Hardware 2
Please don’t give me a two to three sentence replies. It has to look bulky. At least 8 to 10 sentences. Thank you
Reply needed 1
Introduction
Laws, Regulation, and Policies
Red Clay Renovations has field offices in Maryland, Delaware as well as Pennsylvania and must comply with those states laws as well as federal laws and industry regulations when it comes to processing certain types of information. Red Clay Renovations currently receives, stores and transmits Protected Health Information (PHI) in its field offices as well as the operations center which is why it has been advised by its legal counsel to be ready to show compliance with the HIPPA Security Rule (King, 2016). Red Clay Renovations also conducts credit checks which is why they must also comply with the Red Flags Rule which requires that if there is evidence of identity theft customer must be notified. An SSP will have all the laws that a system is required to comply with so that the system owner can implement the required security controls. For example, HIPPA requires that stored PHI be protected. With that knowledge the system owner can use encryption as a form of protection for stored PHI.
Information Value
Knowing the value of your information will help the system owner determine how much security it needs. An SSP places the value on information based on what happens if it is lost or stolen. An SSP has three categories for information and they are low, moderate and high. The Baltimore field office has been placed in the moderate category which means the potential impact to loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals (Technology, 2004). With that information the system owner can employ the necessary security measures to prevent data breaches. A data breach is when an incident were protected, sensitive or confidential information has potentially been viewed, stolen or used by unauthorized personnel (Rouse, 2010). For example, the system owner could place an extra firewall at the entrance to the network or on specific devices that process, stores or transmits sensitive information.
Conclusion
An SSP is a document that is put in place to protect an information system and is constantly being updated. The reason each field office needs its own SSP is because they must comply with different state and federal laws as well as industry regulations. One law that all field offices must comply with is the HIPPA Security Rule. An SSP also helps system owners determine how much security a system needs based on the category it is placed in. The information that was presented in this briefing was meant to help you understand why each field office needed its own SSP.
References
King, V. J. (2016, March 30). Red Clay Renovations. A Case Study for CSIA 413.
Rouse, M. (2010). Data breach. Retrieved from Techtarget: http://searchsecurity.techtarget.com/definition/data-breach
Swanson, M., Hash, J., & Bowen, P. (2006). Guide for Developing Security. Retrieved from NIST: http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf
Technology, N. I. (2004). Standards for Security Categorization of. Retrieved from NIST: http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf
Reply needed 2
Red Clay Renovations currently utilizes NIST SP 800-100 for proper Information Security for managers. Each field field office manager is responsible for the approval and compliance of security plans and procedures for his or her field office. The field office manager is also the system owner for all IT systems in his or her field office. There is an additional Field Office Information Systems Security Officer (ISSO) who is responsible for day to day implementation of security plans, processes, and procedures at each field office. But, there is no system security plan in use as suggested by NIST SP 800-18.
It is vital to the overall Red Clay Renovations Security System Program (SSP) that each field office have their own SSP. NIST SP 800-18 asserts, “the purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements” (2006, vii). More important to the individual field office, “the authorization of a system to process information, granted by a [Field Office] management official, provides an important quality control. By authorizing processing in a system, the [Field Office] manager accepts its associated risk” (2006, vii). Essentially, a field office manager will have greater care and oversight if he or she approves an individual SSP and is responsible for the information systems security of the office. The field office manager, field office systems owner, will then work harder and have have greater insight to the needs of their SSP, can personally develop and maintain the ssp, and ensure proper SETA training, (NIST, 2006, pg 5).
Additionally, a field office manager has the best placement for handling sensitive information and understanding the best security controls to use for them, under the support of the CIO (FCC, n.d., pg 2). Red Clay Renovation field offices handle financial information, HIPAA protected PHI, and customer PII. The field manager can handle the ssp according to the specific needs of the security for their individual office, and reduce mass exposure to other employees who don't need to see the information. NIST 800-100 supports this, stating, “ the system security plan also delineates responsibilities and expected behavior of all individuals who access the system” and then the manager can certify and provide oversight (2006, pg 67). This also applies for understanding the technical specifications for the information systems, and the security controls they use. The Baltimore and Philadelphia field offices are similar, but the Delaware office and the operations center are different. A “one size fits all” SSP wouldn't correctly fit to these individual offices.
