Written Project Plan
Running head: INFRASTRUCTURE AND SECURITY
INFRASTRUCTURE AND SECURITY 2
Infrastructure and Security
Section 1: Infrastructure Document
Patrick B. Magee
Information Systems Capstone (CIS-499)
Mark O’Connell, Professor
March 8, 2015
Introduction
Communication is a key aspect to the success of any organization whether inside itself or to the outside world. In the world today, organizations and companies utilize networks so as to communicate effectively and efficiently. Network design is the process of planning and deploying a computer network for an organization. A computer network can be defined as a connection of two or more computers devices with the goal of sharing information and for communication purposes (Laudon, 2009). Networks are essential for any company and for this data collection and analysis Company it is crucial since it enables the Company to interlace its communication infrastructure. The network infrastructure must be able to interconnect all the network devices in the whole building in a way that allows efficient and effective communication and enhances security of its network and organizational resources.
Relationship between Infrastructure and Security
The network infrastructure for the three floors will be a Local Area Network (LAN) with three subnets one for each floor. The LAN network will be connected to the internet or other WAN network outside the Company’s building through a T1 link preferably from Verizon. The LAN for the building will include a network of computers, and other network devices such as printers for data exchange as well as sharing. The computers in the LAN will communicate through protocols and share data such as files and emails. Every computer in the network will be assigned a unique Internet Protocol (IP). When a computer communicates by sending a request to the LAN, it is routed to a particular server that has the requested data. The server then communicates back to the IP address of requesting computer with the information that was requested (Kenyon, 2002).
Network security measures include access controls measures for accountability, authentication, and authorized access to network as well as organizational resources. Network security measures are aimed at enabling the CIA (Confidentiality, Integrity, and Availability) policy. The network security controls for the this data and analysis Company will be designed in regard to the user group in question, this means that different users will be in different user groups. Access control measures such as access logs will be utilized in managing what each user should have access to in regard to the organizational policies and procedures. Cisco Linksys Firewall will be used so as to enhance security such that guests will not be able to access the organization data highway. The firewall will also be a key device for enhancing security; it will control incoming and outgoing data communication through analyzing data packets and giving permissions based on security rules.
Physical and Logical Topographical Layout
The Physical topographical layout of the network implies the physical connectivity of each of the hosts of a network; the hosts include devices such as computers, printers, servers, switches and so on. The logical topographical layout of a network which is also referred as signal topography is the way the devices on a network are arranged and how they communicate with each other.
Diagram Illustrating Physical Topographical Layout of the Network Design
Diagram Illustrating Logical Topographical Layout of the Network Design
Network Design
There are three servers that will be implemented so as to serve all the computer devices in the three floors of the building; the Web Server will be used to connect the Company to the internet, and the File Server will be utilized for sharing organizational records through a web based customer database server and a Small Business Server that will be utilized as a Mail Server.
Since data and analysis Company may need a network that incorporates a wireless network, the network design for the infrastructure should therefore take several factors into consideration? These factors will impact on the network costs, speed, infrastructure, and functionality. When designing the Local Area Network (LAN) for the three floors, there is need to consider the network requirements. The network should integrate sound, video, synchronous, as well as asynchronous data. The organizational goals of the data and analysis Company will also be factored in the LAN design.
As the CIO, I will also pay attention to network throughput, line charges, security, and the integration of newer technologies in the future. When designing the LAN, some issues will be considered; one of these issues is the organization’s short, medium, and long term goals. Several other factors to be considered include the network equipment, user applications, end-user equipment (workstations), connectivity to the internet, and most importantly the budget.
The network infrastructure for the three floors includes devices such as gateways, routers, firewall, and cables. These are the communication devices that make up a network infrastructure, a router and switch are the most important devices of a network. Networks which are well configured and have a good infrastructure are helpful in improving manageability, performance, reliability and reducing overall operating cost (Kenyon, 2002).
The three floors will share one internet connection preferably from Verizon; this connection will come to a Web Server in a server room located at the first floor. This will be the access point of the LAN network to the three floors. The T-1 link from Verizon will connect the three floors to the internet or other remote branches the Company may establish in the future. The T-1 link utilizes frame relay which will provide the building with high speed data connection between and among all users. This connection will also enable all computers to receive dedicated connection at a speed that every computer requires. This connection will also be affordable for the data and analysis Company since it is only charged for the resources. It costs an average of $1000 per month.
An Intrusion Detection System (IDS) will be utilized to monitor all the outbound and inbound network activities with the goal of identifying any suspicious patterns that can indicate network attack that may compromise the system or network. An Intrusion prevention system (IPS) on the other hand will be utilized for providing security at all levels from the kernel of the operating system to the network data packets. Intrusion prevention systems make the attempt to stop potential attacks and will allow the network administrator to take an action after being alerted (Whitman, 2007).
Network Security Policy
The importance of data security is a trending issue in the current technological world where companies in the corporate world are competing for market and business information with the goal of improving their competitive advantage. For this data and analysis Company, information is one of the core assets and anything that can compromise the company information either in terms of unauthorized access or its misuse should be completely avoided. The impacts for such an occurrence cannot be understated and this calls for the need to have a robust IT security policy to guard against such unauthorized access. With such a framework in place, users of a company’s IT system are provided with parameters of their activities within the system including the legal requirements of the framework (Fitzgerald, 2008).
One security framework that I would recommend for my company is the ISO/IEC 27000 which offers a fine framework for establishing the Information Security Management System. The framework ensures assessment of risks, active involvement of management, implementation of controls, and up to date documentation. The framework warrants an effective security control of data and many other benefits to data security (www.iso.org). Through the adoption of a good network security policy the Company will realize the core goals of data security which are Confidentiality, Integrity, and Availability (CIA).
Ethics is concerned with what is good or bad. Ethical behavior is based on the written and unwritten codes of values and principles that are held in the society and in organizations. Ethical values and principles serve as a guide to behaviors on the personal level of professionals as well as at the collective organizational level. On the other hand business ethics involves personal, professional, as well as corporate level behaviors. Ethics is concerned with all aspects of human behavior (Jonasson, 2013). The Company will employ well defined code of ethics that will guide all the employees including the management regarding its network and organizational resources. Employees will not be allowed to reveal Company confidential information, passwords to network resources, as well as any organizational resource deemed private and confidential. Any violations will be punishable accordingly.
References
Laudon, K., & Laudon, J. (2009). Essentials of management information systems. (8th ed.).
Upper Saddle River, NJ : Pearson Education, Inc
Kenyon, T. (2002). High-performance data network design: Design techniques and tools.
Boston: Digital Press.
Whitman, M. E., & Mattord, H. J. (2007). Principles of incident response and disaster recovery.
Boston, Mass: Thomson Course Technology.
ISO/IEC 27001 (2015) - Information security management, www.iso.org
Fitzgerald, Todd (2008) Information Security Management Handbook, New York. Auerbach
Publications
Jonasson, H. I., & Ingason, H. T. (2013). Project Ethics. Farnham: Ashgate Pub.