For This Portion Of The Assignment You Are To Select A Topic Related To This Course, Cryptography. For The Research Paper You Are To Do A Minimal Of 10 Pages, With A Minimal Of 5 Sources. The Paper Needs To Be In APA Format.

profileAnveshh
CRPYTOGRAPHYINCYBERSECURITYANDPOLICIES1.docx

1

Running Head: CRPYTOGRAPHY IN CYBERSECURITY AND POLICIES

14

CRPYTOGRAPHY IN CYBERSECURITY AND POLICIES

CRPYTOGRAPHY IN CYBERSECURITY AND POLICIES

Name: Anvesh Gourishetty

Institution: University of Cumberlands

Introduction

Cyber security is one of the imperative measures that have been undertaken to reduce the rampant occurrences of cyber-attacks in the world today. It has been technically related to the cryptography in the internet use of the operators. Linking the cryptography with the cyber security involves conducting secure communications within any given business organization with the presence of the third party or adversaries into the respective organization. From the basis of cryptography, it is evident that education, technology as well as security policies are an incredible concept within the incorporation of cryptography into the cyber security. It is education that will teach the employees communication techniques within the business from various mathematical concepts as well as a set of rule-based calculations which may be improvised through technology advancement and implemented via security policies into the organization.

This explains the considerate measures cryptography has made towards cyber security. There is therefore a need to evaluate the three thematic concepts which have been initiated by cryptographic knowledge into the cyber security. There are various measures the cybers security companies as well as the respective business organizations in conjunction with their respective government agencies have implemented to ensuring that the war in cyber-attacks have come into a ceasing end. Nevertheless, the fight against cyber-attacks while utilizing cyber security intel have to been a successful without an entire and ultimate incorporation of the various parameters that govern cyber security into the system.

Such parameters are such a paramount criterion in that their existence within the cyber field is of great presence both to the business organizations as well as the cyber security agencies. Amongst the parameters include the three core themes that significantly help mitigate the rampant wars on computer attacks (Braman, Susmann&Vaseashta, 2014). They essentially include education, technology as well as security policies within the information system of any given or particular business organization. Their incorporation into the cyber security have yielded desirable fruits to lessening the cyber-attacks being experienced throughout the entire world.

The role of education in the cyber security is of paramount concern in acquiring knowledge as well as required skills concerning the mannerisms or even mechanisms in which to curb the cyber-attacks that hit almost every organization in the world today. In fact, more than 82% of the business organizations have been hit by cyber-attacks in Europe according to the recent cyber attacks’ statistics released. It has been reported that approximately 52% of such attacks have been caused by lack of proper knowledge as well as skills of the respective employees within the respective business organizations (Braman, Susmann&Vaseashta, 2014). The role of education in the cyber security is a thematic concern that need to be deeply navigated and explored so as to influence most of the business organization into adapting it.

Role of Education in the Cyber Security

This assessment will evidently justify and exhibit the role of education in the cyber security. It will make efforts to attempt and prove why education in cyber security is a paramount essential that need to be considered in every business organization that have unending zeal to succeed within its information technology sector without any potential cyber-attacks. In addition to the above mentioned, the assessment will also facilitate on the need of education for the respective business organizations to be prosperous despite their geographical location (Dawson, 2017). As well, it will examine external as well as internal conditions of a business organization that help create a conducive workplace environment for all workers. In pertinence with the cyber security, education will also essentially navigate on how it may address issues regarding the utilization of cyber security.

Education in cyber security exclusively begins with the personal education within the cyber security. Generally, self-education concerning the cyber security cannot be stressful enough to shun away from cyber education. This self-education helps the individual to acquire more skills as well as knowledge and the ultimate comprehension about the respective subject under cyber security (Mary, 2017). This significantly improves the opportunities of the respective individual educating themselves on protection against cyber-attacks. Essentially, the cyber IQ of an individual is of significant use towards safety as well as privacy while utilizing internet may either be public or that belonging to a specific business organization. Despite the fact that the individual ought to utilize the internet security software, it is vitally evident that such a security software may not protect them 100% from potential threats in the landscape.

