Running Head: IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
IT 552 : Milestone Two Assignment
SNHU
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 2
Introduction
In the digitalized era, cyber threats can any side and cripple the Information
Technology ecosystem of an organization. In order to be well equipped against unknown
threats and risks, business entities spend huge volumes of finance so that they can safeguard
themselves against sophisticated threats and attacks in the virtual setting. Mainly businesses
invest money to introduce robust defense and detection mechanisms so that cyber attackers
can be kept at a distance.
As per the case relating to Multiple Unite Security Assurance (MUSA) Corporation,
its security posture is low. One of the main reasons for the poor security model can be
attributed to the human factors that operate in the organizational setting (Glaspie &
Karwowski, 2017). As per numerous researchers, in many cases, human factors botch up the
IT security setting of an organization. Due to their intentional or unintentional error,
unauthorized users gain an access into the system which ultimately compromises the security
(Nobles, 2018).
A number of policies have been presented here that can help to address vital security
issues that can arise in the prevailing organizational context due to human factors. By
implementation of such policies, business organizations can be empowered to enhance their
security posture. The effective management of cybersecurity model will only be possible if
the security policies are taken into consideration the security threats and risks that arise due to
the involvement of the human factors (Nobles, 2018).
Proposal for mitigating security threats that arise due to human factors
A perfect security awareness model has been presented here so that it would help to
mitigate the threats that are posed by the human factors to the organization’s security posture.
The proposal that has been designed for the business entity encompasses a total of ten
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 3
security policies that would enable the firm to fill the security gaps that currently exist and
weaken the security posture of MUSA (Threats to Security, 2019). The policies have been
crafted so that the organization would be in a position to address unintentional threats as well
as intentional threats or social engineering. The policies that have been designed also focus
on the quality of data flow so that it could not be tampered with.
As per the strategy that has been presented here, the cybersecurity threats that arise
before the entity can be categorized into two types namely unintentional threats and
intentional threats. The unintentional threats can be defined as the threats that arise due to
human errors or computer failure (Threats to Security, 2019). The intentional threats are the
ones that arise on the online platform due to various kinds of malicious elements such as
viruses, theft of data, denial of service attack and other factors that have been malicious
intent. The security policies have been strategically framed so that the existing security gaps
can be addressed in an effective manner. f
Policies
A. Protection against unintentional threats
The following security policies have been proposed here would help Multiple Unite
Security Assurance Corporation to safeguard itself against various kinds of unintentional
threats that arise due to human factors and adversely impact the security if the organization.
Changes in the remote access mechanism
The remote access is a policy that can enable employees of an organization to work
remotely or work from their home. This policy might be employee friendly but at the same
time, it gives rise to a number of security concerns as unauthorized users have the
opportunity to gain access into the organizational network. The employees that work
remotely can gain access into the organizational system from anywhere at any time. There is
the possibility that these individuals will unintentionally make blunders while surfing the
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 4
internet. Such an innocent error on part of the employees working remotely can have a
detrimental implication on the business entity. For example, in case the employees, click on
the link of a malicious site from their personal computer, unauthorized attackers could gain
entry into their systems and compromise the security, integrity, and confidentiality of the
organizational data.
In order to deal with the cybersecurity threats that arise due to the remote access
policy, there is the need to activate remote access feature that is present in the firewall. It
would make sure that the employees working remotely can gain access in a safe and secure
manner by making use of the Secure Sockets Layer Virtual Private Network feature (What is
SSL VPN (Secure Sockets Layer virtual private network)? - Definition from WhatIs.com,
2019). By using this security feature, the origination’s personnel would be in a position to
create safe access to the MUSA’s system when they are working from home. The employees
could also use their mobile devices to work remotely in a safe working environment after the
implementation of the security policy (Remote Access: The Pros and Cons of Virtual Private
Networking | macchina.io Blog, 2019).
