SEC440 Organizational Information Security System Analysis

profileaussieinmiss
sec440_organizational_information_security_system_analysis.docx

Security of Information

SEC440 Organizational Information Security System Analysis

Name

Class

Date

Professor

SEC440 Organizational Information Security System Analysis

The small business just like the larger business has a responsibility to protect the private information of their customer as well as has to put the necessary security measures in place to protect company data. At Stephanie’s a small boutique and tanning salon the credit card numbers of clients are kept on file as well as the personal information of employees. In order to ensure this information is not accessed by external sources the necessary security measures have been put into place and to prevent internal theft only authorized personnel have access to the private information of customers and employees.

Stephanie’s employs twenty full and part time employees and has a fairly large customer base with several hundred customers. The customers of small businesses have an expectation that their sensitive information will be respected and given adequate and appropriate protection (Kissell, 2009). In order to ensure the customer can be guaranteed this protection the small business will need to employ at minimum a security system that protects information networks from damage from malicious code, viruses, and spyware. The small business will also need to place protections on wireless networks.

Password Protection and Requirements

In order to protect the private information of the customer and the employee information networks and systems security password guidelines have been established. Passwords are essential to ensuring the information of the customer and the employee are properly protected but the number of people that have access to this password is also important to effective security. At Stephanie’s only the owner and two of the managers have access to the password that provides access to user accounts. This security measure is employed so that in the event of any security breaches at the business only a few employees will need to be looked at to determine where the breach occurred.

Password protection is essential to determining accountability for all transactions that occur within the organization. Password restriction ensures that unauthorized personnel do not have access to the private data and helps in preventing external attacks. The password at Stephanie’s is changed every two months and the password is chosen randomly from a list provided by the owner. The password has eight characteristics and is never written down in a place where it can be located by others. Unauthorized users will be denied access and attempts at using the password that fail are emailed to the owner. Each employee has their own access code to ensure that whoever accesses the system can be identified.

Firewalls

Firewall software blocks unauthorized access to computers and is essential to stopping external threats from damaging or accessing the private information. Firewall software prevents hackers from obtaining or intercepting private data and to safeguard the data from being accessed. Firewalls act as security, much like a fence around a building, in order to ensure that attempts to access private information systems will be blocked. At Stephanie’s, each computer has firewall software installed on it and each employee that has access to company computers is trained on how to navigate the security questions that will be required to access the computers private network systems.

Security Features that Prevent Hackers

Hackers or other outside intruders are one of the greatest threats to a company’s private information systems. A hacker is an individual that is highly skilled in computers and has the talent to find back doors into the security systems of the businesses. Some hackers are highly skilled and can easily bypass the security system put into place by the business. Firewalls are the first defense against the hacker but because hackers have been known to access some of the most secure sights in the world other security measures must be employed.

At Stephanie’s firewalls are employed but so is encryption software that ensures even if the information is accessed by a hacker it will be unusable. Hackers gain illegal access to the information systems of a company in order to retrieve passwords, pin numbers, and other information that would give them access to private financial data in order to commit frauds. Hackers also conduct attacks on privation networks and information systems maliciously. In order to stop malicious attacks Stephanie’s has installed antivirus software and uses a bidirectional firewall.

A company’s router is another access point where hackers or other external threats can access the company’s information networks. The router must be password protected to prevent outside access as well as to stop the bad actions of the hacker. At Stephanie’s a router is used and the only employees have access to the password in order to gain access to the wireless. All employees have access to the wireless password while only management has access to passwords that directly open the network systems of the small business.

Confidentiality Requirements and Physical Protection of the System

The confidentiality requirements at Stephanie’s includes protecting the privacy rights of the customer and the employee and ensuring that customers can be assured their private information will not be accessed and their identities stolen. Physical protections involve the physical protection of the computer and other hardware that will pertain to the companies private information systems. Physical protection of the system include making hard copies of all information in the computer which is then stored in a fireproof safe and ensuring there are no obstacles that could create harm to the system. For example no drinks around the computers and all cords are safely stored behind the computer or electronic equipment.

Recommendations for Information Security System Improvement Measures

The first recommendation is to limit access to the wireless password. While the employees that have access to the password to the information system are limited all employees can access the wireless system. Because this weakened the security and will potentially result in a hacker gaining access the access to the wireless needs to also be limited to only necessary personnel. The next recommendation involves the physical protection of the computer. Currently there is little or no physical security in place for the information systems at Stephanie’s. Surveillance and notification systems can be put in place, such as lighting, heat sensors, smoke detectors, intrusion detectors, alarms, and cameras (Rouse, 2005). This would ensure that the equipment that stores the private information of the business is properly protected from potential damage or being destroyed.

References

Kissell, R. (2009). Small Business Information Security: The Fundamentals. Retrieved

December 10, 2012 from http://csrc.nist.gov/publications/nistir/ir7621/nistir-7621.pdf

Rouse, M. (2005). Physical Security. Retrieved December 10, 2012 from

http://searchsecurity.techtarget.com/definition/physical-security