Running Head: IT 552 ac ac ac ac ac a ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 1
IT 552 : Milestone TwoAssignment
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 2
Introduction
In the digitalized era, cyber threats can any side and cripple the Information
Technology ecosystem of an organization. In order to be well equipped against
unknown threats and risks, business entities spend huge volumes of finance so that
they can safeguard themselves against sophisticated threats and attacks in the virtual
setting. Mainly businesses invest money to introduce robust defense and detection
mechanisms so that cyber attackers can be kept at a distance.
As per the case relating to Multiple Unite Security Assurance (MUSA)
Corporation, its security posture is low. One of the main reasons for the poor
security model can be attributed to the human factors that operate in the
organizational setting (Glaspie & Karwowski, 2017). As per numerous researchers, in
many cases, human factors botch up the IT security setting of an organization. Due
to their intentional or unintentional error, unauthorized users gain an access into the
system which ultimately compromises the security (Nobles, 2018).
A number of policies have been presented here that can help to address vital
security issues that can arise in the prevailing organizational context due to human
factors. By implementation of such policies, business organizations can be empowered
to enhance their security posture. The effective management of cybersecurity model
will only be possible if the security policies are taken into consideration the security
threats and risks that arise due to the involvement of the human factors (Nobles,
2018).
Proposal for mitigating security threats that arise due to human factors
A perfect security awareness model has been presented here so that it would
help to mitigate the threats that are posed by the human factors to the organization’s
security posture. The proposal that has been designed for the business entity
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 3
encompasses a total of ten security policies that would enable the firm to fill the
security gaps that currently exist and weaken the security posture of MUSA (Threats
to Security, 2019). The policies have been crafted so that the organization would be
in a position to address unintentional threats as well as intentional threats or social
engineering. The policies that have been designed also focus on the quality of data
flow so that it could not be tampered with.
As per the strategy that has been presented here, the cybersecurity threats that
arise before the entity can be categorized into two types namely unintentional threats
and intentional threats. The unintentional threats can be defined as the threats that
arise due to human errors or computer failure (Threats to Security, 2019). The
intentional threats are the ones that arise on the online platform due to various kinds
of malicious elements such as viruses, theft of data, denial of service attack and other
factors that have been malicious intent. The security policies have been strategically
framed so that the existing security gaps can be addressed in an effective manner. ac
Policies
A. Protection against unintentional threats
The following security policies have been proposed here would help Multiple
Unite Security Assurance Corporation to safeguard itself against various kinds of
unintentional threats that arise due to human factors and adversely impact the security
if the organization.
Changes in the remote access mechanism
The remote access is a policy that can enable employees of an organization to
work remotely or work from their home. This policy might be employee friendly but
at the same time, it gives rise to a number of security concerns as unauthorized users
have the opportunity to gain access into the organizational network. The employees
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 4
that work remotely can gain access into the organizational system from anywhere at
any time. There is the possibility that these individuals will unintentionally make
blunders while surfing the internet. Such an innocent error on part of the employees
working remotely can have a detrimental implication on the business entity. For
example, in case the employees, click on the link of a malicious site from their
personal computer, unauthorized attackers could gain entry into their systems and
compromise the security, integrity, and confidentiality of the organizational data.
In order to deal with the cybersecurity threats that arise due to the remote
access policy, there is the need to activate remote access feature that is present in the
firewall. It would make sure that the employees working remotely can gain access in
a safe and secure manner by making use of the Secure Sockets Layer Virtual Private
Network feature (What is SSL VPN (Secure Sockets Layer virtual private network)? -
Definition from WhatIs.com, 2019). By using this security feature, the origination’s
personnel would be in a position to create safe access to the MUSA’s system when
they are working from home. The employees could also use their mobile devices to
work remotely in a safe working environment after the implementation of the security
policy (Remote Access: The Pros and Cons of Virtual Private Networking |
macchina.io Blog, 2019).
Introduction of encryption or hashing
Encryption and/or hashing are regarded to be some of the most basic security
measures that business undertakings need to implement so that the level of security
of their IT infrastructure can be strengthened to a certain degree. This policy has
been proposed so that the security could be strengthened whether the organizational
data is ready for transmission, it is in the process of transmission or it has already
been transmitted. Data encryption would be made mandatory so that it could deter
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 5
malicious parties from gaining unauthorized access into sensitive business information.
