Assignmenty 1
UMGC_CSCUv2 Purchase Instructions_EC-Council Academia_2021-2022.pdf
EC-Council | Academia
2502 N. Rocky Point Drive Ste. 160 Tampa, FL 33607
The International Council of E-Commerce Consultants (EC-Council) and University of Maryland Global Campus (UMGC)
have partnered to offer select EC-Council Academia Series curriculum. This official EC-Council Academia Series
curriculum qualifies each UMGC student for exclusive curriculum discounts and supporting exam voucher discounts
(post curriculum purchase). Automatic EC-Council exam eligibility privileges are also granted upon the purchase of
official EC-Council courseware, meaning each student does not have to apply to test out on an exam, and can simply
purchase a discounted voucher.
✓ Bypass Exam Eligibility Application
✓ Bypass Exam Eligibility Application Fee’s
✓ Bypass Minimum Work Experience Requirements
✓ Bypass Reference Checks
Move straight to testing post purchase of an EC-Council Exam Voucher!
The following resource has been allocated for your specific UMGC class;
UMGC Course: UMGC CSIA300
EC-Council Academia Series eCourseware: Certified Secure Computer User (C|SCU) v2 eBook
ISBN: 978-1-63567-380-7
UMGC Student Cost (Discounted): $24.99
OPTIONAL EC-Council Exam Voucher: $25.00 (ECC exam voucher w/ remote proctor services)
Click here to purchase an eBook $24.99
Click here to purchase a print book $60.00 Disclaimer: The checkout process will not allow APO addresses. If you have an APO/FPO address, please list the
University address in the billing information when purchasing the eBook. The billing address on the Gilmore Global
eStore does not have to be associated with your Credit Card billing address. For print book purchases, a non-APO/FPO
address is mandatory for UPS shipping.
Redemption Instructions:
To redeem your eCourseware code, please proceed to register via eVantage (Powered by Vital Source Bookshelf)
For additional questions, comments, or feedback, please call 1 844 HACK CEH. To purchase an EC-Council exam
voucher, please email us at [email protected] for more information. Thank you!
CSIA 300 Why do businesses need security 2020.pdf
CSIA 300: Cybersecurity for Leaders and Managers
1
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
Why do Businesses Need Security?
There are many different types of businesses. Each one needs security in some form. In this reading, we will explore the reasons why a business needs to have someone or some group within the business that is responsible for security.
Types of Businesses
A sole proprietorship is a simple form of business in which the owner is personally responsible for the business’s activities (including debts) (Entrepreneur Staff, 2017b). The business may have a trade name but it does not have a legal identity separate from its owner. In this form of business, the owner’s personal knowledge of cybersecurity issues and solutions will be very important.
A partnership is a form of business in which two or more individuals own the business (Entrepreneur Staff, 2017a). Partners contribute resources to the business (“investments”) and then share any resulting profits or losses. Partnership agreements state how those profits or losses will be distributed among the owner. Such agreements also provide for management and authority over the day-to-day operations of the business. A partnership will also need some form of governance structure to guide decision making about how the business will be operated (strategies, goals, policies, etc.). At least one of the partners involved in daily operations will need to have cybersecurity knowledge.
A corporation (Investopedia, 2017) is a legally recognized entity (owned or controlled by a group of people) that enjoys many of the rights, responsibilities, and duties as are granted under the law to a person. The corporation’s rights, responsibilities, and duties exist separately from those of the corporation’s owners. The documents of incorporation provide structure to the company’s governance by outlining key roles and responsibilities. The members of the Board of Directors and the senior leaders / managers of the company all need to have some familiarity with cybersecurity related principles, practices, threats and risks.
Reasons Why Businesses Need Security
Asset Protection (Traditional & Digital Assets)
Businesses exist to make a profit. They do this by creating and selling products and services. Business assets are resources used by the organization to produce the goods and services it will sell or to provide supporting services required to operate the business (Kovacich & Halibozek, 2003).
An asset is a possession (item or object) that has value. This value must be protected against harm or loss.
