Running Head: IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g 1
IT 552 : Milestone TwoAssignment
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 2
Introduction
In the digitalized era, cyber threats can any side and cripple the Information
Technology ecosystem of an organization. In order to be well equipped against unknown
threats and risks, business entities spend huge volumes of finance so that they can
safeguard themselves against sophisticated threats and attacks in the virtual setting. Mainly
businesses invest money to introduce robust defense and detection mechanisms so that
cyber attackers can be kept at a distance.
As per the case relating to Multiple Unite Security Assurance (MUSA)
Corporation, its security posture is low. One of the main reasons for the poor security
model can be attributed to the human factors that operate in the organizational setting
(Glaspie & Karwowski, 2017). As per numerous researchers, in many cases, human factors
botch up the IT security setting of an organization. Due to their intentional or unintentional
error, unauthorized users gain an access into the system which ultimately compromises the
security (Nobles, 2018).
A number of policies have been presented here that can help to address vital
security issues that can arise in the prevailing organizational context due to human factors.
By implementation of such policies, business organizations can be empowered to enhance
their security posture. The effective management of cybersecurity model will only be
possible if the security policies are taken into consideration the security threats and risks
that arise due to the involvement of the human factors (Nobles, 2018).
Proposal for mitigating security threats that arise due to human factors
A perfect security awareness model has been presented here so that it would help to
mitigate the threats that are posed by the human factors to the organization’s security
posture. The proposal that has been designed for the business entity encompasses a total of
ten security policies that would enable the firm to fill the security gaps that currently exist
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 3
and weaken the security posture of MUSA (Threats to Security, 2019). The policies have
been crafted so that the organization would be in a position to address unintentional threats
as well as intentional threats or social engineering. The policies that have been designed
also focus on the quality of data flow so that it could not be tampered with.
As per the strategy that has been presented here, the cybersecurity threats that arise
before the entity can be categorized into two types namely unintentional threats and
intentional threats. The unintentional threats can be defined as the threats that arise due to
human errors or computer failure (Threats to Security, 2019). The intentional threats are
the ones that arise on the online platform due to various kinds of malicious elements such
as viruses, theft of data, denial of service attack and other factors that have been malicious
intent. The security policies have been strategically framed so that the existing security
gaps can be addressed in an effective manner. g
Policies
A. Protection against unintentional threats
The following security policies have been proposed here would help Multiple Unite
Security Assurance Corporation to safeguard itself against various kinds of unintentional
threats that arise due to human factors and adversely impact the security if the
organization.
Changes in the remote access mechanism
The remote access is a policy that can enable employees of an organization to work
remotely or work from their home. This policy might be employee friendly but at the same
time, it gives rise to a number of security concerns as unauthorized users have the
opportunity to gain access into the organizational network. The employees that work
remotely can gain access into the organizational system from anywhere at any time. There
is the possibility that these individuals will unintentionally make blunders while surfing the
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 4
internet. Such an innocent error on part of the employees working remotely can have a
detrimental implication on the business entity. For example, in case the employees, click
on the link of a malicious site from their personal computer, unauthorized attackers could
gain entry into their systems and compromise the security, integrity, and confidentiality of
the organizational data.
In order to deal with the cybersecurity threats that arise due to the remote access
policy, there is the need to activate remote access feature that is present in the firewall. It
would make sure that the employees working remotely can gain access in a safe and secure
manner by making use of the Secure Sockets Layer Virtual Private Network feature (What
is SSL VPN (Secure Sockets Layer virtual private network)? - Definition from
WhatIs.com, 2019). By using this security feature, the origination’s personnel would be in
a position to create safe access to the MUSA’s system when they are working from home.
The employees could also use their mobile devices to work remotely in a safe working
environment after the implementation of the security policy (Remote Access: The Pros and
Cons of Virtual Private Networking | macchina.io Blog, 2019).
