Running Head: ISE 510
1
ISE 510 Video Game Assignment
Carlos Delapaz
SNHU
ISE 510
2
Introduction
The Agent Surefire: InfoSec game has been played and a number of physical
vulnerabilities have been identified. A total of seven vulnerabilities have been
discovered, assessed, and documented which exist in the virtual environmental setting.
These elements have been categorized based on the specific methods that have been
specified in the game.
Seven security vulnerabilities
1. There was a computer system which was not locked and it did not require to be
logged in by a user. This is one of the key vulnerabilities as it contained a folder
which was titled “marketing” and it was saved in the network driver. The folder
contained confidential information such as press releases, budget, artwork and
details on strategic meetings. The vulnerability can be categorized under
“unauthorized access” as anyone could gain access into the system and use or
manipulate the sensitive data and information.
2. There were numerous employees who used the last four digits of their phone
numbers as the PIN for their voicemail. This is another major vulnerability which
falls under the “Using predictable PIN” category. Thus anyone could get access
into the voicemails of the personnel by merely using the phone extension. In the
voice mail by George Himsdale he had stated that he wanted to discuss
international partnership. A listener with malicious intent could disrupt the deal. c
3. An illegal software had been found in the drawer of an employee of the
organization. The disk actually contained Microsoft Office but it had been labeled
as MS Project and the same was cracked. In case the organizational personnel
would insert the specific disk into a computer system of the firm, it could lead to
ISE 510
3
a major ‘Malware infection’ that could compromise the security posture of the
entity.
4. The trash cans that were present there contained documents with official
information which should have been shredded instead of being thrown away in
the dustbin. The category under which the vulnerability can be placed is
“Improper handling or Disposal of Sensitive Documents”. In case anybody would
pass by these trash cans he or she could steal these documents containing
sensitive work-related data such as details about paychecks, information on VIP
clients, debriefs from sales calls and time reports.
5. Numerous drawers and cabinets were not unlocked and the contents contained
information on the company. It is necessary to make sure that all drawers and
cabinets are locked and secure whether the information contained in them is
sensitive or not. This vulnerability can be categorized under “Office Cabinets and
Drawers Security”.
6. Some of the employees of the firm had a large number of documents and files
on their desks which contained details relating to the firm’s business plan. This
physical vulnerability can be categorized under the “improper handling of
sensitive documents”. In order to take care of this vulnerability, the employees
need to make sure that the documents containing confidential information are
kept in a safe and secure manner.
7. There were a couple of Portable Device Assistants (PDAs) and a storage device
that had been placed under a desk. This particular physical vulnerability can be
categorized under “Lost Laptop or Portable Devices”. It is necessary to ensure
that all the devices such as laptops as well as portable devices are secured to the
desk and they have cable locks. In case an employee goes away from his or her
ISE 510
4
desk, then they must ensure that the device that has been assigned to them is
securely locked up in their drawer. This will prevent unauthorized individuals
cannot from gaining access into the systems and stealing or viewing sensitive
information.
It is necessary to eliminate these physical vulnerabilities and keep the company
information on a safe and secure manner. c c c c
Reference:
Federal Incident Reporting Guidelines | CISA. (2019). Us-cert.gov. Retrieved 31 August
2019, from https://www.us-cert.gov/government-users/reporting-requirements