For Prof. MGK

profilemaccol
vulnerability_part_1.docx

Vulnerability Assessment

During the short period that I have been at the accounting firm, I came to the realization that the firms were most vulnerable to network attacks and generally security threats. This attacks presented themselves as unauthorized attacks, access attack, viruses and other malicious programs and disgruntled employees, and finally malicious hackers .The weakness in any network that can be exploited by a threat is known as a Vulnerabilities. This report will try to look at the various vulnerabilities what would be there causes and measures on how to prevent them or put an end to them if it’s already in play.

First, the biggest vulnerability the firm is faced with is the lack of a firewall or a general security measure to protect the network .this leaves the network practically vulnerable to a type of attack may it be from a hacker viruses and worms or even disgruntled employees .to expose this vulnerability I tried hacking the computers of one of the employees to access customers details from a remote computer, and it was as easy as pie. What would be most recommended? This is to create a firewall that will protect the network and install smart antivirus programs in each of the computers to ensure maximum security.

Secondly, the other vulnerability that the firm is exposed to is the number of administrators present in the firm. This leaves a very big gap both for the data security and the firms’ security. The importance of an administrator is to ensure that everything that runs and goes on in the system is monitored in one centralized position, so the availability of more than one admin causes a disrupt in the centralized control system, this is because accountability for either lost data or missing data is not accounted for .Solution is to have one admin who runs the show and is the only

The Third vulnerability is that the firm is prone to unauthorized modification this is where unauthorized modification of data is attacked on data integrity. Any changing in data or software can create big problems; possibly can corrupt databases, spreadsheets or some other important applications. This changes can be made by both authorized and an authorized. What brings about this problem is a lack of data encryption, lack of protection tools Access control mechanism that allow unnecessary write permission.to prevent the easy access of keys each employee should be issued with specific logins that reflect his or her name whenever a login is made in one of the firms machines .this will see the eradication of this vulnerability

Finally, the firm should create a virtual private network, this will be to secure your iPad from hacks from data sniffers and hackers this vulnerability is a risk to not only you but to the firm in general

If all this countermeasure are implemented security of the firms data and accounts data will be protected from any malicious hacker virus network disruptions and hacks .Data traffic in the company will always be safe and convenient ,thus effective and productive working conditions.