Digital assets are information assets that exist only in digital form (electronically stored information). These assets are stored on digital media and are accessed / used via digital
CSIA 300: Cybersecurity for Leaders and Managers
2
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
devices. The term is used to refer to files, software, and firmware. Digital assets may also be physical assets (when they exist in stored form) or they may be classified as intangible assets.
Physical assets include buildings, land, property, etc. Computer hardware and infrastructures are physical assets.
Intangible assets include such things as intellectual property, trade secrets, brand recognition, reputation and good will.
Thus, we have our first reason that businesses need security – to protect business assets. Asset security consists of those measures taken by the business to protect its assets from harm or loss. This harm or loss may be caused by insiders (e.g. employees), outsiders (criminals, competitors), and extraordinary events (force majeure) or acts of God. Business assets that must be protected against loss or harm include:
• buildings and facilities, equipment and furnishings • business processes • computer systems • financial instruments and cash (money) • information (databases, documents, and files) • inventory (completed products, parts, and supplies) • networks and infrastructures • personnel (skilled workforce) • intellectual property (e.g., patents, trade secrets, plans, and strategies) • reputation
Information and information systems are assets. Information is an asset because the organization must spend money to obtain it so that the information can be used to produce goods and services. Examples of valuable information assets include recipes or formulas, customer and vendor lists, sales plans, and marketing strategies. An information system is an asset because each component of the system costs money to purchase or replace. Note: Businesses may also be holders or custodians of information belonging to others. This information must also be protected from harm or loss.
The security measures required to protect business assets are determined by identifying the assets that require protection and then assessing the specific threats and vulnerabilities (for each asset or type of asset) that are present in the organization’s operating environment.
Legal and Regulatory Compliance
Businesses must comply with laws and regulations set forth by certain governments and government agencies (Reynolds, 2010). Sometimes, it can be difficult to determine which laws or regulations apply
CSIA 300: Cybersecurity for Leaders and Managers
3
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
and in what circumstances they apply. Businesses need the advice and services of attorneys or corporate counselors to provide guidance in making such determinations. It is important to have competent legal counsel for areas where the business is at risk or may face penalties for non compliance. Cybersecurity requirements imposed by laws or regulations are an area where specialized legal counsel may be required.
Key concepts from law that affect business operations are due diligence and duty of care (Reynolds, 2010). Due diligence is the obligation to be conscientious in performing your duties. In some uses, this term refers specifically to functions related to contracts and acquisitions. Duty of care is the obligation to be attentive and to avoid causing harm. Leaders and managers need to understand cybersecurity principles, practices, threats, and risks in order to meet their obligations under both due diligence and duty of care.
Integrating Security with Business Operations
Businesses can be described as systems of people, processes, policies, and technologies and the interconnections / relationships between these components (ISACA, 2009). These components can also be viewed as assets, which have value to the organization. Each component, each relationship between components requires some level of protection from harm or loss. Thus, the need for security throughout the system is pervasive and should be approached in a holistic manner.
Figure 1. Systems View of an Organization
Working with the entire system at once can be a daunting task especially when greater levels of detail are required. Breaking the system down into smaller chunks is an obvious solution but, how should those chunks be defined? One organizing strategy, used by business analysts, is to divide the organization into functional areas. Within each functional area, we can identify the components of the system that operate within the functional area and those components which are cross-cutting (apply to multiple functional areas at the same time. Dividing the business into functional areas will also allow us to analyze and assess security needs within each area. After the needs in each area are considered, we
CSIA 300: Cybersecurity for Leaders and Managers
4
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
can identify cross-cutting or system-wide security requirements and gaps. Finding commonalities allows us to identify ways to reduce costs and improve efficient allocation of resources to deliver required levels of security.
