1 / 15100%
Running Head: ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 1
SNHU
ISE 510 Security Risk Analysis & Plan
Security Breach Analysis and Recommendations
FINAL PROJECT
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 2
2
I. Introduction
Limetree Inc. is a well-known research and development business entity that
specializes in research projects in various areas such as biotechnology, healthcare, and
other cutting-edge industries. It works with private corporations as well as the federal
government. Lately, the business undertaking has been experiencing substantial growth in
the operational industry but it is concerned about the rising security breach incidents
that are taking place in the unpredictable industrial setting. One of the core objectives
of the business undertaking is to strengthen its information security program so that it
can achieve its business goal.
The Limetree Inc. organization has been facing significant security breaches
lately. It believes that confidential information was stolen from it including Personal
Health Information (PHI) that were utilized in a research study. The existing security
protocols and policies are inadequate as they do not adhere to the existing industry
standards. The security breach incident could adversely impact the survival and
sustainability of Limetree Inc. in the operational industry. Malicious cybersecurity
incidents had cost the United States economy between USD 57 billion and USD 109
billion in the year 2016 alone. Both large and small businesses need to identify their
security vulnerabilities and strengthen their cybersecurity framework so that security
breach incidents can be prevented or avoided.
The paper captures the security breach incident that took place in Limetree Inc
and compromised the quality of security of the firm. The key vulnerabilities of the
entity have been identified and a robust incident response plan has been designed so
that similar kinds of security incidents could be prevented in the future. A security test
plan has been designed and suitable recommendations have been designed to strengthen
the security infrastructure of the organization.
II. Security Breach
Some of the likely causes of the breach include the poor security posture of the
organization, the lack of proper documentation of the security policies and the lack of
proper training of employees on security awareness. At present Limetree does not have
a robust security framework in place which could give cyber attackers an upper hand to
exploit the vulnerabilities of the organization. The low security posture of the firm is a
major IT concern that could have led to the security breach incident.
A. Attack Location:
The attack that took place in Limetree impacted all the employees of the research
organization especially the research team. This is because personal health information
(PHI) that was used in a recent research study was stolen by the attackers. The
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 3
3
physical and IT environment of Limetree has a number of gaps that could have given
access to online hackers to invade the system and compromise the security.
B. Attack Method and Tools:
In order to carry out the security breach attack, the insider data theft attack is a
probable method that could be used by an attacker. In such an attack, sensitive
information relating to the company could be stolen without the knowledge of the
employees. As the employees lack proper training on security awareness, this method
must have been used to conduct the security breach in Limetree.
C. Vulnerabilities:
As per Jack Sterling, the Security Manager of Limetree Inc, even though the firm
has faced security incidents before, no previous documented history of incidents was
stored which could be used to identify the corrective measures that were taken to deal
with the incidents. Similarly, the process of sharing information on a computer incident
is quite lengthy. For instance, the administrators escalate the incident to the IT manager,
who reports incidents to the security manager if they are considered to be relevant.
These were the two major vulnerabilities that were exploited to affect the attack as per
John.
The physical vulnerabilities that Jack Sterling has identified include:
• Users are not given training on security awareness
• Visitors just sign in at the front desk and are allowed to walk in to see
employees at their respective offices.
• The users are generally allowed to bring in their own laptops and connect to the
corporate system.
The vulnerabilities that Jack Sterling has identified in the Administrative Office
workstations include:
• The low level of security setting of the Internet Explorer browser and the
absence of a standard browser for the environment.
• The low disk space for the SQL database log which is overwritten with new
information when it is full.
• No segmentation or authentication between the wireless and wired LAN. Visitors
are given access code to use the wireless network of the company.
• Absence of logging of network activities on any of the switches.
• The public-facing web server is a part of the LAN and it acts as the key point
where internet users get information on the company.
• Absence of documented security policy, or computer use policy.
• Lack of a properly documented process for changes to the system.
• Absence of any contingency plan.
