Cybersecurity Processes and Technologies (CSIA)

profilevemylami
CSIA310CaseStudy1EndpointSolutionsv8-1.docx

CSIA 310: Cybersecurity Processes & Technologies

Case Study #1: Technology & Product Review for Endpoint Protection Solutions

Case Scenario:

Sifers-Grayson (the “client”) has requested that your company research and recommend an Endpoint Protection Platform, which will provide endpoint protection for the Apple MacBook laptop computers used by some of its employees. The MacBooks are bring your own device (BYOD) computers which some employees use to access company networks and servers while teleworking or working remotely (e.g. at the test range). The company has decided that, for now, it will continue to allow these devices on its networks but, an approved Endpoint Protection Platform must be used to manage the security of these devices.

The client wants an Endpoint Protection product that works with MacBooks (Apple OSX), is easy to use, and automatically updates itself (patches and virus definition files). The “automatic” updates could be a problem since some of the MacBooks are rarely connected to the company’s networks. This is especially true for employees who use an intermittent cellular connection to access the company’s networks while visiting customers or working at the engineering test range.

Research:

1. Review the Week 1 readings. (see resources below)

2. Using one of the product lists provided in Week 1, select a product that works on MacBooks. Research your chosen product using product information sheets (from the vendor’s website).

3. Find three or more additional sources which provide (a) product evaluations or reviews for your chosen product or (b) general information about Endpoint Protection Platforms.

Note: Since your client is a contractor to the US Government, you should be careful as to the reputation and nationality of the vendor you select. For example, Kaspersky AV products no longer have approval for installation on US Government networks due to sanctions against its home nation (See Department of Homeland Security Binding Operational Directive 17-01 https://cyber.dhs.gov/assets/report/bod-17-01.pdf). For this reason you may NOT use a Kaspersky-branded product for this assignment.

Write:

Write a 3 page summary of your research (“briefing paper”). At a minimum, your summary must include the following:

1. An introduction or overview for the security technology category (Endpoint Protection Platforms)

2. A review of the features, capabilities, and deficiencies for your selected vendor and product Make certain that you are reviewing the Apple MacBook version of the product.

3. Discussion of how the selected product could be used by your client to support its cybersecurity objectives by reducing risk, increasing resistance to threats/attacks, decreasing vulnerabilities, etc.

4. A closing section in which you restate your recommendation for a product (include the three most important benefits).

As you write your review, make sure that you address security issues using standard cybersecurity terminology (e.g. protection, detection, prevention, “governance,” confidentiality, integrity, availability, nonrepudiation, assurance, etc.). See the ISACA glossary https://www.isaca.org/pages/glossary.aspx if you need a refresher on acceptable terms and definitions.

Submit For Grading

Submit your case study in MS Word format (.docx or .doc file) using the Case Study #1: EPP Technology & Product Review assignment in your assignment folder. (Attach the file.)

For the submission of this assignment (All Projects), you are required to submit your work through Turnitin.

Additional Information

1. There is no penalty for writing more than 3 pages but, clarity and conciseness are valued. If your case study paper is shorter than 3 pages, you may not have sufficient content to meet the assignment requirements (see the rubric).

2. Your paper should use standard terms and definitions for cybersecurity. See Course Content > Week 1 > Cybersecurity Concepts Review for recommended resources.

3. You must include a cover page with the assignment title, your name, and the due date. Your reference list must be on a separate page at the end of your file. These pages do not count towards the assignment’s page count.

4. You are expected to write grammatically correct English in every assignment that you submit for grading. Do not turn in any work without (a) using spell check, (b) using grammar check, (c) verifying that your punctuation is correct and (d) reviewing your work for correct word usage and correctly structured sentences and paragraphs.

5. You are expected to credit your sources using in-text citations and reference list entries. Both your citations and your reference list entries must follow a consistent citation style (APA, MLA, etc.).

6. Consult the grading rubric for specific content and formatting requirements for this assignment.

Resources for Endpoint Protection Platforms (Case Study #1)

· Sifers-Grayson Overview Presentation Slides v2 – see attachment

· Chapter 7: Malicious Software and Anti-Virus Software in The InfoSec Handbook

Infosec handbook-See attachment

· What is Endpoint Protection?

https://digitalguardian.com/blog/what-endpoint-protection-data-protection-101

· The Best Hosted Endpoint Protection and Security Software of 2018

https://www.pcmag.com/roundup/338257/the-best-hosted-endpoint-protection-and-security-software

· Gartner peer insights: Endpoint Protection Platforms

https://www.gartner.com/reviews/market/endpoint-protection-platforms

· Removal of Kaspersky-Branded Products (DHS BOD 17-01)

https://cyber.dhs.gov/assets/report/bod-17-01.pdf

Rubric Name: Case Study: Technology & Product Review Rubric

Criteria

Excellent

Provided an introduction or overview for the security technology category

Provided an excellent overview of the security technology category assigned for this case study. The overview appropriately used information from 3 or more authoritative sources, i.e. journal articles, industry or trade publications, news articles, industry or government white papers and authoritative Web sites.

Identified and Reviewed a Vendor product

Provided an excellent review of the features, capabilities, and deficiencies for a selected vendor product in the assigned security technology category. The review appropriately used information from 5 or more authoritative sources, i.e. journal articles, industry or trade publications, news articles, industry or government white papers and authoritative Web sites.

Reported on how the product could be used to support cybersecurity objectives (i.e. confidentiality, integrity, availability, authorization, authentication, etc.)

Provided an excellent discussion of how the selected product could be used to support cybersecurity objectives by reducing risk, increasing resistance to threats/attacks, decreasing vulnerabilities, etc. Discussion provided five or more specific examples of how use of this product would positively impact cybersecurity for information, information systems, and/or networks. The discussion was supported by information drawn from authoritative sources.

Professionalism: Use of Cybersecurity Terminology

Demonstrated excellence in the use of standard cybersecurity terminology to support discussion of the technology. Appropriately used 5 or more standard terms.

Professionalism: Use of Authoritative Sources / Resources

Work contains a reference list containing entries for all cited resources. Sufficient information is provided to allow a reader to find and retrieve the cited sources. Reference list entries and in-text citations are consistently and correctly formatted using an appropriate citation style (APA, MLA, etc.). Five or more authoritative sources were used and cited.

Professionalism: Organization & Appearance

Submitted work shows outstanding organization and the use of color, fonts, titles, headings and sub-headings, etc. is appropriate to the assignment type.

Professionalism: Execution

No formatting, grammar, spelling, or punctuation errors.