Business Functions
The day-to-day business operations of organizations are typically organized into five functional areas (see figure 1). Each functional area is supported by business processes and assets. As business becomes e-business and commerce becomes e-commerce, businesses must reevaluate their security programs to ensure that the confidentiality, integrity, and availability of business processes and assets are protected against threats (sources of harm or loss). The figure below shows the five functional areas typically found in the day-to-day operations and activities of an organization. Notice that “security” is a separate business function yet is fully integrated within the business enterprise. Security both supports and is supported by the other functional areas of the business.
Figure 2. Day-to-Day Business Operations
Accounting and Finance Functions
The accounting and finance functions of a business include:
• accounting and bookkeeping • budget preparation and monitoring • fiscal analysis and reporting • sales or other financial transaction processing
CSIA 300: Cybersecurity for Leaders and Managers
5
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
Security is required for devices and information systems which process or provide access to financial information. Required security functions include providing authentication, authorization, and nonrepudiation for access to and use of both physical and digital assets containing financial information.
Additional security services may also be required to ensure compliance with federal and state laws and regulations (e.g., Gramm-Leach-Bliley Act, Sarbanes-Oxley Act, Fair Credit Reporting Act, etc.).
Commercial Functions
The commercial functions of a business include:
• sales • marketing and business intelligence • customer relationship management
Security needs for commercial functions include:
• protection of confidential business information (client lists, sales/marketing plans, etc.), trade secrets, and other forms of intellectual property
• protection of customer and vendor information (including personally identifiable information) • provision of authentication, authorization, and nonrepudiation for access to and use of
information systems involved in the collection, use, reporting, and storage of customer information
Additional security services may be required to comply with provisions federal and state laws regarding privacy, data breach reporting, and corporate transparency.
For marketing and business intelligence functions, the organization may need to incorporate auditing and control functions to ensure that the information collected about competitors does not violate the Economic Espionage Act or other applicable laws.
General and Functional Management Functions
According to Henri Fayol (Svenson, 1961), the management functions of a business include:
• Planning, organizing, and coordinating the work of the organization • Allocating and controlling resources (including budgeting) • Monitoring and controlling (“commanding”) the work of the organization
These management functions frequently involve decision-making activities which require access to and the ability to benefit from a variety of information that the organization collects, processes, transmits, and stores (Tannenbaum, 1950). Such information includes:
CSIA 300: Cybersecurity for Leaders and Managers
6
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
• business records • confidential business information (client lists, sales/marketing plans, corporate strategies, etc.) • customer data (including personally identifiable information) • financial data and forecasts • plans and schedules • trade secrets • other forms of intellectual property
The information and confidential business processes used in the general and functional management activities of an organization must be protected against unauthorized access or disclosure. Typically, this is done by putting restrictions in place which control access to information and information resources. These restrictions must be balanced against legitimate uses and disclosures of information while communicating, coordinating, and collaborating as part of the day-to-day operations of the business.
Security Functions
Security of the business, from assets to operations and all the functions in between, is a shared responsibility for all managers and employees (Kovacich & Halibozek, 2003). This responsibility includes diligence in the performance of duties under the duty of care (Reynolds, 2010). The reasonable person standard is used to determine if an individual has performed these responsibilities with the same level of diligence and care that a conscientious person would put forth.
The effectiveness and efficiency of security functions are improved when there is a single manager with primary responsibility for these functions (Kovacich & Halibozek, 2003).
The security manager has both an operational and a strategic role in the business and must use a great deal of influence and collaboration to ensure cooperation on security matters throughout the organization (Kovacich & Halibozek, 2003). The security manager is usually supported by a dedicated organization whose personnel are specifically trained in security administration, physical security, personnel security, operations security, and information security. The security manager is responsible for the establishment and management of the organization’s security program. These responsibilities include ensuring compliance with laws, regulations, and standards for corporate security. The security manager and supporting security personnel are also trained in risk management, fraud deterrence, internal investigations, contingency planning, disaster recovery, and crisis management.
