1 / 5100%
Running Head: ISE 510
1
SNHU
ISE 510 Security Risk Analysis & Plan
Security Breach Analysis and Recommendations
Milestone 1: Kickoff Agenda
(60 points)
ISE 510
2
2
1. Security Breach. Some of the likely causes of the breach include the poor security posture
of the organization, the lack of proper documentation of the security policies and the lack of
proper training of employees on security awareness. g g g
2. Attack Location: The attack that took place in Limetree impacted all the employees of the
research organization especially the research team. This is because personal health information
(PHI) that was used in a recent research study was stolen by the attackers.
3. Attack Method and Tools: In order to carry out the security breach attack, the insider data
theft attack is a probable method that could be used by an attacker. In such an attack, sensitive
information relating to the company could be stolen without the knowledge of the employees.
As the employees lack proper training ion security awareness, this method must have been
used to conduct the security breach in Limetree (Supplement to ISE510 Security Risk and
Planning, 2019).
4a. Vulnerabilities: What were the two major vulnerabilities that were exploited to affect
the attack?
As per Jack, even though the firm has faced security incidents before, no previous
documented history of incidents was stored which could be used to identify the corrective
measures that were taken to deal with the incidents. Similarly, the process of sharing
information on a computer incident is quite lengthy. For instance, the administrators escalate
the incident to the IT manager, who reports incidents to the security manager if they are
considered to be relevant. These were the two major vulnerabilities that were exploited to
affect the attack as per John.
4b. Vulnerabilities: The physical vulnerabilities that Jack Sterling has identified include:
• Users are not given training on security awareness
• Visitors just sign in at the front desk and are allowed to walk in to see employees at
their respective offices.
• The users are generally allowed to bring in their own laptops and connect to the
corporate system.
4c. Vulnerabilities: The vulnerabilities that Jack Sterling has identified in the Administrative
Office workstations include:
• The low level of security setting of the Internet Explorer browser and the absence of a
standard browser for the environment.
• The low disk space for SQL database log which is overwritten with new information
when it is full.
• No segmentation or authentication between the wireless and wired LAN. Visitors are
given access code to use the wireless network of the company.
• Absence of logging of network activities on any of the switches.
• The public-facing web server is a part of the LAN and it acts as the key point where
internet users get information on the company.
• Absence of documented security policy, or computer use policy.
ISE 510
3
3
• Lack of a proper documented process for changes to the system.
• Absence of any contingency plan.
4d. Vulnerabilities: The vulnerabilities that Jack Sterling identified regarding the Wi-Fi was
that the Wireless network was available with clearly advertised SSID, and it was a part of the
local area network (LAN). There was no segmentation or authentication between the wireless
and wired LAN which was a major security blunder. Visitors are given access code to the
wireless network at the front desk which increases the vulnerability of the firm’s network.
5. Write a Scope Statement.
The scope of the meeting would revolve around conducting a thorough security breach
analysis so that necessary details and information can be captured suitable recommendations
can be made for Limetree Inc. Each of the security-related items would be covered discussed
and described to conduct the risk assessment.
6. What is the purpose of a Risk Analysis? g
The purpose of a Risk Analysis is to identify and assess any potential issue which could
adversely impact the IT environment of LimeTree. The process would help to avoid or
mitigate the risks in an effective manner so that the security posture could be improved.
7a. Considering what was stolen from LimeTree, who/what is the primary Threat source?
Recently, Limetree Inc. had experienced a security breach and it is believed that confidential
company data were stolen such as personal health information (PHI) that were used in a
research study. The primary threat source could be internal employees of the organization.
7b. In the case of LimeTree, give an example of an unintentional (i.e. accidental) Threat
source?
An example of an unintentional or accidental) threat source for Limetree could be the
employees. As they are not provided adequate training on security awareness, while using
their personal computers they could unintentionally be compromising the security of the
entity.
7c. Why is LimeTree not concerned about a denial of service (DoS) attack on its
corporate website for this project?
LimeTree is not concerned about denial of service (DoS) attack on its corporate website for
the project as such a threat would not lead to the loss or theft of any data that is available
with the organization.
8. What controls would you suggest for mitigating these threat-vulnerability pairs:
In order to mitigate the threat-vulnerability pairs that exist in the It setting of Limetree there is
the need to introduce proper documentation of the security policies, provide adequate training
to the employees on security awareness, and bring about necessary changes to the Bring Your
Own Device policy. Similarly, access must not be given to visitors to meet the employees at
their workstations (What is a denial of service attack (DoS) ? - Palo Alto Networks, 2019). g
ISE 510
4
4
8a. Mitigating the threat of unauthorized persons entering the main facility from the
lobby?
There is the need to shift the access control from the lobby to the main facility so that visitors
of the employees will not be allowed to meet them at their work desk.
8b. Mitigating the threat of unauthorized persons entering the exits marked “Emergency
Exits?”
In order to mitigate the risk that arises when unauthorized persons enter the exits marked
‘Emergency Exits’, the physical security of the office must be strengthened and CCTV
cameras must be installed at different office areas.
8c. Mitigating the threat of a vulnerable operating system and/or outdated antivirus
being exploited and hijacking the workstation?
Limetree must regularly update the software, applications and operating system so that the
online vulnerability can be handled effectively. Similarly, the antivirus software must be
regularly upgraded so that it can offer proper protection against malicious elements.
ISE 510
5
5
References
Supplement to ISE510 Security Risk and Planning, (2019). Part 1 The Breach at Limetree,
Interview with Jack Sterling. Retrieved from online Learning Platform at SNHU.
What is a denial of service attack (DoS) ? - Palo Alto Networks. (2019).
Paloaltonetworks.com. Retrieved 11 September 2019, from
https://www.paloaltonetworks.com/cyberpedia/what-is-a-denial-of-service-attack-dos
Students also viewed