(10 points) How well did the Common Criteria (CC) or International Standard
Organization (ISO) 15408 address these (and other) drawbacks of TCSEC?
Despite TCSEC having been the first computer security evaluation it was later replaced
by the common criteria that standardized all security evaluation standards that existed by
1999.Though TCSEC was initially surrounded by many draw backs it still shares some
similarities with common criteria. Both standards evaluate computer systems through classifying
their security levels while at the same time offering security functionality, confidentiality as well
as evaluating computer operation system.
Common criteria, however overrides TCSEC on several attributes. Common criteria is
applied around the globe unlike TCSEC which is only used within the United States. TCSEC
lacks a security model for open system hence making it viable for static model. Common criteria
however addressed the issues through covering user security something that TCSEC had left out
by only considering protecting only the system. TCSEC had completely failed to address
availability and integrity something that common criteria resolved and handled effectively.
Common Criteria(CC) having been recognized by ISO organizations it applies to many
nations. Thus compared to TCSEC, CC is generally more integral.CC extends to focus on
Database and Networks unlike TCSEC which was more aligned towards the operating systems.
Thus common criteria involve a security criterion that focuses on dynamic network and open
system. It through its setting that CC ensures system availability, integrity and confidentiality by
applying TOEs specifications that ensure that no changes affect its evaluation.
Common criteria has since changed the evaluation process that was largely applied by
organizations using TCSEC.TCSEC uses security requirements to access system security which
have to be classified by the evaluation class on the other hand CC simplifies this by applying
common criteria in evaluating a computer system.CC assesses systems through identifying a
TOE, then coming up with a certain Criteria to evaluate the TOE. In knowing whether a system
is secure, certain protection profiles have to be by the system. Due to the drawbacks that existed
on the side of TCSEC common criteria has since replaced it.
(8 points) Is an independent party assigning an Evaluation Assurance Level (EAL) to a
product sufficient for “proof of assurance”? Why or why not? Give one product example
to illustrate.
An independent party assigning an Evaluation Assurance Level to a product is sufficient
for proof of assurance according to the common criteria. The common criteria give standards on
which Evaluation Assurance Levels(EAL1-EAL7) should be assigned. Though not all levels
require developers some of the levels do require a diligent developer. Assurance levels are
necessary as per the common criteria since higher ones tend to offer more viable assurances.
Each level does not in any way measure how secure the system is but only indicates the phase at
which it was eventually tested. All numbers that are assigned to a certain system indicate that the
system is consistent with the common criteria.
One of the product example Oracle Linux which is a commercial operating system that is
tested and reviewed at EAL4.These operating system only provides user based securities.
Though the developer of the product has maximum assurance owing to good commercial
development practices users need high level of independently assured security. This thus makes
an independent party sufficient for proof of assurance.
(7 points) Given the growing demand for higher assurance, increasing complexity of
software and evaluations, and continuing need for innovation, what do you see as the
future of security evaluation over the next decade?
Common criteria is most probably likely to lose it much hyped mutual recognition
especially on those countries that long for higher levels of assurance and an assurance size that
accommodates all evaluations. These developments risk shielding the essence of common
criteria with each software and evaluation market going by its own. The risk that is likely to arise
is that customers may no longer get value for their money if inconsistent assurance requirements
are impost on vendors.
The complexities that are likely to emerge within the next decade, threaten the future of
CC as they will give way for unproven assurance validations that are more likely to be
expensive. Every stakeholder in information technology seems to be aligning towards a given
assurance methodology with the hope that it would emerge as a standard for evaluation.
However, despite CC having certain weakness an improvement through ensuring vendors
employee various tools in a move to unearth security vulnerabilities would be essential. This will
make the system more effective in eliminating vulnerabilities that could weaken security systems
through fixing them.
The demand for higher assurance will likely heighten in the next one decade more so due
to nature of some of the products. Thus future security evaluation methodologies should be more
repeatable and precise while allowing for relevantly lower evaluation costs. Thus standardization
of product testing across board would be largely impossible on some product categories. It would
be largely difficult to bring a standard that would test routers and relational databases at go for
instance.
