of procedures, protocols, and guidelines that define the usage of mobile devices within the company and their connectivity to the internet while dealing with information related to the company's operations. It will start by assessing the current gaps in the existing policies and possible upcoming threats common in financial industries that need to be protected by the MDM.
Critical infrastructure that needs the maximum attention
The hardware and software used by the organization in the storage of data need to be protected in a way that makes it hard for hackers to access and steal confidential information. When a cyber-attack happens, it can result in loss of files sired in the hard drives of mobile devices, complete damage of the devices, and manipulation of the software installed in the mobile devices. Patriot Act of 2001 provided guidelines that required the critical infrastructure of banking and finance services to be protected in a way that makes it had for hackers to access the stored data considering the confidentiality of the user’s information.
Examples of infrastructure cyber-attacks that need to be monitored by all the employees using the mobile devices to perform duties and responsibilities assigned by the company include the Stuxnet computer virus. Stuxnet computer virus is a dangerous computer virus that needs to be controlled totally because of the negative impacts on the system. An example of the Stuxnet computer virus is what affected the nuclear strategy of Iran, which damaged the nuclear program completely. This virus has been modified and can attack organizations from different industries; therefore, more hackers are interested in attacking to get confidential information as a financial organization.
The other cyber-attack is Phishing, where the attackers send an email that looks like a legitimate email to access the username and password. When the user accepts and opens the email, it can result in data loss and damage to the hardware of the laptops or computers where the data is stored. Therefore, it is essential to come up with proper procedures and guidelines that will ensure that all users within the company behave responsibly by not opening or answering phishing emails because it risks the organization when hackers take that opportunity to access client’s information such as bank details, credit card details and home address.
SQL Injections is another attack that hackers can use to access the network infrastructure owned by the company. SQL Injections it's an online attack that an attacker uses to interfere with queries and applications of the databases owned by the target host. A successful attack by SQL Injections can read all the confidential information stored in the database, modify them, and run daily administrative duties that were previously assigned to the host users. Therefore, when SQL Injections are not prevented, it affects the operation of the organization negatively.
Cross-site Scripting is another strategy the attacker uses to access the information stored and shared by the company through the network. Cross-site Scripting creates vulnerability in the organization's network system by injecting client-side scripts into web pages viewed by other users. Therefore, it results in the leaking of confidential information of the company and its clients to the public to damage the organization's reputation.
Defense principle to prevent identified cyber security threats
Phishing
All staff working within the institution and are using mobile devices to send or receive information by the use of the internet are required to be causations when replying to the emails. Then need to verify the source of the email first before making any attempt to responding to the email (Aravindhan, Shanmugalakshmi, Ramya, & Selvan 2016). When the information is coming from seniors within the institution, it is essential to call and verify if they are the original sender of the information before opening and replying.
Sometimes attackers use the Phishing technique to pretend to send emails that seem legitimate emails requesting confidential information such as the username and password. When such a request is granted before the user confirms the email's legitimacy, it will be too late to prevent the damage. Therefore, it is supposed to be a requirement that whenever sensitive information is requested, the receiver of the email confirms it first before opening the email (Shashidhar, 2017).
All the staffs need to have periodic training where they are trained on how a Phishing scam looks like so that when it happens, they can detect and don't into victims. Through the training, it is essential to train the staff to avoid clinking on suspicious emails to ensure that hackers don't get access to the information through the link they provided.
Mobile device users within the organization should not be attempted by tempted by those pop-ups. They usually arise when someone is on the network performing daily activities, and they appear as an exciting advertisement. By any chance, when the user is tempted to open it gives the hackers direct access to the system. Therefore, any pop-ups, despite how attractive they are, should not be opened with the devices connected to the institution's operations.
Cross-site Scripting
To prevent Cross-site Scripting, it is a requirement for all mobile devices being used by the staff within the institution to share the company's information to install firewalls (Gupta, & Chaudhary, 2020). Firewalls shield the computer system from external attackers. It works by blocking malicious filers from being opened by the system of the organization. Additionally, it also helps in regulating unnecessary traffic that hackers can use to access the system. Firewalls also help prevent malicious software from being installed in the system, which acts as one way of raising red flags about the software and gives the monitoring and evaluation team the time to come up with better alternative ways of protecting the system.
Any information about the company and account information should not be shared by any outside website, even if they transact with the organization as third parties. The sharing of such information on other websites is unsecure because the data security measures of the other sites are hard to control. Therefore, sensitive information about the institution's accounts is not supposed to be shared through the network but instead use physical means of exchanging such sensitive information.
SQL Injections
To control the SQL injections, it is recommended that all software that the mobile devices are running are updated because updated software has advanced security measures. The second measure to be implemented is to block URLs at Web Server Level so that they cannot access the information stored in the system after gaining access to the system (Pollack, 2018). There is also the need for Securing the Database and Privileges, which restrict individuals who can access the information stored in the organization's network system. By limiting the number of access to the information stored in the system helps in minimizing the probability of hacking because data will not be exposed to many individuals.
Cybersecurity policy framework
The main objective of the Cybersecurity policy framework is to guide policy-makers within the organization to aid in the development of cyber security regulations to protect the system of the organization from hacking activities.
The setting of password requirement
All mobile devices need a strong password that contains a mixture of alphabetical letters, symbols, numerical and punctuation marks.
