Running Head: ISE 620
1
ISE 620 : Final Project Milestone 3
SNHU
ISE 620
2
Countermeasures Analysis
The proper introduction and execution of the countermeasures would help to
effectively curb the online threats and risks. In addition to this, it would also help to
strengthen the existing security policies and practices that are implemented in the
organizational setting. The countermeasures have been designed so that the negative
implication on various elements could be limited such as organizational Systems,
organizational operations, and organizational personnel.
Reduced negative impact on Organizational Systems
The security analysts are supposed to carefully analyze the activities that are
conducted on the organizational network. Such a countermeasure would play a critical
role to make sure that malicious and suspicious activities or behavior could be identified
right from the start. This approach would be necessary to make sure that the gaps that
could exist in the Organizational Systems can be identified and suitable actions can be
taken to mitigate the security problem (Antivirus Best Practices, 2019).
The application of necessary security tools such as Nmap would help to conduct
the scanning activities so that the target could be identified and suitable measures could
be taken by the Information Technology department for taking effective actions so that
the organizational system would not get compromised. Similarly, the use of the most
effective anti-virus or anti-malware platform in the business setting would ensure that
the system functions in an efficient and secure manner (Antivirus Best Practices, 2019).
Reduced negative impact on Organizational Operations
By making sure that all the security tools and applications are effective to deal
with the vulnerabilities and threats, they must be regularly updated. Similarly, the proper
check of the IP addresses that are a part of the network would help to identify any
suspicious or malicious activity that would be evident in the firm’s Information
ISE 620
3
Technology infrastructure. The proper maintenance of the IP logs would help the
Network Administrators to capture any activities that are not related to the business
activities and processes. Such a holistic approach would be vital to minimizing the
extent of negative impact on the operational activities that are carried out by the
business undertaking.
The use of the Intrusion Detection and Prevention System (IDPS) would play a
critical role to minimize the adverse impact of the security attack on organizational
operations. These vital tools would primarily help to identify suspicious and malicious
activities that could exist in the IT ecosystem of the business undertaking and negatively
impact the operations and processes.
Reduced negative impact on Organizational Personnel
The effective implementation of physical access controls would make sure that
the security policies and protocols are in place. By restricting the movement of outsiders
or visitors, the organization could ensure that confidential and sensitive business
information would not get leaked to outsiders. By carefully keeping a check on the
movement of employees as well as outsiders in the organizational premises, it would be
easier to introduce suitable security measures and strategies so that the adverse impact
on the organizational personnel could be reduced or completely mitigated. Addition
security cameras and CCTVs could be installed so that the security personnel could
assess the actions of the personnel and identify any kind of abnormal action or behavior
in the organizational context. In addition to the physical access policy, a robust user
access policy would ensure that unauthorized personnel do not gain access to
confidential business information. The proper documentation of all the processes would
make sure that the personnel of the organization is well informed about the security
actions that should be taken in case a security breach incident takes place in the future.
ISE 620
4
Such an approach would primarily empower the employees as they would be prepared
to take necessary actions which could minimize the overall vulnerability of the business
undertaking in the uncertain cyber setting.
References
Antivirus Best Practices. (2019). Retrieved September 27, 2019, from
ncb.mu/English/Documents/Downloads/Reports and Guidelines/Anti Virus Best
Practices.pdf