Take time to read your paper against the rubric. I have highlighted yellow important rows which you should target.

profileMichelle_Michy
CYBERSECURITY1.docx

Running head: CYBER SECURITY FRAMEWORK

CYBER SECURITY FRAMEWORK 11

Literature Review

Cyber Security Framework

Action Research

Course Code:

Name:

Table of contents

Literarure review 4

Proposal 8

References 11

List of Figures

Figure 1: 10 steps to cyber security 7

Figure 2: Cyber security 8

Figure 2: Visual representation 10

LITERATURE REVIEW

The ICTs have been observed to evolve rapidly and their usages also expanding rapidly. Currently, the internet and mobile services have become embedded in the people’s daily lives all over the world (th ITU Global Symposium for Regulators, 2009). While this is the case, it has also emerged that that the risks in the ICTs have also evolved and increased in both magnitude and complexity, and this has become a key headaches for the ICT administrators in the various organizations. It is a fact that the organizations cannot do away with the information communication technologies because of the many benefits that are derived from these, and the only option is to focus more on improving the security of the systems. The issue of cyber security is not new, and it has attracted heated debates from various stakeholders and governments. Cybercrime and cyber terrorism are a major threats not only to the organizations, but also to governments (Daya, 2008). So, what is being done about this situation?

There are various definitions of the term cyber security. In some cases, there are various concepts that are used together or in place of the term cyber security, for example, Critical Information Infrastructure Protection (CIIP). Other related concepts include critical infrastructure, critical information infrastructure, and non-critical infrastructure. The definition differs from country to country. A simple definition of the concept of cyber security is the protection of the information and the systems that the organizations or governments rely on every day (State of Alabama IS Division, n.d.). Other definitions offered by Fischer (Fischer, 2016) include the following:

· The set of activities, as well as measures aimed at protecting – from disruption, attacks, and other threats – computer networks, computers, hardware and software components, and the information they contain and communicate among other components of cyberspace.

· The state of being protected from the threats mentioned above.

· The broader discipline of implementing and implementing the activities mentioned above.

There are also concepts that are often mistaken to be the same as cyber security, and these include information sharing, privacy, intelligence gathering, and surveillance. Another concept often related, but not identical, to the concept of cyber security is information security. This concept is defined under federal law (44 U.S.C § 3552(b)(3)) as:

“Protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide-

truction, and includes ensuring information nonrepudiation and authenticity;

(B) Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and

(C) Availability, which means ensuring timely and reliable access to and use of information.

It is a fact that the incidences cyber security attacks are on the increase, as Balasubramanian (n.d.) gives several examples of the recent cyber-attacks that have been executed successfully and caused huge losses to the victim organizations. Among them include the case of European financial Services Company that lost $ 7 billion (Balasubramanian, n.d.). Among the most common threats to the cyber security include the following (Zaharia, 2016):

· Cyber criminals – these are the greatest threat to the cyber security who hack and access organizations’ finances and loots them. The FBI have a list of 19 individuals each of whom has caused consumer losses ranging from $ 350 000 to $ 100 million.

· Computer viruses – currently, the most expensive virus is called MyDoom, and this has caused financial damages amounting to $ 38.5 billion. This was first spotted in 2004, and has since become the fastest-spreading email worm in history.

· Social media – the social media has become the hackers’ new target. The various cyber-attacks targeted at the social media include like-jacking, link-jacking, phishing and social spam.

· Human error – all humans do make mistakes, and human error has also been established as a key cyber security threat. Statistics gathered by IBM have established that about 95 % of the security incidents can be attributed to the human error (Howarth, 2014).

· Computers’ vulnerability to exploit kits.

· Inside jobs

· Social engineering

· Government-created malware

Image result for Cyber Security

Figure 1: 10 steps to cyber security (adapted from https://www.gov.uk/government/publications/cyber-risk-management-a-board-level-responsibility/10-steps-summary)

Cyber security is basically the responsibility of each and every person in the society (Crucial Research, 2014). This is because the threats affect the entire society, and this is has been evidenced by the various incidences of personal accounts hacked and funds stolen. Cyber security is very important for various reasons, among these being the fears that the threats endanger the global economy (Gabel, 2015).

