Running Head: ISE 510
1
SNHU
ISE 510 Security Risk Analysis & Plan
Security Breach Analysis and Recommendations
Milestone 2: Test Plan
(AKA Risk Assessment Planning)
ISE 510
2
2
Introduction
a) Limetree and its capabilities
Limetree Inc. is a well-known research and development entity which is involved in
numerous research projects with the federal government. It also engages in research
projects with a number of private organizations in areas like biotechnology, healthcare,
and other cutting-edge industries. In recent years, it has been experiencing substantial
growth in the dynamic market setting. ab
Some of the key capabilities of the business entity include robust firewall configuration,
high involvement of the Information Technology managers to make network
configuration changes, and the regular backup of the system. The robust information
security framework of the business undertaking gives it an edge in the operational
industry setting. In spite of this, there exist a series of loopholes in the security posture
of Limetree Inc. which increases its level of vulnerability in the cyber setting. Recently,
the firm had experienced a security breach incident and it is believed that sensitive
information was stolen from the organization.
b) Goal for the security breach analysis project
The ultimate goal of carrying out the security breach analysis project is to get a
detailed insight into the vulnerabilities that weaken the security system of the business
and give an unfair advantage to online attackers and cybercriminals. The test will
basically help to identify the key risks that the business is exposed to which could
compromise the overall quality of the security system (Singhal & Ou, 2017).
ISE 510
3
3
Malicious cybersecurity incidents had cost the United States economy between USD 57
billion and USD 109 billion in the year 2016 alone. Both large and small businesses
need to identify their security vulnerabilities and strengthen their cybersecurity
framework so that security breach incidents can be prevented or avoided. The goal of
the security breach analysis project is to assess the security posture of Limetree Inc.
from a cybersecurity perspective so that the vulnerability of the firm can be kept under
check. The assessment will enable the entity to continue to grow the business by
complying with the latest information security protocols and standards.
Scope
a) Scope of the project
The scope of the project revolves around conducting a thorough assessment of the
information security system of Limetree Inc. so that the security breach can be
evaluated. In order to carry out a comprehensive check, there is the need to forensically
analyze all the 250 computers that are used in Limetree Inc. Based on the thorough
analysis, suitable recommendations would be made for the research and development
business so that the security posture of its IT system can be strengthened. The various
risks and threats that the business undertaking is currently exposed to because of its
security loopholes will be identified and accordingly, a roust security model will be
planned for the firm.
Hardware and Software:
a) List of hardware and software
ISE 510
4
4
In the present times, Limetree Inc. has in place certain hardware and software that
make up its Information Technology ecosystem. The firm has a medium-sized network
which enables it to carry out the online activities. The key components of Limetree’s
network include 250 desktops, 7 remotely manageable Cisco switches, 5 file and printer
servers, 3 email servers, 3 web or applications servers, 3 wireless access points, 3
firewall devices, 2 proxy servers, and 1 gateway device to the internet (router).
The software or applications that are used in the research and development entity
include Google Chrome, Firefox, Internet Explorer, Microsoft Office, Adobe Flash, and
Adobe Acrobat. But there exists no standard browser that is used in the business
environment. These browsers even permit the remote installation of applets which
impacts the security posture of the business. The virus software that is employed in the
business undertaking is MacAfee. It is locally deployed on the computer systems of
each and every user and the virus policy needs to be updated every month mandatorily.
The Structured Query Language (SQL) Database is used in the IT setting of Limetree.
But the total disk space for the SQL database log that is available is quite small. In
fact, it is overwritten with new information whenever it gets full.
Resources:
a) Determination of resources required and brief explanation
A number of resources are needed in order to carry out the Security Breach Analysis
and make suitable recommendations for Limetree Inc. The resources can be categories
into people (human factors), software, and hardware.
1) People Resources
ISE 510
5
5
People resources would be of key importance to make sure that security issues, risks
and vulnerabilities can be effectively identified and the overall quality of the security
posture can be strengthened.
Table 1
ACME Team Members - Roles, Skills, and Cost per hour
Team Member
Title
Role
Skills, Experience, and
Certifications
Cost
(see
note 1)
Lead Cyber
Security
Engineer
Develop and field secure
network solutions; Perform
Network Scans, Risk
Assessments, and
penetration testing; Manage
security technology,
implement Security
Technical Implementation
Guidelines (STIG)
CEH: Certified Ethical
Hacker.
CISM: Certified
Information Security
Manager.
CISSP: Certified
Information Systems
Security Professional.
GSEC: SANS GIAC
Security Essentials.
$ 250
Security
Consultant
Design effective
cybersecurity strategies
CISSP: Certified
Information Systems
$ 220
ISE 510
6
6
across Limetree (Arora,
2019)
Security Professional
CEH: Certified Ethical
Hacker
Chief
Information
Security Officer
(CSO)
Protect Limetree’s data
and intellectual property,
strategize and deploy IT
security strategies to
safeguard the research and
development business from
potential risks, threats and
cyber hacking (Arora,
2019).