The vulnerabilities that Jack Sterling identified regarding the Wi-Fi was that the
Wireless network was available with clearly advertised SSID, and it was a part of the
local area network (LAN). There was no segmentation or authentication between the
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 4
4
wireless and wired LAN which was a major security blunder. Visitors are given access
code to the wireless network at the front desk which increases the vulnerability of the
firm’s network.
III. Incident Response
The purpose of the incident response plan is to help the research and
development organization to be prepared in case any security incidents arise. It would
strengthen the security infrastructure of the organization and minimize its vulnerability
on the cyber platform.
The current Incident Response Plan at Limetree is very ineffective and weak. I case
any security incidents arise, the system administrators are notified of the same and they
escalate the issue to the IT Manager. He is then responsible to report the incident to
the Security Manager if it is considered to be an actual incident. Currently, there exists
no documentation process so there is no record of previous security incidents.
A. Purpose of the Incident Response Plan
The purpose of the incident response plan is to help the research and development
organization to be prepared in case any security incidents arise. It would strengthen the
security infrastructure of the organization and minimize its vulnerability on the cyber
platform.
B. Incident Response
A new Incident Response Plan has been proposed that could be introduced at
Limetree to upgrade its security posture. The process has been designed so that the
Incident Response Team could take necessary measures to deal with the security issue
and make sure that the extent of the damage can be curbed to the best possible extent.
The main phases that would be involved in the plan have been highlighted below.
1) Preparation - In the preparation stage, Limetree must make sure to develop suitable
capabilities so that security incidents could be prevented in the future. So the research
and development organization must ensure highly-functional and effective networks,
systems, hardware, and applications are employed. ad
2) Identification - Limetree has to confirm, categorize, determine the scope and
prioritize various kinds of risks that could arise in the IT ecosystem. Such an approach
would enable the business to get a better insight into the threats and risks that could
affect the business in the cyber setting.
3) Containment - Necessary steps have to be in place so that the damage can be
minimized or mitigated to a possible extent. Limetree has to ensure the affected devices
are disconnected from the internet so that the spreading of the breach could be
restricted (Supplement to ISE510 Security Risk and Planning, 2019).
4) Eradication - In order to eliminate the cybersecurity threat, Limetree has to ensure
that the root cause of the issue is dealt with. So, all malicious elements have to be
securely removed and the system would have to be hardened and patched.
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 5
5
5) Recovery - Limetree has to assess the incident to get a detailed insight into the
procedural and policy implementations (CRR Supplemental Resource Guide, 2019). At
this stage, the business undertaking would have to restore the affected systems so that
they could be restored and brought back into the business environment. The firm must
ensure to document each and every process so that in the new future it could prepare
itself in case a similar security breach incident arises (Blair, 2015).
6) Lessons Learned – After the in-depth investigation relating to the cybersecurity
incident has been completed, a post-action meeting must be conducted by the Incident
Response team at Limetree. All the members would get the opportunity to discuss the
learning from the data breach incident. This meeting would allow them to assess and
document every little aspect relating to the security incident. Some of the main
questions that need to be addressed relate to the following areas:
• The changes that need to be introduced in the security model of Limetree so
that its security posture can be strengthened.
• The training process that must be implemented for the employees of the firm
so that their security awareness can be improved
• The exact weaknesses and vulnerabilities that were exploited by the cyber
attackers
• The steps that must be taken to avoid similar kinds of security breach incident
in the future
C. The Incident Response Process:
The new Incident Response Process that would be implemented at Limetree
encompasses a number of procedures that will help to minimize the impact of the
security incident and make a solid recovery. The figure that has been highlighted below
shows that a number of processes of the response plan would be carried out
interchangeably so that proper measures could be introduced to deal with the security
issue. After a security incident has been identified and corrective actions have been
taken, the recovery procedure must be initiated. As highlighted in the figure, in case
fresh malicious elements have been identified, the team can go back to the containment
stage so that suitable measures can be deployed to contain the extent of damage that
might be caused by the IT security breach incident. ad ad ad
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 6
6
The team would have to actively assess the Information Technology ecosystem of
Limetree so that it could be able to identify any kind of malicious behavior in its
network or system. All the phases of the Incident Recovery Plan must be followed in a
disciplined manner. The logging records must be critically analyzed to identify any
potential security incident. IT would help to classify the incident that could arise before
the research and development entity and compromise its security posture.
