Policy 7
Please don’t give me a two to three sentence replies. It has to look bulky. At least 8 to 10 sentences. Thank you
Reply needed 1
Introduction
Finical investment
An ordinary lock is not enough security to protect Red Clay Renovations networking devices and RFID system. Anyone with the intent of bringing down Red Clay Renovation network can simply break the lock and upload malware onto the network or destroy the network devices which would temporarily shut down the network. To prevent that from happening I suggest we upgrade that lock to an x09 lock. The X-09 lock provides all the benefits of high-security electronic locking while maintaining the reliability of a mechanical lock, independent of batteries or outside power sources (Kaba, 2016). With an X-09 lock in place only authorized personnel will gain access to the closet because the X-09 is impervious to external attack (Kaba, 2016). The next thing Red Clay Renovations will need to invest in is the reboot of the training and awareness program that was given to employees annually.
An un-trained employee is a vulnerability to Red Clay Renovations network. Hackers are constantly coming up with new phishing scams and other malware that can negatively affect the network. Phishing is a form of fraud in which the attacker tries to learn information such as login credentials or account information by masquerading as a reputable entity or person in email, IM or other communication channels (Target, 2015). If malware enters the network then it may steal information that will damage Red Clay renovations reputation. To prevent that from happening it would be best to educate employees on the newest scams and forms of malware. The other risk that require a finical investment can be addressed at a later time.
Reducing the Cost of Cyber-Attacks
To reduce the cost of cyber-attacks a strategy from “A Framework for Programming and Budgeting for Cyber-security” recommends that organizations minimize exposure. To minimize exposure the study recommends that organizations reduce the number of networked machines, reduce the number of network access points on networked machines, reduce the amount of computational resources on networked machines and minimize the amount of sensitive data on networked machines. Red Clay Renovations currently already employs some of the minimize exposure strategies but could benefit from using the others. In order to fully implement the strategy Red Clay Renovation will need to reduce the number of networked machines and reduce the number of network access points on networked machines.
Red Clay Renovations operation center currently has a number of networked machines on their network. This is because the operations center is responsible for accounting and finance, customer relations, human resources, information technology services, marketing and corporate management (King, 2016).“The fewer the devices that can be addressed via the Internet, the smaller the attack surface of an organization” (Davis II, et al., 2016). To reduce the attack surface of the operation center some of services the operation services provides should be spread out among the field offices. The next step that needs to be accomplished is reducing the number of access points on networked machines.
Red Clay Renovations uses Dell computers for laptops, desktop computers, and servers running Windows 10 Enterprise for their operating systems (King, 2016). Each computer contains resources, ports, applications and services, that can provide access (Davis II, et al., 2016). For example, port number 80 uses the Hypertext Transfer Protocol (HTTP) protocol to connect to the World Wide Web and defines how messages are formatted and transmitted, and what actions Web servers and browsers should take in response to various commands (Beal, 2016). To reduce the number of network access points on networked machines, unsecured ports should be closed, unused or vulnerable applications should be uninstalled, and only authorized services should be used on machines.
Conclusion
In conclusion Red Clay Renovations needs to invest in some upgraded security. With a new lock on the closet door the network devices will be protected. Bringing back the training and awareness program will ensure educated employees don’t get scammed and contract malware in the process. The new strategy to minimize exposure will reduce the chances of Red Clay Renovations getting hit with a cyber-attack. With a finical investment these upgrades and implementation of the new strategy will be implemented making Red Clay Renovations network more resilient against cyber-attacks.
References
Beal, V. (2016). HTTP - HyperText Transfer Protocol. Retrieved from Webopedia: http://www.webopedia.com/TERM/H/HTTP.html
Davis II, J., Libicki, M., Johnson, S., Kumar, J., Watson, M., & Karode, A. (2016). A Framework for Programming and Budgeting for Cybersecurity. Retrieved from Rand: http://www.rand.org/content/dam/rand/pubs/tools/TL100/TL186/RAND_TL186.pdf
Kaba. (2016). X-09™ High Security Locks. Retrieved from Kaba: http://www.kaba-mas.com/kaba-brand/products/product-archive/366458/x-09.html
Target, T. (2015, October). Phishing. Retrieved from TechTarget: http://searchsecurity.techtarget.com/definition/phishing
King, V. J. (2016, March 30). Red Clay Renovations. A Case Study for CSIA 413
Reply needed 2
Introduction:
Much like any other organization, Red Clay Renovations must also understand their financial investment needs and how they relate to cyber-attack response. The growing cyber-attacks of today can originate from various sources and cyber-terrorists can utilize distinct procedures to launch the attacks; hence, it becomes necessary for organizations to prepare defense mechanisms for all possible attacks (Davis et al., 2016, p. ix). In doing so, the costs associated with cyber-defense strategies must be taken into consideration (Davis et al., 2016, p. ix). The topic of this briefing paper is to provide Red Clay’s senior leadership and corporate board information about risks which warrant a financial investment, a strategy to reduce costs for responding to cyber-attacks, and how this strategy can be used to plan, program, and budget solutions to address technical, operational, and management security controls.