The encryption process would basically make use of algorithms which would convert
ta into unique codes. The computers that have the right key would be able to crack
these codes and put them into the original form. There are two types of encryption
methods including symmetric key and public key (or asymmetric). In the former
method, the same key is used or installed in both the systems that are responsible for
receiving and transmitting the information. The public key encryption, on the other
hand, utilizes two sets of keys simultaneously namely a private key and a public key
to strengthen the security level. In the business context of MUSA, the asymmetric
encryption could be introduced to strengthen the security level (Encryption and Its
Importance to Device Networking, 2019).
Similarly, hashing has also been introduced in the security policy. The hash
methods like Secure Hash Algorithms (SHA-1, SHA-2, and SHA-3) could be
employed so that the integrity of the organizational data could be maintained and
strengthened (Secure Hash Algorithms | Brilliant Math & Science Wiki, 2019). These
algorithms are designed with strong encryptions so that they can effectively respond
to online cyber-attacks. This tool would enable the firm to keep a tab on any kind of
modification or tampering of the data that has been transmitted or received. For
example, in case there is even a slight change in any text file, the hash value of the
modified file will be different from the original hash value. Thus the organization
will come to know that data has been tampered with (Secure Hash Algorithms |
Brilliant Math & Science Wiki, 2019). These methods would facilitate the business
entity to have a stronger control over the data flow and thus capture any kind of
unauthorized alteration of data.
Conducting regular checks and auditing of user accounts
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 6
At present, one of the major security gaps that have been identified in the
MUSA organization relates to the fact that the logs of the employees are not
collected or analyzed. There is the need to introduce a robust auditing protocol so
that the accounts of all the organizational personnel of MUSA would be thoroughly
checked and scrutinized. For instance, this security policy could be applied once in a
quarter or once every six months so that the safety and security of the accounts
could be maintained. While conducting the audit process of the user accounts, it is
necessary to take in to account a number of aspects such as whether the account is
active or inactive (disabled). For example, both these accounts could be targeted by
online attackers so that they could gain unauthorized access into the organization’s
system.
Some of the key settings and properties that must be considered while
implementing the security policy relating to the auditing of user accounts include
checking of the login scripts, the activity of the workstations and the frequency of
change of passwords. The audit procedure would help Multiple Unite Security
Assurance (MUSA) Corporation to determine the real-time status of the accounts of
the users. For example, in case an account that has been disabled for a long time is
active the Information Technology team must take necessary actions to check the
activity. Similarly, in case, an employee or user has failed to change or update his
or her password in more than six months, he must be notified to do the same on an
urgent basis. This security policy would be of vital importance as it would encourage
the employees of the firm to take necessary security measures at the individual level.
Employees of the firm would try to take the necessary steps at their individual level
so that the existing security gaps could be effectively addressed.
Introduction of media access control policy
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 7
A robust media access control policy could be introduced in the business
setting to secure the connections on the online platform. In the current times, a large
number of business activities are taking place in open virtual spaces such as social
media platforms which is increasing the vulnerability of the organization. In order to
give a tough fight to cybercriminals, it is necessary to have in place suitable media
access control policies and guidelines which would guide the employees while
carrying out online business activities.
The policy would play a critical role to strengthen the firm’s security system and
address the existing security gaps. This is because; the employees would be able to
carry out activities in a careful and conscious manner so that online hackers would
not get the scope to gain unauthorized access into the network (Media Access
Control Security Overview - TechLibrary - Juniper Networks, 2019). For example, the
firm could use a single login id on social media platforms to design its social media
marketing strategy. In case a second user id is created or used, the same could be
blocked for security reasons. Similarly, MUSA could also implement Data Loss
Prevention (DLP) tools so that it could keep a tab on the flow of the sensitive
information in the corporate network (What is Data Loss Prevention (DLP)? A
Definition of Data Loss Prevention, 2019).
Implementation of configuration change management policy
Change management refers to the formal process of making some kind of
change in the Information Technology system of an organization. In MUSA, a
configuration change management policy could be implemented so that the processes
relating to change could be effectively controlled. The policy could have a
constructive implication on the security model of the organization. For example, the
security policy would make sure that the integrity of the existing policies and codes
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 8
is in place. In addition to this, the new policy would help to identify security flaws.
