CMGT 431/2
Assignment Content
- After reviewing the material your group has prepared so far, the management team has returned with a list of five specific concerns. They include:
- Access control
- Security enterprise
- Impact of implementing a change management system
- Mitigation
- Risk management
- Management has asked you to address concerns with a visual presentation. Address concerns by providing the following information:
- An overview of the access control
- Required mitigation steps for each concern
- Prioritize concerns
- Concerns with vendor relations from the enterprise security standpoint
- Description of how the organization can apply risk management principles in its efforts
- Description of iterative maintenance effort, including audits and frequency
- Include at least two references formatted according to APA guidelines.
Present the information in one of the following ways:
- A detailed chart along with a brief 1- to 2-page executive summary explaining the decisions made
- A 12- to 14-slide multimedia-rich presentation with speaker notes
Wk 2 - Security Vulnerability Report [due Mon]
Assignment Content
- A security vulnerability report identifies the areas of the organization that are at risk of losing data, outages, etc. Typically, organizations categorize the report to focus on specific areas and highlight the level of risk per area. Based on the vulnerability report, organizations are able to plan appropriately for budgeting and resource improvements.
Write a 2½- to 3 ½-page security vulnerability report in Microsoft Word based on the organization you chose in Week 1. An internal review of your organization was previously conducted and found the following vulnerabilities:
- A formal Password Policy has not been developed that meets your organization’s regulatory requirements.
- The organization only uses single factor authentication using weak passwords.
- Vulnerability Severity: High
- Impact: Threats could easily guess weak passwords allowing unauthorized access.
- Software configuration management does not exist on your organization’s production servers.
- There are different configurations on each server and no operating system patching schedule.
- Vulnerability Severity: Moderate
- Impact: With ad hoc configuration management, the organization could inadvertently or unintentionally make changes to the servers that could cause a self-imposed denial of service.
- An Incident Response Plan has not been developed.
- There is not a formal process for responding to a security incident.
- Vulnerability Severity: High
- Impact: In the event of a security incident, an ad hoc process could allow the security incident to get worse and spread throughout the network; the actual attack may not be recognized or handled in a timely manner giving the attacker more time to expand the attack.
- Consider people, processes, and technology that can be exploited by the source of a threat.
Include recommended countermeasures to mitigate the impacts and risks of the vulnerabilities.
Format your citations according to APA guidelines.
7 years ago
14
Answer(1)![blurred-text]()
![]()
Purchase the answer to view it

- Wk2-SecurityVulnerabilityReportdueMon.docx