Bachelor’s degree in
Computer Science
CISSP: Certified
Information Systems
Security Professional
CISA: Certified
Information Systems
Auditor
CISM: Certified
Information Security
Manager
GSLC: GIAC Security
Leadership Certification
$ 300
Note1: Cost is per hour, charged to Limetree, based on twice the hourly wage
ISE 510
7
7
2) Software Resources
Software resources would be required so that the breach analysis would assist to locate
the core risks and threats that could cripple the IT ecosystem of Limetree Inc. firm.
Table 2
ACME Software Resources for Breach Analysis
Software ab
Description
Retail Cost and URL
Cost
(see
note 1)
Wireshark
Wireshark is a free and open-
source packet analyzer
(Wikipedia, n.d.)
https://www.wireshark.org
Free
Varonis
Varonis is a robust security
software platform which
would help to track,
visualize, evaluate and
safeguard the unstructured
data of Limetree.
https://www.varonis.com/
$ 1,700
Suricata
Suricata is a fast open-source
privacy breach detection
software which could perform
https://suricata-ids.org/
Free
ISE 510
8
8
intrusion detection on a real-
time basis.
TOTAL
1700
Note 1: Cost is one-time only, charged to Limetree, based on one-tenth the retail cost
3) Hardware Resources
Hardware resources would be necessary for carrying out the breach analysis at Limetree.
They would primarily help to critically analyze the IT system and identify security risks
that could adversely impact the IT infrastructure of the Limetree firm.
Table 3
ACME Hardware Resources for Breach Analysis
Hardware and
Software ab
Description
Retail Cost and URL
Cost
(see
note 1)
Dell Laptop with
high internet
connectivity
Dell laptops would
be required by the
security personnel
to conduct the real-
time assessment of
https://www.dell.com/en-
in/shop/scc/sc/laptops?~ck=mn
$ 760
ISE 510
9
9
the IT system of
Limetree.
Breach detection
systems with the
application and
security devices
The combination
of application and
security devices
would play a key
role to enhance
the detection of
risks and threats in
the cyber setting.
https://www.nsslabs.com/tested-
technologies/breach-detection-
system/
$ 440
TOTAL
$ 1200
Note 1: Cost is one-time only, charged to Limetree, based on one-tenth the retail cost
Timeline and Benchmarks:
a) Timeline for the project
For reducing the security risks of Limetree and increasing the level of control of the
security assessment project, the security project would be segmented into three phases.
The three phases that would be involved in the security assessment protocol are review,
examination, and testing. Each of these phases would be of critical importance to
conduct a thorough assessment of the security framework of Limetree. In present times,
the reviewing phase is being carried out. It could take almost three more days to
ISE 510
10
10
complete this phase of the security process. The examination and the testing phase
would take approximately one week each. Ample time would be necessary so that the
Information Technology ecosystem of the firm could be critically assessed to locate any
kind of vulnerabilities that could exist in the system.
b) Regulatory benchmark you to make vulnerability determination
The regulatory benchmark would also play a vital role to make sure that the
vulnerability determination of Limetree could be effectively carried out. National Institute
of Standards and Technology Special Publication 800-30 or NIST 800-30 would govern
the entire security procedure that would be followed to carry out the IT security
assessment of the research and development business entity. While conducting the
project, it would be ensured that all the steps mentioned in the standards and documents
are properly followed while conducting the security assessment procedure (Stoneburner,
Goguen & Feringa, 2002).
Approach:
a) Approach on the following Steps:
Step 1: Identify threats and vulnerabilities
A systematic approach would be adopted to identify the threats and vulnerabilities that
arise or exist in the IT system would involve the interview of the security personnel of
the organization. Data would be collected through the interviewing process. It would be
followed by a thorough investigation of the corporate office of Limetree. This
observation would help to locate loopholes which could have an adverse implication on
the security posture of the organization. The rules highlighted in NIST 800-30 would be
ISE 510
11
11
used to carry out the comprehensive risk assessment. The quantitative data would be
collected so that the exact degree of impact could be determined at the end of the
analytical procedure.
Step 2: Determine the impact of a risk
Both the technical and non-technical data would be collected while carrying out the
security assessment process so that a holistic insight into the security posture of
Limetree would be possible. Based on the recent security breach incident that has jolted
Limetree Inc. and the assessment of the current security posture, it can be stated that
the degree of the risk could be severe. There exists a high degree of vulnerability
which intensifies the overall risk that is faced by the research and development business
firm in the cyber setting. The extent of the risk can be categorized as “very high” as
the online security posture is weak. IN addition to this the office premises of Limetree
does not help the business to safeguard the sensitive business information. Thus, these
surety loopholes increase the risk factor which can compromise the overall security of
the firm.
References
Arora, S. (2019, August 2). Infographic: Top 7 Jobs in IT Security. Retrieved from
https://www.simplilearn.com/top-it-security-jobs-article
ISE 510
12
12
Stoneburner, G., Goguen, A., & Feringa, A. (2002). Risk Management Guide for
Information Technology Systems. Recommendations of the National Institute of
Standards and Technology: NIST SP 800-30 [Електронний ресурс]. NIST. gov-
Computer Security Division-Computer Security Resource Center [сайт]/Gary
Stoneburner, Alice Goguen, and Alexis Feringa, 800-30.
Singhal, A., & Ou, X. (2017). Security risk analysis of enterprise networks using
probabilistic attack graphs. In Network Security Metrics (pp. 53-73). Springer,
Cham.