project 2

profileschool101
Harishvadnala_CS654_ip4.docx

Running Head: COMPUFY LIMITED 2

COMPUFY LIMITED 2

CS654_Security Management

Compufy Limited

Harish Vadnala

Colorado Technical University

9/12/2018

Contents 1.0. Security Requirements 4 1.1. Hypothesized Organization: Compufy Limited 4 1.1.1. Corporate organizational chart 6 1.1.2. Work Group structure and ties added to the corporate organizational chart 6 1.1.3. Communication flows of Work Groups of Compufy Limited 7 2.0. Security Business Requirements 9 2.1.1. Project Planning (PP) 9 2.1.2. Integrated project management (IPM) 10 2.1.3. Project Monitoring and Control (PMC) 10 2.1.4. Quantitative Project Management (QPM) 10 2.1.5. Requirements Management (REQM) 10 2.1.6. Risk Management (RSKM) 11 2.1.7. Supplier Agreement Management (SAM) 11 3.0. Security Policy 12 3.1. Areas of Risk Management 12 3.1.1. Risk Identification 12 3.1.2. Risk Assessment 12 3.1.3. Risk Control Strategies 13 4.0. System Design Principles 15 4.1. Principle 1: Clearly Define Security Dependencies and Trust Boundaries 15 4.2. Principle 2: Assure Robust Identity 15 4.3. Principle 3: Protect the Information Security Triad 16 4.4. Principle 4: Make Systems Secure by Default 16 4.5. Principle 5: Provide Accountability and Traceability 17 5.0. The Training Module 18 References 19

Compufy Limited

1.0. Security Requirements

Network security consists of procedures and practices that are initiated to inhibit access by unsanctioned persons, exploitation, and alteration by these kinds of people or denial of computer network and resources that can be accessed through a given interface. Such networks are controlled by network administrators who are given authority to authorize access of certain data to a given group of individuals. The focus of this paper is on the security of networks which involves a number of significant features for it to be considered secure. Some of these features include the authentication of users and the denial of a computer network to intruders (Lincke, 2015).

There are a number of attacks that can be faced in any network, more so where a loophole is noted by the attackers. Some of these attacks include: Port Scanning, Wiretapping Denial-of-Service (DoS), Distributed Denial-of-Service (DDoS) attack, Phishing, Cross-Site Request Forgery (CSRF), SQL Injections, XSS Attack, ARP Poisoning, Buffer Overflow (McNab, 2007). With these being identified, a strong security management plan needs to be put into place whereby, these loopholes need to be secured.

1.1. Hypothesized Organization: Compufy Limited

Compufy Limited, a company that was established to help different organizations to secure their information through ensuring that there exists a high and efficient level of network and information security, is located in the United States, and was set up in 2016 with the aim of developing the network and information security (NIS) in the society and also to create awareness of NIS and as a result, contributing towards the development of the internal market. Its primary aim was to create minimal risks associated to the network, thus allowing their users and organizations to handle their network easily without any disruption. The company is, therefore, found to contain all these strengths where the use of IDs and passwords are used to authorize viewing of information among other network management strategies. The company aims to ensure that the community and its members are protected from malfunctions in the network that affects the information saved on anyone’s device. Of much importance, Compufy Limited aims at managing risks and assessing them. These are found to be essential parts of information security management and, as a result, are vital to the founding of security in organizations.

1.1.0. Initial Security Projects

Primarily, the company has been working hand in hand with different organizations to secure their networks. One of the first security projects was the accountability of information use. This involved the privacy and fairness in decision-making systems (Zubairi, 2009). This project dealt with the making of decisions of the automated systems that process personal data of the company’s clients. Most organizations and working groups which linked up with the Compufy Limited were excited over the positive contributions of the systems installed in their premises. However, most of them raised severe trepidations of their data not being secure and private. This, after this project, has been identified to be the major concern of most organizations. With updated systems containing machine learning algorithms, such problems have been curbed, and the company aims at helping more organizations stabilize and gain control of their network and information systems. Thus, the issue was subdued by explaining to the users how the systems were automated to be accountable for their privacy.

The cloud is rapidly changing the face of the web infrastructure, allowing even the minute corporates to create quick web and mobile applications for their users through taking advantage of the of the scale of flexibility of the physical shared infrastructure created by cloud providers, the academic community, however, is at risk of being left out of this hypothetical change. A problem Compufy identified was the network virtualization, which was found to be a hindrance. However, the company came up with suitable network virtualization that puts all the non-significant packet transformations at the verge of the corporeal system. The company is further planning on developing programs that will extend to a more sophisticated network functionality that will enable clients to be able to manage all their data in the small cloud space.

