Project Paper: Network Infrastructure vulnerabilities
Name
Institutional Affiliations
Section 1: Infrastructure Document
Computer networks have increasingly become ubiquitous and synonymous especially with the organizations that thrive on excellence, as well as, those who would want to adopt cloud technology and virtualization within their companies. Today, most organizations that set up their businesses ensure that they have incorporated an efficient computer network infrastructure that will connect the business to the outside world through Internets. This is because, research has shown that the present business depend heavily on network infrastructure platforms that make communication easy, efficient, available, as well as, accessible. Consequently, despite the fact that robust computers networks have made it easier by providing a basis of interactivity and bringing a whole lot of people and businesses together, all these at one point have amounted to growing security concerns over the past years across various sectors and industries. This paper will therefore identify some of the possible network infrastructure vulnerabilities, as well as, describing a comprehensive security policy that helps in protecting the company infrastructure and assets by applying the principle of CIA.
A network consists of devices such as routers, firewalls, generic and hosts which include servers and workstations. Equally, there are thousands of network vulnerabilities; therefore, organizations should ensure that they focus on tests that will produce a good overall assessment of the network especially when they store their data in the cloud, however, there may be risk of non-compliance and regulation, due to lack of control over where data is stored. The possible network infrastructure vulnerabilities include; improper system configuration, poor firewall deployment, poor anti-virus implementation, weak password implementation, lack of efficient physical security, lack of appropriate security policies and many others. Vulnerabilities can be successfully contained by putting measure in place, for example, the Network Administrator should be in position to gather information about viruses and worms, as well as, identifying network vulnerabilities by getting information that helps in preventing security problems. Security measures for Network vulnerabilities can be accessed through three main stages which involve planning, conducting and inference (Markluec, 2010). In planning stage, there is an official agreement that is signed between the concerned parties. The document signed is important because it will contain both legal and non-disclosure causes that serve to protect the ethical hacker against possible law suit. Conducting stage involves the evaluation of technical reports prepared based on testing potential vulnerabilities. Lastly, in inference stage, the results of the evaluation are communicated to the organization and corrective action is taken if needed.
A logical and a physical layout of planned network
A logical topographical layout of network illustrates all the logical features of the network which comprises of logical networks, routing tables, as well as, assigned IP addresses to a variety of hosts and devices. Conversely, a physical layout of the networks, on the other hand, represents the physical location and the association between the different devices participating on the network. In a physical network layout, each computer is connected to the hub and a cable line, this is important because it helps the administrator to visualize how much equipment he or she will need. Having a well planned illustration view of both physical and logical network is significant because it helps to facilitates identify probable security problems. For example, when unnecessary visitor attempts to acquire access to sensitive data or information, he or she will first generate a map of network to check on security checkpoint that is firewall or other similar devices that are established, and to what access can be attained. The diagrams below show a logical and a physical layout of planned network.
Physical network diagram
Internet
Router
Switch
WIFI router
Switch
PC
PC
PC
PC
Ring
Server
PC
Printer
Scanner
PC
IP Phone
IP Phone
Logical Network diagram
PC
PC
PC
PC
172.16.44.1 172.16.48.21
172.16.52.1
172.16.56.23 172.16.60.9
PC
Illustrate the possible placement of servers
When designing a logical and physical network, the network administrator should thoroughly illustrate the possible placement of servers, including the access paths to firewalls, as well as, internets. Conversely, facility limitations, routers, printers, switches, bridges, workstations, and access points should be as well considered when designing a network. The basic design of this network demonstrates the relation to the Internet using a broader router and firewall. In order to design a well secured network, various factors must be considered into contemplation such as the topology and placement of hosts inside the network, the selection of software and hardware technologies, as well as, the suspicious configuration of the components.
