1 / 5100%
Running Head: ISE 510
1
SNHU
ISE 510 Security Risk Analysis & Plan
Security Breach Analysis and Recommendations
Milestone 1: Kickoff Agenda
(60 points)
ISE 510
2
2
1. Security Breach. Some of the likely causes of the breach include the poor security
posture of the organization, the lack of proper documentation of the security policies and
the lack of proper training of employees on security awareness. c c c
2. Attack Location: The attack that took place in Limetree impacted all the employees of
the research organization especially the research team. This is because personal health
information (PHI) that was used in a recent research study was stolen by the attackers.
3. Attack Method and Tools: In order to carry out the security breach attack, the insider
data theft attack is a probable method that could be used by an attacker. In such an attack,
sensitive information relating to the company could be stolen without the knowledge of the
employees. As the employees lack proper training ion security awareness, this method must
have been used to conduct the security breach in Limetree (Supplement to ISE510 Security
Risk and Planning, 2019).
4a. Vulnerabilities: What were the two major vulnerabilities that were exploited to
affect the attack?
As per Jack, even though the firm has faced security incidents before, no previous
documented history of incidents was stored which could be used to identify the corrective
measures that were taken to deal with the incidents. Similarly, the process of sharing
information on a computer incident is quite lengthy. For instance, the administrators
escalate the incident to the IT manager, who reports incidents to the security manager if
they are considered to be relevant. These were the two major vulnerabilities that were
exploited to affect the attack as per John.
4b. Vulnerabilities: The physical vulnerabilities that Jack Sterling has identified include:
• Users are not given training on security awareness
• Visitors just sign in at the front desk and are allowed to walk in to see employees
at their respective offices.
• The users are generally allowed to bring in their own laptops and connect to the
corporate system.
4c. Vulnerabilities: The vulnerabilities that Jack Sterling has identified in the
Administrative Office workstations include:
• The low level of security setting of the Internet Explorer browser and the absence of
a standard browser for the environment.
• The low disk space for SQL database log which is overwritten with new information
when it is full.
• No segmentation or authentication between the wireless and wired LAN. Visitors are
given access code to use the wireless network of the company.
• Absence of logging of network activities on any of the switches.
• The public-facing web server is a part of the LAN and it acts as the key point
where internet users get information on the company.
• Absence of documented security policy, or computer use policy.
ISE 510
3
3
• Lack of a proper documented process for changes to the system.
• Absence of any contingency plan.
4d. Vulnerabilities: The vulnerabilities that Jack Sterling identified regarding the Wi-Fi
was that the Wireless network was available with clearly advertised SSID, and it was a part
of the local area network (LAN). There was no segmentation or authentication between the
wireless and wired LAN which was a major security blunder. Visitors are given access
code to the wireless network at the front desk which increases the vulnerability of the
firm’s network.
5. Write a Scope Statement.
The scope of the meeting would revolve around conducting a thorough security breach
analysis so that necessary details and information can be captured suitable recommendations
can be made for Limetree Inc. Each of the security-related items would be covered
discussed and described to conduct the risk assessment.
6. What is the purpose of a Risk Analysis? c
The purpose of a Risk Analysis is to identify and assess any potential issue which could
adversely impact the IT environment of LimeTree. The process would help to avoid or
mitigate the risks in an effective manner so that the security posture could be improved.
7a. Considering what was stolen from LimeTree, who/what is the primary Threat
source?
Recently, Limetree Inc. had experienced a security breach and it is believed that
confidential company data were stolen such as personal health information (PHI) that were
used in a research study. The primary threat source could be internal employees of the
organization.
7b. In the case of LimeTree, give an example of an unintentional (i.e. accidental)
Threat source?
An example of an unintentional or accidental) threat source for Limetree could be the
employees. As they are not provided adequate training on security awareness, while using
their personal computers they could unintentionally be compromising the security of the
entity.
7c. Why is LimeTree not concerned about a denial of service (DoS) attack on its
corporate website for this project?
LimeTree is not concerned about denial of service (DoS) attack on its corporate website for
the project as such a threat would not lead to the loss or theft of any data that is available
with the organization.
8. What controls would you suggest for mitigating these threat-vulnerability pairs:
In order to mitigate the threat-vulnerability pairs that exist in the It setting of Limetree
there is the need to introduce proper documentation of the security policies, provide
adequate training to the employees on security awareness, and bring about necessary
ISE 510
4
4
changes to the Bring Your Own Device policy. Similarly, access must not be given to
visitors to meet the employees at their workstations (What is a denial of service attack
(DoS) ? - Palo Alto Networks, 2019). c
8a. Mitigating the threat of unauthorized persons entering the main facility from the
lobby?
There is the need to shift the access control from the lobby to the main facility so that
visitors of the employees will not be allowed to meet them at their work desk.
8b. Mitigating the threat of unauthorized persons entering the exits marked
“Emergency Exits?”
In order to mitigate the risk that arises when unauthorized persons enter the exits marked
‘Emergency Exits’, the physical security of the office must be strengthened and CCTV
cameras must be installed at different office areas.
8c. Mitigating the threat of a vulnerable operating system and/or outdated antivirus
being exploited and hijacking the workstation?
Limetree must regularly update the software, applications and operating system so that the
online vulnerability can be handled effectively. Similarly, the antivirus software must be
regularly upgraded so that it can offer proper protection against malicious elements.
ISE 510
5
5
References
Supplement to ISE510 Security Risk and Planning, (2019). Part 1 The Breach at Limetree,
Interview with Jack Sterling. Retrieved from online Learning Platform at SNHU.
What is a denial of service attack (DoS) ? - Palo Alto Networks. (2019).
Paloaltonetworks.com. Retrieved 11 September 2019, from
https://www.paloaltonetworks.com/cyberpedia/what-is-a-denial-of-service-attack-dos
Students also viewed