Introduction of encryption or hashing
Encryption and/or hashing are regarded to be some of the most basic security
measures that business undertakings need to implement so that the level of security of their
IT infrastructure can be strengthened to a certain degree. This policy has been proposed so
that the security could be strengthened whether the organizational data is ready for
transmission, it is in the process of transmission or it has already been transmitted. Data
encryption would be made mandatory so that it could deter malicious parties from gaining
unauthorized access into sensitive business information. The encryption process would
basically make use of algorithms which would convert ta into unique codes. The computers
that have the right key would be able to crack these codes and put them into the original
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 5
form. There are two types of encryption methods including symmetric key and public key (or
asymmetric). In the former method, the same key is used or installed in both the systems that
are responsible for receiving and transmitting the information. The public key encryption, on
the other hand, utilizes two sets of keys simultaneously namely a private key and a public key
to strengthen the security level. In the business context of MUSA, the asymmetric encryption
could be introduced to strengthen the security level (Encryption and Its Importance to Device
Networking, 2019).
Similarly, hashing has also been introduced in the security policy. The hash methods
like Secure Hash Algorithms (SHA-1, SHA-2, and SHA-3) could be employed so that the
integrity of the organizational data could be maintained and strengthened (Secure Hash
Algorithms | Brilliant Math & Science Wiki, 2019). These algorithms are designed with
strong encryptions so that they can effectively respond to online cyber-attacks. This tool
would enable the firm to keep a tab on any kind of modification or tampering of the data that
has been transmitted or received. For example, in case there is even a slight change in any
text file, the hash value of the modified file will be different from the original hash value.
Thus the organization will come to know that data has been tampered with (Secure Hash
Algorithms | Brilliant Math & Science Wiki, 2019). These methods would facilitate the
business entity to have a stronger control over the data flow and thus capture any kind of
unauthorized alteration of data.
Conducting regular checks and auditing of user accounts
At present, one of the major security gaps that have been identified in the MUSA
organization relates to the fact that the logs of the employees are not collected or analyzed.
There is the need to introduce a robust auditing protocol so that the accounts of all the
organizational personnel of MUSA would be thoroughly checked and scrutinized. For
instance, this security policy could be applied once in a quarter or once every six months so
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 6
that the safety and security of the accounts could be maintained. While conducting the audit
process of the user accounts, it is necessary to take in to account a number of aspects such as
whether the account is active or inactive (disabled). For example, both these accounts could
be targeted by online attackers so that they could gain unauthorized access into the
organization’s system.
Some of the key settings and properties that must be considered while implementing
the security policy relating to the auditing of user accounts include checking of the login
scripts, the activity of the workstations and the frequency of change of passwords. The audit
procedure would help Multiple Unite Security Assurance (MUSA) Corporation to determine
the real-time status of the accounts of the users. For example, in case an account that has been
disabled for a long time is active the Information Technology team must take necessary
actions to check the activity. Similarly, in case, an employee or user has failed to change or
update his or her password in more than six months, he must be notified to do the same on an
urgent basis. This security policy would be of vital importance as it would encourage the
employees of the firm to take necessary security measures at the individual level. Employees
of the firm would try to take the necessary steps at their individual level so that the existing
security gaps could be effectively addressed.
Introduction of media access control policy
A robust media access control policy could be introduced in the business setting to
secure the connections on the online platform. In the current times, a large number of
business activities are taking place in open virtual spaces such as social media platforms
which is increasing the vulnerability of the organization. In order to give a tough fight to
cybercriminals, it is necessary to have in place suitable media access control policies and
guidelines which would guide the employees while carrying out online business activities.
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 7
The policy would play a critical role to strengthen the firm’s security system and address the
existing security gaps. This is because; the employees would be able to carry out activities in
a careful and conscious manner so that online hackers would not get the scope to gain
unauthorized access into the network (Media Access Control Security Overview -
TechLibrary - Juniper Networks, 2019). For example, the firm could use a single login id on
social media platforms to design its social media marketing strategy. In case a second user id
is created or used, the same could be blocked for security reasons. Similarly, MUSA could
also implement Data Loss Prevention (DLP) tools so that it could keep a tab on the flow of
the sensitive information in the corporate network (What is Data Loss Prevention (DLP)? A
Definition of Data Loss Prevention, 2019).
Implementation of configuration change management policy
Change management refers to the formal process of making some kind of change in the
Information Technology system of an organization. In MUSA, a configuration change
management policy could be implemented so that the processes relating to change could be
effectively controlled. The policy could have a constructive implication on the security model
of the organization. For example, the security policy would make sure that the integrity of the
existing policies and codes is in place. In addition to this, the new policy would help to
identify security flaws. It would act as a baseline that could be used for comparing the
technical codes after any changes have been introduced in the IT system. The policy would
be necessary for improving the security of the firm as it would make sure that there exists
compliance with the minimum acceptable system configuration requirements (IT0125 -
Configuration Management, 2019, p 1). The policy could safeguard MUSA against
malicious threats and risk that could arise in the virtual environment of the company.