The IT staff members and personnel would be playing an active role throughout
the cybersecurity incident in the organizational setting of Limetree so that all traces of
malicious elements could be effectively identified and suitable actions could be taken
against them. Throughout the process, the roles of communication among the team
members would be of paramount importance. Such an approach would make sure that
the proper flow of information and details takes place among the organizational
personnel on a real-time basis. The knowledge of the professionals on the latest
cybersecurity incidents must be upgraded on a regular basis so that they could play an
active role throughout the incident response process within Limetree Inc.
IV. Impact
A. Application
Limetree Inc. is a reliable research and development organization that conducts
research activities in various curing edge fields for both the federal government as well
as private corporations. As it has a close link with the federal government, and its
research projects, the R&D firm has to abide by the latest federal legislation as well as
industrial regulations and standards so that it can keep a robust security framework in
place. There are a number of Acts and laws that the organization must give special
attention to so that a strong security posture can be maintained. For instance, the
business undertaking must comply with the Health Insurance Portability and
Accountability Act (HIPAA) which relates to data privacy and security provisions. The
objective is to safeguard the confidential medical information (Rouse & Biscobing,
2019).
Limetree must also adhere to the Health Information Technology for Economic and
Clinical Health Act. This act was initiated to encourage the implementation of electronic
health records (EHR) and strengthen the use of technology in the United States of
America. The HITECH Act was introduced in the year 2009 so that the exchange of
electronic protected health information (ePHI) between hospitals, physicians and other
bodies could be simplified (What is the HITECH ACT?: What HITECH Compliance
Means, 2019). Limetree Inc. has to ensure that the security model that is implemented
throughout the organization is in sync with the regulations and legislation that exist in
the industrial setting. The National Institute of Standards and Technology (NIST) must
be considered as the main body which would provide proper guidelines so that the IT
security infrastructure of the organization could be strengthened.
B. Impact
The regulations and industry standards that have been introduced by NIST would
playa vital role and help Limetree to strengthen the IT security framework of the
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 7
7
organization. It must make sure to adhere to NIST guidelines, HIPAA and HITECH so
that the confidentiality and integrity of the sensitive business information would not get
compromised. The regulations would basically guide the research and development firm
to introduced robust and appropriate security controls in place which could upgrade the
effectiveness of the security system. The inability to comply with the security legislation
and standards would have a negative impact on the business reputation of Limetree. In
addition to this, legal action could be taken by its clients in case a security breach
incident is extremely serious in nature.
C. Financial and Legal Implications
The implications that Limetree Inc. would face if it fails to adhere to the
regulations and a security breach incident occurs would affect it legally and financially.
The trustworthiness of the business in the market environment could be adversely
affected which would affect its credibility before its clients and customers. If clients
would lose trust, they would shift to Limetree’s competitors and its profitability could
drastically decline. In case Limetree gets involved in a major security breach incident
where confidential and highly sensitive information of the clients gets leaked then it
could be taken to the court of law.
V. Security Test Plan
The security test plan primarily captures the scope of the security test, the key
resources that would be used to strengthen the security posture of the organization. The
resources that have been highlighted in this section include the people resources. In
addition to this, the hardware and software of Limetree Inc. have also been captured as
they make up the Information Technology infrastructure of the organization. The special
tools that would be required by the ACME Cybersecurity, based on Limetree’s hardware
and software have also been highlighted in the security test plan.
A. Scope:
The scope of the project is to conduct a thorough assessment of the information
security system of Limetree Inc. so that the security breach incident can be evaluated.
