Running Head: IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
IT 552 : Milestone TwoAssignment
SNHU
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
Introduction
In the digitalized era, cyber threats can any side and cripple the Information
Technology ecosystem of an organization. In order to be well equipped against unknown
threats and risks, business entities spend huge volumes of finance so that they can
safeguard themselves against sophisticated threats and attacks in the virtual setting.
Mainly businesses invest money to introduce robust defense and detection mechanisms
so that cyber attackers can be kept at a distance.
As per the case relating to Multiple Unite Security Assurance (MUSA)
Corporation, its security posture is low. One of the main reasons for the poor security
model can be attributed to the human factors that operate in the organizational setting
(Glaspie & Karwowski, 2017). As per numerous researchers, in many cases, human
factors botch up the IT security setting of an organization. Due to their intentional or
unintentional error, unauthorized users gain an access into the system which ultimately
compromises the security (Nobles, 2018).
A number of policies have been presented here that can help to address vital
security issues that can arise in the prevailing organizational context due to human
factors. By implementation of such policies, business organizations can be empowered to
enhance their security posture. The effective management of cybersecurity model will
only be possible if the security policies are taken into consideration the security threats
and risks that arise due to the involvement of the human factors (Nobles, 2018).
Proposal for mitigating security threats that arise due to human factors
A perfect security awareness model has been presented here so that it would help
to mitigate the threats that are posed by the human factors to the organization’s security
posture. The proposal that has been designed for the business entity encompasses a total
of ten security policies that would enable the firm to fill the security gaps that currently
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
exist and weaken the security posture of MUSA (Threats to Security, 2019). The
policies have been crafted so that the organization would be in a position to address
unintentional threats as well as intentional threats or social engineering. The policies that
have been designed also focus on the quality of data flow so that it could not be
tampered with.
As per the strategy that has been presented here, the cybersecurity threats that
arise before the entity can be categorized into two types namely unintentional threats
and intentional threats. The unintentional threats can be defined as the threats that arise
due to human errors or computer failure (Threats to Security, 2019). The intentional
threats are the ones that arise on the online platform due to various kinds of malicious
elements such as viruses, theft of data, denial of service attack and other factors that
have been malicious intent. The security policies have been strategically framed so that
the existing security gaps can be addressed in an effective manner. e
Policies
A. Protection against unintentional threats
The following security policies have been proposed here would help Multiple Unite
Security Assurance Corporation to safeguard itself against various kinds of unintentional
threats that arise due to human factors and adversely impact the security if the
organization.
Changes in the remote access mechanism
The remote access is a policy that can enable employees of an organization to
work remotely or work from their home. This policy might be employee friendly but at
the same time, it gives rise to a number of security concerns as unauthorized users have
the opportunity to gain access into the organizational network. The employees that work
remotely can gain access into the organizational system from anywhere at any time.
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
There is the possibility that these individuals will unintentionally make blunders while
surfing the internet. Such an innocent error on part of the employees working remotely
can have a detrimental implication on the business entity. For example, in case the
employees, click on the link of a malicious site from their personal computer,
unauthorized attackers could gain entry into their systems and compromise the security,
integrity, and confidentiality of the organizational data.
In order to deal with the cybersecurity threats that arise due to the remote access
policy, there is the need to activate remote access feature that is present in the firewall.
It would make sure that the employees working remotely can gain access in a safe and
secure manner by making use of the Secure Sockets Layer Virtual Private Network
feature (What is SSL VPN (Secure Sockets Layer virtual private network)? - Definition
from WhatIs.com, 2019). By using this security feature, the origination’s personnel
would be in a position to create safe access to the MUSA’s system when they are
working from home. The employees could also use their mobile devices to work
remotely in a safe working environment after the implementation of the security policy
(Remote Access: The Pros and Cons of Virtual Private Networking | macchina.io Blog,
2019).
