Assignment and discussion
Week 1 Cyber Defence and Countermeasures/cf_anchor_hosp_scenario.docx
IT4070
Anchor Hospital Scenario
You are a network specialist hired by Anchor Hospital to address network infrastructure vulnerabilities. Your initial work is broad and expected to encompass the following:
Understanding the network.
Firewalls.
Physical security.
Cloud solutions.
Intrusion detection.
VPN solutions.
Incident response and countermeasures.
Policy and regulatory issues.
Network exposure assessment and control.
Company Information
Anchor Hospital is a small independent care facility in a stand-alone building that houses its IT staff and assets in the basement. The IT infrastructure and staff of six serve 1,200 employees and other users.
Physical Security
The hospital is on a 10-acre campus in an urban neighborhood. Its IT-related physical security consists of:
A contracted security firm, which supplies two 24/7 guards: one of whom conducts hourly foot patrols, and the second who monitors cameras and performs additional security-related functions.
High-definition cameras that record continuously, located at all points of building entry and sensitive access points including the server room.
Three locked data-center doors requiring key card access that records all traffic. All staff have access cards for their respective departments; only IT staff, janitors, and upper management have access to the IT facility.
IT Overview
Network
Hospital connected to the Internet.
Network segmented into virtual LANs for medical data, IT, and finance user groups.
Hardware
Windows 2008 domain servers: email, file/print, data servers.
Routers connect switches to VLANs.
Switches connect desktops and servers to network.
Web server located in the DMZ.
100 antimalware-protected Windows XP workstations with Internet access.
Wireless access point.
Software
Windows firewall on a workstation at the edge of the network.
SNORT intrusion detection system (IDS), located in front of the Windows firewall.
MS Office installed on workstations.
Enterprise-level proprietary medical software.
Oracle Enterprise Resource Planning (ERP) software.
2017 version of free AVG Antivirus.
1
2
Week 1 Cyber Defence and Countermeasures/Cyber Defence- Week 1.docx
Discussion – 1 page
Common Network Attacks
For this discussion, review the Anchor Hospital Scenario (linked in Resources) and complete the following:
Discuss a common attack that might be perpetrated on the Anchor Hospital network infrastructure. How might this attack be conducted? What might be its goals? Identify a countermeasure to mitigate such an attack.
Assignment –
Identifying Network Security Components
Overview
Getting to know your network is an important first step in securing it. In this assignment you diagram the Anchor Hospital network, identifying its vulnerabilities and a significant threat that it might face.
Preparation
· Review the Anchor Hospital Scenario (linked in Resources).
· Identify an appropriate graphics or diagramming tool (such as Visio) to complete the assignment diagram.
· Refer to the Create a Network Diagram tutorial in Resources as needed.
Instructions
Complete the following:
· Create a diagram that accurately reflects the Anchor Hospital Network as defined in the scenario. There are several possible interpretations. The goal is to include all network components listed in the scenario and place them in reasonable locations. You will develop this diagram further in future assignments.
· Describe two network vulnerabilities and two countermeasures currently on the network.
· Identify and describe a significant threat to the Anchor Hospital network infrastructure given its current configuration. There is no single correct answer, but it is critical that you support your choice with strong rationale and evidence.
Additional Requirements
· Label your document clearly.
· Use an appropriate typeface and size, such as Times New Roman, 12 points, for body copy. Use double-spacing.
· Apply current APA style and formatting. An optional APA template is linked in Resources for your convenience.