Introduction of encryption or hashing
Encryption and/or hashing are regarded to be some of the most basic security
measures that business undertakings need to implement so that the level of security of their
IT infrastructure can be strengthened to a certain degree. This policy has been proposed so
that the security could be strengthened whether the organizational data is ready for
transmission, it is in the process of transmission or it has already been transmitted. Data
encryption would be made mandatory so that it could deter malicious parties from gaining
unauthorized access into sensitive business information. The encryption process would
basically make use of algorithms which would convert ta into unique codes. The
computers that have the right key would be able to crack these codes and put them into the
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 5
original form. There are two types of encryption methods including symmetric key and
public key (or asymmetric). In the former method, the same key is used or installed in both
the systems that are responsible for receiving and transmitting the information. The public
key encryption, on the other hand, utilizes two sets of keys simultaneously namely a
private key and a public key to strengthen the security level. In the business context of
MUSA, the asymmetric encryption could be introduced to strengthen the security level
(Encryption and Its Importance to Device Networking, 2019).
Similarly, hashing has also been introduced in the security policy. The hash
methods like Secure Hash Algorithms (SHA-1, SHA-2, and SHA-3) could be employed so
that the integrity of the organizational data could be maintained and strengthened (Secure
Hash Algorithms | Brilliant Math & Science Wiki, 2019). These algorithms are designed
with strong encryptions so that they can effectively respond to online cyber-attacks. This
tool would enable the firm to keep a tab on any kind of modification or tampering of the
data that has been transmitted or received. For example, in case there is even a slight
change in any text file, the hash value of the modified file will be different from the
original hash value. Thus the organization will come to know that data has been tampered
with (Secure Hash Algorithms | Brilliant Math & Science Wiki, 2019). These methods
would facilitate the business entity to have a stronger control over the data flow and thus
capture any kind of unauthorized alteration of data.
Conducting regular checks and auditing of user accounts
At present, one of the major security gaps that have been identified in the MUSA
organization relates to the fact that the logs of the employees are not collected or analyzed.
There is the need to introduce a robust auditing protocol so that the accounts of all the
organizational personnel of MUSA would be thoroughly checked and scrutinized. For
instance, this security policy could be applied once in a quarter or once every six months
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 6
so that the safety and security of the accounts could be maintained. While conducting the
audit process of the user accounts, it is necessary to take in to account a number of aspects
such as whether the account is active or inactive (disabled). For example, both these
accounts could be targeted by online attackers so that they could gain unauthorized access
into the organization’s system.
Some of the key settings and properties that must be considered while
implementing the security policy relating to the auditing of user accounts include checking
of the login scripts, the activity of the workstations and the frequency of change of
passwords. The audit procedure would help Multiple Unite Security Assurance (MUSA)
Corporation to determine the real-time status of the accounts of the users. For example, in
case an account that has been disabled for a long time is active the Information
Technology team must take necessary actions to check the activity. g Similarly, in case, an
employee or user has failed to change or update his or her password in more than six
months, he must be notified to do the same on an urgent basis. This security policy would
be of vital importance as it would encourage the employees of the firm to take necessary
security measures at the individual level. Employees of the firm would try to take the
necessary steps at their individual level so that the existing security gaps could be
effectively addressed.
Introduction of media access control policy
A robust media access control policy could be introduced in the business setting to
secure the connections on the online platform. In the current times, a large number of
business activities are taking place in open virtual spaces such as social media platforms
which is increasing the vulnerability of the organization. In order to give a tough fight to
cybercriminals, it is necessary to have in place suitable media access control policies and
guidelines which would guide the employees while carrying out online business activities.
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 7
The policy would play a critical role to strengthen the firm’s security system and address
the existing security gaps. This is because; the employees would be able to carry out
activities in a careful and conscious manner so that online hackers would not get the scope
to gain unauthorized access into the network (Media Access Control Security Overview -
TechLibrary - Juniper Networks, 2019). For example, the firm could use a single login id
on social media platforms to design its social media marketing strategy. In case a second
user id is created or used, the same could be blocked for security reasons. Similarly,
MUSA could also implement Data Loss Prevention (DLP) tools so that it could keep a tab
on the flow of the sensitive information in the corporate network (What is Data Loss
Prevention (DLP)? A Definition of Data Loss Prevention, 2019).
Implementation of configuration change management policy
Change management refers to the formal process of making some kind of change in
the Information Technology system of an organization. In MUSA, a configuration change
management policy could be implemented so that the processes relating to change could be
effectively controlled. The policy could have a constructive implication on the security
model of the organization. For example, the security policy would make sure that the
integrity of the existing policies and codes is in place. In addition to this, the new policy
would help to identify security flaws. It would act as a baseline that could be used for
comparing the technical codes after any changes have been introduced in the IT system.
