Project 1: Vulnerability and Threat Assessment Step 2: Create a Scope of Work (SoW)
Project 1: Vulnerability and Threat Assessment Step 2: Create a Scope of Work (SoW)
In this step, you will perform a vulnerability assessment once again as the CISO. Since the previous contractor was an external consultant, you will be able to offer insights and consider the big picture of the organization when conducting the assessment. You will prepare for the assessment by creating a comprehensive list of security needs based on findings from the previous step. This list should identify threats, risks, and vulnerabilities to achieve a holistic view of the risk across the entity.
The scope of work is the key element to any project and important to learn. It should be filed as supplementary documentation for purposes of evaluating execution and directional purposes of meeting milestones of a multiphase comprehensive project plan within the vulnerability assessment. The scope of work will be the first section of the final vulnerability assessment report.
Combine the overview from the previous step with the list of security needs into a one-page SoW report. Submit the report for feedback.
· Protect Your Information From Physical Threats
· Vulnerability Scanning With Metasploit Using Nessus
Learning Topic
Cybersecurity Vulnerability
An old adage goes: "The only computer that is not in danger is a computer that is turned off." Cybersecurity professionals must identify and explain the main vulnerabilities against a company's critical infrastructure.
A cybersecurity vulnerability is any weakness that may compromise the CIA triad (confidentiality, integrity, and availability) of a product. A cybersecurity vulnerability can never be completely eliminated; therefore, countermeasures must be in place to mitigate the potential disaster to a business's ability to operate after a potential attack.
The confidentiality, integrity, and availability (CIA) triad is at the core of information system security. Information system security professionals use the CIA triad as a mechanism for quantifying the key security considerations of an information system. When a system is under development, each of the CIA concepts must be considered as part of the system's design objectives. Below is a model of the CIA triad.
Confidentiality, Integrity, Availability (CIA)
Source: Janet Zimmer
Confidentiality refers to the methods used to protect information from unauthorized disclosure. Protecting the confidentiality of proprietary or sensitive information is of vital importance.
Integrity refers to the processes that ensure accuracy of information.
Availability addresses the need of a system to provide continued, reliable access to information while maintaining an acceptable level of performance. Consider organizations with technology and services that must be nearly 100 percent available 24 hours a day, 365 days a year, such as financial institutions, emergency service providers, power providers, and communication providers. Every moment that these organizations cannot exchange information, there is the potential for serious financial loss, injury, or even death.
Learning Topic
Vulnerability Assessment
A vulnerability is a "weakness in any information system, security production, internal controls, or implementation that could be exposed by a threat source" (NIST, 2012, p. 9). Vulnerabilities may result from an improperly configured system (weak passwords, unnecessary ports and protocols, etc.), as well as from missing software patches.
Vulnerability assessments involve the use of tools and processes to identify vulnerabilities present in the systems for which an organization is responsible. A vulnerability assessment identifies errors which could be used by hackers.
Vulnerability assessment is an important part of an organization's overall risk management strategy. Such assessments are conducted to meet governmental regulations and requirements, and to help guide organizational IT security practices, stay on top of emerging security threats, ensure that staff members are using appropriate measures, and to demonstrate to customers that your organization is vigilant on security issues.
One commonly used assessment tool is a vulnerability scanner, used to create a network map or inventory that identifies systems that are functional on a network, as well as their open ports, running services, and operating systems (such as Microsoft Windows 7, Linux, etc.). Once a map has been created, the vulnerability scanner can assess systems with a database of known vulnerabilities.
Other tools and processes used to identify, quantify, and prioritize a system's vulnerabilities include network discovery, network port and service identification, documentation and log review, integrity checking, or a combination of several methods.
References
National Institute of Standards and Technology (NIST). (2012, September). Special publication 800-30, revision 1: Guide for conducting risk assessments. http://dx.doi.org/10.6028/NIST.SP.800-30r1
Learning Topic
Project Statement of Work
By Adrienne Watt and bpayne
The statement of work (SOW), sometimes called the scope of work, is a definition of a project’s parameters—factors that define a system and determine its behavior—and describes the work done within the boundaries of the project, and the work that is outside the project boundaries.
The SOW is typically a written document that defines what work will be accomplished by the end of the project—the deliverables of the project. The project scope defines what will be done, and the project management plan defines how the work will be accomplished.
No template works for all projects. Some projects have a detailed scope of work, and some have a short summary document. The quality of the scope is measured by the ability of the project manager and project stakeholders to develop and maintain a common understanding of the products or services the project will deliver.
The size and detail of the project scope is related to the complexity profile of the project. A more complex project often requires a more detailed and comprehensive scope document.
According to the Project Management Institute (2008), the scope statement should include the following components:
· description of the scope
· product acceptance criteria
· project deliverables
· project exclusions
· project constraints
· project assumptions
The scope document is the basis for agreement by all parties. A clear project scope document is also critical to managing change on a project. Since the project scope reflects what work will be accomplished on the project, any change in expectations that is not captured and documented creates an opportunity for confusion.
One of the most common trends in project management is the incremental expansion in the project scope. This trend is labeled scope creep. Scope creep threatens the success of a project because the small increases in scope require additional resources that were not in the plan.
Increasing the scope of the project is a common occurrence, and adjustments are made to the project budget and schedule to account for these changes. Scope creep occurs when these changes are not recognized or not managed. The ability of a project manager to identify potential changes is often related to the quality of the scope documents.
References
Project Management Institute, Inc. (2008). A guide to the project management body of knowledge (PMBOK guide) (4th ed.). Project Management Institute, Inc.
Licenses and Attributions
Chapter 4: Framework for Project Management by bpayne and Adrienne Watt from Project Management is available under a Creative Commons Attribution 4.0 International license. © 2014, Adrienne Watt. UMUC has modified this work and it is available under the original license. Download this book for free at http://open.bccampus.ca.
Project 1: Vulnerability and Threat Assessment Step 2: Create a Scope of Work (SoW)
In this step, you will perform a vulnerability assessment once again as the CISO. Since the previous contractor was an external consultant, you will be able to offer insights and consider the big picture of the organization when conducting the assessment. You will prepare for the assessment by creating a comprehensive list of security needs based on findings from the previous step. This list should identify threats, risks, and vulnerabilities to achieve a holistic view of the risk across the entity.
The scope of work is the key element to any project and important to learn. It should be filed as supplementary documentation for purposes of evaluating execution and directional purposes of meeting milestones of a multiphase comprehensive project plan within the vulnerability assessment. The scope of work will be the first section of the final vulnerability assessment report.
Combine the overview from the previous step with the list of security needs into a one-page SoW report. Submit the report for feedback.