The security functions of an organization include (Kovacich & Halibozek, 2003):
• protect against harm or loss • detect attempts to cause harm or loss • react to events causing harm or loss • document incidents and responses
CSIA 300: Cybersecurity for Leaders and Managers
7
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
• prevent by planning and implementing security measures to prevent future incidents • assist in ensuring compliance with laws and regulations
The protection of business functions which depend upon cyberspace and digital assets which can be accessed from cyberspace has become an increasingly important area of responsibility for security managers. A separate sub-specialty or functional area for security, Cybersecurity (Department of Homeland Security, 2017), has emerged as a result of this growing need.
Technical Functions
The technical functions of a business are those activities, which directly or indirectly contribute to the conversion of inputs (raw materials and labor) into outputs (products and services which can be sold or otherwise converted into monetary value). These functions include:
• business operations • product development and production • purchasing and logistics • research and development
The security needs of each activity area vary by the types and sensitivity levels of the processes and information required by the activity and the degree to which each activity interacts with or relies upon the external environment. These activities require security protections that ensure the confidentiality, integrity, and availability of information (data) and services. Many of these activities also require auditing, monitoring, and control capabilities (security services) that provide for nonrepudiation of actions taken by both insiders and external actors.
E-Business/E-Commerce Infrastructure
E-business and e-commerce infrastructures are built from capabilities provided by the technical and commercial functions of a business. These infrastructures are then used to provide products and services that are either delivered in cyberspace or which are accessible from cyberspace (e.g. products ordered via an online ordering system). Special care must be taken to ensure that the data storage, processing, and transmission capabilities (see figure 2) within the e-business and e-commerce infrastructure protect the confidentiality, integrity, and availability of information and services.
CSIA 300: Cybersecurity for Leaders and Managers
8
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
Figure 3. E-Business/E-Commerce Infrastructure
Cybersecurity and Businesses
Cybersecurity is a type of security that a business needs to have in place to protect its operations and assets which exist in cyberspace or which can be accessed via computers, devices, and networks that have connections into cyberspace. Put another way, Cybersecurity focuses primarily upon protecting and defending assets that exist in digital form or assets that receive, process, store, and transmit digital information. Cybersecurity is also concerned with providing protection that ensures the confidentiality, availability, and integrity of information and information based services which are accessed via the Internet. Cyberspace exists because enabling technologies such as the Internet provide global connections between computers and between people using computers.
Figure 4. Cyberspace (the Internet)
CSIA 300: Cybersecurity for Leaders and Managers
9
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
References
Department of Homeland Security. (2017). Glossary. Retrieved from https://niccs.us-cert.gov/glossary
Entrepreneur Staff. (2017a). Partnership. Retrieved from https://www.entrepreneur.com/encyclopedia/partnership
Entrepreneur Staff. (2017b). Sole proprietorship. Retrieved from https://www.entrepreneur.com/encyclopedia/sole-proprietorship
Investopedia. (2017). Corporation. Retrieved from http://www.investopedia.com/terms/i/incorporate.asp
ISACA. (2009). An introduction to the Business Model for Information Security. Retrieved from http://www.isaca.org/knowledge-center/research/documents/introduction-to-the-business- model-for-information-security_res_eng_0109.pdf
Kovacich, G. L., & Halibozek, E. P. (2003). The manager’s handbook for corporate security: Establishing and managing a successful assets protection program. Burlington, MA: Elsevier.
Reynolds, G. W. (2010). Ethics in information technology (3rd ed.). Boston, MA: Course Technology.
Svenson, A. L. (1961). Pioneers of management organization theory. Management International 1(5/6), 115-130.
Tannenbaum, R. (1950). Managerial decision-making. The Journal of Business of the University of Chicago, 23(1), 22-39.
- Why do Businesses Need Security?
- Types of Businesses
- Reasons Why Businesses Need Security
- Asset Protection (Traditional & Digital Assets)
- Legal and Regulatory Compliance
- Integrating Security with Business Operations
- Business Functions
- Accounting and Finance Functions
- Commercial Functions
- General and Functional Management Functions
- Security Functions
- Technical Functions
- E-Business/E-Commerce Infrastructure
- Cybersecurity and Businesses
- References
CSIA 300 Padgett-Beale Intern Welcome Letter 2020.pdf
CSIA 300: Cybersecurity for Leaders and Managers
© 2020 by University of Maryland Global Campus. All Rights Reserved.