It would act as a baseline that could be used for comparing the technical codes after
any changes have been introduced in the IT system. The policy would be necessary
for improving the security of the firm as it would make sure that there exists
compliance with the minimum acceptable system configuration requirements (IT0125 -
Configuration Management, 2019, p 1). The policy could safeguard MUSA against
malicious threats and risk that could arise in the virtual environment of the company.
B. Social Engineering
Social engineering can be defined as the act of tricking someone so that he or
she will make security blunders which can ultimately have an adverse impact on the
security model. In the case of Multiple Unite Security Assurance Corporation, the
following policies have been designed so that protection against social engineering
could be possible (What is Social Engineering | Attack Techniques & Prevention
Methods | Imperva, 2019). In the current times, online hackers are using sophisticated
tools so that they can con professionals to disclose sensitive information such as
passwords. The security policies can help MUSA to be well equipped against such
kinds of online threats.
Providing annual cybersecurity awareness training
One of the basic steps is that the organization must design a robust annual
cyber security awareness training program so that its employees in all the departments
would be empowered to handle a tricky situation. As the name suggests, the training
program would be conducted on a yearly basis so that every time, the employees
would be able to handle sophisticated online threats. The training would encompass
basis security concepts such as:
❖ Do not download attachments from unknown parties.
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 9
❖ Do not open the emails and messages that are in spam mail.
❖ Do not open emails that have been sent by unknown parties.
In addition to this, the annual cybersecurity awareness training would also
involve technical concepts that the users need to understand so that the security of
the organization could be strengthened. For instance, MUSA could introduce
educational resources relating to cybersecurity training and conduct regular tests. Only
after the employees of MUSA would be able to pass these tests, they would gain
access to the firm’s system and network.
Introduction of intrusion detection/prevention system
An intrusion detection/ prevention system could be introduced in Multiple
Unite Security Assurance Corporation so that it could thoroughly examine the traffic
of the network. This system would be set behind the firewall so that it could detect
and prevent ‘vulnerability exploits’. Vulnerability exploits can come in the form of
malicious input and could compromise the security of the IT infrastructure of the
business. By introducing this layer of security, harmful content could be filtered out
(What is an Intrusion Prevention System? - Palo Alto Networks, 2019). The intrusion
detection system would be responsible to scan the network traffic and report back on
any identified threats or risks. The intrusion prevention system could be employed as
it would help to carefully analyze and take suitable actions on the network traffic
flow of MUSA. By introducing these tools, the security system of the firm could be
improved and harmful elements in the network could be identified.
Adoption of mandatory vacation policy
Multiple Unite Security Assurance (MUSA) Corporation could implement a
mandatory vacation policy which would require its employees to take leaves on a
yearly basis. Such a policy would have a direct impaction on the security model that
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 10
is implemented in the business setting. A mandatory vacation policy could play a key
role in the organizational context, as the firm would be able to detect fraudulent
activities. The policy would force all employees including the suspicious employees to
take leave. So they would have less amount of time with them to use their position
in the firm to conduct activities with malicious intention (Time off to discover fraud -
FSS, 2019). During the vacation time of suspicious employees, the management of
the company could carry out checks of the Information Technology infrastructure so
that malicious behavior could be identified.
Segregation of duties
Segregation of duties would act as one of the key concepts of internal control
that could positively impact the security of the IT system. By creating specific
responsibilities and duties that each and every employee has to perform in the
business setting, the management of MUSA could make sure that unwanted threats or
risks and conflicts of interests could be avoided (Behr, 2019). The fundamental
objective of the policy would be to disseminate the business activities and linked
privileges so that the security model could be strengthened. Such a policy would
make sure that the employees would use their workstations in a responsible manner
so that no one can use their computer systems to do any work without their prior
knowledge. This regulatory mandate would have a direct impact on the IT security of
MUSA. The proper categorization and division of work would be a major step
towards a safe and secure IT system as the employees would take ownership of their
duties and act in a responsible manner. It could minimize the vulnerability of MUSA
in the virtual setting (Behr, 2019).
Personally identifiable information breaches
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 11
Personally identifiable information could be introduced so that any data or
information could be used for the purpose of identifying particular organizational
personnel in MUSA. Private data could be saved by the company so that it would be
in a position to identify the individuals that are responsible for a data breach
incident. This policy would make sure that MUSA has the power to take necessary
action or precautionary action to safeguard itself from unauthorized access, data loss
or theft (Behr, 2019). This is a vital security policy that could be implemented at the
organizational level so that specific measures could be taken to tackle data security
breaches and incidents.
