Network Security and Analysis - For Science Prodigy - APA Format Due Nov 4

profiletqross0g
sof_web_design_company_overview.docx

No plagiarized work. I need 8 to 9 page paper analyzing the security weaknesses within the company listed below. Two weaknesses within the existing company must be analyzed – hardware, software, or the existing security policy not to include the password policy. The two items (hardware, software, or policy ) must be identified as an item that requires security.

To clarify an item that requires improved security, you must identify one of these items:

· one hardware and one software weakness

· one hardware and one policy weakness

· one software and one policy weakness

It must be in APA format and the Quality Web Design organization listed below is the Project Company Overview / Scenario.

6 Cited and verifiable resources are needed. Scholarly articles or sources I can gain access to are a must.

The paper is due November 4th, 2014. I will pay $75 for QUALITY and on-time delivery.

Suggested Reference – Security in Computing – Charles P. Pfleeger and Shari Lawrence Pfleeger

Company Overview

Quality Web Design (QWD) is an organization that specializes in Web site and Web content design for all types of businesses. QWD's mission is to provide top quality Web design that will increase consumer generated revenue to QWD's customer Web sites. QWD's database contains over 250,000 proprietary images and graphical designs that will enhance most Web site's appeal to a target demographic.

Business Processes

Quality Web Design has several mission critical business processes. First is the use of the repository of Web site templates, custom written scripts and/or custom applications. This repository is stored in a Microsoft Visual Studio Team Foundation Service (TFS) server. This application is used to monitor the project development lifecycle of custom Visual Studio applications from inception to deployment, including the quality assurance testing phase. Other critical business processes are QWD's accounting, payroll and Marketing operations all of which are supported by IT assets. There are strict technology-based access controls associated with each of these systems to ensure that only authorized personnel can access them.

Digital Assets

These are shown in the network diagrams below

WAN

· (2) T1 Frame Relay circuits connected to the Internet.

· ISP controlled Internet routers

· Corporate Firewall Model: Juniper ISG2000 integrated Firewall, VPN, and Intrusion Detection and Prevention system. Remote office firewall is a Juniper SSG140.

· L2TP/IPSec VPN tunnel between the corporate firewall and the office firewall to allow for secure data flow.

Corporate Office

· Internal LAN switch is an HP 5400zl series with 147 ports with 10/100/1000 GB connectivity.

· (2) HP ProCurve MSM410 Access Point US wireless access points.

· Microsoft TFS code repository consists of 1 Web server, 1 application server, and 1 database code repository.

· Web server includes, Microsoft Share Point portal for department document and Web sites. Corporate intranet site.

· Microsoft SQL 2008 Database server used for storage of custom designed graphics and custom application image control system.

· File and Print server services.

· Microsoft Exchange 2007 email servers, include (2) Client Access (CAS) and Hub Transport (HT) Servers, 1 backend mailbox servers.

· HP Storage Works SAN with 6 TB disk space.

· (2) Microsoft Windows 2008 domain controllers.

· Approximately 50 user computers, 35 laptops and 15 desktops.

· (4) network printers

· (30) Mobile devices, IPhones, and Windows Mobile 6 devices.

Remote Office:

· HP ProCurve Switch 3500yl-48G0PWR intelligent Edge. This is a 48 10/100/1000 GB port intelligent switch.

· (2) HP ProCurve MSM410 Access Point US wireless access points.

· Microsoft TFS code repository, consists of 1 Web server, 1 application server that connects to the database server in the corporate office through the IPSec tunnel.

· (2) Microsoft Windows 2008 domain controllers.

· File and Print server services.

· Approximately 20 user computers, 15 laptops and 5 desktops.

· (2) Network printers

· (15) Mobile devices consisting of IPhones, and Windows Mobile 6 devices.

Externally Published Services

Corporate and remote offices have the following services that are accessible for employees. From corporate owned computer or mobile device employees can access VPN, Outlook Web Access for email, or Active Sync for Exchange server. On any computer in the world employees can access Outlook Web Access for email. Customers are only allowed to access to the Corporate Web site.

Security Controls

There is a published corporate security manual that covers the following security practices. Username standard including having a separate account for any elevated privileges. Password length, complexity, rotation and history requirements. Data classification levels depend upon what type of data each system contains and security group accounts control access to each data classification level. Security training is also describe and required communications quarterly and annual training classes.