In order to carry out a comprehensive check, there is the need to forensically analyze
all the 250 computers that are used in Limetree Inc. Based on the thorough analysis,
suitable recommendations would be made for the research and development business so
that the security posture of its IT system can be strengthened. The various risks and
threats that the business undertaking is currently exposed to because of its security
loopholes will be identified and accordingly, a roust security model will be planned for
the firm.
The risk assessment will help Limetree to get an in-depth idea about the
effectiveness or ineffectiveness of the existing security approach. The ACME
Cybersecurity Consulting Team would enable the research and development entity to
understand the IT vulnerabilities that exist in the business undertaking which give an
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 8
8
edge to cybercriminals and attackers. The security test plan has been designed with the
intention to identify the threats and vulnerabilities so that suitable strategies can be
introduced in order to mitigate the same. The team of experts that have been hired
would play a vital role to execute the project security plan. They would help to
develop robust secure network solutions, safeguard the firm’s confidential data and
design suitable cybersecurity strategies across the organization.
B. Resources:
People resources would be of chief importance to make sure that security issues,
risks and vulnerabilities in Limetree Inc. can be effectively identified and the overall
quality of the security posture can be strengthened.
Table 1
ACME Team Members - Titles and Roles
Team Member Title
Role
Lead Cyber Security
Engineer
The role would include the development of secure
network solutions, performing network scans, conducting
risk assessments, and penetration testing. He would also
manage the firm’s security technology, implement the
Security Technical Implementation Guidelines (STIG)
throughout the entity.
Chief Information
Security Officer
(CSO)
His primary responsibility is to safeguard Limetree’s data
and intellectual property. In addition to this, he has to
strategize and employ IT security strategies so that
adequate security could be given to the research and
development business from potential risks, threats, and
cyberattacks.
Security Consultant
He would be responsible to design effective
cybersecurity strategies across the Limetree organization.
C. Hardware and Software:
Currently, Limetree Inc. has in place numerous hardware and software that make
up its Information Technology ecosystem. The firm has a medium-sized network which
enables it to carry out the online activities. The key components of Limetree’s network
include 250 desktops, 7 remotely manageable Cisco switches, 5 file and printer servers,
3 email servers, 3 web or applications servers, 3 wireless access points, 3 firewall
devices, 2 proxy servers, and 1 gateway device to the internet (router).
The software or applications that are used in the research and development entity
include Google Chrome, Firefox, Internet Explorer, Microsoft Office, Adobe Flash, and
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 9
9
Adobe Acrobat. But there exists no standard browser that is used in the business
environment. These browsers even permit the remote installation of applets which
impacts the security posture of the business. The virus software that is employed in the
business undertaking is MacAfee. It is locally deployed on the computer systems of
each and every user. The antivirus needs to be updated every month mandatorily in all
the systems of the organization.
The Structured Query Language (SQL) Database is used in the IT setting of
Limetree. But the total disk space for the SQL database log that is available is quite
small. In fact, it is overwritten with new information whenever it gets full.
ad
D. Tools:
For conducting a thorough security test in Limetree Inc., the ACME team would
require a number of tools and resources so that a critical risk assessment procedure
could be conducted which would help to get an insight into the security posture of the
research and development organization. Firstly, a team of experienced and qualified IT
professionals would be required so that they could assess the existing IT ecosystem of
the firm. At present, Limetree already has an efficient Security Manager Jack Sterling.
The team members would assist the firm’s Security Manager so that a holistic risk
assessment could be carried out. The tools that the specialized team would need for
conducting the risk assessment have been highlighted in the table.
Table 2
ACME – Software Resources for Breach Analysis
Software
Description
Wireshark
The free and open-source packet analyzer would be used
for various purposes such as network troubleshooting,
software, and communication protocol development,
analysis, and education. The data traffic could be
effectively analyzed and abnormal behavior could be
identified.
Varonis
Varonis is a robust security software platform that would
help to track, visualize, evaluate and safeguard the
unstructured data of Limetree.
