1 / 16100%
Running Head: IT 552
1
IT 552 : Milestone TwoAssignment
IT 552
2
Introduction
In the digitalized era, cyber threats can any side and cripple the
Information Technology ecosystem of an organization. In order to be well
equipped against unknown threats and risks, business entities spend huge
volumes of finance so that they can safeguard themselves against
sophisticated threats and attacks in the virtual setting. Mainly businesses
invest money to introduce robust defense and detection mechanisms so that
cyber attackers can be kept at a distance.
As per the case relating to Multiple Unite Security Assurance
(MUSA) Corporation, its security posture is low. One of the main reasons
for the poor security model can be attributed to the human factors that
operate in the organizational setting (Glaspie & Karwowski, 2017). As per
numerous researchers, in many cases, human factors botch up the IT
security setting of an organization. Due to their intentional or unintentional
error, unauthorized users gain an access into the system which ultimately
compromises the security (Nobles, 2018).
A number of policies have been presented here that can help to
address vital security issues that can arise in the prevailing organizational
context due to human factors. By implementation of such policies, business
organizations can be empowered to enhance their security posture. The
effective management of cybersecurity model will only be possible if the
security policies are taken into consideration the security threats and risks
that arise due to the involvement of the human factors (Nobles, 2018).
IT 552
3
Proposal for mitigating security threats that arise due to human
factors
A perfect security awareness model has been presented here so that
it would help to mitigate the threats that are posed by the human
factors to the organization’s security posture. The proposal that has been
designed for the business entity encompasses a total of ten security
policies that would enable the firm to fill the security gaps that currently
exist and weaken the security posture of MUSA (Threats to Security,
2019). The policies have been crafted so that the organization would be
in a position to address unintentional threats as well as intentional threats
or social engineering. The policies that have been designed also focus on
the quality of data flow so that it could not be tampered with.
As per the strategy that has been presented here, the cybersecurity
threats that arise before the entity can be categorized into two types
namely unintentional threats and intentional threats. The unintentional threats
can be defined as the threats that arise due to human errors or
computer failure (Threats to Security, 2019). The intentional threats are the
ones that arise on the online platform due to various kinds of malicious
elements such as viruses, theft of data, denial of service attack and other
factors that have been malicious intent. The security policies have been
strategically framed so that the existing security gaps can be addressed in
an effective manner.
Policies
A. Protection against unintentional threats
IT 552
4
The following security policies have been proposed here would help
Multiple Unite Security Assurance Corporation to safeguard itself against
various kinds of unintentional threats that arise due to human factors and
adversely impact the security if the organization.
Changes in the remote access mechanism
The remote access is a policy that can enable employees of an
organization to work remotely or work from their home. This policy
might be employee friendly but at the same time, it gives rise to a
number of security concerns as unauthorized users have the opportunity to
gain access into the organizational network. The employees that work
remotely can gain access into the organizational system from anywhere at
any time. There is the possibility that these individuals will unintentionally
make blunders while surfing the internet. Such an innocent error on part
of the employees working remotely can have a detrimental implication on
the business entity. For example, in case the employees, click on the link
of a malicious site from their personal computer, unauthorized attackers
could gain entry into their systems and compromise the security, integrity,
and confidentiality of the organizational data.
In order to deal with the cybersecurity threats that arise due to
the remote access policy, there is the need to activate remote access
feature that is present in the firewall. It would make sure that the
employees working remotely can gain access in a safe and secure manner
by making use of the Secure Sockets Layer Virtual Private Network
feature (What is SSL VPN (Secure Sockets Layer virtual private network)?
- Definition from WhatIs.com, 2019). By using this security feature, the
IT 552
5
origination’s personnel would be in a position to create safe access to
the MUSA’s system when they are working from home. The employees
could also use their mobile devices to work remotely in a safe working
environment after the implementation of the security policy (Remote Access:
The Pros and Cons of Virtual Private Networking | macchina.io Blog,
2019).
