05823 - 2 - Pages Within 12Hrs

profileltdprinwival
Wk1-JamesMoring-security_overview.pptx

Security Overview

CMGT/433 Cyber Security

Name

University of Phoenix

April 3, 2019

Dayton Soft Products

Executive Staff Presentation

Introduction

Good morning, and thank you for attending this important presentation. We will begin momentarily. **PAUSE**

1

Introduction

Introduction

Dayton Soft Products was established in 2001 and has recently hired 55 new employees which brings our current onsite employee count to 155. In addition to onsite employees, we also employ over 743 offsite employees who reside in locations all across the globe. The reason for our increased hiring trends is as a direct result of our product line tripling over the last five years. With this growth, our annual revenues have increased from $73k in 2010 to over $3.3 million at the end of Financial Year 2017. While this is exciting news, protecting our data and information assets is paramount to long-term business continuity. Therefore, this presentation represents an overview of our new Cyber security Plan for Dayton Soft Products.

2

National Institute of Standards and Technology

cybersecurity makes reference to the protection of information through detection, response and prevention of attacks (NIST, 2019).

National Initiative for Cyber Security Careers and Studies

ability, process, or activity through which communication and information systems are protected against unauthorized use, damage, exploitation or modification (NICCS, 2019).

Cybersecurity Defined

Cybersecurity Defined

In today’s society, data and information are considered valuable assets. Protecting data is paramount to sustaining long-term business continuity for most companies. Companies must manage and control data to provide a secure environment that is protected from cyber attack. Security goals are identified as being accountability, integrity, availability, and confidentiality of data and information assets. According to the “National Institute of Standards and Technology” (NIST), cybersecurity makes reference to the protection of information through detection, response and prevention of attacks (Kahyaoglu & Caliyurt, 2018). Another definition for Cybersecurity comes from the “National Initiative for Cyber Security Careers and Studies” (NICCS), who views Cybersecurity as an ability, process, or activity through which communication and information systems are protected against unauthorized use, damage, exploitation or modification (NICCS, 2019). In simpler terms cybersecurity can be viewed as the protection of data from cyberspace.

3

Cybersecurity vs. Enterprise Security

Cyber security versus Enterprise Security – How do they differ?

Cyber security is different from Enterprise security in that it is focused on protecting digital data from threats in cyberspace. Enterprise security, on the other hand, protects all types of data in general. Both cyber security and enterprise security work together in protecting a company’s main asset, its data, from destruction, modification, theft, recording, unauthorized use, unauthorized access, inspection, and disclosure (Secureworks.com, 2019). Cybersecurity can be seen as protecting both enterprise and data from outside sources.

4

Dayton Soft Products

Cybersecurity Milestones Timeline

Timeline & Brief Explanation of Cyber Milestones

Timelines are very important when creating a solid Security Plan. The Dayton Soft Products timeline, as shown on the screen, illustrates individual milestones that describe elements of a cybersecurity plan and identifies when and how these elements will be implemented. According to Pfleeger & Pfleeger (2015), the dates have been used to set milestones to ensure the management keeps track of the implementation progress (Timetable, p. 677). Milestones are an important part of a timeline, within a Security plan, because it helps ensure that security controls are implemented in a specific order, usually, the critical threats take priority. (Excel Spreadsheet/Chart attached).

5

Dayton Soft Products

Cybersecurity Milestones Brief Explanation

Brief Explanation of Cyber Milestones

The milestones identified on the screen represents an on-going schedule to assist in remaining vigilant against cyber threats and attacks. By reaching these milestones, Dayton Soft Products can be assured they are protecting company data and information assets. With the increase in the number of employees on and off-site, these milestones are a critical part of keeping our data secure. (Excel Spreadsheet/Chart attached).