Suricata
Suricata is a fast open-source privacy breach detection
software that could perform intrusion detection on a real-
time basis.
VI. Risk Mitigation:
Risk mitigation is a vital strategy that would be necessary for Limetree Inc. so that
it could minimize the impact of threats and risks that could arise in its online setting.
Suitable security controls would be introduced which would ensure that similar breach
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 10
10
incidents would not reoccur in the future and compromise the security posture of the
research and development entity. Some of the core elements that have been captured in
the section relates to security controls, mitigation of vulnerabilities and evaluation of the
effectiveness of the controls (Rouse & Sullivan, 2019).
A. Security Controls at Limetree Inc:
1. Access control (for transmission medium) – Limetree must control the physical
access to the telecommunication medium by enclosing them in the rigid conduit
that is sealed with tamper-resistant epoxy and locking pull and drop boxes.
Risk – If a malicious actor were to get physical access to network cabling, they
could acquire unauthorized access and Limetree would never know without a
physical inspection or audit.
Impact – The most significant impact would be financial due to loss of
contracts or leaked proprietary information.
Likelihood – Low. Before implementing the recommended controls in this
document, there were many easier opportunities to exploit, and after Limetree
implements this control, a malicious actor would be detected due to the metal
conduit encasing the unencrypted cabling would obviously show the signs of
tampering.
2. Awareness and Training (Security Awareness Training) – Limetree must
provide necessary training to the employees so that they would be aware of the
basic security elements. While making changes to the firm’s information system
model, proper training would be vital to make sure the personnel are skilled to
identify any kind of abnormality in the firm’s network (Nvd - Control - At-2 -
Security Awareness Training, 2019).
Risk – In case any abnormal behavior would appear in the network, for
example, receipt of hundreds of spam emails, the employees could intimate the
network administrator about it so that appropriate actions could be taken. ad
Impact – The main impact on the human factors as they would be empowered
to strengthen the security posture of the business organization.
Likelihood – High. This control would be of paramount importance that could
upgrade the overall effectiveness of the security model of the entity.
3. Incident Response Control (Incident Reporting) – A proper reporting protocol
must be in place in Limetree so that the employees would be able to use them
in case they come across a possible security breach incident (Nvd - Control - At-
2 - Security Awareness Training, 2019).
Risk – The employees of Limetree would know the exact steps that they can
take at the individual level to report any suspected security incident to the firm’s
incident response capability. One of the main risks includes the receipt of
suspicious or malicious communication mails on a frequent basis.
Impact – This security control would impact the entire IT system of Limetree
Inc. and help to address formal incident reporting requirements as well as
specific incident reporting requirements.
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 11
11
Likelihood – High. The likelihood of introducing the security control is High in
Limetree Inc. as it could be well prepared to deal with any unpredictable
security incident that could arise at any time.
4. Physical and Environmental Protection Control – Limetree must design proper
procedures to facilitate the implementation of functional physical and
environmental protection rules so that the documents could be properly disposed
of and unauthorized personnel would not gain access into the office premises
(Nvd - Control - At-2 - Security Awareness Training, 2019).
Risk – No outsider or guests would be able to loiter inside the office premises.
This security control would help to ensure that such unprofessional behavior is
controlled and the official documents are safe from inaccessible to outsiders.
Impact – The control would have a direct impact on the human resources as
they would have to entertain outsiders such as clients and guests outside the
office premises.
Likelihood – Moderate. The likelihood of introducing the control is moderate but
it would play a key role to strengthen the security infrastructure of Limetree. ad
5. Risk Assessment Control – Limetree must conduct a regular risk assessment of
the IT infrastructure so that it could get a detailed insight into the magnitude of
harm from any unauthorized users (Nvd - Control - At-2 - Security Awareness
Training, 2019).
Risk – Any kind of threats or vulnerabilities that would exist in the IT setting
of the business undertaking could be identified. Thus, the scope of cyber hackers
could be restricted to a significant degree.