Introduction of encryption or hashing
Encryption and/or hashing are regarded to be some of the most
basic security measures that business undertakings need to implement so
that the level of security of their IT infrastructure can be strengthened to
a certain degree. This policy has been proposed so that the security
could be strengthened whether the organizational data is ready for
transmission, it is in the process of transmission or it has already been
transmitted. Data encryption would be made mandatory so that it could
deter malicious parties from gaining unauthorized access into sensitive
business information. The encryption process would basically make use of
algorithms which would convert ta into unique codes. The computers that
have the right key would be able to crack these codes and put them
into the original form. There are two types of encryption methods
including symmetric key and public key (or asymmetric). In the former
method, the same key is used or installed in both the systems that are
responsible for receiving and transmitting the information. The public key
encryption, on the other hand, utilizes two sets of keys simultaneously
namely a private key and a public key to strengthen the security level.
In the business context of MUSA, the asymmetric encryption could be
IT 552
6
introduced to strengthen the security level (Encryption and Its Importance
to Device Networking, 2019).
Similarly, hashing has also been introduced in the security policy.
The hash methods like Secure Hash Algorithms (SHA-1, SHA-2, and SHA-
3) could be employed so that the integrity of the organizational data
could be maintained and strengthened (Secure Hash Algorithms | Brilliant
Math & Science Wiki, 2019). These algorithms are designed with strong
encryptions so that they can effectively respond to online cyber-attacks.
This tool would enable the firm to keep a tab on any kind of
modification or tampering of the data that has been transmitted or
received. For example, in case there is even a slight change in any text
file, the hash value of the modified file will be different from the
original hash value. Thus the organization will come to know that data
has been tampered with (Secure Hash Algorithms | Brilliant Math &
Science Wiki, 2019). These methods would facilitate the business entity to
have a stronger control over the data flow and thus capture any kind of
unauthorized alteration of data.
Conducting regular checks and auditing of user accounts
At present, one of the major security gaps that have been
identified in the MUSA organization relates to the fact that the logs of
the employees are not collected or analyzed. There is the need to
introduce a robust auditing protocol so that the accounts of all the
organizational personnel of MUSA would be thoroughly checked and
scrutinized. For instance, this security policy could be applied once in a
quarter or once every six months so that the safety and security of the
IT 552
7
accounts could be maintained. While conducting the audit process of the
user accounts, it is necessary to take in to account a number of aspects
such as whether the account is active or inactive (disabled). For example,
both these accounts could be targeted by online attackers so that they
could gain unauthorized access into the organization’s system.
Some of the key settings and properties that must be considered
while implementing the security policy relating to the auditing of user
accounts include checking of the login scripts, the activity of the
workstations and the frequency of change of passwords. The audit
procedure would help Multiple Unite Security Assurance (MUSA)
Corporation to determine the real-time status of the accounts of the users.
For example, in case an account that has been disabled for a long time
is active the Information Technology team must take necessary actions to
check the activity. Similarly, in case, an employee or user has failed
to change or update his or her password in more than six months, he
must be notified to do the same on an urgent basis. This security
policy would be of vital importance as it would encourage the employees
of the firm to take necessary security measures at the individual level.
Employees of the firm would try to take the necessary steps at their
individual level so that the existing security gaps could be effectively
addressed.
Introduction of media access control policy
A robust media access control policy could be introduced in the
business setting to secure the connections on the online platform. In the
current times, a large number of business activities are taking place in
IT 552
8
open virtual spaces such as social media platforms which is increasing the
vulnerability of the organization. In order to give a tough fight to
cybercriminals, it is necessary to have in place suitable media access
control policies and guidelines which would guide the employees while
carrying out online business activities.
The policy would play a critical role to strengthen the firm’s security
system and address the existing security gaps. This is because; the
employees would be able to carry out activities in a careful and
conscious manner so that online hackers would not get the scope to gain
unauthorized access into the network (Media Access Control Security
Overview - TechLibrary - Juniper Networks, 2019). For example, the firm
could use a single login id on social media platforms to design its
social media marketing strategy. In case a second user id is created or
used, the same could be blocked for security reasons. Similarly, MUSA
could also implement Data Loss Prevention (DLP) tools so that it could
keep a tab on the flow of the sensitive information in the corporate
network (What is Data Loss Prevention (DLP)? A Definition of Data Loss
Prevention, 2019).
Implementation of configuration change management policy
Change management refers to the formal process of making some
kind of change in the Information Technology system of an organization.
In MUSA, a configuration change management policy could be implemented
so that the processes relating to change could be effectively controlled.