B. Social Engineering
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 8
Social engineering can be defined as the act of tricking someone so that he or she will
make security blunders which can ultimately have an adverse impact on the security model.
In the case of Multiple Unite Security Assurance Corporation, the following policies have
been designed so that protection against social engineering could be possible (What is Social
Engineering | Attack Techniques & Prevention Methods | Imperva, 2019). In the current
times, online hackers are using sophisticated tools so that they can con professionals to
disclose sensitive information such as passwords. The security policies can help MUSA to be
well equipped against such kinds of online threats.
Providing annual cybersecurity awareness training
One of the basic steps is that the organization must design a robust annual cyber
security awareness training program so that its employees in all the departments would be
empowered to handle a tricky situation. As the name suggests, the training program would be
conducted on a yearly basis so that every time, the employees would be able to handle
sophisticated online threats. The training would encompass basis security concepts such as:
❖ Do not download attachments from unknown parties.
❖ Do not open the emails and messages that are in spam mail.
❖ Do not open emails that have been sent by unknown parties.
In addition to this, the annual cybersecurity awareness training would also involve
technical concepts that the users need to understand so that the security of the organization
could be strengthened. For instance, MUSA could introduce educational resources relating to
cybersecurity training and conduct regular tests. Only after the employees of MUSA would
be able to pass these tests, they would gain access to the firm’s system and network.
Introduction of intrusion detection/prevention system
An intrusion detection/ prevention system could be introduced in Multiple Unite
Security Assurance Corporation so that it could thoroughly examine the traffic of the
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 9
network. This system would be set behind the firewall so that it could detect and prevent
‘vulnerability exploits’. Vulnerability exploits can come in the form of malicious input and
could compromise the security of the IT infrastructure of the business. By introducing this
layer of security, harmful content could be filtered out (What is an Intrusion Prevention
System? - Palo Alto Networks, 2019). The intrusion detection system would be responsible
to scan the network traffic and report back on any identified threats or risks. The intrusion
prevention system could be employed as it would help to carefully analyze and take suitable
actions on the network traffic flow of MUSA. By introducing these tools, the security system
of the firm could be improved and harmful elements in the network could be identified.
Adoption of mandatory vacation policy
Multiple Unite Security Assurance (MUSA) Corporation could implement a
mandatory vacation policy which would require its employees to take leaves on a yearly
basis. Such a policy would have a direct impaction on the security model that is implemented
in the business setting. A mandatory vacation policy could play a key role in the
organizational context, as the firm would be able to detect fraudulent activities. The policy
would force all employees including the suspicious employees to take leave. So they would
have less amount of time with them to use their position in the firm to conduct activities with
malicious intention (Time off to discover fraud - FSS, 2019). During the vacation time of
suspicious employees, the management of the company could carry out checks of the
Information Technology infrastructure so that malicious behavior could be identified.
Segregation of duties
Segregation of duties would act as one of the key concepts of internal control that
could positively impact the security of the IT system. By creating specific responsibilities and
duties that each and every employee has to perform in the business setting, the management
of MUSA could make sure that unwanted threats or risks and conflicts of interests could be
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 10
avoided (Behr, 2019). The fundamental objective of the policy would be to disseminate the
business activities and linked privileges so that the security model could be strengthened.
Such a policy would make sure that the employees would use their workstations in a
responsible manner so that no one can use their computer systems to do any work without
their prior knowledge. This regulatory mandate would have a direct impact on the IT security
of MUSA. The proper categorization and division of work would be a major step towards a
safe and secure IT system as the employees would take ownership of their duties and act in a
responsible manner. It could minimize the vulnerability of MUSA in the virtual setting (Behr,
2019).