It is thus worth noting that the common criteria form a basic of many assurances and the
digital world is largely in need of it. However, need arises in supporting the innovation of higher
assurance evaluations, allowing for quicker security innovations as well as embracing repeatable
validation and testing despite the drawbacks that could arise in the future.
Question 3
(10 points) Briefly describe what it is and why it is needed. Estimate the current maturity
of your organization in each area and give evidence that this is an accurate estimate.
Our company is currently investing much on employee management system since it is the
quality of workforce that either lead businesses to thrive or fail. In building the system the
organization focuses on what motivates employees to achieve organizational goals and their
capabilities in the designated areas. Being a customer services business interaction between
employees and clients cannot be ignored hence the need for having a pool of employees that are
highly capable of serving potential customers.
Configuration management(CM) is of essence to the organization given the fact IT
service management architectures are continuously changing.CM ensures that changes in the
simulator software is under control and follows the intended design specifications. Majority of
the issues that would potentially affect the organizations employee management system would be
due to configuration issues. Thus in order to maintain appropriate service levels configuration
management can no longer be ignored within the organization. The employee management
system will host data in the organizational database and through configuration management it
will be possible for stakeholders to monitor and audit employee performance as well as attributes
with ease. Since the organization recently implemented the program it is worth saying that the
maturity level is largely low given that the organizations continuously reviews the performance
with the system host to ensure whether it can fit the organization.
Risk management(RSKM) is carried out continuously during the lifetime of a project
with the aim of mitigating risks that could easily occur. It aims at addressing those issues that
could derail the achievement of organizational goals. Effective risk management is carried out
through identifying risks early enough and involving all the concerned stakeholders. It is so
diverse that it includes technical and non-technical attributes of costs, performance and other
potential risks. Potential risks in our organization would most arise from phishing by competitors
especially on attacks directed towards our servers. To manage this risks the stakeholders
implementing employee management system often review servers and check on any attacks that
are directed towards the organization information technology infrastructure. In the 21st century
many organizations have lost good employees through information theft by competitors hence
the organization cannot disregard this particular phenomenon. The organization has a high level
of maturity in carrying out risk management given that apart from developing a pool of
employees within a system it has to protect their crucial data to deter it from being accessed by
third parties.
Requirement development aims at analyzing product component requirements and
customers to ensure that stakeholders interests are well taken care of. All development projects
tend to have different requirements with changes being aligned to existing needs and
implantation necessities. Major development requirements include coordinating stakeholders
needs as well as coming up with cycle requirements as well as customer requirements. In an
employee management system stakeholders are interested in retaining those employees who can
ensure that an organization meets customer requirements. Customers as well look upon the
organization to come up with broad measures that ensure that their needs are adequately met. It
is only through understanding the customer that an organization can initiate an employee
management system that suits them. The maturity level is low given that the organization is still
making different measures that will help in ensuring that the system is properly executed to meet
all the stakeholder needs.
(10 points) Enumerate improvements in maturity level within your organization. Describe
specific goals, practices, and work products. Be sure to list resources/tools you may use to
assist in automating each process area
It is essential that organization factor on their own maturity level in order to ensure
processes, decisions and functions are adequately performed. Organizational maturity is an
indicator of organizational capabilities and is often expressed through the workforce as well as
available technologies, data and processes. Enumerating organizational maturity level gives an
avenue for outlaying an organizations ls and goals and checking on how they can be improved.
Currently the organization has created an employee performance database that is independent
from its previously used employee database. The employee performance database is an employee
management system that indicates how employees within the organization are faring in regard to
customer satisfaction. It is mainly updated through data that is collected from customer feedback
regarding to both good and bad customer responses. Through these data employees are
automatically ranked from the best to the worst performing. It goes without a saying that
organizations would always wish to retain the best performing employees hence the automatic
ranking helps the organization in making informed decisions.
