project 2
Running Head: COMPUFY LIMITED 2
COMPUFY LIMITED 2
CS654_Security Management
Compufy Limited
Harish Vadnala
Colorado Technical University
Contents 1.0. Security Requirements 2 1.1. Hypothesized Organization: Compufy Limited 2 1.1.1. Corporate organizational chart 4 1.1.2. Work Group structure and ties added to the corporate organizational chart 4 1.1.3. Communication flows of Work Groups of Compufy Limited 5 2.0. Security Business Requirements 7 3.0. Security Policy 8 4.0. System Design Principles 9 5.0. The Training Module 10 References 11
Compufy Limited
1.0. Security Requirements
Network security consists of procedures and practices that are initiated to inhibit access by unsanctioned persons, exploitation, and alteration by these kinds of people or denial of computer network and resources that can be accessed through a given interface. Such networks are controlled by network administrators who are given authority to authorize access of certain data to a given group of individuals. The focus of this paper is on the security of networks which involves a number of significant features for it to be considered secure. Some of these features include the authentication of users and the denial of a computer network to intruders (Lincke, 2015).
There are a number of attacks that can be faced in any network, more so where a loophole is noted by the attackers. Some of these attacks include: Port Scanning, Wiretapping Denial-of-Service (DoS), Distributed Denial-of-Service (DDoS) attack, Phishing, Cross-Site Request Forgery (CSRF), SQL Injections, XSS Attack, ARP Poisoning, Buffer Overflow (McNab, 2007). With these being identified, a strong security management plan needs to be put into place whereby, these loopholes need to be secured.
1.1. Hypothesized Organization: Compufy Limited
Compufy Limited, a company that was established to help different organizations to secure their information through ensuring that there exists a high and efficient level of network and information security, is located in the United States, and was set up in 2016 with the aim of developing the network and information security (NIS) in the society and also to create awareness of NIS and as a result, contributing towards the development of the internal market. Its primary aim was to create minimal risks associated to the network, thus allowing their users and organizations to handle their network easily without any disruption. The company is, therefore, found to contain all these strengths where the use of IDs and passwords are used to authorize viewing of information among other network management strategies. The company aims to ensure that the community and its members are protected from malfunctions in the network that affects the information saved on anyone’s device. Of much importance, Compufy Limited aims at managing risks and assessing them. These are found to be essential parts of information security management and, as a result, are vital to the founding of security in organizations.
1.1.0. Initial Security Projects
Primarily, the company has been working hand in hand with different organizations to secure their networks. One of the first security projects was the accountability of information use. This involved the privacy and fairness in decision-making systems (Zubairi, 2009). This project dealt with the making of decisions of the automated systems that process personal data of the company’s clients. Most organizations and working groups which linked up with the Compufy Limited were excited over the positive contributions of the systems installed in their premises. However, most of them raised severe trepidations of their data not being secure and private. This, after this project, has been identified to be the major concern of most organizations. With updated systems containing machine learning algorithms, such problems have been curbed, and the company aims at helping more organizations stabilize and gain control of their network and information systems. Thus, the issue was subdued by explaining to the users how the systems were automated to be accountable for their privacy.
The cloud is rapidly changing the face of the web infrastructure, allowing even the minute corporates to create quick web and mobile applications for their users through taking advantage of the of the scale of flexibility of the physical shared infrastructure created by cloud providers, the academic community, however, is at risk of being left out of this hypothetical change. A problem Compufy identified was the network virtualization, which was found to be a hindrance. However, the company came up with suitable network virtualization that puts all the non-significant packet transformations at the verge of the corporeal system. The company is further planning on developing programs that will extend to a more sophisticated network functionality that will enable clients to be able to manage all their data in the small cloud space.
1.1.1. Corporate organizational chart
The company’s structure can briefly be outlined as below.
This is based on the major departments, their functions and sub-functions, and also their activities.
1.1.2. Work Group structure and ties added to the corporate organizational chart
The Workgroup structure is based on the realistic goal of the company which is aimed at reaching maximum security stabilization in the networks. To begin with, there is the deputy of Compufy who reports to the head of the company. The deputy is also advised by the Information Security Council that is made up of the Chief Risk Officer, CFO among other major leaders of the company who take part in major decisions of the company before any process is executed.
1.1.3. Communication flows of Work Groups of Compufy Limited
For an organization to have realistic goals there must be an order in which decisions are made. For Compufy Limited, the Chief Strategy Officer (CSO), who is responsible for executing the major security programs and protecting the information assets of the company, reports to the Chief Information Officer (CIO). In exceptional cases that require financial aid, the CSO reports to the Chief Risk Officer. This, therefore, helps in the coordination of the security team in the execution of the security policies of the organization. Moving down, there is the network infrastructure officer who ensures that security of data, i.e., through networks, endpoints and data centers are safe and secure. Irrespective of where the work is being done, the infrastructure officer needs to ensure that all resources are well-coordinated.
There is also the application and asset security department which ensures that the CSO is not caught by surprise in case of any Network and Information System failures. The officer always checks all systems and networks randomly to ensure that there are no exploits that can compromise the client or organization. If any faults are found, then suitable assets are provided to fix concerns found. The officer has also the mandate to issue internal social engineering for respective companies to prepare for attacks. If, for instance, a new network attack vector is identified, in a penetration test, then the manager is held accountable. The program Management officer (PMO) and the entire department perform all the activities required to develop and implement an information security plan for client companies including the program based on the plan. There are many roles to be executed by the PMO. They include; is expected to develop and execute the information security programs and procedures; outline the roles and responsibilities of information security; report and communicate with both the interior and exterior clients and stakeholders and manage funds allocated for any information security activities. The PMO, in conjunction with the network infrastructure department, is also expected to manage the servers of the company where they should ensure that the servers are always secure to use and reliable. They should also be able to liaise in checking for threats in their systems and those of their clients.