The policy could have a constructive implication on the security model of
the organization. For example, the security policy would make sure that
IT 552
9
the integrity of the existing policies and codes is in place. In addition
to this, the new policy would help to identify security flaws. It would
act as a baseline that could be used for comparing the technical codes
after any changes have been introduced in the IT system. The policy
would be necessary for improving the security of the firm as it would
make sure that there exists compliance with the minimum acceptable
system configuration requirements (IT0125 - Configuration Management, 2019,
p 1). The policy could safeguard MUSA against malicious threats and
risk that could arise in the virtual environment of the company.
B. Social Engineering
Social engineering can be defined as the act of tricking someone so
that he or she will make security blunders which can ultimately have an
adverse impact on the security model. In the case of Multiple Unite
Security Assurance Corporation, the following policies have been designed
so that protection against social engineering could be possible (What is
Social Engineering | Attack Techniques & Prevention Methods | Imperva,
2019). In the current times, online hackers are using sophisticated tools so
that they can con professionals to disclose sensitive information such as
passwords. The security policies can help MUSA to be well equipped
against such kinds of online threats.
Providing annual cybersecurity awareness training
One of the basic steps is that the organization must design a robust
annual cyber security awareness training program so that its employees in
all the departments would be empowered to handle a tricky situation. As
the name suggests, the training program would be conducted on a yearly
IT 552
10
basis so that every time, the employees would be able to handle
sophisticated online threats. The training would encompass basis security
concepts such as:
❖ Do not download attachments from unknown parties.
❖ Do not open the emails and messages that are in spam mail.
❖ Do not open emails that have been sent by unknown parties.
In addition to this, the annual cybersecurity awareness training would
also involve technical concepts that the users need to understand so that
the security of the organization could be strengthened. For instance, MUSA
could introduce educational resources relating to cybersecurity training and
conduct regular tests. Only after the employees of MUSA would be able
to pass these tests, they would gain access to the firm’s system and
network.
Introduction of intrusion detection/prevention system
An intrusion detection/ prevention system could be introduced in
Multiple Unite Security Assurance Corporation so that it could thoroughly
examine the traffic of the network. This system would be set behind the
firewall so that it could detect and prevent ‘vulnerability exploits’.
Vulnerability exploits can come in the form of malicious input and could
compromise the security of the IT infrastructure of the business. By
introducing this layer of security, harmful content could be filtered out
(What is an Intrusion Prevention System? - Palo Alto Networks, 2019).
The intrusion detection system would be responsible to scan the network
traffic and report back on any identified threats or risks. The intrusion
prevention system could be employed as it would help to carefully
IT 552
11
analyze and take suitable actions on the network traffic flow of MUSA.
By introducing these tools, the security system of the firm could be
improved and harmful elements in the network could be identified.
Adoption of mandatory vacation policy
Multiple Unite Security Assurance (MUSA) Corporation could
implement a mandatory vacation policy which would require its employees
to take leaves on a yearly basis. Such a policy would have a direct
impaction on the security model that is implemented in the business
setting. A mandatory vacation policy could play a key role in the
organizational context, as the firm would be able to detect fraudulent
activities. The policy would force all employees including the suspicious
employees to take leave. So they would have less amount of time with
them to use their position in the firm to conduct activities with malicious
intention (Time off to discover fraud - FSS, 2019). During the vacation
time of suspicious employees, the management of the company could carry
out checks of the Information Technology infrastructure so that malicious
behavior could be identified.
Segregation of duties
Segregation of duties would act as one of the key concepts of
internal control that could positively impact the security of the IT system.
By creating specific responsibilities and duties that each and every
employee has to perform in the business setting, the management of
MUSA could make sure that unwanted threats or risks and conflicts of
interests could be avoided (Behr, 2019). The fundamental objective of the
policy would be to disseminate the business activities and linked privileges
IT 552
12
so that the security model could be strengthened. Such a policy would
make sure that the employees would use their workstations in a
responsible manner so that no one can use their computer systems to do
any work without their prior knowledge. This regulatory mandate would
have a direct impact on the IT security of MUSA. The proper
categorization and division of work would be a major step towards a
safe and secure IT system as the employees would take ownership of
their duties and act in a responsible manner. It could minimize the
vulnerability of MUSA in the virtual setting (Behr, 2019).