SEE THE PROJECT EXAMPLE BELOW FOR A SUGGESTED FORMAT

Course Project Format Example

Table of Contents

Executive Summary 1

Company Overview 1

Security Vulnerabilities 3

A Hardware Example Title 3

A Software Example Title 4

Recommended Solutions 5

A Hardware Example Solution 6

A Software Example Solution 8

Impact on Business Processes 9

Budget 1 0

Summary 11

References 12

Executive Summary

The executive summary can’t really be completed until the course project is completed. This is because the section should summarize BRIEFLY the entire paper.

Company Overview

Here you should identify which of the two company scenarios you are using and briefly summarize the organizations products or services, and business processes.

Two Security Vulnerabilities

Software Vulnerability

Remember, you need to choose only two vulnerabilities from the three categories: hardware, software and policy. It is recommended that you make them limited in scope and very specific. Also, before starting on this section, be sure you have a very clear idea of the definition of the following terms: threat, vulnerability, risk, and consequences. A vulnerability is a weakness such as an unpatched Web server, but it need not be a “weakness” per se. It can simply be an asset exposed to risk unnecessarily. A Web server, no matter how secure, is still exposed to risk. However, what you are going to define is a situation where you will, later in the paper, make a recommendation for a security control that will mitigate risk.

Be sure that, in this section, you clearly define the asset(s) involved, the vulnerability specific to your company’s situation and implementation, the threat(s), risks, and consequences.

Recommended Solutions

You may want to make some general statements about how you went about the process of making recommendations and/or other general information about the solutions section. If not, simply go to the solutions. Do not summarize anything previously stated. Also, do not use the first-person (e.g. “I recommend that….”), if necessary, use “we.” Remember, you are trying to give your paper professional credibility and an objective tone.

Telecommunications Closet Security Recommendation

Here a VERY brief summary of the vulnerability is appropriate but usually, it doesn’t need to be even a complete sentence. This section should focus on defining the specific product or service recommended, the reason that it is better than other plausible solutions, if applicable, and evidence of the efficacy of the solution. This evidence needs to be supported by research. Statements like, “Anti-virus software is effective at protecting workstations,” is, in a business environment, of no use. Managers need to justify their budgets and need facts.

Impact on Business Processes

Usually, security controls have some impact on business processes. For example, recommending that users be forced to change their passwords every week is going to cause a lot of frustration for users. They will lose productivity while they’re contacting IT to have their forgotten passwords reset. But, if it HAS to be, then explain what the impact will be on business processes and how the “pain” of the solution is justified by the reduction in risk. Also, remember that the focus of this paper (and all IT work) is optimizing the organization’s ability to meet its goals. While you may need to address how IT itself is impacted by these solutions (changes is staffing, procedures, training, etc.) the focus should be on how users will be impacted.

Budget

Product

Features

Cost

Acme Device

28.v

$1,255

CiloTronic

1.5 Gbps

$14,589

Acme Device

28.v

$1,255

CiloTronic

1.5 Gbps

$14,589

Acme Device

28.v

$1,255

CiloTronic

1.5 Gbps

$14,589

Acme Device

28.v

$1,255

While a budget table is not required, it’s usually the easiest and clearest way to show this information. Be sure that you are using the most reliable figures available and that your list is complete with a notation that the figure is a rough estimation if necessary. Most of your figures must be real costs obtained through your research. Your client will be grilled by upper management and, if you don’t give your client the ammunition needed to justify the budget request, you have just lost a client.

Summary

Like the Executive Summary, this section should not be long. A summary should not include a lot of new information, it is appropriate to note smaller issues such as time to implement. This section should remind the reader of the key issues raised and how acting on them constitutes a prudent approach.

Internet

T1

Internet router

Corporate FirewallOffice Firewall

T1

Corporate

Network

Office

Network

DMZ

Internet router

O

f

f

i

c

e

I

P

S

e

c

T

u

n

n

e

l

O

f

f

i

c

e

I

P

S

e

c

T

u

n

n

e

l

WAN

Diagram

Title 

Wireless Connection

Internal LAN

Internet

Office Firewall

T1

ISP Router

Email ServerFile Server

Web Services

Active Directory Server

TFS code repository

Print Server

Wireless

Access

Point

Wireless

Access

Point

Company Owned Desktop

Company Owned Laptop

Company Owned

Mobile Device

Database Server

Corporate Network

Diagram