1
Running Head: ISE 510
SNHU
ISE 510 Security Risk Analysis & Plan
Security Breach Analysis and Recommendations
Milestone 2: Test Plan
(AKA Risk Assessment Planning)
Delapaz Carlos
Due September 15,2019
Submitted on September 15,2019
2
ISE 510
Introduction
a) Limetree and its capabilities
Limetree Inc. is a well-known research and development entity which is involved in numerous
research projects with the federal government. It also engages in research projects with a number
of private organizations in areas like biotechnology, healthcare, and other cutting-edge
industries. In recent years, it has been experiencing substantial growth in the dynamic market
setting.
Some of the key capabilities of the business entity include robust firewall configuration, high
involvement of the Information Technology managers to make network configuration changes,
and the regular backup of the system. The robust information security framework of the business
undertaking gives it an edge in the operational industry setting. In spite of this, there exist a
series of loopholes in the security posture of Limetree Inc. which increases its level of
vulnerability in the cyber setting. Recently, the firm had experienced a security breach incident
and it is believed that sensitive information was stolen from the organization.
b) Goal for the security breach analysis project
The ultimate goal of carrying out the security breach analysis project is to get a detailed insight
into the vulnerabilities that weaken the security system of the business and give an unfair
advantage to online attackers and cybercriminals. The test will basically help to identify the key
risks that the business is exposed to which could compromise the overall quality of the security
system (Singhal & Ou, 2017).
Malicious cybersecurity incidents had cost the United States economy between USD 57 billion
and USD 109 billion in the year 2016 alone. Both large and small businesses need to identify
their security vulnerabilities and strengthen their cybersecurity framework so that security breach
incidents can be prevented or avoided. The goal of the security breach analysis project is to
assess the security posture of Limetree Inc. from a cybersecurity perspective so that the
vulnerability of the firm can be kept under check. The assessment will enable the entity to
continue to grow the business by complying with the latest information security protocols and
standards.
Scope
a) Scope of the project
The scope of the project revolves around conducting a thorough assessment of the information
security system of Limetree Inc. so that the security breach can be evaluated. In order to carry
out a comprehensive check, there is the need to forensically analyze all the 250 computers that
are used in Limetree Inc. Based on the thorough analysis, suitable recommendations would be
made for the research and development business so that the security posture of its IT system can
be strengthened. The various risks and threats that the business undertaking is currently exposed
to because of its security loopholes will be identified and accordingly, a roust security model will
be planned for the firm.
Hardware and Software:
a) List of hardware and software
In the present times, Limetree Inc. has in place certain hardware and software that make up its
Information Technology ecosystem. The firm has a medium-sized network which enables it to
carry out the online activities. The key components of Limetree’s network include 250 desktops,
7 remotely manageable Cisco switches, 5 file and printer servers, 3 email servers, 3 web or
2
3
ISE 510
applications servers, 3 wireless access points, 3 firewall devices, 2 proxy servers, and 1 gateway
device to the internet (router).
The software or applications that are used in the research and development entity include Google
Chrome, Firefox, Internet Explorer, Microsoft Office, Adobe Flash, and Adobe Acrobat. But
there exists no standard browser that is used in the business environment. These browsers even
permit the remote installation of applets which impacts the security posture of the business. The
virus software that is employed in the business undertaking is MacAfee. It is locally deployed on
the computer systems of each and every user and the virus policy needs to be updated every
month mandatorily.
The Structured Query Language (SQL) Database is used in the IT setting of Limetree. But the
total disk space for the SQL database log that is available is quite small. In fact, it is overwritten
with new information whenever it gets full.
Resources:
a) Determination of resources required and brief explanation
A number of resources are needed in order to carry out the Security Breach Analysis and make
suitable recommendations for Limetree Inc. The resources can be categories into people (human
factors), software, and hardware.
1) People Resources
People resources would be of key importance to make sure that security issues, risks and
vulnerabilities can be effectively identified and the overall quality of the security posture can be
strengthened.
Table 1
ACME Team Members - Roles, Skills, and Cost per hour
Team Member
Title
Role Skills, Experience, and
Certifications
Cost
(see
note 1)
Lead Cyber
Security Engineer
Develop and field secure
network solutions; Perform
Network Scans, Risk
Assessments, and penetration
testing; Manage security
technology, implement
Security Technical
Implementation Guidelines
(STIG)
CEH: Certified Ethical
Hacker.
CISM: Certified Information
Security Manager.
CISSP: Certified Information
Systems Security
Professional.
GSEC: SANS GIAC Security
Essentials.
$ 250
Security
Consultant
Design effective
cybersecurity strategies
across Limetree (Arora,
2019)
CISSP: Certified Information
Systems Security
Professional
CEH: Certified Ethical
Hacker
$ 220
Chief
Information
Protect Limetree’s data and
intellectual property,
Bachelor’s degree in
Computer Science
$ 300
3
4
ISE 510
Security Officer
(CSO)
strategize and deploy IT
security strategies to
safeguard the research and
development business from
potential risks, threats and
cyber hacking (Arora, 2019).