The policy would be necessary for improving the security of the firm as it would make
sure that there exists compliance with the minimum acceptable system configuration
requirements (IT0125 - Configuration Management, 2019, p 1). The policy could
safeguard MUSA against malicious threats and risk that could arise in the virtual
environment of the company.
B. Social Engineering
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 8
Social engineering can be defined as the act of tricking someone so that he or she
will make security blunders which can ultimately have an adverse impact on the security
model. In the case of Multiple Unite Security Assurance Corporation, the following
policies have been designed so that protection against social engineering could be possible
(What is Social Engineering | Attack Techniques & Prevention Methods | Imperva, 2019).
In the current times, online hackers are using sophisticated tools so that they can con
professionals to disclose sensitive information such as passwords. The security policies can
help MUSA to be well equipped against such kinds of online threats.
Providing annual cybersecurity awareness training
One of the basic steps is that the organization must design a robust annual cyber
security awareness training program so that its employees in all the departments would be
empowered to handle a tricky situation. As the name suggests, the training program would
be conducted on a yearly basis so that every time, the employees would be able to handle
sophisticated online threats. The training would encompass basis security concepts such as:
❖ Do not download attachments from unknown parties.
❖ Do not open the emails and messages that are in spam mail.
❖ Do not open emails that have been sent by unknown parties.
In addition to this, the annual cybersecurity awareness training would also involve
technical concepts that the users need to understand so that the security of the organization
could be strengthened. For instance, MUSA could introduce educational resources relating
to cybersecurity training and conduct regular tests. Only after the employees of MUSA
would be able to pass these tests, they would gain access to the firm’s system and network.
Introduction of intrusion detection/prevention system
An intrusion detection/ prevention system could be introduced in Multiple Unite
Security Assurance Corporation so that it could thoroughly examine the traffic of the
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 9
network. This system would be set behind the firewall so that it could detect and prevent
‘vulnerability exploits’. Vulnerability exploits can come in the form of malicious input and
could compromise the security of the IT infrastructure of the business. g By introducing this
layer of security, harmful content could be filtered out (What is an Intrusion Prevention
System? - Palo Alto Networks, 2019). The intrusion detection system would be responsible
to scan the network traffic and report back on any identified threats or risks. The intrusion
prevention system could be employed as it would help to carefully analyze and take
suitable actions on the network traffic flow of MUSA. By introducing these tools, the
security system of the firm could be improved and harmful elements in the network could
be identified.
Adoption of mandatory vacation policy
Multiple Unite Security Assurance (MUSA) Corporation could implement a
mandatory vacation policy which would require its employees to take leaves on a yearly
basis. Such a policy would have a direct impaction on the security model that is
implemented in the business setting. A mandatory vacation policy could play a key role in
the organizational context, as the firm would be able to detect fraudulent activities. The
policy would force all employees including the suspicious employees to take leave. So
they would have less amount of time with them to use their position in the firm to conduct
activities with malicious intention (Time off to discover fraud - FSS, 2019). During the
vacation time of suspicious employees, the management of the company could carry out
checks of the Information Technology infrastructure so that malicious behavior could be
identified.
Segregation of duties
Segregation of duties would act as one of the key concepts of internal control that
could positively impact the security of the IT system. By creating specific responsibilities
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 10
and duties that each and every employee has to perform in the business setting, the
management of MUSA could make sure that unwanted threats or risks and conflicts of
interests could be avoided (Behr, 2019). The fundamental objective of the policy would be
to disseminate the business activities and linked privileges so that the security model could
be strengthened. Such a policy would make sure that the employees would use their
workstations in a responsible manner so that no one can use their computer systems to do
any work without their prior knowledge. This regulatory mandate would have a direct
impact on the IT security of MUSA. The proper categorization and division of work
would be a major step towards a safe and secure IT system as the employees would take
ownership of their duties and act in a responsible manner. It could minimize the
vulnerability of MUSA in the virtual setting (Behr, 2019).
