1 / 5100%
1
Running Head: ISE 510
SNHU
ISE 510 Security Risk Analysis & Plan
Security Breach Analysis and Recommendations
Milestone 1: Kickoff Agenda
(60 points)
Delapaz Carlos
Due <September 1,2019
Submitted on <September 13,2019
If late let me know why: Resubmission
=====================================
2
ISE 510
1. Security Breach. Some of the likely causes of the breach include the poor security posture of
the organization, the lack of proper documentation of the security policies and the lack of proper
training of employees on security awareness.
2. Attack Location: The attack that took place in Limetree impacted all the employees of the
research organization especially the research team. This is because personal health information
(PHI) that was used in a recent research study was stolen by the attackers.
3. Attack Method and Tools: In order to carry out the security breach attack, the insider data
theft attack is a probable method that could be used by an attacker. In such an attack, sensitive
information relating to the company could be stolen without the knowledge of the employees. As
the employees lack proper training ion security awareness, this method must have been used to
conduct the security breach in Limetree (Supplement to ISE510 Security Risk and Planning,
2019).
4a. Vulnerabilities: What were the two major vulnerabilities that were exploited to affect
the attack?
As per Jack, even though the firm has faced security incidents before, no previous documented
history of incidents was stored which could be used to identify the corrective measures that were
taken to deal with the incidents. Similarly, the process of sharing information on a computer
incident is quite lengthy. For instance, the administrators escalate the incident to the IT manager,
who reports incidents to the security manager if they are considered to be relevant. These were
the two major vulnerabilities that were exploited to affect the attack as per John.
4b. Vulnerabilities: The physical vulnerabilities that Jack Sterling has identified include:
Users are not given training on security awareness
Visitors just sign in at the front desk and are allowed to walk in to see employees at their
respective offices.
The users are generally allowed to bring in their own laptops and connect to the corporate
system.
4c. Vulnerabilities: The vulnerabilities that Jack Sterling has identified in the Administrative
Office workstations include:
The low level of security setting of the Internet Explorer browser and the absence of a
standard browser for the environment.
The low disk space for SQL database log which is overwritten with new information
when it is full.
No segmentation or authentication between the wireless and wired LAN. Visitors are
given access code to use the wireless network of the company.
Absence of logging of network activities on any of the switches.
The public-facing web server is a part of the LAN and it acts as the key point where
internet users get information on the company.
Absence of documented security policy, or computer use policy.
Lack of a proper documented process for changes to the system.
2
3
ISE 510
Absence of any contingency plan.
4d. Vulnerabilities: The vulnerabilities that Jack Sterling identified regarding the Wi-Fi was
that the Wireless network was available with clearly advertised SSID, and it was a part of the
local area network (LAN). There was no segmentation or authentication between the wireless
and wired LAN which was a major security blunder. Visitors are given access code to the
wireless network at the front desk which increases the vulnerability of the firm’s network.
5. Write a Scope Statement.
The scope of the meeting would revolve around conducting a thorough security breach analysis
so that necessary details and information can be captured suitable recommendations can be made
for Limetree Inc. Each of the security-related items would be covered discussed and described to
conduct the risk assessment.
6. What is the purpose of a Risk Analysis?
The purpose of a Risk Analysis is to identify and assess any potential issue which could
adversely impact the IT environment of LimeTree. The process would help to avoid or mitigate
the risks in an effective manner so that the security posture could be improved.
7a. Considering what was stolen from LimeTree, who/what is the primary Threat source?
Recently, Limetree Inc. had experienced a security breach and it is believed that confidential
company data were stolen such as personal health information (PHI) that were used in a research
study. The primary threat source could be internal employees of the organization.
7b. In the case of LimeTree, give an example of an unintentional (i.e. accidental) Threat
source?
An example of an unintentional or accidental) threat source for Limetree could be the employees.
As they are not provided adequate training on security awareness, while using their personal
computers they could unintentionally be compromising the security of the entity.
7c. Why is LimeTree not concerned about a denial of service (DoS) attack on its corporate
website for this project?
LimeTree is not concerned about denial of service (DoS) attack on its corporate website for the
project as such a threat would not lead to the loss or theft of any data that is available with the
organization.
8. What controls would you suggest for mitigating these threat-vulnerability pairs:
In order to mitigate the threat-vulnerability pairs that exist in the It setting of Limetree there is
the need to introduce proper documentation of the security policies, provide adequate training to
the employees on security awareness, and bring about necessary changes to the Bring Your Own
Device policy. Similarly, access must not be given to visitors to meet the employees at their
workstations (What is a denial of service attack (DoS) ? - Palo Alto Networks, 2019).=
8a. Mitigating the threat of unauthorized persons entering the main facility from the
lobby?
3
4
ISE 510
There is the need to shift the access control from the lobby to the main facility so that visitors of
the employees will not be allowed to meet them at their work desk.
8b. Mitigating the threat of unauthorized persons entering the exits marked “Emergency
Exits?”
In order to mitigate the risk that arises when unauthorized persons enter the exits marked
‘Emergency Exits’, the physical security of the office must be strengthened and CCTV cameras
must be installed at different office areas.
8c. Mitigating the threat of a vulnerable operating system and/or outdated antivirus being
exploited and hijacking the workstation?
Limetree must regularly update the software, applications and operating system so that the online
vulnerability can be handled effectively. Similarly, the antivirus software must be regularly
upgraded so that it can offer proper protection against malicious elements.
4
5
ISE 510
References
Supplement to ISE510 Security Risk and Planning, (2019). Part 1 The Breach at Limetree,
Interview with Jack Sterling. Retrieved from online Learning Platform at SNHU.
What is a denial of service attack (DoS) ? - Palo Alto Networks. (2019).=Paloaltonetworks.com.
Retrieved 11 September 2019, from https://www.paloaltonetworks.com/cyberpedia/what-
is-a-denial-of-service-attack-dos
5
Students also viewed