CISSP: Certified Information
Systems Security
Professional
CISA: Certified Information
Systems Auditor
CISM: Certified Information
Security Manager
GSLC: GIAC Security
Leadership Certification
Note1: Cost is per hour, charged to Limetree, based on twice the hourly wage
4
5
ISE 510
2) Software Resources
Software resources would be required so that the breach analysis would assist to locate the core
risks and threats that could cripple the IT ecosystem of Limetree Inc. firm.
Table 2
ACME Software Resources for Breach Analysis
Software Description Retail Cost and URL Cost
(see
note 1)
Wireshark Wireshark is a free and open-
source packet analyzer
(Wikipedia, n.d.)
https://www.wireshark.org Free
Varonis Varonis is a robust security
software platform which would
help to track, visualize, evaluate
and safeguard the unstructured
data of Limetree.
https://www.varonis.com/ $ 1,700
Suricata Suricata is a fast open-source
privacy breach detection
software which could perform
intrusion detection on a real-time
basis.
https://suricata-ids.org/ Free
TOTAL 1700
Note 1: Cost is one-time only, charged to Limetree, based on one-tenth the retail cost
3) Hardware Resources
Hardware resources would be necessary for carrying out the breach analysis at Limetree. They
would primarily help to critically analyze the IT system and identify security risks that could
adversely impact the IT infrastructure of the Limetree firm.
Table 3
ACME Hardware Resources for Breach Analysis
Hardware and
Software
Description Retail Cost and URL Cost
(see
note 1)
Dell Laptop with high
internet connectivity
Dell laptops would
be required by the
security personnel to
conduct the real-time
assessment of the IT
system of Limetree.
https://www.dell.com/en-in/shop/
scc/sc/laptops?~ck=mn
$ 760
5
6
ISE 510
Breach detection
systems with the
application and
security devices
The combination of
application and
security devices
would play a key role
to enhance the
detection of risks and
threats in the cyber
setting.
https://www.nsslabs.com/tested-
technologies/breach-detection-
system/
$ 440
TOTAL $ 1200
Note 1: Cost is one-time only, charged to Limetree, based on one-tenth the retail cost
Timeline and Benchmarks:
a) Timeline for the project
For reducing the security risks of Limetree and increasing the level of control of the security
assessment project, the security project would be segmented into three phases. The three phases
that would be involved in the security assessment protocol are review, examination, and testing.
Each of these phases would be of critical importance to conduct a thorough assessment of the
security framework of Limetree. In present times, the reviewing phase is being carried out. It
could take almost three more days to complete this phase of the security process. The
examination and the testing phase would take approximately one week each. Ample time would
be necessary so that the Information Technology ecosystem of the firm could be critically
assessed to locate any kind of vulnerabilities that could exist in the system.
b) Regulatory benchmark you to make vulnerability determination
The regulatory benchmark would also play a vital role to make sure that the vulnerability
determination of Limetree could be effectively carried out. National Institute of Standards and
TechnologyHSpecial Publication 800-30 or NIST 800-30 would govern the entire security
procedure that would be followed to carry out the IT security assessment of the research and
development business entity. While conducting the project, it would be ensured that all the steps
mentioned in the standards and documents are properly followed while conducting the security
assessment procedure (Stoneburner, Goguen & Feringa, 2002).
Approach:
a) Approach on the following Steps:
Step 1: Identify threats and vulnerabilities
A systematic approach would be adopted to identify the threats and vulnerabilities that arise or
exist in the IT system would involve the interview of the security personnel of the organization.
Data would be collected through the interviewing process. It would be followed by a thorough
investigation of the corporate office of Limetree. This observation would help to locate loopholes
which could have an adverse implication on the security posture of the organization. The rules
highlighted in NIST 800-30 would be used to carry out the comprehensive risk assessment. The
quantitative data would be collected so that the exact degree of impact could be determined at the
end of the analytical procedure.
Step 2: Determine the impact of a risk
6
7
ISE 510
Both the technical and non-technical data would be collected while carrying out the security
assessment process so that a holistic insight into the security posture of Limetree would be
possible. Based on the recent security breach incident that has jolted Limetree Inc. and the
assessment of the current security posture, it can be stated that the degree of the risk could be
severe. There exists a high degree of vulnerability which intensifies the overall risk that is faced
by the research and development business firm in the cyber setting. The extent of the risk can be
categorized as “very high” as the online security posture is weak. IN addition to this the office
premises of Limetree does not help the business to safeguard the sensitive business information.
Thus, these surety loopholes increase the risk factor which can compromise the overall security
of the firm.
References
Arora, S. (2019, August 2). Infographic: Top 7 Jobs in IT Security. Retrieved from
https://www.simplilearn.com/top-it-security-jobs-article
Stoneburner, G., Goguen, A., & Feringa, A. (2002). Risk Management Guide for Information
Technology Systems. Recommendations of the National Institute of Standards and
Technology: NIST SP 800-30 [Електронний ресурс].HNIST. gov-Computer Security
Division-Computer Security Resource Center [сайт]/Gary Stoneburner, Alice Goguen,
and Alexis Feringa, 800-30.
Singhal, A., & Ou, X. (2017). Security risk analysis of enterprise networks using probabilistic
attack graphs. InHNetwork Security MetricsH(pp. 53-73). Springer, Cham.
7