6

Dayton Soft Products

Importance of Knowing Cyber Milestones

Importance of Knowing Cybersecurity Milestones

Understanding the difference between a project deadline and a milestone is very important when managing a cybersecurity project. A milestone shows that an important goal has been reached and signals that the project can move forward. Many times the project is stuck until a milestone is reached and can, therefore, put a project behind, which can be detrimental to a project, especially where cybersecurity is concerned. Cyber milestones are very important for improving security for a company because it signals the company is one step closer to securing its digital data and protecting a viable asset. Milestones do not make a project take longer, in and of themselves, however not reaching one can impact the end date of a cybersecurity project. For Dayton Soft Products current environment, milestones let personnel know that there is still work to do before the systems are secure. Milestones affect a company's future environment because as each one is accomplished, the company reaches a more secure threshold. Additionally, milestones help enterprises determine client, server, device, and network vulnerabilities coupled with successful prediction of behavioral and human vulnerabilities.

7

4 Strategies that Can Determine Current Security Environment

4 Strategies that could be Used to Determine Dayton Soft Products Security Environment, the Impact of the Strategy, and the Resources required.

Dayton Soft Products can use several strategies to determine the status of their current security environment. The following slides illustrate each strategy, along with the impact of the strategy, and the resources required to implement the strategy. The four strategies chosen for Dayton Soft Products include Analysis and Assessment of Risk, Treatment for Risks, Risk Mitigation, and Security Assurance and Auditing.

8

Current Security Environment

Risk Analysis

Risk Treatment

Security Awareness

Risk Management

Risk Analysis / Risk Assessment

Dayton Soft Products

Determine Current Security Environment – Strategy #1

LIKELIHOOD Of IMPACT SEVERITY OF IMPACT
Low Impact Minor Damage Moderate Damage Major Damage Catastrophic
Highly Unlikely
Unlikely
Possible
Probable
Certain

Dayton Soft Products Strategy #1 – Risk Assessment Impact

A Risk Analysis can be used to help determine Dayton Soft Product’s current security environment. Potential scenarios are examined and the likelihood of impact along with the severity of impact are categorized to determine potential losses in the event of a cyber attack. According to Pfleeger & Pfleeger (2015), a Risk Analysis can be used by an organization to (1) increase awareness, (2) create a linkage between management objectives and security mission, (3) evaluate vulnerabilities, assets, and controls, and (4) create a foundation for decision making (“Arguments For and Against Risk Analysis”, p. 705). Improved awareness occurs while discussing security issues with peers or co-workers who have a general knowledge of cyber attacks. Discussions help to educate them on ways that security relates to individual job roles. Additionally, a Risk Analysis can assist management in understanding the need to spend money on security software and controls.

Resources Required

A Risk Analysis requires resources to identify and tag company computers and equipment that the company may not be tracking. Employee resources are necessary to go from machine to machine to tag/document each piece of equipment. Tagging equipment assists in putting a dollar value to the equipment that can now be counted and tracked for depreciation purposes. Vulnerabilities reside with unknown laptops or other equipment that may be connected to the company network, that security personnel may be unaware of existing on the network. Finally, the most important part of a Risk Analysis, in my opinion, is the betterment of decision making regarding upgrades and new equipment purchases. A Risk Analysis can support this need and assist in getting equipment purchase requests approved because they support the request for approval. Risk Analysis’ should be updated annually and serve as a living document.

Financial Impact

The only real downside to a Risk Analysis is that the financial impact is only a guess.