Dear Intern,
Welcome to Padgett-Beale – a world leader in the hospitality industry! We are excited to have you join us as a management intern and hope that your participation in our virtual / online program will be beneficial for both you and our company. This year, our management interns will have the opportunity to participate in Padgett-Beale’s pervasive cybersecurity initiative. This initiative is designed to help our employees and managers better understand and address the cybersecurity problems that our company is facing. These problems include a host of privacy and data security related concerns, intellectual property protection issues, and the appropriate use of information technology resources. During this eight-week program, you will have an opportunity to participate in a number of management and leadership activities and assessments related to cybersecurity. Since you are joining us as a management intern, you will also be participating in our new security awareness training program, Certified Secure Computer User (C|SCU), published by EC-Council. As you complete the modules in this training, we will ask you to keep notes on the training so that you can evaluate it from a management perspective as well as from the perspective of an employee taking the training.
As you move through our internship program, we hope that you and your peers will take advantage of the numerous communication channels made available to you via our internal Websites and discussion forums. We are truly interested in learning from you and hearing your thoughts on the management and leadership issues that you encounter during your time with us.
Finally, our goal is to help you find opportunities to take what you learn here and apply it to your future studies and career. We hope that you, in turn, will help us by providing feedback during and at the end of this program. Thank you for your participation and, again, Welcome!
Sincerely,
Edwina L. Beale
Edwina L. Beale Chief of Staff and Manager, Internship Programs
Introduction to the Secure Computer User Training Course.html
Welcome Interns!
As part of your virtual internship experience here at Padgett-Beale, we have arranged for you to participate in our internal cybersecurity awareness training course. This year, we have selected the EC-Council Certified Secure Computer User (CSCU) course for our awareness training. The course includes explanations of important concepts, presents best practices for using computers in a secure manner, and includes some "how-to" instructions ("click-by-click" activities) for securing a computer workstation or laptop.
Note: You will NOT be asked to perform the "click-by-click" activities in the course and you SHOULD NOT attempt these activities on computers which you do not personally own. This portion of the training course is included for situational awareness since, as a manager or supervisor, you will need to know that these activities, e.g. turning on whole disk encryption, are possible and may be implemented by your organization's IT department as part of the overall security program.
You will need to PURCHASE the Certified Secure Computer User e-book (CSCU) using the link in your syllabus or course registration materials. You may also purchase the eBook using the link in the flyer posted under Week 1 > Course Introduction. Use the link sent in your purchase materials to redeem your access code and then to access the eBook.
The table of contents for the Certified Secure Computer User e-book is shown below. Please pay careful attention to the assigned readings for each week as we may need to cover the modules in a different order than presented in the book.