The role of education in the cyber security is of great significance as it helps the workers of the respective business organization to become elite of using strong business and secure passwords. It is the role of education in the cyber security to teach the employees that the antivirus they utilize in their respective computer systems of the business organization may fail to protect the accounts which operate online (Kshetri, 2013). This circumstance literally implies that they need to be the first to defend against any security break through that may be experienced in the business organization. They can achieve through cryptographic hidden information of the business. Therefore, they ought to ensure that the computer passwords as well as the network passwords are incredibly strong enough to avoid any potential cracking of the respective passwords in the business organization. Strong passwords make it difficult for the cybercriminals to easily crack the passwords for am intended security breach into the respective business organization.

Education on the defense against data breaches have also essentially helped the cyber security in fighting against the cyber-attacks that keep on occurring in the modern world. Education teaches the respective employees to be first aware of any possible threats which may trigger data breach. Education besides enhances the workers to often monitor the financial accounts of the respective business organization which are the main targets of data breach by cybercriminals (Dawson, 2017). The information system department of the organization will semi-annually educate their workers on changing the financial accounts passwords which help the respective business organization to keep track of the cyber security within the business organization. The department also educates their employees on the possible implications of a data breach and perhaps what might be taken into cryptographic action in the event in which the business organization may fall as a victim.

Business organizations also educate their employees on the need to cease ignoring their software updates as they may essentially help mitigate cyber-attacks that may happen to the respective business organization. Generally, cybercriminals or hackers love exploiting the weaknesses or holes within a popular software program. The execution of such updates facilitated through education in the respective business organization will help in fixing of the security holes which may be discovered within the computer systems (Rayton& Richard, 2013). Such education exhibits the integral role of education within the cyber security. Education in various business organization besides steer vivid of social engineering scams. It shows how the internet security software may fail to intercept social engineering. Cybercriminals generally utilize human-to-human interaction to try and trick the operators into divulging sensitive information. They modify partial scare-tactics and partial manipulation of people.

Generally, the world is encountering an eyebrow-raising talent shortfall in cyber security. This can be denoted by the recent findings of a current inquiry by the United Kingdom’s National Audit Office (Dawson, 2017). The statement generated emphasized not only that the existing tarn of security-educated graduates for a short demand but also that it may take more than twenty years to address the skills gap. The report also stresses on the need to educate the employees of an organization on the importance of acquiring security knowledge as well as feeding them with such security knowledge. Such prevalence has been indicated in the graph below for the cyber security talent in various leading countries in the world to show the efforts of technology towards fighting against cyber-attacks (Rayton& Richard, 2013).

In addition, education has tended to teach various cyber security agencies on their imperative recommendations to take in mitigate the cyber-attack disaster within a nation. Such outlined recommendations include increment in facilitating of public awareness for the cyber threats that they maybe exposed to. In addition, education helps the cyber security agencies to expand the information technology workforce which will massively help minimize occurrences of cyber-attacks. In addition, the education system has also substantially promoted the cybersecurity as an enterprise leadership responsibility (Dawson, 2017). This helps popularize the cyber security in the world which in return sensitize the employees and other concerned individuals on the awareness of cyber-attacks and cybercriminals. This help reduces such rampant cyber-attacks hence positively helping the cyber security.

Role of Technology in Cyber Security

Technology is the most emergent concern today in the modern world. In fact, numerous business organizations have been craving all their efforts in advancing their technologies to the modern state. Indeed, technology has an incredible and critical role within the cyber security field. The measure is incomparable with its ultimate efforts to curbing and ceasing cyber-attacks in the world. There are numerous emergent technological innovations and inventions that are bursting out within the cyber security field (Dorothy & Frank, 2013). Technology have deeply emaciated cybercriminals and engulfed them so as not to be in a position to crack passwords and access any information breach. Thanks to the technological innovations and inventions erupting throughout the world every day. This has even made the tradition information technology to subside and gradually die in their existence. Technology have also positively subsided the types of data breaches that may be experienced within any given organization. The graph chart below helps analyze the magnitude of these data breaches (Adams & Heard, 2016).

In today’s world, cyber security experts now ought to operate against data threats which have potentially be generated by Cloud, the Internet of Things, mobile or wireless and wearable technology. This literally implies that data which once were embedded in systems are currently roving through a dizzying diversity of routers, data centers as well as data hosts that are being geographically positioned in various centers across the world (Adams & Heard, 2016). There are various technological advancements that cyber criminals as well as hackers are utilizing in the modern world. Such technological advancements include man-in-the-middle commonly abbreviated as MiM which they utilize to attack eavesdrop on the whole data conversation. Spying software as well as Google glass are another technological advancement that they use to trace fingerprints movements on touch screens. Besides, other cyber criminals utilize memory-scraping malware on point-of-sale systems. They also employ the use of bespoke attacks which snip explicit information instead of conceding an entire system.

