Submit a draft of your class project report if you want feedback before submitting your final deliverable.

profileshahezama
GroupProjectPart4.docx

DOD-COMPLIANT POLICIES, STANDARDS, AND CONTROLS 5

University of the Cumberlands

Sha He Zama Khan

Mohammed Omer Khan

Ayub Khan Mohammed

Baseer Ahmed Syed

Syed Mujtaba Hussain

Team Leader: Mohammed Abdul Rahman

Course: Operations Security

Date: 03/25/2018

DoD-compliant policies, standards, and controls that affect the WAN, Remote Access, and System/Application Domains.

WAN (Wide Area Network)

· A description of policies used by the organization to control accessibility. This will include policies such as logical accessibility to the WAN resources.

· The development of access controls policies such as session termination and lock, concurrent session lock and control, publicly accessible information and many more controls.

· There is also the need for ensuring a logical acceptable of use of external information systems. The controls should include remote accessibility and descriptions of protocols to help in the control of information resources.

· There is also the need of developing physical barriers to the protection of airport structures housing critical information systems.

· There is also a finality in using and sharing the necessary electronic barriers for the protection of the critical information systems (Gorman, 2016).

· Authentication for information systems. Authentication will ensure the development of policies to control accessing sensitive information. Employees and staff will need to have access cards and usernames for authorization and authentication.

· There is also the need for developing security monitoring such as wireless accessibility and remote access.

· The WAN should also use and include a rise in the protection of threats against the remote information resources and networks.

Remote Access

· There is need for development of a logical access to the protection of the sensitive information contained by the airport’s infrastructure.

· The logical access should also include a separation of duties controls

· The remote access should also include system feedback controls for collecting information on unsuccessful login attempts.

· The remote access should also increase a strong multifactor authentication method.

· The strong authentication and multifactor system will be used for controlling the identity of system users and any who have logged into the system.

· Public key infrastructure should be well developed to control the rising threats of cyber security (Gorman, 2016).

· The organization should have a well-developed access control policies and measures. These will be well documented, and backups stored within the DOD premises. If the organization does not have an access control policy, it should describe the reasons as to why it has not implemented such policies.

· The organization should also develop a network access agreement and signed by each staff. These agreements will be a security training which will help the organization against violation of privacy.

System/Application Domains

· The organization should provide a documentation of all information systems used within the organization for communication, security, flow of information, data storage and analysis.

· The organization should also have conducted system and software inventories to ensure all infrastructure is accounted for (Gorman, 2016).

· The organization should always develop the necessary and needed data loss prevention capabilities. The capabilities should effectively address data backup processes and plans.

· The organization should also include the list of the security mechanisms in the protection against threats.

· The organization should ensure the staff and employees are trained on the importance of security training.

· The organization should develop capabilities to protect against digital theft of its information.

· The organization should have capabilities to protect against accessibility such as firewalls, system log and reviews, intrusion detection and prevention among many others.

References

Ballad, B., Ballad, T., & Banks, E. (2010). Access control, authentication, and public key infrastructure. Jones & Bartlett Publishers.

Gorman, C. N. (2016). DoDs Policies, Procedures, and Practices for Information Security Management of Covered Systems (REDACTED). Department of Defense Inspector General Alexandria United States.

Weiss, M., & Solomon, M. (2010). Auditing IT infrastructures for compliance. Jones & Bartlett Publishers.