References
Bowen, P., Hash, J., & Swanson, M. (2006, February). Guide for Developing Security Plans for Federal Information Systems. Retrieved September 26, 2016, from http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf
Bowen, P., Hash, J., & Wilson, M. (2006, October). Information Security Handbook: A Guide for Managers. Retrieved September 26, 2016, from http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-100.pdf
Federal Communications Commision. (n.d.). Cyber Security Planning Guide. Retrieved September 26, 2016, from https://transition.fcc.gov/cyber/cyberplanner.pdf
REPLY 3 Needed
Introduction
Red Clay Renovations (RCR) is a small company of about 100 employees with 2015 top-line revenue of $15 million. Part of the company’s success has been due to its geographic diversity along a 100 mile stretch of I-95 anchored by Baltimore MD on the south and Philadelphia PA to the north. At both endpoints are two RCR field offices. The Baltimore office services the Maryland market while Philadelphia serves both Delaware and Pennsylvania.
While each office contains similar IT architectures and is equally served by the Owings Mills Operations Center, both locations present their own unique RCR enterprise security challenges. To manage the systems security risk associated with these two locations, each office requires an exclusive Systems Security Plan that takes into account the offices’ unique situations. A Systems Security Plan provides field leadership with an overview of the security needs of the office with a focus on protecting company proprietary and client-confidential information (Swanson, Hash, & Bowen, 2006).
Analysis
Plans vary in complexity but usually contain sections which cover applications, systems, network, personnel, facility and incident response contingency planning (Federal Communications Commission, 2016). While throughout the RCR enterprise the applications, computer hardware and network connectivity are similar, each office has individual nuances which must be specifically addressed. For example, the Baltimore office occupies the middle floor of a three-story building. Since RCR rents its space, it has no control over the businesses that occupy the first and third floor. Consequently its wireless access point can easily be compromised from these other locations (Testout.com, 2016). Equally concerning is this access point is already behind the office’s firewall meaning it is inside the network. The Baltimore office needs to take extra precautions in this area.
From an environmental standpoint, the Philadelphia office is located near the Betsy Ross Bridge -- an area prone to frequent power outages and flooding. To make matters worse, the company occupies the first floor in this flood-prone area. Consequently, RCR-Philadelphia needs to incorporate into its System Security Plan provisions for alternate power sources and contingency operations in the event they need to relocate. These needs are, of course, different from the Baltimore office requirements.
Lastly, the Baltimore office is located in Cherry Hill, an area fraught with petty property crime. Their Systems Security Plan must incorporate additional physical security measures to help protect against break-in and theft. While both offices use Radio-Frequency IDentification (RFID) systems, the Philadelphia Office’s is under a different maintenance plan than the Baltimore Location.
Summary
Red Clay is a successful company and is geographically dispersed along a 100-plus mile corridor in the Eastern United States. Although the technology between these offices is similar, the unique environment each location finds itself in requires a customized Systems Security Plan. This plan needs to cover RCR applications, systems, network, personnel, facility and incident response requirements. The CISO stands ready to assist each individual office build their unique plan.
References:
Federal Communications Commission. (2016, 9 27). Cyber Security Planning Guide. Retrieved from Federal Communications Commission: https://transition.fcc.gov/cyber/cyberplanner.pdf
Swanson, M., Hash, J., & Bowen, P. (2006, 2 1). Guide for Developing Security Plans for Federal Information Systems. Retrieved from National Institute of Standards and Technology: U.S. Department of Commerce: http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf
Testout.com. (2016, 9 27). 6.14.8: Wireless Security Facts. Retrieved from Testout.com: http://cdn.testout.com/client-v5-1-10-373/startlabsim.html?culture=en-us
Follow-up replies needed 4
HI John,
your opening paragraph is good. I can tell that you are very knowledgeable about the case study. Your closing sentence in your opening paragraph informs the reader of what this briefing is about. Your answers as to why each field office needs its own SSP is well supported by your sources. The body of your briefing is a little confusing. I learned from Areeza that it helps for you to separate your discussion within sections to better organize what constitutes the introduction, body, and conclusion. You can also use a little more content to support your answers. Your conclusion wraps up your briefing very well but I think a summary of your answers would have made a better conclusion and would have also been more beneficial to the reader.