Passwords need to be stored in safe places where no one can access them. Storing of passwords on the internet browsers should be discouraged, and no password or security key codes of the institution ensure that third parties do not have to access passwords and usernames that can be used to grant them unauthorized access into the system of the organization.
Passwords should be updated after every month to ensure the security of the passwords used by the organization and the usernames. When the password is maintained for a longer time, it can be used by ex-employees of the organization to access the system, and it becomes a threat to the organization.
When opening different accounts for the institution dealing with other services and customers served by the organization, each account should have unique passwords only to allow individuals permitted to access the information to have the opportunity of accessing the report by the use of password requirement.
The passwords for the organization and update will be controlled by the chief information officer, who will be responsible for generating unique passwords and assign to different users depending on their responsibilities.
Handling of sensitive data managed by the organization
Data will be categorized into groups based on the nature of sensitivity. Information obtaining that password and user names of the company should be considered sensitive information. Additionally, information about the bank details and credit card information of the customers should be treated as confidential information protected at all costs.
The sharing of confidential information of the company within the staff should be performed under the authorization of the chief information officer. When the data is shared through the internet, it should be encrypted to ensure that it is not accessed and modified before reaching the final receiver.
Physical placers for the storage of data where the databases are located, there is a need to place physical security and minimize the movement of people in such locations so that the probability of data theft can be minimized. Physical data protection on top of network protection is essential because hard drives are also used to store data, and hackers can still target hard drives to access sensitive information.
Confidential information that the organization no longer needs should be taken by the quality assurance team in supervision of the chief information officer and destroyed by burning to ensure that no data remains behind. In the case of hard drives used for storage, all the data have to be erased before physical destruction of the hardware so that there is no chance for the risk of such information landing in the hand of hackers.
The standard for accessing social media accounts
The information of the businesses shared on social media should be regulated and ensure that no organization's sensitive information is shared on the social media accounts.
When dealing with the company's official email, staff are only required to sign to the business's social media accounts and not mix with personal social media account.
Websites and social media accounts shared by the public and lack cybersecurity measures to assure users of the security of the data they share should be avoided.
Rules for connecting mobile devices on the internet
The location from which the employee can access the company's account using mobile devices should be from the registered location. Any attempt outside the registered place should be treated as a threat, and control measures are taken immediately.
In case the mobile device connected to the organization's accounts should be reported immediately to the chief information officer so that the accounts logged in should be logged off before the damage happens.
When the mobile devices are not in use, they should be stored in the organization's offices for respective departments. Individual use of mobile devices of the company should be avoided. The shutting down of computers connected to the organization's accounts should be managed by a monitoring officer who is answerable to the chief information officer.
Data stored in the devices should be protected through double protection mechanism. Apart from username and password, USB data protection should be added as the second security protection measure in case hackers bypass the first protection. There's still the double protection.
Preparation of the incident
It is hard to protect all the risks with certainty. Therefore, the organization needs to be ready in case a cybersecurity threat happens. Any cyber security incident should respond to with immediate effect to avoid the damage and restore the situation as early as possible. Employees should be trained on different cybersecurity threats and possible control measures to be updated and ready if the incident happens—everyone at the organization to have specific roles and responsibilities toward protecting the system of the organization.
Crucial Concerns Worksheet
|
Cybersecurity threats |
Impact on Critical infrastructure |
Control measure |
|
Phishing |
· Steaking of sensitive information stored in hard drives and networks. · Damage of mobile devices hardware. · They are stealing usernames and passwords, resulting in modification of the stored data. |
· Avoiding replies to suspicious emails. · Voiding to open pop-ups that appear when one is browsing through the internet. · Periodic training of the staff on cyber security protection measures. · Protection of passwords and usernames by not sharing online. |
|
Stuxnet computer virus |
· Damage to the software and hardware of mobile devices. · Destruction of stored files in the system. |
· Updating the operating systems to ensure security measures are updated. · Avoiding suspicious websites and only dealing with legit websites. |
|
Cross-site Scripting |
Leaking of confidential information to public websites. Manipulation of the stored data |
· Installation and updating of Firewalls · Use of updated software · Avoid sharing passwords and usernames for the account of the company to an external website. |
|
SQL Injections |
· Results in malfunctioning of the software and hardware of the mobile devices. · Corrupts files resulting in loss of data. |
· Providing security for the database and granting access privileges. · Blocking suspicious URLs at the Web server level. · Updating all software that runs on the mobile device used by the staff within the organization. |
References
Aravindhan, R., Shanmugalakshmi, R., Ramya, K., & Selvan C. (2016). Specific investigation on web application security: Phishing detection and phishing target discovery. 2016 3rd International Conference on Advanced Computing and Communication Systems (ICACCS). https://doi.org/10.1109/icaccs.2016.7586405
Gupta, B. B., & Chaudhary, P. (2020). Fundamentals of cross-site scripting (XSS) attack. Cross-Site Scripting Attacks, 53-74. https://doi.org/10.1201/9780429351327-3
International law and cybersecurity background. (2017). Cybersecurity, 55-69. https://doi.org/10.1201/9781315370231-4
Pollack, E. (2018). Protecting against SQL injection. Dynamic SQL, 31-60. https://doi.org/10.1007/978-1-4842-4318-3_2
Shashidhar, S. K. (2017). Spear phishing - The new face of Phishing. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.2905041