Impact – The impact of the security control would be technical in nature as the
assessment would inspect the IT infrastructure of the business entity.
Likelihood – High. The likelihood of the security control is high s it would
enable Limetree to conduct a thorough risk analysis to identify any kind of
suspicious or malicious activity within its organizational network.
6. Maintenance control – Limetree has to maintain the robust nature of the IT
security so that unauthorized actors would not get the chance to exploit the
vulnerabilities of the research and development entity (Nvd - Control - At-2 -
Security Awareness Training, 2019).
Risk – The regular upgradation of antivirus would enable the strengthening of
the IT infrastructure and thus it could safeguard itself from infiltration by online
hackers.
Impact – The impact would be financial in nature as Limetree Inc. would have
to make significant financial investments to upgrade, install and maintain the
security level of the IT system.
Likelihood – Moderate. The likelihood of implementing the maintenance control
in the organizational setting is moderate. This is because it could introduce more
important security measures in place to strengthen the IT security posture.
7. System and Information Integrity (Information System Monitoring) –
Limetree Inc. has to ensure that regular and timely Information System
Monitoring is carried out so that no abnormality could be ignored by the team
(Nvd - Control - At-2 - Security Awareness Training, 2019).
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 12
12
Risk – Any kind of attacks or potential attacks could be identified by
introducing the control relating to Information System Monitoring.
Impact – The impact of the security control would be technical as a thorough
monitoring process would be carried out in the technical environment of the
organization.
Likelihood – Moderate. The likelihood of conducting the Information System
Monitoring is moderate as Limetree would have to implement other vital security
controls to strengthen its security posture.
8. Personnel Security Control (Access Agreements) – Limetree must make sure
to introduce access agreements with certain employees so that the accessibility of
the confidential information could be strengthened (NVD - Family - Personnel
Security, 2019). ad
Risk – No unauthorized personnel would be able to gain entry into the location
or the IT folders where sensitive and confidential information has been stored.
Prior approval would be required from the respective managers for doing so.
Impact – The impact would be felt on the human factors as their accessibility
in the organizational setting would be restricted.
Likelihood – Moderate. There is a moderate likelihood of Limetree to introduce
access agreements so that the confidentiality of the data and information could be
strengthened (Force ad & Initiative, 2013).
B. Vulnerabilities:
The security controls that have been designed for Limetree Inc. would play a critical
role to strengthen the overall effectiveness of the measures that could be introduced to
minimize the extent of the harm or threat. For instance, the introduction of physical and
environmental protection policy would ensure that a professional and secure work
environment can be established where the internal business information would not be
leaked to the outsiders. Similarly, access control for transmission medium would prevent
unauthorized access to telecommunications lines so that the risk due to electronic
eavesdropping can be reduced.
B. Evaluation:
A thorough assessment of the security controls is necessary to ensure they add value
to the quality of security of Limetree. A number of criteria must be introduced for
measuring the controls to make sure that they are properly implemented in the
organizational setting. Limetree Inc. organization must carefully review its
telecommunication wiring diagrams, and carry out tests to ensure that the
telecommunications media is encased in rigid conduit which is sealed with tamper-
resistant epoxy and locking pull and drop boxes. Similarly, the CTV cameras must be
used to assess the office environment and ensure that no unauthorized individuals have
been given access to the office premises. Such evaluation techniques would help to
ensure that the security controls have been effectively implemented throughout Limetree
Inc.
VII. Conclusion
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 13
13
A number of recommendations have been made for Limetree Inc. relating to the
administrative aspects, technical features, organizational personnel, and physical
environment. The objective is to help the research and development entity so that it can
strengthen its security infrastructure.
A. Administrative Recommendations – All the administrative and regulatory
policies must be designed in a simple and understandable manner so that the
organizational personnel of Limetree Inc. would be able to get a detailed insight
into the actions or measures that could be taken by them at the individual level
to improve the effectiveness of the security model. The guidelines must be able
to convey the information relating to Limetree Inc.’s security model with both
technical as well as the non-technical audience. Frequent workshops could be
conducted so that all the administrative guidelines could be shared with the
employees of Limetree in a transparent manner.