Introduction of encryption or hashing
Encryption and/or hashing are regarded to be some of the most basic security
measures that business undertakings need to implement so that the level of security of
their IT infrastructure can be strengthened to a certain degree. This policy has been
proposed so that the security could be strengthened whether the organizational data is
ready for transmission, it is in the process of transmission or it has already been
transmitted. Data encryption would be made mandatory so that it could deter malicious
parties from gaining unauthorized access into sensitive business information. The
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5
encryption process would basically make use of algorithms which would convert ta into
unique codes. The computers that have the right key would be able to crack these codes
and put them into the original form. There are two types of encryption methods
including symmetric key and public key (or asymmetric). In the former method, the
same key is used or installed in both the systems that are responsible for receiving and
transmitting the information. The public key encryption, on the other hand, utilizes two
sets of keys simultaneously namely a private key and a public key to strengthen the
security level. In the business context of MUSA, the asymmetric encryption could be
introduced to strengthen the security level (Encryption and Its Importance to Device
Networking, 2019).
Similarly, hashing has also been introduced in the security policy. The hash
methods like Secure Hash Algorithms (SHA-1, SHA-2, and SHA-3) could be employed
so that the integrity of the organizational data could be maintained and strengthened
(Secure Hash Algorithms | Brilliant Math & Science Wiki, 2019). These algorithms are
designed with strong encryptions so that they can effectively respond to online cyber-
attacks. This tool would enable the firm to keep a tab on any kind of modification or
tampering of the data that has been transmitted or received. For example, in case there
is even a slight change in any text file, the hash value of the modified file will be
different from the original hash value. Thus the organization will come to know that
data has been tampered with (Secure Hash Algorithms | Brilliant Math & Science Wiki,
2019). These methods would facilitate the business entity to have a stronger control over
the data flow and thus capture any kind of unauthorized alteration of data.
Conducting regular checks and auditing of user accounts
At present, one of the major security gaps that have been identified in the
MUSA organization relates to the fact that the logs of the employees are not collected
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 6
or analyzed. There is the need to introduce a robust auditing protocol so that the
accounts of all the organizational personnel of MUSA would be thoroughly checked and
scrutinized. For instance, this security policy could be applied once in a quarter or once
every six months so that the safety and security of the accounts could be maintained.
While conducting the audit process of the user accounts, it is necessary to take in to
account a number of aspects such as whether the account is active or inactive (disabled).
For example, both these accounts could be targeted by online attackers so that they
could gain unauthorized access into the organization’s system.
Some of the key settings and properties that must be considered while
implementing the security policy relating to the auditing of user accounts include
checking of the login scripts, the activity of the workstations and the frequency of
change of passwords. The audit procedure would help Multiple Unite Security Assurance
(MUSA) Corporation to determine the real-time status of the accounts of the users. For
example, in case an account that has been disabled for a long time is active the
Information Technology team must take necessary actions to check the activity.
Similarly, in case, an employee or user has failed to change or update his or her
password in more than six months, he must be notified to do the same on an urgent
basis. This security policy would be of vital importance as it would encourage the
employees of the firm to take necessary security measures at the individual level.
Employees of the firm would try to take the necessary steps at their individual level so
that the existing security gaps could be effectively addressed.
Introduction of media access control policy
A robust media access control policy could be introduced in the business setting
to secure the connections on the online platform. In the current times, a large number of
business activities are taking place in open virtual spaces such as social media platforms
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 7
which is increasing the vulnerability of the organization. In order to give a tough fight
to cybercriminals, it is necessary to have in place suitable media access control policies
and guidelines which would guide the employees while carrying out online business
activities.
The policy would play a critical role to strengthen the firm’s security system and
address the existing security gaps. This is because; the employees would be able to
carry out activities in a careful and conscious manner so that online hackers would not
get the scope to gain unauthorized access into the network (Media Access Control
Security Overview - TechLibrary - Juniper Networks, 2019). For example, the firm
could use a single login id on social media platforms to design its social media
marketing strategy. In case a second user id is created or used, the same could be
blocked for security reasons. Similarly, MUSA could also implement Data Loss
Prevention (DLP) tools so that it could keep a tab on the flow of the sensitive
information in the corporate network (What is Data Loss Prevention (DLP)? A
Definition of Data Loss Prevention, 2019).
Implementation of configuration change management policy
Change management refers to the formal process of making some kind of change
in the Information Technology system of an organization. In MUSA, a configuration
change management policy could be implemented so that the processes relating to
change could be effectively controlled. The policy could have a constructive implication
on the security model of the organization. For example, the security policy would make
sure that the integrity of the existing policies and codes is in place. In addition to this,
the new policy would help to identify security flaws. It would act as a baseline that
could be used for comparing the technical codes after any changes have been introduced
in the IT system. e The policy would be necessary for improving the security of the firm
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 8
as it would make sure that there exists compliance with the minimum acceptable system
configuration requirements (IT0125 - Configuration Management, 2019, p 1). The
policy could safeguard MUSA against malicious threats and risk that could arise in the
virtual environment of the company.
