1
Domain Threats, Vulnerability, and Risks
Student’s Name
Institutional Affiliation
Course Code and Title
Instructor’s Name
Due Date
2
Most organizations and job places have improved their services in a competitive business
environment by automating most of them. With the rise of automation and the use of AI in most
organization systems, there creates a gap for risks, threats, and vulnerable attacks from groups
such as hackers or access to information protected from unauthorized groups. To resist, manage
and protect the information from hacking or leaks from unauthorized personnel, companies have
employed different methods to prevent the threats before they occur. Since most of these attacks
happen online, we ask ourselves a key question: what assets and activities are to be protected?
There are several assets and activities in IT domain infrastructure to be protected, including User
Domain, LAN Domain, Wan Domain, LAN-to-WAN Domain, Remote access Domain, System/
Application Domain, and Workstation Domain.
WorkStation Domain
Workstation is the computing gadgets or devices that connect end-users to a network.
Threats Vulnerabilities Risks
Coordinated attacks .SSH clients are vulnerable to
X-forwarding attacks from
malicious SSH servers
Loss of credit information
and theft of money
Unauthorized access to a
workstation
Desktop or laptop computer
operating system software
vulnerabilities
Infection of a user’s
workstation or laptop
computer by viruses,
malicious code, or malware
Social engineering Lack of using social Loss of data and leaks in the
3
engineering knowledge and
skills.
system security.
LAN Domain
This refers to the interconnection of all computers/equipment through a common medium. They
include routers, APNs, Wi-Fi, hubs, and switches that connect to the workstation.
Threats Vulnerabilities Risks
Unauthorized access to LAN LAN server operating system
software vulnerabilities
Compromised confidentiality
of data transmissions via
WLAN - encryption.
Hackers LAN Server Configurations
and software patches update.
Rogue access to LAN servers
System network
infrastructure manipulation.
Lack of user confidentiality.
WAN Domain
This is a wide area network that connects remote locations. Businesses, external endpoints,
websites, and all other external entities are hosted here.
Threats Vulnerabilities Risks
Internet traffic Email of Trojans, worms, and
malicious software by
hackers, attackers, and
Theft of data
4
perpetrators
Viruses and Malware attack Weak/Lack of antivirus system breakdown and Loss
of data
Remote Access Domain
The function of this domain is to connect remote users to IT infrastructure. This represents
entities such as employees, vendors, or other workers who work in the field or at home instead of
in the office.
Threats Vulnerabilities Risks
Brute force USER ID and
password attacks
DDOS and MITM attack Unauthorized remote access
to IT systems, applications,
and data.
Virus Open backdoor in the system
or weak/weary system
antivirus leading to virus
attack
Break down of network
infrastructure and workstation
System/Application Domain
5
This domain holds all the mission-critical systems, data, and applications, especially collection,
access, storage, and other software that runs on servers and workstations.
Threats Vulnerabilities Risks
Downtime of servers to
perform maintenance
Unauthorized access to data
centers, computer rooms, and
wiring closets
Data breach where private
data of individuals are
compromised and Loss or
corruption of data
System administrator failure Mismanagement of the
system
Improper function of the
system leads to poor output.
User Domain
The user domain gives the user access to Information System.
Threats Vulnerabilities Risks
Ransomware DDOS and MITM attack The capture of data and
failure of the system.
Lack of user
awareness
Security policy violations Attacks on the organization
or acts of sabotage by
disgruntled employees of IT
infrastructure during off-
hours.
6
Reference
Mahmood Saqib, R., Shahid Khan, A., Javed, Y., Ahmad, S., Nisar, K., A Abbasi, I., ... &
Ahmadi Julaihi, A. (2022). Analysis and intellectual structure of the multi-factor authentication
in information security..Intelligent Automation & Soft Computing,.32(3), 1633
Fundamentals of Information Systems Security - David Kim, Michael G.Solomon.