1.1.1. Corporate organizational chart

The company’s structure can briefly be outlined as below.

D:\client\organizational chart.PNG

This is based on the major departments, their functions and sub-functions, and also their activities.

1.1.2. Work Group structure and ties added to the corporate organizational chart

The Workgroup structure is based on the realistic goal of the company which is aimed at reaching maximum security stabilization in the networks. To begin with, there is the deputy of Compufy who reports to the head of the company. The deputy is also advised by the Information Security Council that is made up of the Chief Risk Officer, CFO among other major leaders of the company who take part in major decisions of the company before any process is executed.

1.1.3. Communication flows of Work Groups of Compufy Limited

For an organization to have realistic goals there must be an order in which decisions are made. For Compufy Limited, the Chief Strategy Officer (CSO), who is responsible for executing the major security programs and protecting the information assets of the company, reports to the Chief Information Officer (CIO). In exceptional cases that require financial aid, the CSO reports to the Chief Risk Officer. This, therefore, helps in the coordination of the security team in the execution of the security policies of the organization. Moving down, there is the network infrastructure officer who ensures that security of data, i.e., through networks, endpoints and data centers are safe and secure. Irrespective of where the work is being done, the infrastructure officer needs to ensure that all resources are well-coordinated.

There is also the application and asset security department which ensures that the CSO is not caught by surprise in case of any Network and Information System failures. The officer always checks all systems and networks randomly to ensure that there are no exploits that can compromise the client or organization. If any faults are found, then suitable assets are provided to fix concerns found. The officer has also the mandate to issue internal social engineering for respective companies to prepare for attacks. If, for instance, a new network attack vector is identified, in a penetration test, then the manager is held accountable. The program Management officer (PMO) and the entire department perform all the activities required to develop and implement an information security plan for client companies including the program based on the plan. There are many roles to be executed by the PMO. They include; is expected to develop and execute the information security programs and procedures; outline the roles and responsibilities of information security; report and communicate with both the interior and exterior clients and stakeholders and manage funds allocated for any information security activities. The PMO, in conjunction with the network infrastructure department, is also expected to manage the servers of the company where they should ensure that the servers are always secure to use and reliable. They should also be able to liaise in checking for threats in their systems and those of their clients.

Data management and cloud computing are deemed to be a vital aspect of network and information security (Vacca, 2012). As a result, the management of data in the networks needs to be reliable since all users rely on them to run their daily company programs. As a result, Compufy Limited has set policies to ensure that the privacy of such data is guaranteed, together with their encryption. Moreover, the Company stores most of their data and that of their client on Cloud which is the most basic practice incorporated into the successful management of data. Thus, cloud computing in conjunction with big data is one of the most exceptional effects that could transpire in any networking system.

2.0. Security Business Requirements

2.1. Capability Maturity Model Integration

Kneuper (2008) defines CMMI in the context of IT as an approach which guides an organization through the process of improving its cyber security. The model guides a firm in the process of assessing its current capabilities and to identify the areas of improvement. Generally, a cyber security CMMI is comprised of the following 5 major components (Paulk, 2009):

a) Devising cyber policy and strategy

b) Encouraging responsible cyber culture within society

c) Building cyber skills into the workforce and leadership

d) Creating effective legal and regulatory frameworks

e) Controlling risks through organization, standards and technology

According to Becker, Knackstedt & Pöppelbuß (2009), CMMI is comprised of several process areas (PA) with each PA being comprised of specific practices that must be implemented together in order to achieve a set of specific objectives. For this security plan, the PA selected is project management which falls under the umbrella of category wise process areas. The choice of this PA is informed by the fact that activities involved in this category are of essential importance to effective implementation of a security plan. The selected PA, its components as well its significance to the selected organization are described hereafter:

2.1.1. Project Planning (PP)

The activities that fall under this purview of PA include budget estimations, scheduling of tasks, risk assessment, and determining human capital requirements (Kneuper, 2008). These activities happen prior to the commencement of the project. This process is highly significant to the operations of Compufy because the firm must develop a comprehensive implementation plan before implementing a security program in a client’s organization.

2.1.2. Integrated project management (IPM)

The activities involved in this category include assessing whether the identified items of capital are available to smooth run the process of implementing the project. For Compufy, this process is essential because without the resources, it cannot successfully implement security programs on the clients’ firms.

2.1.3. Project Monitoring and Control (PMC)

This process aims at providing the relevant guidance for monitoring the progress of implementation of the project (Oberkampf, Pilch & Trucano, 2007). For a project to be successfully completed within the specified time and meet the predefined standards, it must be monitored to avoid deviations. For Compufy, monitoring is an important component because it must satisfy its clients’ security needs within a specified period of time.

