CIS 333: Networking Security Fundamentals
January 27, 2019
MEMO
From: IT Security Dept.
Date: January 2019
Re: Security Policy
New tech internet café is a business located in California. It offers customers with services such as browsing, emailing, printing, chatting, scanning, cloud storage, and uploading and downloading files. It is one of the most competitive internet cafés in the area, as it is strategically located and well equipped with fast browsing internet connection and digital cyber equipment like scanners, photocopiers, and printers. However, the business is faced with many risks. This, if not attended to, can profoundly affect the productivity of the business. According to Chiu, Chiu, & Mansumitrchai, (2016), some of the risks include privacy; it is an issue that has come forth where few cybercafés interrupt the customer. Young customers browse porno websites and engage in objectionable behavior. This has brought panic to the customers who greatly affect the internet cafés. Thus, creating a need for clear monitoring of customers to ensure there are no such behaviors in the internet cafés and also ensure that all the history of a customer is cleared once the session is over. Cloud security issues, according to Shen, Gong, and Bao, (2018), cloud store large amounts of valuable and sensitive data. Even though the café has put more effort in ensuring the security of this service, according to Shen, Gong, and Bao, (2018), there are still some security issues like cloud misconfigurations; this is due to complexities associated with the cloud in securing data, thus, causing errors during the storage of data leading to compromised data. This brings the need for more education and training of the personnel regarding the storage of data using the cloud. Data loss, it is one risk that cannot be ignored, many companies tend to lose data due to human error or other malware attacks. The only way to reduce the risk is backing up data and valuable information about the company in physical encrypted external disks and storing them in different sites. Malware attacks, there is an increase in a file-less malware attack. According to Shen, Gong, and Bao, (2018), it is very difficult to detect and stop malware attacks. Because they have few indicators of compromise and can use victim’s tools pretending to be a genuine process in the system, this attack calls for protection of the websites with antiviruses ensuring safe links. Denial of service (DoS) attack, this is where malicious code is loaded in the web links causing loss or compromised of data. This risk has triggered some measures being implemented to prevent the continuation of these attacks. According to Peltier, (2016), there is a need to create security policies.
New Tech internet café decided to implement some policies in trying to reduce the rate of risks it was experiencing. The policies are:
1. Data loss prevention strategy policy
2. Antivirus protection strategy policy
3. Customer monitoring strategy policy
Data loss prevention strategy policy will help the business to minimize huge cases of data loss and will ensure the safety of sensitive and valuable information both to the café and also third parties, who store their data in the café's cloud. Antivirus protection strategy policy will help the business in fighting the denial of service (DoS) attack, as it will make the website links safe and protected. Customer monitoring strategy policy will help in monitoring the activities of the customers to ensure they do not engage in objectionable behaviors.
· Data loss prevention strategy policy: data loss is one of the serious risks in data storage, it can cause serious problem to the internet café, making it lose trust from its customers. According to Rao, and Selvamani, (2015), data loss prevention becomes one of the most needed roles in internet café, as it ensures the safety of data from the clients and also data from the company. To define the data loss prevention strategy, it important to identify the standards, which are:
· Backing up data before switching off the computer.
· Training of all the personnel on how to store data in the cloud
· Transfer of new sensitive and valuable information to disks taken to IT office
· Data encryption of the data.
Practice: workers need to save and backup every data in the computer by storing in external disks and taking them to the IT department. This will help in ensuring the safety and confidentiality of the information. The external drives with the sensitive information will be encrypted to deny every person the access. Training sessions will be arranged to train the personnel on how to store data in the cloud and prevent the data from having errors or being compromised due to the complexity of the cloud.
· Antivirus protection strategy policy: due to the denial of service (DoS) attack, there is a need to secure the website through antivirus protection; this will ensure safe browsing without the information being tampered with. To define the antivirus protection strategy, it is essential to identify the standards, which are:
· Installation of new antivirus software.
· Personnel to ensure software is enabled and working.
· Scanning of all the websites before switching off the computers
Practice: due to attacks by malware, there is need to secure the websites, thus calling the need for installation of antivirus, which will be double checked by the workers and regularly checked by technicians to ensure they are working efficiently. Also, workers will be scanning the websites before switching off the computers.
· Customer monitoring strategy policy: due to the use of internet café by young customers, there is a need to monitor the café to ensure good behavior. To define the customer monitoring strategy policy, it is important to identify the standards, which are:
· Installation of cameras in the café
· Clearing of the history of the customer before shutting down the computer
Practice: the installation of cameras is essential to monitor the behavior of the customers and also trying to reduce cases of theft in the café. The cameras will be operated and monitored in the operating room, where footage will be recorded every day. Workers should make sure that every customer’s history is cleared at the end of the session.
References
Chiu, C. L., Chiu, J. L., & Mansumitrchai, S. (2016). Privacy, security, infrastructure and cost issues in internet banking in the Philippines: initial trust formation. International Journal of Financial Services Management, 8(3), 240-271.
Peltier, T. R. (2016). Information Security Policies, Procedures, and Standards: guidelines for effective information security management. Auerbach Publications.
Rao, R. V., & Selvamani, K. (2015). Data security challenges and its solutions in cloud computing. Procedia Computer Science, 48, 204-209.
Shen, J., Gong, S., & Bao, W. (2018). Analysis of Network Security in Daily Life. Information and Computer Security, 1(1).