Follow-up replies needed 5
John,
Your post straight to the point and easy read. This statement, However, as had been noted in the analysis, the SSPs that have continually been put to use by the company are outdated.", was a very good point. It is difficult to have an effective system security plan if it is out of date considering technology changes constantly. I would like to point out another reason different system security plans are needed for each office is located in a different state and state internet laws vary. Therefore each system security plan has to be customized for the state in which they operate as well as for the type of clients and the type of provided services. Overall great post.
Follow-up replies needed 6
John,
Love how short and sweet and to the point. You seem very well informed around what an ssp is and everything and have more of an idea about SSP's and I do. But I did like how you pointed out that the separation also makes it easy to evaluate the realization objectives. Very good to know as well that separate SSP's makes it possible to easily optimize the networks in order to reflect the ecosystem.
Follow-up replies needed 7
Great job on your discussion, Oluwatobi! Your introduction really compelled me to read the rest of your discussion as it not only mentioned information about Red Clay Renovations’ IT infrastructure, but it also mentioned the fact that past system security plans are outdated which helped the audience to understand the importance of delegating a unique plan for each field office. Your answers regarding the requirement of a different system security plan per field office were very straightforward, which is an amazing quality of an efficient discussion. However, I do have some suggestions to strengthen your post. The only weakness present within your introduction was the fact that you did not explicitly state the purpose of your post, as required by the grading rubric. Such a statement is required so that the audience understands what the subsequent sections will enfold and it sets a scope for the discussion. Additionally, although the main question presented within the discussion instructions was regarding the significance of a separate system security plan (SSP) for each field office, the instructions also stated that the discussion should include information about the purpose of the SSP as the audience may not be familiar with the subject matter. For example, you could have stated that the purpose of this plan is to address the security necessities of the system and the controls to implement to secure those necessities (Swanson, Hash, & Bowen, 2006, p. vii). Lastly, an additional requirement of the discussion was to present the contents of a standard system security plan as all members of the corporate board may not be familiar with it. Examples of the information required for the plan include but are not limited to the assignment of security responsibility, system interconnections, and minimum security controls (Swanson, 2006). In conclusion, you did a great job in addressing the main question presented in the discussion to its entirety, but you should incorporate the previously mentioned aspects within your post to strengthen it.
References
Swanson, M., Hash, J., & Bowen, P. (2006, February). Guide for developing security plans for federal information systems. Retrieved from http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-18r1.pdf
Replies needed 6
The type of motherboard impacts almost everything within the computer, including the type of CPU and RAM that can be used. The type of which motherboard you are going with will affect what RAM and CPU you should choose, it should be the same manufacture and just as powerful. You should not mix different types of motherboard, CPU's, and RAMs.
Even with a great CPU and RAM but an old/weak motherboard the computer will not preform well because the motherboard is the powerhouse for the computer. You want a good balance between the three. Pairing a motherboard with a CPU that will be in sync with each other should be the first step and will be slighty more important than pairing the motherboard and CPU with a equal RAM. It is not mandatory to have the same manufacture but it is recommended, not all brands are compatible. For example, if you are looking at Intel vs AMD; CCM.net writes "If you opt for an Intel CPU, you will probably want a motherboard with an Intel or an nVidia chipset", "If you choose an AMD CPU, the chipset should be either AMD or nVidia". So it seems that AMD and Intel are not compatible with each other but both are compatible with nVidia.
Reference:
Choosing the right motherboard. (2016, September). Retrieved September 26, 2016, from http://ccm.net/faq/1876-choosing-the-right-motherboard
Reply needed 7
In today’s computer systems, does the type of motherboard impact the type of CPU and RAM that can be used? Why?
The motherboard does impact the type of CPU and RAM. The motherboard provides electrical connections that either support or interrupt the mission of the CPU and its’ buses whether internal or external networks. The power house of many abodes such as connectors, ports, slots input/output components, expansion, blue tooth, cards, graphics,etc reside. The motherboard serves as the main logic board for larger systems and, the circuit board is usually located internally of the micro computer. The motherboard main function is to store and allow communication between the CPU, Memory, peripherals and to house the different connectors for the software and hardware interactions. The motherboard is scalable depending upon the range of activities of systems integration, system implementation, processing speed, storage, power. The CPU has to components 1.) Data Path which is for housing instructions, data, codes, register to be executed upon commands and, 2.) Control Units that sequence the instructions to be executed to perform commands to the computer systems.
