Homework Responses Wk 5
Defense-in-Depth (DiD)
The DiD strategy can be translated and utilized in all forms of security. This approach's main objective is to implement a series of security controls and features that are layered to protect the integrity of a system or organization. DiD is widely used amongst IT professionals when implementing protocols to protect sensitive data. Detection systems employed, especially in the modern age, are heavily monitored by software systems and other technological equipment. DiD, if implemented correctly, can ensure that the technology that maintains the operational capabilities of the detection systems remains working and doing what its intended purpose was. Hackers may try to tap into a system to stop whatever piece of equipment is used actually to make the entry. If the proper defense-in-depth measures are implemented within the network system, then the intruders will not be able to or will have a hard time breaking through the IT security measures. Therefore, the detection systems will remain operational, thwarting any kind of intrusion or alerting to it. DiD promotes the safety and security of the system's integrity.
Methods that ensure system performance in detection systems
Ensuring that a detection system an organization uses remains to the standard that is expected, quantitative testing must be done regularly. Certain detection systems, such as motion detection or camera systems, can be physically tested to document the detection rate and detection quality. If a motion sensor does not send a signal to the operator promptly, the intruder may swiftly move past the detector and to a new area making it hard to determine the exact location of the intruder. Utilizing software such as a Network Security Monitor to construct user-simulations can also help ensure the detection systems are working properly. Conducting simulated tests for a piece of equipment or software puts the technology through rigorous scenarios to push the capabilities to the brink. This is the best way to determine if the systems can meet the organization's needs, expectations, and specifications deemed necessary. Simulations can also be run periodically to test the durability of a system by an organization. Durability should be a key element for conducting inspections and quality assurance. Otherwise, an organization possibly spending thousands to hundreds of thousands of dollars on a detection system could have a costly paperweight after a short period of time. Overall, incorporating testing and simulations based on best-known scenarios is the best option to ensure that the detection system in question can meet the organizations' needs.
· Nick
References:
N. J. Puketza, K. Zhang, M. Chung, B. Mukherjee, and R. A. Olsson, "A methodology for testing intrusion detection systems," in IEEE Transactions on Software Engineering, vol. 22, no. 10, pp. 719-729, Oct. 1996, DOI: 10.1109/32.544350.