B. Technical Recommendations – Limetree must deploy a robust Host Intrusion
Detection System (HIDS) so that it would be able to identify and block common
attacks that could arise in the online environment of the business undertaking. In
the current times, cyber attackers are using a broad range of sophisticated
techniques to gain unauthorized access into the networks of businesses (Intrusion
Detection System (IDS) - GeeksforGeeks, 2019). So, Limetree could strengthen
the IT security infrastructure and technical ability by introducing the IDS which
would enable the firm to monitor the online traffic that is present in its network.
The Network Administrator of the Research and Development entity would also
be able to receive alerts in case any suspicious or malicious activity has been
detected in its network or online infrastructure.
C. Personnel Recommendations – Technical training must be provided to the
organizational personnel of Limetree Inc. so that they would be well aware of
the latest security approaches and techniques. The organizational personnel are
one of the most vital parts of each and every business entity including Limetree
Inc. They are also known to be the weakest link when it comes to the security
system of the IT ecosystem of an organization. In the case of the Research and
Development undertaking, there is the need to ensure that the technical know-
how and expertise of the organizational personnel is constantly upgraded so that
their basic awareness of IT security can be improved. Such a step would be vital
as it would empower the employees to take necessary action in case any
abnormal or suspicious behavior is observed in the network of the organization.
D. Physical Recommendations – Strict guidelines and rules need to be introduced
in Limetree Inc. relating to the work setting and the physical environment of the
organization. The management must ensure that outsiders, guests or unauthorized
individuals are not given access to enter the official premises where the
employees carry out the day to day official work. Such a step would be
extremely vital to ensure that they would not gain an access to confidential
business information. The physical environment in which the employees of
Limetree operate must be thoroughly secured. The security personnel must ensure
that the official premises cannot be accessed by anyone other than the current
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 14
14
employees of the organization. Such a security measure would play a critical role
to safeguard the confidential and sensitive business information of Limetree Inc.
ISE 510 ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 15
15
References
Blair, M. A. (2015). Computer Security Incident Response Plan. Retrieved October 12,
2019, from
https://www.cmu.edu/iso/governance/procedures/docs/incidentresponseplan1.0.pdf.
CRR Supplemental Resource Guide. (2019). Retrieved October 12, 2019, from
https://www.us-
cert.gov/sites/default/files/c3vp/crr_resources_guides/CRR_Resource_Guide-IM.pdf.
Force, J. T., & Initiative, T. (2013). Security and privacy controls for federal
information systems and organizations. NIST Special Publication, 800(53), 8-13.
Intrusion Detection System (IDS) - GeeksforGeeks. (2019). GeeksforGeeks. Retrieved 12
October 2019, from https://www.geeksforgeeks.org/intrusion-detection-system-ids/
Nvd - Control - At-2 - Security Awareness Training . (2019). Nvd.nist.gov. Retrieved 12
October 2019, from https://nvd.nist.gov/800-53/Rev4/control/AT-2
NVD - Family - Personnel Security . (2019). Nvd.nist.gov. Retrieved 12 October 2019,
from https://nvd.nist.gov/800-53/Rev4/family/Personnel%20Security
Rouse, M., & Biscobing, J. (2019). What is HIPAA (Health Insurance Portability and
Accountability Act) ? - Definition from WhatIs.com. Retrieved October 12, 2019,
from https://searchhealthit.techtarget.com/definition/HIPAA.
Rouse, M., & Sullivan, E. (2019). What is risk mitigation? - Definition from
WhatIs.com. Retrieved October 12, 2019, from
https://searchdisasterrecovery.techtarget.com/definition/risk-mitigation.
What is the HITECH ACT?: What HITECH Compliance Means. (2019, September 16).
Retrieved October 12, 2019, from https://compliancy-group.com/what-is-the-hitech-act/
Students also viewed