B. Social Engineering
Social engineering can be defined as the act of tricking someone so that he or she
will make security blunders which can ultimately have an adverse impact on the security
model. In the case of Multiple Unite Security Assurance Corporation, the following
policies have been designed so that protection against social engineering could be
possible (What is Social Engineering | Attack Techniques & Prevention Methods |
Imperva, 2019). In the current times, online hackers are using sophisticated tools so that
they can con professionals to disclose sensitive information such as passwords. The
security policies can help MUSA to be well equipped against such kinds of online
threats.
Providing annual cybersecurity awareness training
One of the basic steps is that the organization must design a robust annual cyber
security awareness training program so that its employees in all the departments would
be empowered to handle a tricky situation. As the name suggests, the training program
would be conducted on a yearly basis so that every time, the employees would be able
to handle sophisticated online threats. The training would encompass basis security
concepts such as:
❖ Do not download attachments from unknown parties.
❖ Do not open the emails and messages that are in spam mail.
❖ Do not open emails that have been sent by unknown parties.
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 9
In addition to this, the annual cybersecurity awareness training would also involve
technical concepts that the users need to understand so that the security of the
organization could be strengthened. For instance, MUSA could introduce educational
resources relating to cybersecurity training and conduct regular tests. Only after the
employees of MUSA would be able to pass these tests, they would gain access to the
firm’s system and network.
Introduction of intrusion detection/prevention system
An intrusion detection/ prevention system could be introduced in Multiple Unite
Security Assurance Corporation so that it could thoroughly examine the traffic of the
network. This system would be set behind the firewall so that it could detect and
prevent ‘vulnerability exploits’. Vulnerability exploits can come in the form of malicious
input and could compromise the security of the IT infrastructure of the business. By
introducing this layer of security, harmful content could be filtered out (What is an
Intrusion Prevention System? - Palo Alto Networks, 2019). The intrusion detection
system would be responsible to scan the network traffic and report back on any
identified threats or risks. The intrusion prevention system could be employed as it
would help to carefully analyze and take suitable actions on the network traffic flow of
MUSA. By introducing these tools, the security system of the firm could be improved
and harmful elements in the network could be identified.
Adoption of mandatory vacation policy
Multiple Unite Security Assurance (MUSA) Corporation could implement a
mandatory vacation policy which would require its employees to take leaves on a yearly
basis. Such a policy would have a direct impaction on the security model that is
implemented in the business setting. A mandatory vacation policy could play a key role
in the organizational context, as the firm would be able to detect fraudulent activities.
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 10
The policy would force all employees including the suspicious employees to take leave.
So they would have less amount of time with them to use their position in the firm to
conduct activities with malicious intention (Time off to discover fraud - FSS, 2019).
During the vacation time of suspicious employees, the management of the company
could carry out checks of the Information Technology infrastructure so that malicious
behavior could be identified.
Segregation of duties
Segregation of duties would act as one of the key concepts of internal control
that could positively impact the security of the IT system. By creating specific
responsibilities and duties that each and every employee has to perform in the business
setting, the management of MUSA could make sure that unwanted threats or risks and
conflicts of interests could be avoided (Behr, 2019). The fundamental objective of the
policy would be to disseminate the business activities and linked privileges so that the
security model could be strengthened. Such a policy would make sure that the
employees would use their workstations in a responsible manner so that no one can use
their computer systems to do any work without their prior knowledge. This regulatory
mandate would have a direct impact on the IT security of MUSA. The proper
categorization and division of work would be a major step towards a safe and secure IT
system as the employees would take ownership of their duties and act in a responsible
manner. It could minimize the vulnerability of MUSA in the virtual setting (Behr, 2019).