Comprehensive Security Policy for the Company
The acts of providing trust information; confidentiality, Integrity and availability (CIA) of the information are not violated. For instance many companies ensure that they have backups just in case data is lost when critical issues arise. Confidentiality, integrity and availability, also known as the CIA triad is a model that has been designed to guide policies for information security within organizations. Confidentiality is a set of rules that limits access to information, integrity is the assurance that the information is accurate, while availability is a guarantee of reliable access to the information by authorized people. The business’ assets may be measured in terms of its employees and buildings, all these are stored in the form of information, whether electronic data or written documents, therefore, if these information are disclosed to unauthorized individuals, is inaccurate, or not available when it is needed, then the business may suffer significant harm, which include, loss of customer confidence, contract damages, or even reduction in market share.
Confidentiality of information is very important not only for corporations but for Governments as well. Most organizations have developed various measures to ensure the confidentiality of information by preventing sensitive information from reaching wrong people, as well as, making sure that the right people get the information at the right time they need them. Access must be restricted to those authorized to view data, however, sometimes, safeguarding data confidentiality may require special training, which typically include security risks that may threaten information. One way to ensure confidentiality of information is through data encryption. For example, users are encouraged to use Passwords that have at least eight characters that will prevent the attackers from hacking into their passwords and gaining access to their personal information. Integrity on the other hand involves maintaining the accuracy and consistency of data over its entire life cycle. For example, data should not be changed in transit; therefore, steps should be taken to ensure that data cannot be altered by unauthorized people (TechTarget, 2016).
Employees within organizations should ensure that they do not disclose any information regarding the organization because when they do so, those who are not authorized to accessing the information may get the opportunity to leak out the information by hacking into the system. Conversely, users should ensure that they created passwords that make it hard for attackers to hack these passwords. Passwords should never have only lower case or upper case letters, however, both lower and upper case letters can be used together, since this will make it a bit difficult for hackers to guess the password of the users. Organizations on the other hand, should make sure that they have implemented a secured network within the organization using firewalls that prevent hackers from bringing the whole system down.
Section 2: Revised Project Plan
One of the critical factors for project success is having a well-developed project plan. There are various step approaches to follow when creating a project plan. These include; project description, project objectives, project management plan purpose, project deliverables, project milestones, project Roles and Responsibilities, project scope management, project time management, and many others. In this case, we shall revise the previous project plan while updating the project plan template; from Project Deliverables 4: Cloud Technology and Virtualization with at least three new project tasks each consisting five to ten subtasks.
I personally support the need for use of cloud technology and virtualization. Use of cloud computing can change the risk posture and profile of a company. For example, companies that have adopted cloud technology avoid the risks that a large investment in IT resources will not pay off. Conversely, cost savings in hardware infrastructure are relatively easy to quantify particularly for those companies that adopt cloud technologies in a public cloud, on-site hardware will be replaced less often and less new hardware is purchased.
Cloud and virtualization technology align with the company’s business processes and assist with attainment of organizational goals by providing a more productive environment not only for a collaborative working, but also it improves the company’s productivity by enabling participants in a business ecosystem to share processing logic (Parker, 2012). Some of the new project tasks in project deliverables for Cloud Technology and Virtualization include; host server patching, monitoring the virtual machine sprawl, as well as exploring backup options. These tasks are important in ensuring efficient, healthy and a secure virtual environment. Some of the subtasks involve in host server patching include configuring the software updates installation and running compliance and vulnerabilities. A compelling recommendation for solution providers and partners that could help a company secures a firm competitive advantage by using cloud and virtualization technologies is to ensure that all the systems are up-to-date and firewalls are installed in the systems to prevent attackers from hacking the system.
References
Markluec, M. (2010). Some Common network vulnerabilities persist. Retrieved on 26 Feb, 2016 from http://gsnmagazine.com/article/20994/some_common_network_vulnerabilities_persist
TechTarget, (2016). Confidentiality, Integrity, and availability (CIA triad). Retrieved on 26 Feb, 2016 from http://whatis.techtarget.com/definition/Confidentiality-integrity-and-availability-CIA
Parker, J. (2012). Business Requirements vs. Functional Requirements. Retrieved on 26 Feb, 2016 from http://enfocussolutions.com/business-requirements-vs-functional-requirements/