9

Risk Treatment Plan

Dayton Soft Products

Determine Current Security Environment – Strategy #2

Communication with Stakeholders

Monitor and Review Risks and Controls

Dayton Soft Products Strategy #2 – Risk Treatment Impact

A Risk Treatment Plan is typically done once the Risk Analysis is completed. Dayton Soft Products can utilize a Risk Treatment Plan (RTP) to summarize risks identified in the Risk Analysis. Also noted in the RTP are the risk responses and mitigation, risk owners, and risk treatment target date. The RTP is a document that describes employee roles and their responsibilities as well as detailed actions that will need to be done and the date to implement these actions in order to obtain an acceptable level of risk for each occurrence. The impact that the RTP will have on Dayton Soft Products is substantial since they will now have a document to follow with detailed instructions on how to respond to a cyber-related incident. There are four main options in response to an attack including: (1) tolerate/retain if the risk is too costly to treat or too small of an impact to justify treating or modifying it, (2) terminate / avoid if the decision to stop the cause of or activity that is creating the risk, (3) transfer / share if the risk is something that has been identified as a risk that a third party is contracted to handle for the company, and (4) treat / modify the risk by implementing specific controls to reduce impact to Dayton or the likelihood that the incident will occur, if appropriate,

Resources Required

Resources required for a Risk Treatment Plan include security personnel’s time and expertise. Financial impacts include employee payroll, third-party fees, etc.

10

Establish Context

What are our objectives?

Identify Risks

Why, How, and When

Analyze Risks

Determine Action

Alignment with Business Goals

Evaluate Risks

Determine Priority

Mitigate Risks

Risk Management

Dayton Soft Products

Determine Current Security Environment – Strategy #3

Dayton Soft Products Strategy #3 – Risk Management Impact

Risk management encompasses the calculation of asset values in relation to the potential harm that may be caused by risk. The impact to Dayton Soft Products from a cyber attack includes the amount of damage caused, cost of protecting data and systems, countermeasures and controls, and loss of business if the risk brings down the company's system. Financial impact in creating a Risk Management Plan (RMP) includes costs of implementing countermeasures to protect the company from potential threats. The negative aspect of an RMP is the complexities involved in attaching a value to an asset. Assets can be the time the network is down, corrupted files, loss/leaking of data, and literally thousands of other similar threats. It is best to gauge the financial impact over a time period to get a more accurate account of financial impacts to various threats. Risk infiltration impacts Dayton Soft Products in many ways, including loss of employee productivity, loss of sales, loss of customer trust, etc.

Resources Required

Professional security personnel is needed to calculate potential losses. Also, the company will be impacted financially because they will need the services of an Attorney due to legal liabilities involved in some types of cyber attacks, such as identity theft which may result from criminals stealing customer information.

11

Risk Management

Assess

Identify

Control

Review

Security Assurance & Auditing

Dayton Soft Products

Determine Current Security Environment – Strategy #4

CYBER

Dayton Soft Products Strategy #4 – Security Assurance & Auditing Impact

Dayton Soft Products would greatly benefit by utilizing the strategy of a Cybersecurity Assurance and Auditing Plan. This plan is a great tool that assists in lowering risk potential by putting into place standardized procedures, and testable criteria for risks, weaknesses, and vulnerabilities. Dayton Soft Products would benefit from a Security Assurance and Auditing Plan by using it to identify and address known malware and viruses to help in lowering exposure to exploitation. This plan can also help enhance security awareness efforts and expand security controls for the company.

12

Security

Technology

Intelligence

Training

Dayton Soft Products Security Overview REFERENCES

Reference Slide

CESG (2012). Assurance of ICT systems and services, Good Practice Guide, No. 30, CESG Information Assurance Portal. Retrieved from www.ncsc.gov.uk/content/files/guidance_files/GPG%2030%20-%20Assurance%20of%20ICT%20Systems%20and%20Services%20-%20issue%202.1%20-%20Oct%2015%20-%20NCSC%20Web.pdf 

NIST.gov (2019). Glossary of key information security terms. National Institute of Standards and Technology Interagency or Internal Report, NISTIR 7298, Revision 2. Retrieved from http://csrc.nist.gov/publications 

NICCS.gov (2019). A Glossary of Common Cybersecurity Terminology. Retrieved from https://niccs.us-cert.gov/about-niccs/glossary

Pfleeger, C. P., Pfleeger, S. L., Margulies, J. (2015). Security in computing (5th ed.). Saddle River, NJ: Pearson/Prentice Hall.