Proposal

The purpose of this action research is to implement a cyber-security framework untended for protecting the organizations information infrastructure and systems. Being an action research, the researcher will involve various groups of people including organizational executives and government officials, as well as IT experts in order to accomplish this implementation. The action research will highly rely on the input from the various stakeholders and also acceptance by the government and the organizations.

Image result for Cyber Security

Figure 2: Cyber security (adapted from https://www.cesg.gov.uk/articles/infographics-cesg)

The action research will have four iterations, and these are as discussed in the paragraphs that follow.

Iteration 1: Understanding cyber security. The first iteration will involve gaining more insight into the concept of cyber security and the various measures already taken to improve the cyber security situation. The iteration will also establish the current trends in the cyber security in order to fully define the problem and design the cyber security framework.

Iteration 2: Design the cyber security framework. The second iteration will entail designing the cyber security framework, keeping in mind that here are existing frameworks that still have failed to offer the ultimate cyber security.

Iteration 3: Implementing the cyber security framework. The third iteration involves the implementation of the cyber security framework that has been designed previously. The implementation will be done taking into account the fact that each organization of government has different cyber security needs. Issues of customization will also be addressed during the third iteration.

Iteration 3: Monitoring. The last iteration will entail monitoring the implementation process and taking the relevant corrective actions. Changes and modifications will also be done to the initial implementation plan in order to cover for the deviations from the plans.

Iteration flow diagram

The diagram below illustrates the iteration flows of this action research.

Iteration 1: Understanding cyber security

Reflect

Observe

Act

Plan

Iteration 2: Designing cyber security framework

Reflect

Observe

Act

Plan

Iteration 3: Implementing cyber security framework

Reflect

Observe

Act

Plan

Reflect

Observe

Act

Plan

Iteration 4: Monitoring

Figure 3: Iteration Flow Diagram

Each of the above iteration will have four phases – plan, act, observe, and reflect. The planning phase involves laying out the course of action for the iteration among other things. The action phase entails actual undertaking the various activities for the iteration. Observe phase will entail taking note of the happenings of the iteration, while the reflection phase intends to explain various things that happen within the iteration.

References Balasubramanian, V. (n.d.). Combating Cyber Security Threats. Threat, Threat Everywhere; Cyber-Criminals on the Prowl, 1-10. Retrieved from https://download.manageengine.com/products/passwordmanagerpro/combating-cyber-security-threats.pdf Crucial Research. (2014). People’s Role in Cyber Security: Academics’ Perspective. Crucial Research, 1-8. Retrieved from https://www.crucial.com.au/pdf/Peoples_Role_in_Cyber_Security.pdf Daya, B. (2008). Network Security: History, Importance, and Future. 1-33. Retrieved from http://web.mit.edu/~bdaya/www/Network%20Security.pdf Fischer, E. (2016). Cybersecurity Issues and Challenges: In Brief. Congressional Research Service, 1-12. Gabel, D. (2015, July 01). Cyber risk: Why cyber security is important. Retrieved from Whitecase.com: http://www.whitecase.com/publications/insight/cyber-risk-why-cyber-security-important Howarth, F. (2014, Sept 2). The Role of Human Error in Successful Security Attacks. Retrieved from Securityintelligence.com: https://securityintelligence.com/the-role-of-human-error-in-successful-security-attacks/ State of Alabama IS Division. (n.d.). Cyber Security is our Shared Responsibility. 1-2. Retrieved from http://cybersecurity.alabama.gov/Documents/security/WhyCyberSecurityisImportant.pdf th ITU Global Symposium for Regulators. (2009). Cybersecurity: The Role and Responsibilities of an Effective Regulator. Draft Background Paper, 1-40. Zaharia, A. (2016, May 12). 10 Alarming Cyber Security Facts that Threaten Your Data [Updated]. Retrieved from Heimdalsecurity.com: https://heimdalsecurity.com/blog/10-surprising-cyber-security-facts-that-may-affect-your-online-safety/