Personally identifiable information breaches
Personally identifiable information could be introduced so that any data or
information could be used for the purpose of identifying particular organizational
personnel in MUSA. Private data could be saved by the company so that it would be in
a position to identify the individuals that are responsible for a data breach incident. This
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 11
policy would make sure that MUSA has the power to take necessary action or
precautionary action to safeguard itself from unauthorized access, data loss or theft
(Behr, 2019). This is a vital security policy that could be implemented at the
organizational level so that specific measures could be taken to tackle data security
breaches and incidents.
Ensuring a sound connection between the data sender and the data receiver
In order to make sure that there exist a sound and secure connection between a
data sender and a data receiver, it is necessary to keep a number of security instruments
in place such as firewall, intrusion detection/ prevention system and antivirus. Such
security tools would play a key role to address the security concerns and establish a safe
environment where communication between a data sender and a data receiver could take
place. Similarly, the use of encryptions or hashing would also play a critical role. This
is because these security approaches would make sure that the data that is being
received or transmitted cannot be tampered with or altered from its intended meaning
(Behr, 2019). These security measures would be of paramount importance for MUSA as
they could strengthen the security infrastructure and limit the scope of online attackers
to alter the sensitive data or information relating to the business. Thus in order to
address the issue relating to poor communication on the IT platform of MUSA, it is
necessary to encrypt all the messages so that its real meaning could only be deciphered
by the intended user.
Conclusion
The security policies that have been presented here must be introduced by
Multiple Unite Security Assurance (MUSA) Corporation so that it would be in a
position to address the security gaps that exist in its organization. The policies have
been designed in a strategic manner so that the firm would be in a position to deal with
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 12
intentional threats as well as unintentional threats that could arise before it. These
policies would primarily empower the business entity and its employees so that they
could take necessary measures to protect the security system. The policies that have
been designed specifically revolve around human errors that give an unfair advantage to
unauthorized individuals and cyber attackers in the virtual platform. These policies could
be effective only if the employees would follow them strictly in the organizational
context. e
References
Behr, A. (2019). Separation of duties and IT security. Retrieved from
https://www.csoonline.com/article/2123120/separation-of-duties-and-it-security.html
Encryption and Its Importance to Device Networking. (2019). Retrieved from
https://www.lantronix.com/wp-content/uploads/pdf/Encryption-and-Device-
Networking_WP.pdf
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 13
Glaspie, H. W., & Karwowski, W. (2017, July). Human factors in information security
culture: A literature review. In International Conference on Applied Human
Factors and Ergonomics (pp. 269-280). Springer, Cham.
IT0125 - Configuration Management. (2019). Retrieved from
https://policy.tennessee.edu/wp-content/uploads//policytech/system-wide/it/IT0125-
Configuration-Management.pdf
Media Access Control Security Overview - TechLibrary - Juniper Networks. (2019).
Retrieved from https://www.juniper.net/documentation/en_US/junos-space-
apps/network-director3.3/topics/concept/macsec-understanding.html
Nobles, C. (2018). Botching Human Factors in Cybersecurity in Business Organizations.
HOLISTICA–Journal of Business and Public Administration, 9(3), 71-88.
Remote Access: The Pros and Cons of Virtual Private Networking | macchina.io Blog.
(2019). Retrieved from https://macchina.io/blog/security/remote-access-the-pros-and-
cons-of-virtual-private-networking/
Secure Hash Algorithms | Brilliant Math & Science Wiki. (2019). Retrieved from
https://brilliant.org/wiki/secure-hashing-algorithms/
Time off to discover fraud - FSS. (2019). Retrieved from
https://www.forensicstrategic.com/blog/time-off-to-discover-fraud
Threats to Security. (2019). Retrieved from https://www.cerias.purdue.edu/assets/pdf/k-
12/infosec_newsletters/03threats.pdf
What is SSL VPN (Secure Sockets Layer virtual private network)? - Definition from
WhatIs.com. (2019). Retrieved from
https://searchsecurity.techtarget.com/definition/SSL-VPN
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 14
What is Data Loss Prevention (DLP)? A Definition of Data Loss Prevention. (2019).
Retrieved from https://digitalguardian.com/blog/what-data-loss-prevention-dlp-
definition-data-loss-prevention
What is Social Engineering | Attack Techniques & Prevention Methods | Imperva.
(2019). Retrieved from https://www.imperva.com/learn/application-security/social-
engineering-attack/
What is an Intrusion Prevention System? - Palo Alto Networks. (2019). Retrieved from
https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-prevention-system-
ips