The RAM is impacted because of the amount of storage available to perform tasks, if there is not enough storage it could cause freezes, system outages, etc. RAM is scalable and, should be a fit for the type of hardware or software that will be connected or utilized.
The motherboard can be likened to building a house to host power. Efficient designing blueprints to furnishing the entire home with meaning decoration and power is mission critical. Depending upon the size of the home you would need to accommodate it very strategically. If you do not develop a successful blueprint or design to prevent the building or home from caving in then you will loose everything. If you do not include in the design or install electrical outlets correctly you may have regularly blackouts or other safety concerns. The electricity flowing you will have light. Therefore it is a matter of having day or night sustainment in your building or home. Everything is scalable depending upon the requirements to complete the final solution. Likewise with the the motherboard, CPU and Ram -- all must synchronize.
Is it possible for the motherboard, CPU and RAM out of balance? Why or why not?
According to the ACM Digital library, it states that “Effective power provisioning strategies are needed to determine how much computing equipment can be safely and efficiently hosted within a given power budget”.
Therefore if the power of components are not commensurate with requirements of internal and external components could cause problems. An example is the Samsung Note 7 had to be recalled because of exploding and overheating. Therefore, depending of upon the requirements the systems integration has to be tested and well designed to meet IEEE safety standards.
Overall impact is real when the systems components are not evenly yoked.
Reference
Retrieved on 09/26/2015, http://dl.acm.org/citation.cfm?id=1250665
Reply needed 8
In today’s computer systems, does the type of motherboard impact the type of CPU and RAM that can be used? Why or why not?
The motherboard is referred to as the heart of the computer. It is the main component in the computer, it holds the main electronic of the system to include the CPU and RAM. The motherboards chipset will determine what specific model processors can be used with the motherboard. Like with the processors, the type of motherboard can also impact the amount and format of RAM that can be used. Even today there are many things to consider when selecting a motherboard. Upgradability and proprietary are important and will hugely impact on your chose.
Is it possible for the motherboard, CPU and RAM out of balance? Why or why not?
It is possible for a motherboard, CPU’s and RAM to become out of balance because of heat, but there is help in Balanced Technology Extended and Advanced Technology Extended (ATX). ATX helps because it improved the support for I/O devices and processor technology, making it a lot easier to add or remove components. The air is blown directly on the processor and expansion cards to improve cooling and reduce noise. BTX is designed to decrease power needs and reduce heat.
Vikont (2016) OEMPCWORLD. Motherboard RAM guide. Retrieved from: https://www.oempcworld.com/support/Motherboard_RAM_Guide.html
Intel Corporation. Balanced Technology Extended (BTX) Interface Specification. Retrieved from: http://www.formfactors.org/developer/specs/BTX_Specification%20v1.0a.pdf
Reply needed 9
In today’s computer systems, does the type of motherboard impact the type of CPU and RAM that can be used? Why or why not? The motherboard is the main circuit board of a computer through which all internal and external functions are connected. Hence the name "Motherboard". In fact, two major components that allow the computer to function are housed on the motherboard, the Central Processing Unit (CPU) and memory. Things like profile, thermal design, and structural design can certainly affect the type of CPU and RAM that can be used with a given motherboard. Because there are different types of motherboards that accommodate different functions, the type of motherboard can affect the type of CPU and RAM due to size and design differences that may occur.
· Is it possible for the motherboard, CPU, and RAM out of balance? Why or why not? Yes, it is possible for the motherboard, CPU, and RAM to be out of balance. Speed is one factor that should be carefully considered. Because device speeds can vary vastly, balance is key to each device's stability. In these cases, multipliers and dividers are used to maintain balance. Other factors like temperature and power can contribute to a motherboard's balance. Installing too many peripherals or devices that consume too much power can overload a system and cause to be out of balance.
References:
Types of Motherboard: All That You Need to Know. (n.d.). Retrieved September 29, 2016, from https://blog.udemy.com/types-of-motherboard/
What Combination of Processor Speed Memory & Hard Drive Capacity Will Give the Best Performance? (n.d.). Retrieved September 29, 2016, from http://smallbusiness.chron.com/combination-processor-speed-memory-hard-drive-capacity-give-performance-70115.html
less