Secureworks.com (2019). Cybersecurity versus Network Security versus Information Security. Retrieved from https://www.secureworks.com/blog/cybersecurity-vs-network-security-vs-information-security

Sezer Bozkus KahyaogluKiymet Caliyurt, (2018). Cyber Security Assurance Process from the Internal Audit Perspective. Managerial Auditing Journal, Vol. 33 Issue: 4, pp.360-376. Retrieved from https://doi-org.contentproxy.phoenix.edu/10.1108/MAJ-02-2018-1804

13

Dayton Soft Products

Project StartEstablish Cybersecurity TeamIdentify Critical Digital Assets & SystemsImplement Communication BarriersImplement Access Control for Portable and Mobile Devices.Remote Access Testing for offsite employeesConduct Training for Offsite EmployeesConduct Training for Onsite EmployeesUpdate and document cyber security controls and protocolsAssessment and Monitoring Full Cybersecurity Plan ImplementationProject End1 Jan1 Feb1 Mar1 Apr1 May1 Jun1 Jul1 Aug1 Sep1 Oct1 Nov1 Dec

Project Timeline

Dayton Soft Products
Project Milestones
Date Milestone Description Position Baseline
1/1/19 Project Start -20 0
1/31/19 Establish Cybersecurity Team Team members chosen for the Cybersecurity Team may require additional training to ensure adequate performance of cybersecurity assessments and testing. 10 0
2/28/19 Identify Critical Digital Assets & Systems This includes offsite communications, support systems, system components and structures that if compromised would cause great harm to Dayton Soft Products. -10 0
3/31/19 Implement Communication Barriers This protects critical systems from cyber attacks from the Internet and company business systems by isolating them. Prevents remote access to core business systems. 25 0
4/30/19 Implement Access Control for Portable and Mobile Devices. Portable and mobile devices are used to transfer digital data and can be used to spread malicious software to company systems. This milestone includes updating firmware and software on equipment. -15 0
5/31/19 Remote Access Testing for offsite employees This protects business systems and the company network by ensuring that appropriate access controls are in place for offsite employees and vendors who are accessing company systems from outside the office. 15 0
6/30/19 Conduct Training for Offsite Employees Training is paramount to provide cyber threat awareness to offsite employees. -15 0
7/31/19 Conduct Training for Onsite Employees Training is paramount to provide cyber threat awareness to onsite employees. 15 0
8/31/19 Update and document cyber security controls and protocols Keeping Security controls and protocols involved keeping procedures up-to-date, which is a critical milestone, especially as new cyber threats are identified and mitigation procedures are changed. -20 0
9/30/19 Assessment and Monitoring Implementation of ongoing assessment and monitoring activities. 20 0
12/1/19 Full Cybersecurity Plan Implementation Cybersecurity Plan is fully implemented and all security controls and actions have been completed. -15 0
12/31/19 Project End 10 0
Position

[CELLRANGE]

[CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CATEGORY NAME] Project Start Establish Cybersecurity Team Identify Critical Digital Assets & Systems Implement Communication Barriers Implement Access Control for Portable and Mobile Devices. Remote Access Testing for offsite employees Conduct Training for Offsite Employees Conduct Training for Onsite Employees Update and document cyber security controls and protocols Assessment and Monitoring Full Cybersecurity Plan Implementation Project End -20 10 -10 25 -15 15 -15 15 -20 20 -15 10 Date 43466 43496 43524 43555 43585 43616 43646 43677 43708 43738 43800 43830 0 0 0 0 0 0 0 0 0 0 0 0

Project Milestones

DateMilestoneDescriptionPosition

1/1/2019Project Start-20

1/31/2019Establish Cybersecurity Team

Team members chosen for the Cybersecurity Team may require

additional training to ensure adequate performance of cybersecurity

assessments and testing.