Personally identifiable information breaches
Personally identifiable information could be introduced so that any data or
information could be used for the purpose of identifying particular organizational personnel
in MUSA. Private data could be saved by the company so that it would be in a position to
identify the individuals that are responsible for a data breach incident. This policy would
make sure that MUSA has the power to take necessary action or precautionary action to
safeguard itself from unauthorized access, data loss or theft (Behr, 2019). This is a vital
security policy that could be implemented at the organizational level so that specific
measures could be taken to tackle data security breaches and incidents.
Ensuring a sound connection between the data sender and the data receiver
In order to make sure that there exist a sound and secure connection between a data
sender and a data receiver, it is necessary to keep a number of security instruments in
place such as firewall, intrusion detection/ prevention system and antivirus. Such security
tools would play a key role to address the security concerns and establish a safe
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 11
environment where communication between a data sender and a data receiver could take
place. Similarly, the use of encryptions or hashing would also play a critical role. This is
because these security approaches would make sure that the data that is being received or
transmitted cannot be tampered with or altered from its intended meaning (Behr, 2019).
These security measures would be of paramount importance for MUSA as they could
strengthen the security infrastructure and limit the scope of online attackers to alter the
sensitive data or information relating to the business. Thus in order to address the issue
relating to poor communication on the IT platform of MUSA, it is necessary to encrypt all
the messages so that its real meaning could only be deciphered by the intended user.
Conclusion
The security policies that have been presented here must be introduced by Multiple
Unite Security Assurance (MUSA) Corporation so that it would be in a position to address
the security gaps that exist in its organization. The policies have been designed in a
strategic manner so that the firm would be in a position to deal with intentional threats as
well as unintentional threats that could arise before it. These policies would primarily
empower the business entity and its employees so that they could take necessary measures
to protect the security system. The policies that have been designed specifically revolve
around human errors that give an unfair advantage to unauthorized individuals and cyber
attackers in the virtual platform. These policies could be effective only if the employees
would follow them strictly in the organizational context. g
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 12
References
Behr, A. (2019). Separation of duties and IT security. Retrieved from
https://www.csoonline.com/article/2123120/separation-of-duties-and-it-security.html
Encryption and Its Importance to Device Networking. (2019). Retrieved from
https://www.lantronix.com/wp-content/uploads/pdf/Encryption-and-Device-
Networking_WP.pdf
Glaspie, H. W., & Karwowski, W. (2017, July). Human factors in information security
culture: A literature review. In International Conference on Applied Human Factors
and Ergonomics (pp. 269-280). Springer, Cham.
IT0125 - Configuration Management. (2019). Retrieved from
https://policy.tennessee.edu/wp-content/uploads//policytech/system-wide/it/IT0125-
Configuration-Management.pdf
Media Access Control Security Overview - TechLibrary - Juniper Networks. (2019).
Retrieved from https://www.juniper.net/documentation/en_US/junos-space-
apps/network-director3.3/topics/concept/macsec-understanding.html
Nobles, C. (2018). Botching Human Factors in Cybersecurity in Business Organizations.
HOLISTICA–Journal of Business and Public Administration, 9(3), 71-88.
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 13
Remote Access: The Pros and Cons of Virtual Private Networking | macchina.io Blog.
(2019). Retrieved from https://macchina.io/blog/security/remote-access-the-pros-and-
cons-of-virtual-private-networking/
Secure Hash Algorithms | Brilliant Math & Science Wiki. (2019). Retrieved from
https://brilliant.org/wiki/secure-hashing-algorithms/
Time off to discover fraud - FSS. (2019). Retrieved from
https://www.forensicstrategic.com/blog/time-off-to-discover-fraud
Threats to Security. (2019). Retrieved from https://www.cerias.purdue.edu/assets/pdf/k-
12/infosec_newsletters/03threats.pdf
What is SSL VPN (Secure Sockets Layer virtual private network)? - Definition from
WhatIs.com. (2019). Retrieved from
https://searchsecurity.techtarget.com/definition/SSL-VPN
What is Data Loss Prevention (DLP)? A Definition of Data Loss Prevention. (2019).
Retrieved from https://digitalguardian.com/blog/what-data-loss-prevention-dlp-
definition-data-loss-prevention
What is Social Engineering | Attack Techniques & Prevention Methods | Imperva. (2019).
Retrieved from https://www.imperva.com/learn/application-security/social-
engineering-attack/
What is an Intrusion Prevention System? - Palo Alto Networks. (2019). Retrieved from
https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-prevention-system-
ips