Module 01: Introduction to Data Security Security News...................................................................................................................... 2 Module Objectives .............................................................................................................. 2 Data—Digital Building Blocks.............................................................................................. 3 Importance of Data in the Information Age ....................................................................... 3 Threats to Data ................................................................................................................... 4 Data Security ....................................................................................................................... 6 Elements of Security ........................................................................................................... 7 Implementing Security........................................................................................................ 9 Module Summary.............................................................................................................. 11 Discussion Questions ........................................................................................................ 11
Module 02: Securing Operating Systems Security News.................................................................................................................... 14 Module Objectives ............................................................................................................ 14 Securing Operating Systems ............................................................................................. 16 Guidelines to Secure Windows 10 .................................................................................... 16 Guidelines for MAC OS X Security..................................................................................... 54 Module Summary.............................................................................................................. 71 Discussion Questions ........................................................................................................ 71
Module 03: Malware and Antivirus Security News.................................................................................................................... 74 Module Objectives ............................................................................................................ 74 What is Malware? ............................................................................................................. 75 Antivirus ............................................................................................................................ 77 Kaspersky PURE 3.0........................................................................................................... 80 Avast Antivirus .................................................................................................................. 88 Module Summary.............................................................................................................. 93 Discussion Questions ........................................................................................................ 94
Module 04: Internet Security Security News.................................................................................................................... 96 Module Objectives ............................................................................................................ 96 Understanding Web Browser Concepts............................................................................ 97 Instant Messaging ........................................................................................................... 109 Child Online Safety.......................................................................................................... 111 Module Summary............................................................................................................ 115 Discussion Questions ...................................................................................................... 115
Module 05: Security on Social Networking Sites Security News.................................................................................................................. 118 Module Objectives .......................................................................................................... 118 Introduction to Social Networking Sites ......................................................................... 119 Geotagging ...................................................................................................................... 125 Social Networking Threats to Minors ............................................................................. 131 Social Networking Site: Facebook................................................................................... 132 Social Networking Site: Twitter ...................................................................................... 173 Module Summary............................................................................................................ 184 Discussion Questions: ..................................................................................................... 184
Module 06: Securing Email Communications Security News.................................................................................................................. 186 Module Objectives .......................................................................................................... 186 Introduction to Email ...................................................................................................... 187 Email Security.................................................................................................................. 190 Email Security Procedures .............................................................................................. 201 Encryption ....................................................................................................................... 214 Email Security Tools ........................................................................................................ 218 Module Summary............................................................................................................ 220 Discussion Questions ...................................................................................................... 220
Module 07: Securing Mobile Devices Security News.................................................................................................................. 224 Module Objectives .......................................................................................................... 224 Securing Mobile Devices ................................................................................................. 225 Understanding Mobile Device Threats ........................................................................... 226 Understanding Various Mobile Security Procedures...................................................... 228 Understanding How to Secure iPhone and iPad Devices ............................................... 235 Understanding How to Secure Android Devices............................................................. 242 Understanding How to Secure Windows Phone Devices ............................................... 253 Mobile Security Tools...................................................................................................... 259 Mobile Phone and Bluetooth Security Checklists........................................................... 260 Module Summary............................................................................................................ 261 Discussion Questions ...................................................................................................... 262
Module 08: Securing the Cloud Security News.................................................................................................................. 264 Module Objectives .......................................................................................................... 264 The Concept of Cloud...................................................................................................... 265 Threats to Cloud Security................................................................................................ 267 Cloud Privacy Issues ........................................................................................................ 269 Choosing a Cloud Service Provider ................................................................................. 270 Module Summary............................................................................................................ 273 Discussion Questions ...................................................................................................... 273
Module 09: Securing Network Connections Security News.................................................................................................................. 276 Module Objectives .......................................................................................................... 276 Understanding Various Networking Concepts ............................................................... 277 Understanding Setting Up a Wireless Network .............................................................. 279 Understanding Threats to Wireless Network Security and Countermeasures .............. 282 Home Network Safety Checklist ..................................................................................... 284 Module Summary............................................................................................................ 285 Discussion Questions ...................................................................................................... 285
Module 10: Data Backup and Disaster Recovery Security News.................................................................................................................. 288 Module Objectives .......................................................................................................... 288 Data Backup Concepts .................................................................................................... 289 Types of Data Backup...................................................................................................... 291 Windows 10 Backup and Restore Procedures ................................................................ 296 Mac OS X Backup and Restore Procedures..................................................................... 306 Understanding Safe Data Destruction ............................................................................ 308 Module Summary............................................................................................................ 312 Discussion Questions ...................................................................................................... 312 References .................................................................................................................................. 31
Table of Contents.html
| CSIA 300 7381 Cybersecurity for Leaders and Managers (2218) - Week 1: Need for Cybersecurity
1. UMGC_CSCUv2 Purchase Instructions_EC-Council Academia_2021-2022 2. CSIA 300 Why do businesses need security? 3. CSIA 300 Padgett-Beale Intern Welcome Letter 4. Introduction to the Certified Secure Computer User Training Course |