2.1.4. Quantitative Project Management (QPM)

QPM, on the other hand, involves making more advanced assessment of the project’s objectives and designing measures aimed at achieving quality needs (Paulk, 2009). Quality is an important aspect of project management which demonstrates why this activity is of essential significance to Compufy limited.

2.1.5. Requirements Management (REQM)

This process occurs during the implementation process and it seeks to advise the implementers whether the project will eventually be a success in terms of solving the problem at hand (Essmann & Du Preez, 2009). If the implementers note substantial failures during the initial days, then the project may be redesigned so that the final objectives are met. For the firm described in this paper, this activity is essential because the firm must align each project it undertakes with the client’s security requirement.

2.1.6. Risk Management (RSKM)

Next, risk management involves assessing the potential risks that are likely to affect the successful implementation of a project (Oberkampf et al. 2007). This process is continuous, and it is based on the historical and present experiences. For Compufy, this endeavor is highly important because for the company to successfully implement security projects in clients’ firms, it must assess all the potential risks and devise strategies to mitigate or reduce them before they occur otherwise the project will fail.

2.1.7. Supplier Agreement Management (SAM)

Lastly, SAM involves controlling delivery and quality of products and services obtained from third parties (Paulk, 2009). Basically, when executing a project, some products and services must be procured from external suppliers. Such supplies must be delivered in a timely manner and in the right quantity and quality. Compufy being a provider of IT security services, it must ensure that the supplies meet the required standards otherwise the client firms might not fully benefit from the project.

3.0.  Security Policy

The main reason why organizations create security policies is to minimize the risk of threats to the organization's security. An organization needs to evaluate possible threats and be able to implement countermeasures to guard against those threats. This is not an easy thing to accomplish; however, with the right leadership, security models, and organizational vision, risk can be minimized.

3.1. Areas of Risk Management

An organization must understand the risks that it faces. An initial step in risk management involves the discovery and evaluation of threats. The evaluation process includes the identification of an organization’s assets and rating the probability of attack for each asset in the organization. The following are the key areas of risk management that should be addressed by an organization to minimize the impact of threats (Whitman &Mattord, 2008):

3.1.1. Risk Identification

In risk identification, an organization inventories its assets and identifies assets that are vulnerable to attack. Vulnerabilities are identified for each asset. Organizational assets include people, places, data, and technology. Assets are classified by placing them into categories and prioritizing categories based on their value to the organization.

3.1.2. Risk Assessment

In risk assessment, a risk score is assigned to each vulnerability. This score is used as a comparative rating against the risk scores of all identified vulnerabilities for the organization. There are several factors that go into this risk score, including the probability of the vulnerability occurring, the value of the asset for which the vulnerability is identified, the quality of the controls to mitigate the risk, and the uncertainty of the vulnerability.

3.1.3. Risk Control Strategies

After an organization has identified and assessed risks, it must implement strategies to control those risks. There are several strategies that can be considered. One preferred strategy is avoidance, which prevents the exploitation of the risk. This can be accomplished with the following techniques (Whitman &Mattord, 2008):

a) Policy application- Mandating that certain policies be followed

b) Training and evaluation- Continuous training for employees on security risks and threats

c) Threat countermeasures- Countering a threat before it strikes

d) Implementation of technical controls- Implementing hardware and software controls to stop a threat when it appears

To effectively implement the above listed risk control strategies, the firm needs to perform certain procedures that are described hereafter:

a) System Description

Identify the characteristics of the IT system for which the risk management plan is being developed. Examples include identifying the information, hardware, software, and boundaries of the system.

b) Identification of Threats

Identify sources of threats that have the potential to take advantage of a weakness in an IT system.

c) Identification of Vulnerability

Identify weaknesses in the IT system that predisposes the firm to the risk of security breaches.

d) Control Evaluation

Evaluate controls that are in place or are planned that will protect the system from threats.

e) Potential of Impact

Analyze the impact of a threat successfully exploiting a system weakness.

f) Risk Assessment

Evaluate the likelihood of threat occurrence, its impact on the system, and the controls in place to counter the threat.

g) Identification of Controls

Determine the controls that will protect the system from threats.

h) Results Analysis

Develop a management report that discusses the results of the risk analysis.

4.0. System Design Principles

4.1. Principle 1: Clearly Define Security Dependencies and Trust Boundaries

One of the most important security principles in the context of Compufy is clearly defining the security dependencies between the different components of a system. Defining such dependencies facilitates formulation of suitable strategies to ensure that the entire system remains secure (Pentikousis, Wang & Hu, 2013). Based on this principle, Compufy needs to identify any interrelations between the systems’ components. Such interrelations should be clearly defined, and the information should be made accessible to the ground security personnel. Also, of great importance as regards trust boundaries is that the company should avoid circular dependencies because this may complicate the process of administering network and infrastructure security.