From the above scenarios, Garner reports have manifested that 60% of the digital business will be infested by main service failures by the year 2020. This is due to the fact that that the information technology security team is unable to manage digital risk in advancing technologies as well as how to utilize the cases. This situation has essentially resulted to numerous business organizations being held on by meaningless security alerts. Nevertheless, the technology has ensured a critical role within the cyber security field. For instance, it has facilitated sophisticated behavioral analytics which manage as well as identify any given suspicious behavior or even transactions (Dawson, 2018). This helps mitigate such an overwhelming meaningless security alert. Such behavior-based analytics may essentially include the bioprinting, mobile location tracking, behavioral profiles, third-party big data as well as external hazard astuteness which helps cyber security. There are indeed numerous websites which suffers from DDoS attack (Martti&Pekka, 2018).

Hackers have also enumerated a fond of utilizing the zero-day feats which permit them to launch a purchase as well as a mine data in networks as well as systems for month. This for instance include stolen credit numbers for their respective targets. The technology has however found a solution for the above complication. In relation with the role of education in cyber security, numerous business organizations who have fallen being victims of the above situation have developed technologies which combine machine learning as well as behavioral analytics in sensing any possible breaches as well as tracking these data breaches to the source (Martti&Pekka, 2018). Such a magnificent technology trail advancement has helped massively curb various incidents of cyber-attacks in the world.

The technology use in the cyber security have also mitigated the bespoke attacks in which numerous business organizations were not even aware of the bespoke attack scenarios which they later became victims of the bespoke attacks. For instance, next generation breach detection has intensively concentrated on what may occur when the felonious is already into the computer organization. Through use of behavioral analytics which may entail other additional tools, it is now possible to locate the breadcrumbs which the cyber attacker may leave behind after the respective attack.

The emerging technologies have also essentially helped in protection of the computer systems against any potential threat. Such emerging trends in technology include the cloud workload protection platforms as well as cloud access security brokers. Modern data centers essentially facilitate workloads which run in physical machines, virtual machines (VMs), containers as well as private cloud infrastructure. Hybrid cloud workload protection platforms have facilitated the data security leaders which are accompanied by an integrated method to secure such workloads while utilizing a single management console as well as a single method in expressing the security policy (Mansur, 2014). This will therefore outline the correlation between the technology as well as the security policy in cyber security field. This was recently reported is regardless of where the workload may be running. The cloud access security brokers may discourse holes in safekeeping consequential from momentous upsurge in cloud service and mobile practice.

Role of Policy in Cyber Security

Generally, a cyber security policy has a significance of establishing the rules and regulations of engagement for protection of the business organization in online matters. The policy in a cyber security situation significantly entails the simple security controls which are associated to the stuff utilization of the business organization’s network as well as the business operations of the computer devices as well as computer systems which are being utilized in the respective business organization (David, Herbert & Thomas, 2014). A policy especially security policy in a business organization have a critical role of protecting the business computer systems of the respective business organization from external exposure. This external exposure may practically subject the business being prone to various external threats such as ransom malware and many others. It also protects the business organization from being subjected to potential legal issues. Such business protection by security policies may be relevant for business organizations which conduct e-commerce as well as gather customer information online.

In addition, cyber security policy enhances a cyber security agency to facilitate instructions for the employees within the acceptable utilization of computer devices as well as online material. This will efficiently help them comprehend the vital duty they operate in protection of the cyber security of the respective business organization. In relation to the above, a cyber security policy besides enhances the respective business organization to entrust their consumers’ confidence within the business entity (George, 2016). This explains why it is crucially advisable to incorporate the business cyber security policy in the websites of the respective business organization to gain customers’ confidence.

The cyber security policy will besides essentially ensure that the passwords of various departments within the business organization are strong enough to withhold any potential cyber threats as well as respective cyber-attacks into the computer systems. In addition, it is the role of the cyber security policy to ensure that network passwords of the sensitive sectors within the business organization are customary and often renewed. Such sensitive areas of the business organization include the financial accounts department of the respective business organization (George, 2016). Likewise, it details the acceptable use of email as well as the internet of the respective business organization to the workers. It is the cyber security policy which will determine if some of websites of the business organization need to be blocked to their respective workers. This shows some of the critical roles of policy in cyber security.