Creating an employment management system inform of a database was to allow for
independent opinion from customers. Initially the organization used to rely on data collected
from the human resource management to promote employees. With time this data has become
unnecessary since customers often interact with employees on different touch points unlike the
human resources. Thus the system is driven by an initiative to push employees towards
recognizing the importance of customers within their organizational setting. Organizational
websites, social media and customer care desks all offer avenues for rating employees with ease.
These are the tools that are used to gather the information that is held within the employee
management system.
Question 4
(15 oints) Pick ANY TWO of the above and answer each of the following:
a) (6 points) Why it exists? What it does?
i) Payment Card Industry Data Security Standard (PCI DSS)
PCI DSS is a combination of security standards that were initiated to ensure that those
companies that process, accept, store or transmit credit card data run on secure environments. It
main reason of formation was to check on the growing transformation of the Payment Card
Industry(PCI) security standards by ensuring that the transaction process is secure.
The PCI DSS performs the following functions,
Ensuring that secure networks are maintained within transactional environments. This is
done through the utilization of firewalls that are highly effective.
It serves to protect cardholder information at any store. Repository that contain card
holder’s information should be encrypted to protect them from being hacked.
It ensures that systems are protected from hackers through using up to date ant-spywares.
It ensures that any access to system operations and information is largely controlled. Thus
cardholders are limited from providing their critical financial information.
It serves to ensure that formal information security is adhered to throughout by all
concerned parties.
ii) Gramm-Leach-Bliley Act (GLBA)
GLBA gives an outline of how nonpublic personal information held by financial
institutions that belongs to their consumers should be treated. It prohibits the disclosure
of such information to all parties that are not affiliated to consumers unless such
information meets other requirements by law.
GLBA performs the following undertaking;
Ensures that financial institutions give their privacy policies and practices thus
allowing consumers to give willingly consent in the event their nonpublic
information has to be shared to nonaffiliated parties.
If a financial institution has to share customer nonpublic information regardless of
the situation it has to equip its customers with a notice.
It ensures that financial institutions do not disclose information regarding to their
customer accounts to marketing parties.
iii) (6 points) How it relates to cybersecurity and information security? How
effective it has (or not) been? Justify your answer.
Payment Card Industry Data Security Standard (PCI DSS)
A lot of information is exchanged between cardholders and financial institutions. This is
potentially dangerous as such information if not well secured could fall in the hands of hackers.
Hackers use different vulnerabilities to gain access to consumer information which they
eventually utilize to swindle them billions of money. Thus ,PCI DSS is actually a cybersecurity
measure undertaken to ensures that client information does not fall into the wrong hands. It
serves to assure customers that their information is largely protected by the parties they transact
with.
The level in which customer information has been falling in the wrong hands has
gradually reduced since PCI DSS was implemented. This is an indication that the standards
requirements have triggered financial institutions to take more measures in protecting their
customers information given that consequences too arise if such information falls into the wrong
hands if due diligence was not factored.
ii) GLBA
GLBA was necessary in capping cybersecurity breaches that usually were done
intentionally. Financial institutions initially shared some of their customer non-public data with
marketing companies with the sole aim of helping them increase their client base. Unknowingly
this information used to fall in the wrong hands triggering hackers to utilize vulnerabilities to
combine client information that they would essentially end up in withdrawing money from the
financial institutions without client’s consent
GLBA has largely been effective given that financial institutions have no other
alternative but to protect customer’s nonpublic information. However, it is worth noting that
customers at times too make blunders by unknowingly disclosing nonpublic information while
shopping online opening loopholes for both marketers and hackers to pursue them. Despite its
success thus both parties should be quitted with advance knowledge related to information
management.
iv) (3 points) What improvement you would recommend?
PCI DSS was a masterpiece of protecting cardholder’s information but given the changes
in information technology some changes are necessary. Standards on card information shared on
social media platforms for promotion purposes should be revised to so that cardholder’s
information cannot be compromised with ease.
GLBA too has had concerns in the recent past despite having helped control the sharing
of customer nonpublic information by financial institutions. Enforcing authorities should
regularly monitor transactions that happen between financial institutions and marketers. At the
era of targeting marketing anything skeptical can happen despite the existence of the rules.