Personally identifiable information breaches
Personally identifiable information could be introduced so that any
data or information could be used for the purpose of identifying particular
organizational personnel in MUSA. Private data could be saved by the
company so that it would be in a position to identify the individuals
that are responsible for a data breach incident. This policy would make
sure that MUSA has the power to take necessary action or precautionary
action to safeguard itself from unauthorized access, data loss or theft
(Behr, 2019). This is a vital security policy that could be implemented at
the organizational level so that specific measures could be taken to tackle
data security breaches and incidents.
Ensuring a sound connection between the data sender and the data
receiver
In order to make sure that there exist a sound and secure
connection between a data sender and a data receiver, it is necessary to
keep a number of security instruments in place such as firewall, intrusion
IT 552
13
detection/ prevention system and antivirus. Such security tools would play
a key role to address the security concerns and establish a safe
environment where communication between a data sender and a data
receiver could take place. Similarly, the use of encryptions or hashing
would also play a critical role. This is because these security approaches
would make sure that the data that is being received or transmitted
cannot be tampered with or altered from its intended meaning (Behr,
2019). These security measures would be of paramount importance for
MUSA as they could strengthen the security infrastructure and limit the
scope of online attackers to alter the sensitive data or information relating
to the business. Thus in order to address the issue relating to poor
communication on the IT platform of MUSA, it is necessary to encrypt
all the messages so that its real meaning could only be deciphered by
the intended user.
Conclusion
The security policies that have been presented here must be
introduced by Multiple Unite Security Assurance (MUSA) Corporation so
that it would be in a position to address the security gaps that exist in
its organization. The policies have been designed in a strategic manner so
that the firm would be in a position to deal with intentional threats as
well as unintentional threats that could arise before it. These policies
would primarily empower the business entity and its employees so that
they could take necessary measures to protect the security system. The
policies that have been designed specifically revolve around human errors
that give an unfair advantage to unauthorized individuals and cyber
IT 552
14
attackers in the virtual platform. These policies could be effective only if
the employees would follow them strictly in the organizational context.
References
Behr, A. (2019). Separation of duties and IT security. Retrieved from
https://www.csoonline.com/article/2123120/separation-of-duties-and-it-security.html
Encryption and Its Importance to Device Networking. (2019). Retrieved
from https://www.lantronix.com/wp-content/uploads/pdf/Encryption-and-Device-
Networking_WP.pdf
Glaspie, H. W., & Karwowski, W. (2017, July). Human factors in
information security culture: A literature review. In International
Conference on Applied Human Factors and Ergonomics (pp. 269-280).
Springer, Cham.
IT 552
15
IT0125 - Configuration Management. (2019). Retrieved from
https://policy.tennessee.edu/wp-content/uploads//policytech/system-wide/it/IT0125-
Configuration-Management.pdf
Media Access Control Security Overview - TechLibrary - Juniper Networks.
(2019). Retrieved from https://www.juniper.net/documentation/en_US/junos-
space-apps/network-director3.3/topics/concept/macsec-understanding.html
Nobles, C. (2018). Botching Human Factors in Cybersecurity in Business
Organizations. HOLISTICA–Journal of Business and Public
Administration, 9(3), 71-88.
Remote Access: The Pros and Cons of Virtual Private Networking |
macchina.io Blog. (2019). Retrieved from
https://macchina.io/blog/security/remote-access-the-pros-and-cons-of-virtual-private-
networking/
Secure Hash Algorithms | Brilliant Math & Science Wiki. (2019).
Retrieved from https://brilliant.org/wiki/secure-hashing-algorithms/
Time off to discover fraud - FSS. (2019). Retrieved from
https://www.forensicstrategic.com/blog/time-off-to-discover-fraud
Threats to Security. (2019). Retrieved from
https://www.cerias.purdue.edu/assets/pdf/k-12/infosec_newsletters/03threats.pdf
What is SSL VPN (Secure Sockets Layer virtual private network)? -
Definition from WhatIs.com. (2019). Retrieved from
https://searchsecurity.techtarget.com/definition/SSL-VPN
What is Data Loss Prevention (DLP)? A Definition of Data Loss
Prevention. (2019). Retrieved from https://digitalguardian.com/blog/what-data-
loss-prevention-dlp-definition-data-loss-prevention
IT 552
16
What is Social Engineering | Attack Techniques & Prevention Methods |
Imperva. (2019). Retrieved from https://www.imperva.com/learn/application-
security/social-engineering-attack/
What is an Intrusion Prevention System? - Palo Alto Networks. (2019).
Retrieved from https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-
prevention-system-ips
Students also viewed