4.2. Principle 2: Assure Robust Identity

The other principle that is important to the security of the company identified in this project is the assurance of robust identity. This principle entails identifying each component of the system and ascertaining that the components are from trusted sources. This principle is greatly important to the security of a firm in that it helps an organization to build effective authentication, authorization, and accounting implementations. According to Chen et al. (2016), an effective robust identity system should exhibit the following characteristics:

Should have the ability to distinguish its owner from other entities within a pre-defined scope

Should have the ability to be generated, updated, and revoked

Impersonation prevention, preferably through strong cryptographic mechanisms.

4.3. Principle 3: Protect the Information Security Triad

Next, although the company’s primary objective should be to achieve confidentiality, integrity, and availability (CIA) of the system, it needs to go past the core pillars and ensure that each security control added to the system does not predispose other parts of the system to the risk of security threats. Additionally, a firm must check to see if a proposed security control limits the availability of the entire system (Pentikousis et al. 2013). If such limitation is detected, then the control should be rejected, and an alternative control should be installed. An installation of a centralized security server, for example, must be closely monitored to ensure that its installation does not impact the availability of the system. If the security personnel foresee any limitation to the system’s performance because of this installation, then an effective control strategy should be formulated.

4.4. Principle 4: Make Systems Secure by Default

The other security principle applicable in this case is default security mechanisms. According to Wyglinski, Nekovee & Hou (2009), default security involves configuring an automatic security controls to ensure that the system remains secure. An example of a default security system is the requirement for passwords when accessing a company’s network. These automatic controls should not be removable by third parties. In other words, the controls should only be removable by the security operator. These controls should never, however, be completely disabled as this would predispose the firm to the risk of security threats.

4.5. Principle 5: Provide Accountability and Traceability

For a security policy to be effective, it must be regularly audited to ensure that it meets the set thresholds. To facilitate auditing, a firm must ensure that any logged data is enough to facilitate auditing as when such an endeavor becomes inevitable (Scott-Hayward, Natarajan & Sezer, 2016). In addition to sufficiency, the logged data need to be traceable which implies that an auditor should easily determine the beneficiary of each action taken by a firm. The application of this principle in Compufy would entail ensuring that the companies it serves have proper mechanisms to ensure data auditing.

5.0. The Training Module

TBD

TBD

TBD

References

Becker, J., Knackstedt, R., & Pöppelbuß, J. (2009). Developing maturity models for IT management. Business & Information Systems Engineering1(3), 213-222.

Chen, M., Qian, Y., Mao, S., Tang, W., & Yang, X. (2016). Software-defined mobile networks security. Mobile Networks and Applications21(5), 729-743.

Essmann, H., & Du Preez, N. (2009). An innovation capability maturity model–development and initial application. World Academy of Science, Engineering and Technology53(1), 435-446.

Goguen, A., & Feringa, A. (2002, July). Risk management guide for information technology systems (NIST Special Publication 800-30). Retrieved May 23, 2007, from the National Institute of Standards and Technology Web site: http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf

Kneuper, R. (2008). CMMI: Improving Software and Systems Development Processes Using Capability Maturity Model Integration. Rocky Nook.

Lincke, S. (2015). Security Planning: An Applied Approach. Cham : Springer International Publishing.

McNab, C. (2007). Network security assessment: know your network. " O'Reilly Media, Inc.".

Oberkampf, W. L., Pilch, M., & Trucano, T. G. (2007). Predictive capability maturity model for computational modeling and simulation (No. SAND2007-5948). Albuquerque, NM: Sandia National Laboratories.

Paulk, M. C. (2009). A history of the capability maturity model for software. ASQ Software Quality Professional12(1), 5-19.

Pentikousis, K., Wang, Y., & Hu, W. (2013). Mobileflow: Toward software-defined mobile networks. IEEE Communications magazine51(7), 44-53.

Scott-Hayward, S., Natarajan, S., & Sezer, S. (2016). A survey of security in software defined networks. IEEE Communications Surveys & Tutorials18(1), 623-654.

Vacca, J. R. (2012). Computer and information security handbook.Newnes.

Whitman, M. E., &Mattord, H. J. (2008). Management of information security (2nd ed.). Boston: Course Technology.

Wyglinski, A. M., Nekovee, M., & Hou, T. (Eds.). (2009). Cognitive radio communications and networks: principles and practice. Academic Press.

Zubairi, J. A. (Ed.). (2009). Applications of Modern High Performance Networks.Bentham Science Publishers.