Personally identifiable information breaches
Personally identifiable information could be introduced so that any data or
information could be used for the purpose of identifying particular organizational personnel
in MUSA. Private data could be saved by the company so that it would be in a position to
identify the individuals that are responsible for a data breach incident. This policy would
make sure that MUSA has the power to take necessary action or precautionary action to
safeguard itself from unauthorized access, data loss or theft (Behr, 2019). This is a vital
security policy that could be implemented at the organizational level so that specific
measures could be taken to tackle data security breaches and incidents.
Ensuring a sound connection between the data sender and the data receiver
In order to make sure that there exist a sound and secure connection between a data
sender and a data receiver, it is necessary to keep a number of security instruments in place
such as firewall, intrusion detection/ prevention system and antivirus. Such security tools
would play a key role to address the security concerns and establish a safe environment
where communication between a data sender and a data receiver could take place. Similarly,
the use of encryptions or hashing would also play a critical role. This is because these
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 11
security approaches would make sure that the data that is being received or transmitted
cannot be tampered with or altered from its intended meaning (Behr, 2019). These security
measures would be of paramount importance for MUSA as they could strengthen the security
infrastructure and limit the scope of online attackers to alter the sensitive data or information
relating to the business. Thus in order to address the issue relating to poor communication on
the IT platform of MUSA, it is necessary to encrypt all the messages so that its real meaning
could only be deciphered by the intended user.
Conclusion
The security policies that have been presented here must be introduced by Multiple
Unite Security Assurance (MUSA) Corporation so that it would be in a position to address
the security gaps that exist in its organization. The policies have been designed in a strategic
manner so that the firm would be in a position to deal with intentional threats as well as
unintentional threats that could arise before it. These policies would primarily empower the
business entity and its employees so that they could take necessary measures to protect the
security system. The policies that have been designed specifically revolve around human
errors that give an unfair advantage to unauthorized individuals and cyber attackers in the
virtual platform. These policies could be effective only if the employees would follow them
strictly in the organizational context. f
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 12
References
Behr, A. (2019). Separation of duties and IT security. Retrieved from
https://www.csoonline.com/article/2123120/separation-of-duties-and-it-security.html
Encryption and Its Importance to Device Networking. (2019). Retrieved from
https://www.lantronix.com/wp-content/uploads/pdf/Encryption-and-Device-
Networking_WP.pdf
Glaspie, H. W., & Karwowski, W. (2017, July). Human factors in information security
culture: A literature review. In International Conference on Applied Human Factors
and Ergonomics (pp. 269-280). Springer, Cham.
IT0125 - Configuration Management. (2019). Retrieved from
https://policy.tennessee.edu/wp-content/uploads//policytech/system-wide/it/IT0125-
Configuration-Management.pdf
Media Access Control Security Overview - TechLibrary - Juniper Networks. (2019).
Retrieved from https://www.juniper.net/documentation/en_US/junos-space-
apps/network-director3.3/topics/concept/macsec-understanding.html
Nobles, C. (2018). Botching Human Factors in Cybersecurity in Business Organizations.
HOLISTICA–Journal of Business and Public Administration, 9(3), 71-88.
Remote Access: The Pros and Cons of Virtual Private Networking | macchina.io Blog.
(2019). Retrieved from https://macchina.io/blog/security/remote-access-the-pros-and-
cons-of-virtual-private-networking/
IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 13
Secure Hash Algorithms | Brilliant Math & Science Wiki. (2019). Retrieved from
https://brilliant.org/wiki/secure-hashing-algorithms/
Time off to discover fraud - FSS. (2019). Retrieved from
https://www.forensicstrategic.com/blog/time-off-to-discover-fraud
Threats to Security. (2019). Retrieved from https://www.cerias.purdue.edu/assets/pdf/k-
12/infosec_newsletters/03threats.pdf
What is SSL VPN (Secure Sockets Layer virtual private network)? - Definition from
WhatIs.com. (2019). Retrieved from
https://searchsecurity.techtarget.com/definition/SSL-VPN
What is Data Loss Prevention (DLP)? A Definition of Data Loss Prevention. (2019).
Retrieved from https://digitalguardian.com/blog/what-data-loss-prevention-dlp-
definition-data-loss-prevention
What is Social Engineering | Attack Techniques & Prevention Methods | Imperva. (2019).
Retrieved from https://www.imperva.com/learn/application-security/social-
engineering-attack/
What is an Intrusion Prevention System? - Palo Alto Networks. (2019). Retrieved from
https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-prevention-system-
ips