For Prof. MGK

profilemaccol
remaining_portions.docx

II. Network/System Security Recommendations

This section will provide network/system security recommendations on how to address the vulnerabilities identified in Section I. Provide specific courses of action along with any pertinent information about the recommendations. In this section, you will cover recommendations only to network infrastructure or network devices. Don’t cover software recommendations here.

Example

In order to resolve the vulnerability created by using a Master Lock combination lock, it is recommended that it be replaced by a more secure deadbolt door lock—specifically, a Falcon D241. This lock is rated as the top standard lock by Consumer Reports. They rate its resistance tokicking, prying, wrenching and hammering as excellent, and the resistance to picking and sawing as very good. The only thing that was considered poor was its resistance to drilling, but no standard lock was anything other than poor. Only the high security locks had higher ratings for drilling, and only one of those, the Medeco Macum 11WC60L, was rated higher than the Falcon [

]. Given its price of almost three times as much as the Falcon, the cost does not seem worth the benefit. However, it is a more secure option that the warehouse administration may want to consider.

III. Application/End-User Security Recommendations

This section will provide application/end-user security recommendations. Provide specific course of actions along with any pertinent information about the recommendations. This section will include any network protocol or software as well as actions that end-user must do.

Example

In addition to installing a new lock on the back door of the warehouse, there are policy recommendations that warehouse administration should implement. The most important policy recommendation is that the number of keys to the back entrance of the warehouse should be limited to only those that need it and in most cases only when they need it. As this is a secondary entrance, it is not necessary that all employees have a permanent key. The warehouse manager should have one key that he keeps at all times. Additionally, he should have access to a secondary key in the warehouse office that only he can access. This secondary key can be given on a temporary basis to employees who need to access the back entrance. Also, this secondary key should be given on a sign-out basis. Employees who are given the key should have their name noted in a log book. When they return it, another notation is made indicating such. This tracks who is responsible for the key at any given time, and should it go missing, will serve as a paper trail for who had the key last.