10

2/28/2019Identify Critical Digital Assets & Systems

This includes offsite communications, support systems, system

components and structures that if compromised would cause great

harm to Dayton Soft Products.

-10

3/31/2019Implement Communication Barriers

This protects critical systems from cyber attacks from the Internet and

company business systems by isolating them. Prevents remote access

to core business systems.

25

4/30/2019

Implement Access Control for Portable and

Mobile Devices.

Portable and mobile devices are used to transfer digital data and can

be used to spread malicious software to company systems. This

milestone includes updating firmware and software on equipment.

-15

5/31/2019

Remote Access Testing for offsite

employees

This protects business systems and the company network by ensuring

that appropriate access controls are in place for offsite employees

and vendors who are accessing company systems from outside the

office.

15

6/30/2019Conduct Training for Offsite Employees

Training is paramount to provide cyber threat awareness to offsite

employees.

-15

7/31/2019Conduct Training for Onsite Employees

Training is paramount to provide cyber threat awareness to onsite

employees.

15

8/31/2019

Update and document cyber security

controls and protocols

Keeping Security controls and protocols involved keeping procedures

up-to-date, which is a critical milestone, especially as new cyber

threats are identified and mitigation procedures are changed.

-20

9/30/2019Assessment and Monitoring Implementation of ongoing assessment and monitoring activities.20

12/1/2019Full Cybersecurity Plan Implementation

Cybersecurity Plan is fully implemented and all security controls and

actions have been completed.

-15

12/31/2019Project End10

Project Timeline

Dayton Soft Products
Project Milestones
Date Milestone Description Position Baseline
1/1/19 Project Start -20 0
1/31/19 Establish Cybersecurity Team Team members chosen for the Cybersecurity Team may require additional training to ensure adequate performance of cybersecurity assessments and testing. 10 0
2/28/19 Identify Critical Digital Assets & Systems This includes offsite communications, support systems, system components and structures that if compromised would cause great harm to Dayton Soft Products. -10 0
3/31/19 Implement Communication Barriers This protects critical systems from cyber attacks from the Internet and company business systems by isolating them. Prevents remote access to core business systems. 25 0
4/30/19 Implement Access Control for Portable and Mobile Devices. Portable and mobile devices are used to transfer digital data and can be used to spread malicious software to company systems. This milestone includes updating firmware and software on equipment. -15 0
5/31/19 Remote Access Testing for offsite employees This protects business systems and the company network by ensuring that appropriate access controls are in place for offsite employees and vendors who are accessing company systems from outside the office. 15 0
6/30/19 Conduct Training for Offsite Employees Training is paramount to provide cyber threat awareness to offsite employees. -15 0
7/31/19 Conduct Training for Onsite Employees Training is paramount to provide cyber threat awareness to onsite employees. 15 0
8/31/19 Update and document cyber security controls and protocols Keeping Security controls and protocols involved keeping procedures up-to-date, which is a critical milestone, especially as new cyber threats are identified and mitigation procedures are changed. -20 0
9/30/19 Assessment and Monitoring Implementation of ongoing assessment and monitoring activities. 20 0
12/1/19 Full Cybersecurity Plan Implementation Cybersecurity Plan is fully implemented and all security controls and actions have been completed. -15 0
12/31/19 Project End 10 0
Position

[CELLRANGE]

[CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CELLRANGE] [CATEGORY NAME] Project Start Establish Cybersecurity Team Identify Critical Digital Assets & Systems Implement Communication Barriers Implement Access Control for Portable and Mobile Devices. Remote Access Testing for offsite employees Conduct Training for Offsite Employees Conduct Training for Onsite Employees Update and document cyber security controls and protocols Assessment and Monitoring Full Cybersecurity Plan Implementation Project End -20 10 -10 25 -15 15 -15 15 -20 20 -15 10 Date 43466 43496 43524 43555 43585 43616 43646 43677 43708 43738 43800 43830 0 0 0 0 0 0 0 0 0 0 0 0