Ensuring a sound connection between the data sender and the data receiver
In order to make sure that there exist a sound and secure connection between
a data sender and a data receiver, it is necessary to keep a number of security
instruments in place such as firewall, intrusion detection/ prevention system and
antivirus. Such security tools would play a key role to address the security concerns
and establish a safe environment where communication between a data sender and a
data receiver could take place. Similarly, the use of encryptions or hashing would
also play a critical role. This is because these security approaches would make sure
that the data that is being received or transmitted cannot be tampered with or altered
from its intended meaning (Behr, 2019). These security measures would be of
paramount importance for MUSA as they could strengthen the security infrastructure
and limit the scope of online attackers to alter the sensitive data or information
relating to the business. Thus in order to address the issue relating to poor
communication on the IT platform of MUSA, it is necessary to encrypt all the
messages so that its real meaning could only be deciphered by the intended user.
Conclusion
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 12
The security policies that have been presented here must be introduced by
Multiple Unite Security Assurance (MUSA) Corporation so that it would be in a
position to address the security gaps that exist in its organization. The policies have
been designed in a strategic manner so that the firm would be in a position to deal
with intentional threats as well as unintentional threats that could arise before it.
These policies would primarily empower the business entity and its employees so that
they could take necessary measures to protect the security system. The policies that
have been designed specifically revolve around human errors that give an unfair
advantage to unauthorized individuals and cyber attackers in the virtual platform.
These policies could be effective only if the employees would follow them strictly in
the organizational context. ac
References
Behr, A. (2019). Separation of duties and IT security. Retrieved from
https://www.csoonline.com/article/2123120/separation-of-duties-and-it-security.html
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 13
Encryption and Its Importance to Device Networking. (2019). Retrieved from
https://www.lantronix.com/wp-content/uploads/pdf/Encryption-and-Device-
Networking_WP.pdf
Glaspie, H. W., & Karwowski, W. (2017, July). Human factors in information
security culture: A literature review. In International Conference on Applied
Human Factors and Ergonomics (pp. 269-280). Springer, Cham.
IT0125 - Configuration Management. (2019). Retrieved from
https://policy.tennessee.edu/wp-content/uploads//policytech/system-wide/it/IT0125-
Configuration-Management.pdf
Media Access Control Security Overview - TechLibrary - Juniper Networks. (2019).
Retrieved from https://www.juniper.net/documentation/en_US/junos-space-
apps/network-director3.3/topics/concept/macsec-understanding.html
Nobles, C. (2018). Botching Human Factors in Cybersecurity in Business
Organizations. HOLISTICA–Journal of Business and Public Administration, 9(3),
71-88.
Remote Access: The Pros and Cons of Virtual Private Networking | macchina.io
Blog. (2019). Retrieved from https://macchina.io/blog/security/remote-access-the-
pros-and-cons-of-virtual-private-networking/
Secure Hash Algorithms | Brilliant Math & Science Wiki. (2019). Retrieved from
https://brilliant.org/wiki/secure-hashing-algorithms/
Time off to discover fraud - FSS. (2019). Retrieved from
https://www.forensicstrategic.com/blog/time-off-to-discover-fraud
Threats to Security. (2019). Retrieved from https://www.cerias.purdue.edu/assets/pdf/k-
12/infosec_newsletters/03threats.pdf
IT 552 ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac
ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac a ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac ac 14
What is SSL VPN (Secure Sockets Layer virtual private network)? - Definition from
WhatIs.com. (2019). Retrieved from
https://searchsecurity.techtarget.com/definition/SSL-VPN
What is Data Loss Prevention (DLP)? A Definition of Data Loss Prevention. (2019).
Retrieved from https://digitalguardian.com/blog/what-data-loss-prevention-dlp-
definition-data-loss-prevention
What is Social Engineering | Attack Techniques & Prevention Methods | Imperva.
(2019). Retrieved from https://www.imperva.com/learn/application-security/social-
engineering-attack/
What is an Intrusion Prevention System? - Palo Alto Networks. (2019). Retrieved
from https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-prevention-
system-ips