Work for BRAVO BRAINS ONLY
Full Paragraph response needed for each discussion (6-7 sentences)
Discussion Questions Response Needed 1
· Outline three parameters that should be considered when designing and implementing physical security into the information protection scheme. Suggest two activities that could be performed to address these parameters and explain how.
When designing and implementing physical security into the information protection scheme, first parameter that should be considered is the definition of the physical space, second parameter should be the effective set of countermeasures that will secure the area, and last parameter will refer to identification of all practical points of weakness that can be exploited. threat identification, and the establishment of the right internal counter measures are two activities that could be performed to address these parameters because they make sure that all information processing equipment is safeguarded properly and can't be accessed without authorization, long -established controls methods such as gates, fences, video cameras, and visitor accompaniment procedure can be applied after risk assessment that will allow protection by ensuring the integrity and security of the space where equipment resides.
· Suggest three activities that could be performed to ensure that physical security plans are adequate. Describe two measures that you could perform in order to evaluate the installed physical security.
Incorporation of normal means of access, the identification and evaluation of the likelihood and the potential impact of unauthorized access through the potential point of entry can be performed o ensure that physical security plans are adequate. To evaluate the installed physical security is to develop a full and accurate picture of the entity which is under scrutiny by auditing that is a process of standardized interviews and observation of human behavior and system documentation. Penetration testing that evaluates system security by attacking it.
Discussion Questions Response Needed 2
· Select what you believe to be the top-three benefits of making a business and assurance case prior to proceeding with a procurement plan. Support your response with a rationale. Describe potential challenges that the procurement process may experience by not having a proper business and assurance case.
Ensuring the right product functionality, making sure that the product come with all the security requirements, and maximizing the value for all the stakeholders by providing a better balanced set of functions are the top three benefits of making a business and assurance case prior to proceeding with a procurement plan. Making the case and assurance case prior the procurement plan will help with the procurement process practical goal which to allow that everybody who will be involved with the purchase, or use the product such as managers, technical support, and security professionals to have their say in the process. All expenditures have to benefit the organization by satisfying the needs of competing groups and also each group's personal agenda for what it is required. Potential challenges that an procurement process can face by not having a proper business and assurance case are expenses that are not documented, embezzlement of funds, and internal and external audit findings that can result in penalties or lawsuits. fundings have to justified and be tracked to the associated purchase, and supplier.
· Recommend two practices that should be performed when administering procurement contracts and explain why you recommend them. Determine how these practices will ensure that subcontractors fully comply with the requirements of the contract within your recommendation.
i would recommend that oversight and control elements must be enforced throughout the life of the contract, and that costs, schedules, and project status have to be reviewed and also to resolve any relevant problems that are identified in the performance should be performed when administering procurement contracts. I recommend them because they allow that security is practiced as a discipline throughout the process, and they allow managers to oversee the progress of the technical work. These practices will ensure that subcontractors fully comply with the requirements of the contract by helping the supplying organization to make sure that applicable contracts requirements and conditions are understood clearly by all sub-contractors and by allowing the supplier to conduct all required verifications, validations or tests of subcontractor work by contract.
Discussion Questions Response Needed 3
Propose three factors that should be considered when designing policies for legal and regulatory compliance. Determine how each factor would minimize liability for the organization.
Whenever designing compliance requirements for cybersecurity, it is crucial to clearly identify the context, scope, and feasibility of the policies. As Shoemaker and Conklin (2011) explain, context is the first step, because the compliance requirements must fit the requirements of the surroundings, not the other way around. If a low-tech manufacturing environment were saddled with an overly complex and rigorous set of requirements more suited to a high-security environment, then compliance would likely be low, setting up the organization for compliance failure. The second area is scope. It is crucial to define the area that must be secured, but again – overreaching can cause the potential for compliance failure. Defining scope includes the technologies to be secured, who is responsible for it, what reporting will take place, and who is eventually accountable. Finally, feasibility is an important component, but not one to be overlooked. If a security system has been designed for a small installation that contains requirements far beyond that unit’s financial capacity, the plan is sure to fail.
Outline the steps required in order to define what is needed to meet compliance requirements. Determine the most important step in this process and support your answer with a rationale.
There are five steps that should be designed in an effective compliance requirement. As Donaldson, Siegel, Williams and Aslam (2015) explain, the first is the IT system or business process to be secured. The second is the specific malicious activity or activities that must be defended against. The third is the security capability or audit control required. The fourth is the incident response required. Finally, validation audits must be clearly defined. The most important of these steps is the first – to clearly define the IT system or business process to be secured. If the actual system or process to be protected is unclear, then the response of the business to the regulation or compliance requirement will likely lead to failure, but if the business has clear in mind what needs to be protected, they will be better equipped to respond to the regulation.
References:
Donaldson, S., Siegel, S., Williams, C. K., & Aslam, A. (2015). Enterprise cybersecurity: How to build a successful cyberdefense program against advanced threats. Apress.
Shoemaker, D., & Conklin, W. A. (2011). Cybersecurity: The essential body of knowledge. Boston, MA: Course Technology.
Discussion Questions Response Needed 4
Analyze a well-designed risk management plan to determine how it can prevent risk and control residual risk. Identify what you believe to be the most important step in the risk management process and explain why.
Risk management is an important business process for any organization. As Kohnke, Shoemaker and Sigler (2016) delineate, the main goal of the risk management process is to peruse each activity in an organization with the goal of identifying, quantifying, mitigating, and observing the results of such activity against any risks, either active or latent in an organization. As they put it, risk management really is a data collection process. At the heart of risk management, all the potential risks have been identified, then the systems and processes in the organization have been compared to the risks, mitigation plans have been put into place, then measurements that assure that the risks have been fully mitigated have been executed. In this way, a risk management plan can be said to be not only complete, but effective.
Construct two examples that demonstrate how qualitative and quantitative methods could be applied to measure risk and prioritize risk responses. Recommend two factors that should be considered when prioritizing risk responses.
In reality, when measuring the extent of risk in risk management programs, as well as the effectiveness of the response, both qualitative and quantitative measurements are used. As Kohnke, Shoemaker and Sigler (2016) explain, qualitative measures are not producing actual metrics, but show differences within the elements being measured. Thinking back to introductory statistics, the so-called “bell curve” which indicates high, medium, and low would be a typical way of representing results in a qualitative measure (Morrel-Samuels, 2002). As Kohnke, Shoemaker and Sigler (2016) continue, bbecause qualitative measures cannot tell the entire story, quantitative measures must also be used. Rather than the ranges typical of qualitative measures, in quantitative measurement, an actual number or score is generated through a mathematical process, algorithm, or function. Performance of the risk management method is then compared against that number to determine success or failure. Caution must be exercised in using quantitative measures where a standard scale does not exist to ensure consistent interpretation of the results. Otherwise, the validity of using the selected quantitative measure may be questioned. Simply put, one may not be measuring what one expects to be measuring.
References:
Kohnke, A., Shoemaker, D., & Siigler, K. E. (2016). Complete guide to cybersecurity risks and controls.
Morrel-Samuels, P. (2002, February). Getting the truth into workplace surveys. Harvard Business Review, 1. Retrieved from https://hbr.org/2002/02/getting-the-truth-into-workplace-surveys