A Proposal to Improve Security of IT Systems in UOTC Inc.
A Proposal to Improve Security of IT Systems in UOTC Inc.
From the preliminary findings in the first internal audit report about the security conditions of the ICT-reliant systems, the company’s critical assets are so much exposed to cyber-based threats and are vulnerable to attacks. To enhance security and protect of these assets, the company should adhere to the recommendations discussed herein.
Corporate Wireless Network
At the moment the wireless network is only protected by Wired Equivalent Privacy (WEP) security protocol. This type of protection has two major weaknesses which make it incapable of providing adequate security for a given WLAN; these flaws are (a) provide a short initialization vector (IV) which is also reusable and (b) the authentication messages can be easily forged by an adversary (Juwaini, Alsaqour, Alsokour, & Abdelhaq, 2015). Apart from these gaps in the protection of the corporate wireless network, customers in a nearby coffee shop can access the network, thus, adding another channel which could be exploited by a malicious customer to sabotage critical systems in the company. Indeed, the incapability of WEP to determine whether data packets from a given source are valid or not make it necessary for the company to prevent external users from accessing the WLAN (Juwaini, Alsaqour, Alsokour, & Abdelhaq, 2015). WEP can also be cracked with ease using tools which are readily available to any internet user.
To secure the corporate wireless network from the risks mentioned above, the security team should replace the Rivest Cipher 4 (RC4) WEP algorithm with Linear Feedback Shift Register (LFSR). LFSR would improve wireless network security by 70 percent without the need to replace the hardware already in place (Juwaini, Alsaqour, Alsokour, & Abdelhaq, 2015). Alternatively, the company could choose to replace WEP with Wi-Fi Protected Access (WPA), either WPA or WPA2; these two security protocol eliminates the security deficiencies of WEP by using “Temporal Key Integrity Protocol (TKIP) for data encryption” (Wireless Network Security, 2010). For instance, WPA2 would eliminate the possible threats from the coffee shop’s customers by denying them access to the wireless network.
Application and Access Control
It is unfortunate that the company has allowed all users to have full administrative access to every application in the organizations including access to critical applications that should be used only by management because this exposes the IT infrastructures to attacks. An article by Harvard Business Review (2016), highlighted that the inside users of IT systems cause up to 60 percent of all attacks in a company (Zadelhoff, 2016). Therefore, as the CISO in UOTC Incorporation, I recommend that the company adopt a more diverse and dynamic access control strategy to eliminate the risks due to access to critical applications by many users. The company can achieve this by adopting layered access controls which includes two types of access control, i.e., one for the application environment and the other one for the operating system which host the applications (Amoroso, 2011). In this case, only the management should possess the access combination for the operating system such that the applications can only be accessed through the authorization by the administration. The other users could be given access to use the applications, but they can only access the application environment through the management.
Data Encryption Level
The company is currently using an outdated cryptographic algorithm. Before the start of 21st century, Data Encryption Standard (DES) was considered as a well-established and standard encryption algorithm; however, as the digital era matured, the strength of DES algorithm was rendered insufficient in protecting confidential information. And in the year 2005, DES was discredited as an approved encryption algorithm; therefore, the company should replace it with an alternative security mechanism (Barker, 2016). DES uses a standard 56-bit encryption key for defense making is vulnerable to cracker by the use of brute force methods; such weakness led to its disapproval as a reliable encryption algorithm (Stapko, 2008). And for the company to continue using a symmetric key, DES should be replaced by a Triple Data Encryption Algorithm (TDEA) which unlike DES uses three 56-bit keys (offering a larger key size) to allow a higher level of security for the company’s assets (Stapko, 2008).
References
Amoroso, E. G. (2011). Cyber Attacks: Protecting the National Infrastructure. Burlington: Elsevier Inc.
Barker, E. (2016, August). Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms. Retrieved from National Institute of Standards and Technology: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-175b.pdf
Juwaini, M., Alsaqour, R., Alsokour, O., & Abdelhaq, M. (2015). A review on WEP wireless security protocol. Journal of Theoretical and Applied Information Technology, 40(1), 39-42.
Stapko, T. (2008). Practical Embedded Security: Building Secure Resource-Constrained Systems. Elsevier Inc.
(2010). Wireless Network Security. Hong Kong: The Government of the Hong Kong Special Administrative Region. Retrieved from https://www.infosec.gov.hk/english/technical/files/wireless.pdf
Zadelhoff, M. V. (2016, September 19). The Biggest Cybersecurity Threats Are Inside Your Company. Retrieved from Havard Business Review: https://hbr.org/2016/09/the-biggest-cybersecurity-threats-are-inside-your-company
2