1
Infrastructure Research A & B
Name
Institution
Professor
Course
Date
2
Project Part 2: Infrastructure Research A
Policy Frameworks for the Project
In the case of the Blue Stripe Tech project, the chief governing policy that will be used is
the NIST Cybersecurity Framework CSF. This framework is attributed to the detailed strategy
for managing and mitigating cybersecurity threats. The NIST CSF is divided into five essential
functions. The acronym to describe the five core components of the DISC framework is IDRR
(Johnson & Easttom, 2020). Thus, each function covers the critical aspects of cybersecurity and
is relevant to the U. S. Department of Defense requirements.
The Identify function addresses cybersecurity threats to systems, inventory, information,
and capacities. It consists of asset management, which tracks all the equipment, applications, and
data, and risk management, which assesses the strength of cyber threats to IT assets (Johnson &
Easttom, 2020). This function is vital in assisting other functions by initially understanding an
organization's situation from a cybersecurity perspective.
The Protect function comprises several activities aimed at protecting infrastructure.
These include identity management, which concerns allowing or prohibiting specific individuals,
and data security, which concerns preventing the violation of accessed information. Moreover,
the Protect function includes awareness training that aims to increase the employees' level of
knowledge regarding cybersecurity measures, management of security technologies, and
protective measures that help mitigate cyber risks.
3
The Detect function is solely focused on quickly discovering cybersecurity events. It
includes regular surveillance for abnormalities and occurrences that may predict security
violations. The next area within the IT security framework is detection processes, which are
crucial for identifying threats early and preventing them from causing much damage.
The Respond function contains details of the procedures practiced to identify a cyber
threat. It entails responding to indicate readiness for disaster by planning with available
resources, consulting with the stakeholders, understanding the extent of the threat, and taking
necessary measures to prevent and counteract it (Johnson & Easttom, 2020). Business continuity
management specifies the action plan in case of a cyber attack, thus enabling the organization to
respond quickly and efficiently.
Finally, the Recover function deals with reconstructing the services and capabilities after
a cyber incident occurs. This includes operational recovery, changes incorporating information
from the event, and the interaction with others regarding recovery (2022). The Recover function
will enable the organization to carry out a plan that will help it get back on its feet as soon as
possible without the effects of a specific incident interfering with operations.
DoD-Compliant Policies, Standards, and Controls
The User Domain, Workstation Domain, LAN Domain, and LAN-to-WAN Domain all
require the implementation of DoD-compliant Policies, Standards, and Controls.
Policies in the User Domain must limit access to information and programs to officials in
charge. This includes using multi-factor authentication (MFA) and role-based access control
(RBAC). Users should be regularly trained on cybersecurity to stay updated on modern practices
4
and threats. Additionally, the DoD must audit user activities to identify unauthorized access or
malicious use.
From this perspective, the Workstation Domain should take more decisive steps to
protect endpoints. This includes ensuring anti-virus software is correctly installed and frequently
updated, applying firewalls, and confirming the proper encryption of your device. Computing
workstations must be set up with tight DoD security guidelines and address patches for their
safeguard (Sherman et al., 2021). For passwords, we need to make policies saying that users
must have complex passwords and not use ones that are easy to guess or crack. Besides this,
policies suggest changing passwords periodically and having different passwords for different
accounts.
In the LAN Domain, we focus on practical matters like separating parts of the network to
lessen threat effects. This involves dividing the network into subnets and controlling traffic flow
between them. The LAN protection plan needs IDPS and NAC to cover the network security
control function. In addition, we must apply secure communication protocols such as TLS/SSL
to enhance data transfer encryption within the LAN.
The principle for the domain LAN-to-WAN is Perimeter Security. It includes filtering
traffic through firewalls, where you can only allow or deny outgoing and incoming traffic,
Virtual Private Networks to improve remote access, and secure gateway solutions that enhance
protection from external risks (Sherman et al., 2021). The DoD also requires vulnerability testing
to identify and describe possible security weaknesses. So, the company can provide better and
complete protection in four areas, user, workstation, LAN, and LAN-to-WAN, by using rules,
norms, and restrictions that match the DoD agreement.
5
Project Part 3: Infrastructure Research B
DoD-Compliant Policies, Standards, and Controls
For the WAN, Remote Access, and System/Application Domains, the following DoD-
compliant policies, standards, and controls must be implemented to maintain security and
compliance (Sherman & GOVERNMENT ACCOUNTABILITY OFFICE, 2021).
WAN Domain:
Follow safe routing techniques and encrypt the data that may be in transit.
Leverage firewalls and Intrusion Prevention Systems (IPS) to help anticipate and contain
the threats.
Establish and consistently update the vulnerability assessment and penetration testing
schedule (Sherman & GOVERNMENT ACCOUNTABILITY OFFICE. 2021).
Design for network availability and network failure recovery.
Remote Access Domain:
Ensure and implement MFA for any users accessing the organization’s network remotely.
Use Virtual Private Networks (VPNs) to enhance communication security over the
Internet.
Some recommendations for the avoidance of unauthorized access and the level of
security of remote sessions:
Ensure that other devices connected to the network are secure and have up-to-date anti-
virus protection, among other measures.
System/Application Domain:
6
Ensure that programmers follow the best security standards and often conduct code scans
to detect problems.
Ensure that only the authorized software is allowed to run through the implementation of
the application allowlisting.
Implement encryption to cover data stored and data in transmission to improve security
(Rodriguez, 2021).
Ensure that the system and the various applications are updated and patched frequently to
eliminate any risk that security openings may cause.
Achieve security conformity using security auditing and vulnerability testing of
applications and systems.
Through these policies, standards, and controls, Blue Stripe Tech will be in a position to
have a secure and compliant IT Environment that'll meet the DoD regulatory compliance of the
United States of America. With this approach, the organization's resources and the credibility of
its systems will be safeguarded, with a particular emphasis on data confidentiality and
accessibility.
7
References.
Johnson, R., & Easttom, C. (2020).>Security policies and implementation issues. Jones & Bartlett
Learning.
https://link.springer.com/chapter/10.1007/978-3-658-37182-1_4
Rodriguez, J. F. (2021).>Risk Management Framework on Platform Information Technology
Systems: An Exploratory Qualitative Inquiry of the Naval Sea Systems
Command>(Doctoral dissertation, Capella University).
https://www.proquest.com/openview/f6125e95520f1ae06179911c8b0a2bb1/1?pq-
origsite=gscholar&cbl=18750&diss=y
Sherman, T. W., & GOVERNMENT ACCOUNTABILITY OFFICE. (2021). Military Service
Uniforms: DOD Could Better Identify and Address Out-of-Pocket Cost Inequities.
https://apps.dtic.mil/sti/citations/AD1147989
Sherman, Howard J., and Paul D. Sherman. “The Trump Depression.” Challenge, 1 Feb. 2021,
pp. 1–14, https://doi.org/10.1080/05775132.2020.1804740.