In addition, the cyber security policy helps protect the computer devices as well as systems of the respective business organization. It is the role of the cyber security policy to articulate what work computer devices ought to be shares under the BYOD (Bring Your Own Device) policy. This explains why most of the business organizations in the world restrain the sharing of their mobile devices while working with the respective business organizations. The cyber security policy also helps the business organization in handling of the sensitive information of the business entity (Jeffrey & Peter, 2013). It articulates the mannerism as well as the location in which the sensitive information of the business organization ought to be handled. Other crucial roles of the policy in the cyber security field include security as well as the handling of the business equipment in determination whether there is any system in place that will essentially track the worker utilizing the equipment in the business organization. The policy also monitors the utilization of the internet safely as well as the remote access.

The correlation of the policy as well as technology in the cyber security facilitates the phases of the certification as well as the accreditation process. Their integration in addition evaluates on the mannerism in which the government agency may validate the process in case the federal information is compliant to the law. Besides, it adjudicates the mechanism in which the cyber security agency will sustain its compliance to the law throughout its entire life cycle of the system. There are generally four phases of the certification and accreditation process (Jeffrey & Peter, 2013).

The first phase is essentially the definition phase. This phase literally includes the initiation as well as planning of the certification and accreditation process. It is in this phase that the department as well as agency policies are established and founded. Here, the aggregate certification and accreditation process is established (Susan, 2017). Normally, it is in this phase that the information system owner as well as the designated information system security officer will officially initiate the certification and accreditation process. The second phase is the verification phase which is commonly referred to as the certification phase. It is in this phase that the security procedures and controls are officially implemented.

The third stage of the certification and accreditation process is the validation phase which is also known as the accreditation stage of the certification and accreditation process. It is in this stage that the compliance with the controls is independently tested. After the testing, the authority to operate is formally granted. The fourth phase of the certification and accreditation process is the post accreditation. This stage is definitely the final stage of the certification and accreditation process (Susan, 2017). It is in this stage that compliance with the controls is periodically independently tested. The technological advancement is updated to the RMS to make the certification and accreditation process more adjustable to the latest functioning within the information technology baseline. Here, the certification and accreditation process are ready for use.

References

Adams Niall M. & Heard Nicholas A. (2016), Dynamic Networks & Cybersecurity, pp. 106.

Braman E., Susmann P. &Vaseashta A. (2014), Cyber Security and Resiliency Policy Framework, pp. 133.

David Clark, Herbert Lin & Thomas A. Berson (2014), At the Nexus of Cybersecurity and Public Policy, Some Basic Concepts, pp. 302.

Dawson, Maurice (2017), Hyper-Connectivity: Intricacies of National and International Cyber Securities, London Metropolitan University, pp. 56.

Dawson, M. (2018). Applying a holistic cybersecurity framework for global IT organizations. Business Information Review, 35(2), pp. 60-67.

Dorothy Marinucci& Frank Hsu (2013), Advances in Cyber Security, Technology, Operation and Experiences, pp. 245-248.

George Christou (2016), Cybersecurity in the European Union, Resiliency and Adaptability in Governance Policy, pp. 159.

George Finney, Joseph Barnes & Michael Hites (2018), What Board Members Need to Know About Cyber Security, pp. 111-113.

Jeffrey Allen Hunker & Peter M. Shane (2013), Cybersecurity, Shared Risks, Shared Responsibilities, pp. 456.

Kshetri N. (2013), Cybercrime and Cyber Security in the Global South, pp. 106.

LeronZinatullin (2016), The Psychology of Information Security, Resolving Conflicts Between Security Compliance and Human Behavior, pp. 123-124.

Mansur Hasib (2014), Cybersecurity Leadership, Powering the Modern Organization, pp. 96.

MarttiLehto&PekkaNeittaanmaki (2018), Cyber Security, Power and Technology, pp. 235.

Mary Manjikian (2017), Cyber Security Ethics, An Introduction, pp. 97-99.

Rayton R. Sianjina& Richard Phillips (2013), Cyber Security for Educational Leaders, A Guide to Understanding and Implementing Technology Policies, pp. 500.

Susan Eva Landau (2017), Listening in, Cybersecurity in an Insecure Age, pp. 256.