Data management and cloud computing are deemed to be a vital aspect of network and information security (Vacca, 2012). As a result, the management of data in the networks needs to be reliable since all users rely on them to run their daily company programs. As a result, Compufy Limited has set policies to ensure that the privacy of such data is guaranteed, together with their encryption. Moreover, the Company stores most of their data and that of their client on Cloud which is the most basic practice incorporated into the successful management of data. Thus, cloud computing in conjunction with big data is one of the most exceptional effects that could transpire in any networking system.
2.0. Security Business Requirements
2.1. Capability Maturity Model Integration
Kneuper (2008) defines CMMI in the context of IT as an approach which guides an organization through the process of improving its cyber security. The model guides a firm in the process of assessing its current capabilities and to identify the areas of improvement. Generally, a cyber security CMMI is comprised of the following 5 major components (Paulk, 2009):
a) Devising cyber policy and strategy
b) Encouraging responsible cyber culture within society
c) Building cyber skills into the workforce and leadership
d) Creating effective legal and regulatory frameworks
e) Controlling risks through organization, standards and technology
According to Becker, Knackstedt & Pöppelbuß (2009), CMMI is comprised of several process areas (PA) with each PA being comprised of specific practices that must be implemented together in order to achieve a set of specific objectives. For this security plan, the PA selected is project management which falls under the umbrella of category wise process areas. The choice of this PA is informed by the fact that activities involved in this category are of essential importance to effective implementation of a security plan. The selected PA, its components as well its significance to the selected organization are described hereafter:
2.1.1. Project Planning (PP)
The activities that fall under this purview of PA include budget estimations, scheduling of tasks, risk assessment, and determining human capital requirements (Kneuper, 2008). These activities happen prior to the commencement of the project. This process is highly significant to the operations of Compufy because the firm must develop a comprehensive implementation plan before implementing a security program in a client’s organization.
2.1.2. Integrated project management (IPM)
The activities involved in this category include assessing whether the identified items of capital are available to smooth run the process of implementing the project. For Compufy, this process is essential because without the resources, it cannot successfully implement security programs on the clients’ firms.
2.1.3. Project Monitoring and Control (PMC)
This process aims at providing the relevant guidance for monitoring the progress of implementation of the project (Oberkampf, Pilch & Trucano, 2007). For a project to be successfully completed within the specified time and meet the predefined standards, it must be monitored to avoid deviations. For Compufy, monitoring is an important component because it must satisfy its clients’ security needs within a specified period of time.
2.1.4. Quantitative Project Management (QPM)
QPM, on the other hand, involves making more advanced assessment of the project’s objectives and designing measures aimed at achieving quality needs (Paulk, 2009). Quality is an important aspect of project management which demonstrates why this activity is of essential significance to Compufy limited.
2.1.5. Requirements Management (REQM)
This process occurs during the implementation process and it seeks to advise the implementers whether the project will eventually be a success in terms of solving the problem at hand (Essmann & Du Preez, 2009). If the implementers note substantial failures during the initial days, then the project may be redesigned so that the final objectives are met. For the firm described in this paper, this activity is essential because the firm must align each project it undertakes with the client’s security requirement.
2.1.6. Risk Management (RSKM)
Next, risk management involves assessing the potential risks that are likely to affect the successful implementation of a project (Oberkampf et al. 2007). This process is continuous, and it is based on the historical and present experiences. For Compufy, this endeavor is highly important because for the company to successfully implement security projects in clients’ firms, it must assess all the potential risks and devise strategies to mitigate or reduce them before they occur otherwise the project will fail.
2.1.7. Supplier Agreement Management (SAM)
Lastly, SAM involves controlling delivery and quality of products and services obtained from third parties (Paulk, 2009). Basically, when executing a project, some products and services must be procured from external suppliers. Such supplies must be delivered in a timely manner and in the right quantity and quality. Compufy being a provider of IT security services, it must ensure that the supplies meet the required standards otherwise the client firms might not fully benefit from the project.
3.0. Security Policy
TBD
TBD
TBD
4.0. System Design Principles
TBD
TBD
TBD
5.0. The Training Module
TBD
TBD
TBD
References
Becker, J., Knackstedt, R., & Pöppelbuß, J. (2009). Developing maturity models for IT management. Business & Information Systems Engineering, 1(3), 213-222.
Essmann, H., & Du Preez, N. (2009). An innovation capability maturity model–development and initial application. World Academy of Science, Engineering and Technology, 53(1), 435-446.
Kneuper, R. (2008). CMMI: Improving Software and Systems Development Processes Using Capability Maturity Model Integration. Rocky Nook.
Lincke, S. (2015). Security Planning: An Applied Approach. Cham : Springer International Publishing.
McNab, C. (2007). Network security assessment: know your network. " O'Reilly Media, Inc.".
Oberkampf, W. L., Pilch, M., & Trucano, T. G. (2007). Predictive capability maturity model for computational modeling and simulation (No. SAND2007-5948). Albuquerque, NM: Sandia National Laboratories.
Paulk, M. C. (2009). A history of the capability maturity model for software. ASQ Software Quality Professional, 12(1), 5-19.
Vacca, J. R. (2012). Computer and information security handbook.Newnes.
Zubairi, J. A. (Ed.). (2009). Applications of Modern High Performance Networks.Bentham Science Publishers.