Analysis:
There are multiple categories of financial investments, which include people, process, and technology investments. Red Clay Renovations has several risks associated with its operations that necessitates financial investment. One of these risks can be the installation of smart home and Internet of Things (IoT) technologies by Red Clay Renovations (King, 2016, p. 7). For example, the company could be liable if the aforementioned technologies are unable to provide sufficient security for customers (King, 2016, p. 7). Hence, the company must purchase cyber liability insurance, which is an example of a risk treatment that would require financial investment (King, 2016, p. 7). Another example of a risk treatment requiring financial investment is the implementation of an asset management and protection program (King, 2016, p. 7). A process that requires financial investment is the need for a security education, training, and awareness (SETA) program to mitigate the risks associated with a lack of employee knowledge (King, 2016, p. 8). Furthermore, guidance provided by the National Institute of Standards and Technology (NIST) is another process that needs financial investment to act as a standard for managing IT systems and services (King, 2016, p. 8).
The purpose of cybersecurity is presumed to be a reduction in the financial investments required for cyber-attacks (Davis et al., 2016, p. 7). The actions we must take to respond to cyber-attacks are categorized in four main strategies: minimize exposure, neutralize attacks, increase resilience, and accelerate recovery (Davis et al., 2016, p. 9). This discussion will address the minimum exposure strategy and how it can be used in the planning and programming phases of budgeting preparation to discover inexpensive solutions for implementing technical, operational, and management controls. The planning process typically deals with what is required to be performed by the organization. The answer to this question is, senior executives and the corporate board must devise ways to “reduce the number of networked machines, reduce the number of network access points on networked machines, reduce the amount of computational resources on networked machines, and minimize the amount of sensitive data on networked machines” (Davis et al., 2016, p. 13).
Now that we have decided what it is we need to do, we must address the programming phase by detailing the way in which these actions should be performed. In order to reduce the number of networked machines of an organization, Red Clay personnel can perform a variety of actions. For example, devices should be locally accessible, rather than globally accessible so that access is limited, which also reduces the attack surface of an organization (Davis et al., 2016, p. 14). Additionally, the devices which have sensitive information stored within them should be air-gapped (Davis et al., 2016, p. 14). An air-gapped system is defined as a system that is not connected to the Internet in real-time (Davis et al., 2016, p. 14). Virtual air-gapping is also a possibility that Chief Information Security Officers (CISOs) consider as the two systems would be able to communicate encrypted traffic via the Internet (Davis et al., 2016, p. 14). Access points on computers include ports, applications, and services which can be utilized by outsiders to gain external access (Davis et al., 2016, p. 14). Hence, it becomes necessary to reduce the amount of access points on networked machines by limiting them (Davis et al., 2016, p. 14). “A variation on this activity involves using nonstandard ports for important network applications (configuring SSH [Secure Shell] with a TCP [Transmission Control Protocol] port other than 22, for instance)” (Davis et al., 2016, p. 14). The fewer the amount of computational resources on networked machines, the less chances of an executed attack on the machine (Davis et al., 2016, p. 14). To perform this, organizations can substitute desktop computers for tablets so that additional resources and costs are reduced which would also lessen the associated cybersecurity risks (Davis et al., 2016, p. 14). Lastly, reducing the amount of data stored on networked machines is helpful in responding to cyber-attacks if this data is placed on machines that are secluded from the Internet or by not digitizing the data in the first place (Davis et al., 2016, p. 14).
Summary:
The amount to budget for cybersecurity initiatives depends upon the potential for risk; increased risk should result in an increased budget for cybersecurity response (Schrader, 2014, para. 5). To minimize exposure, the connections between a system and the rest of the world must be reduced, and the information accessible from the system should be limited (Davis et al., 2016, p. 9). This can be performed by “reducing the number of networked machines, reducing the number of network access points on networked machines, reducing the amount of computational resources on networked machines, and minimizing the amount of sensitive data on networked machines” (Davis et al., 2016, p. 13). In conclusion, it is necessary for senior leadership and the corporate board to understand what actions are required to decrease costs associated with responding to cyberattacks and the way in which these actions are to be performed.
