1 / 7100%
Running Head: ISE 690 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 1
Milestone 2B: Technical Recommendations
ISE 690 Cyber Security Capstone
SNHU
ISE 690 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 2
Introduction
In Callego, there is a need to introduce three robust technical control
measures so that it can be aligned with the privacy protection expectations of the
General Data Protection Regulation and the organization’s emerging revised privacy
statement. The control mechanisms that have been designed taking into account the
firm’s mission relating to customer service, the budgetary constraints, and the
advanced time frame. The objective is to ensure that the security posture of the
organization would not get compromised in any manner and the confidential data
relating to the clients, customers and the business could not be accessed by
unauthorized individuals or parties.
Recommended control measures
The three control measures that have been recommended for the Callego
organization so that its networks could be secured include the application of intrusion
detection and prevention system, firewalls and malware scanners to strengthen the
network security. GDPR states that it is necessary to introduce appropriate technical
and organizational measures” so that its principles can be adhered to (Know Your
Compliance, 2019). By introducing these recommended control measures, the
cybersecurity framework of the firm could be strengthened and the requirements of
the regulations could be met.
Intrusion detection and prevention system –
By introducing a functional intrusion detection and prevention system, Callego
would be able to safeguard against external risks. The tool would help the firm to
comply with the GDPR principles and safeguard the confidential data that it has
relating to the clients and its business (3 Things You Need to Know About GDPR
and Intrusion Detection, 2019).
ISE 690 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 3
Firewalls –
The use of a network firewall would be extremely vital for the business
undertaking as it could help the firm to protect the customer data. One of the most
vital elements that have been highlighted in GDPR relates to ‘preventing data
breaches’ (Zeichick, 2018). BY installing network firewalls, Callego would be able to
prevent data breaches in the enterprise networks. In addition to this firewalls would
also help to limit data exfiltration, i.e. the removal of data through an internet
download by malware or outsiders.
Malware scanners –
In order to ensure that the firm complies with GDPR, robust malware
scanners must be deployed. It would help to conduct thorough threat analysis and
help to identify suspicious elements such as malware that could compromise the
security of the organization’s network (Is Your Cloud-based Anti-Malware Solution
GDPR Compliant, 2019).
Present state and future state description
The Capability Maturity model has been used to get a detailed insight into
the present state and the future state of the recommended control measures.
Currently, the Intrusion detection and prevention system that is deployed in the firm
is in the initial stage as it is disorganized and not completely functional (Rouse &
Jayaram, 2019). It would have to move to the optimum level so that the detection
and prevention process could be optimally strengthened. It is necessary to make
significant progress so that the control measure could create value for the
organization.
Callego has employed network firewalls that play a vital role to improve the
safety posture of the organization. But there is scope to strengthen the control
ISE 690 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 4
measure so that it could safeguard the firm’s network against sophisticated threats
and attacks. Its current level is “repeatable” as it carries out the basic functions. But
there is scope to take it to the “optimizing” level so that consistent improvements
can be introduced.
The role of malware scanners is restricted in the organizational context. So it
is necessary to define the software process and gradually make progress so that it
would act as a vital control measure for Callego.
Recommended measures will function systematically
The control measures that have been recommended primarily focus on the
security of the organizations’ network. The three approaches would work together
and complement one another in a systematic manner. This would be possible as the
firewall, Intrusion detection and prevention system and malware scanners would offer
integrated safety of the firm’s network which acts as a pathway for outsiders. The
tools would function in a uniform manner so that comprehensive security of the
system network would e possible so that the instances of a data breach could be
restricted and mitigated. By complying with the General Data Protection Regulation
and Callego’s emerging revised privacy statement, the security posture of the firm
could be upgraded to a substantial degree.
Principle for information security
The recommended control measures that have been selected for Callego use
the least privilege principle for information security to support GDPR conceptions of
privacy as well as the revised Callego privacy statement. The control measures
would ensure that the users would have access to sensitive data or information that
is relevant for their functions and work (The principle of least privilege: A strategy
of limiting access to what is essential, 2018). The ‘least privilege’ principle is
ISE 690 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 5
considered to be one of the most effective security practices that ensure that
unauthorized users do not gain entry into the system. The recommended control
measures would help the business undertaking to keep a check on the users as well
as their accessibility rights so that the instances of a data breach could be restricted.
Justification
The security measures that have been designed have been selected by taking
into consideration the practicality, value or cost-effectiveness, and the available time.
The control measures such as firewalls and intrusion detection and prevention
systems have become a basic necessity in the unpredictable technology-driven times.
So by strengthening these models in the organization setting, Callego would be able
to abide by the GDPR principles and fight against the instances of data breach
incidents. Similarly, it is also necessary for the business firm to deploy malware
scanners so that it would be able to keep a tab on suspicious or malicious elements
such as malware. The identification of such harmful elements would help the firm to
take suitable measures so that its vulnerability could be minimized and the security
breach incident could be managed in the most effective and efficient manner. It
would be simple for the firm to introduced these control measures within the
restricted time frame.
In the evolving technological setting, the control measures that have been
recommended for Callego would play a key role to safeguard the confidential data
and information that it has relating to the business, clients, and customers. By
implementing these control measures, the firm could strengthen its security
framework. ab
ISE 690 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 6
References
3 Things You Need to Know About GDPR and Intrusion Detection. (2019).
Retrieved November 30, 2019, from
https://www.insightsforprofessionals.com/it/security/need-to-know-gdpr-intrusion.
Is Your Cloud-based Anti-Malware Solution GDPR Compliant? (2019). Retrieved
November 30, 2019, from https://www.opswat.com/blog/cloud-based-anti-malware-
solution-gdpr-compliant.
Know Your Compliance. (2019, November 7). GDPR Appropriate Technical and
Organisational Measures. Retrieved November 30, 2019, from
https://www.knowyourcompliance.com/gdpr-technical-organisational-measures/.
Rouse, M., & Jayaram, M. N. (2019). What is Capability Maturity Model (CMM)? -
Definition from WhatIs.com. Retrieved November 30, 2019, from
https://searchsoftwarequality.techtarget.com/definition/Capability-Maturity-Model.
ISE 690 ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 7
The principle of least privilege: A strategy of limiting access to what is essential.
(2018, July 3). Retrieved November 30, 2019, from
https://www.welivesecurity.com/2018/07/02/principle-least-privilege-strategy/.
Zeichick, A. (2018). GDPR Should Change Your Thinking About Network Firewalls.
Retrieved November 30, 2019, from
https://www.securitynow.com/author.asp?section_id=716&doc_id=743272.
Students also viewed