References
Davis, J. S., Libicki, M. C., Johnson, S. E., Kumar, J., Watson, M., & Karode, A. (2016). A framework for programming and budgeting for cybersecurity. Retrieved from http://www.rand.org/content/dam/rand/pubs/tools/TL100/TL186/RAND_TL186.pdf
King, V. J. (2016, March 30). Red Clay Renovations: A case study for CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu
Schrader, C. (2014, December 8). Cyber security budget planning for small businesses. Retrieved from http://www.nationalcybersecurityinstitute.org/general-public-interests/cyber-security-budget-planning-for-small-businesses/
REPLY 3 Needed
The purpose of this briefing paper is to address the budgeting for Red Clay Renovations’ IT security program management. This information is intended for the company’s senior leadership and corporate board to gain an important understanding of this topic. According to a recent Global Information Security Survey conducted by PricewaterhouseCoopers, businesses spend an average amount of $4.3 million a year on cyber security budgets (Hulme, 2014). This amount is nearly doubled what was spent in 2010. Jay Leek, CIO at The Blackstone Group, says, “Many organizations are infatuated with buying the latest trendy thing, whether or not it makes the most sense for their specific security poster” (Yasin, 2016). It is essential for organizations to access their IT architecture and implement the proper cyber security resources that apply to their specific needs.
Red Clay faces various risks regarding its IT architecture and this requires financial investment. One of the most obvious risks the company’s faces is the unauthorized disclosure and/or access to the sensitive information that the computer systems store and process. These systems contain data that is crucial to the protection of the company and its clients. This risk involves the financial investments of people, processes, and technology. Another risk that Red Clay faces is the use of “smart home” and “Internet of Things” technology. These devices have a controller that allows user to access a Web-based interface that runs on each field office’s application server. Username and password credentials is all that is required to access these controllers and this creates a risk of unauthorized access. This risk requires the financial investment of technology. All of the network interconnections that Red Clay uses, such as the LAN, WAN, and VPN, is a risk if they are not properly protected. This risk requires the investment in the technology and software that will defend the unauthorized access of hackers. Red Clay also faces the security threat of having employees that are not given proper training and awareness of the company’s cyber security. This risk requires the investment in the people and processes needed for training and awareness to be sufficient. All of Red Clay’s IT architecture needs to be properly managed. Without proper management, this becomes a threat to the company. Red Clay must invest the appropriate personnel that will manage the company’s IT architecture and the processes that need to be conducted regularly to improve its security.
There are various strategies that will reduce Red Clay’s costs involved with cyberattack responses. One of these strategies is accelerate the recovery. This is associated with the repair and replacement that should occur after the event of a cyberattack (Davis II et al., 2016). The main aspect of this strategy is to implement many actions prior to a cyberattack in order to speed up and lower the recovery costs (Davis II et al., 2016). Red Clay needs to create a rapid response plan so that actions can occur immediately after a cyberattack arises. It is important to increase response competence which requires competent personnel that have decision authority and proper training and knowledge (Davis II et al., 2016). Red Clay must also ensure that systems are able to be restored to its previous configuration if a cyberattack occurs. Systems should be built for a quicker, rather than slow, restoration (Davis II et al., 2016). The company should also install systems that are able to detect attacks rapidly. The sooner a cyberattack is detected, the quicker it can be stopped and the less damage to the availability of a system and the system itself (Davis II et al., 2016). This strategy stresses the importance of cleaning of malware from the affected system. This guarantees that the reason for the shut down or access to a system is no longer present and cannot occur again (Davis II et al., 2016).
It is crucial that Red Clay does not assume that no budget is necessary for its IT security program management. The proper way to create a budget is to evaluate the company’s IT architecture and determine the risks involved. Every organization is different, depending on their size and function. This means that organizations must develop a unique budget plan that adheres to their needs. By doing this, Red Clay will be able to apply IT security program management that is both successful against cyber risks and cost-effective.
References
Davis II, J.S., Libicki, M.C., Johnson, S.E., Kumar, J., Watson, M., & Karode, A. (2016). A framework for programming and budgeting for cybersecurity. Retrieved from http://www.rand.org/content/dam/rand/pubs/tools/TL100/TL186/RAND_TL186.pdf
Hulme, G. (2014). How to optimize your security budget. Retrieved from http://www.csoonline.com/article/2153713/security-leadership/how-to-optimize-your-security-budget.html
Yasin, R. (2016). 4 tips for planning an effective security budget. Retrieved from http://www.darkreading.com/careers-and-people/4-tips-for-planning-an-effective-security-budget/d/d-id/1325290
Reply 4 Needed
Red Clay Renovations (RCR) faces important budget decisions just like every business operating currently. The decisions on budgeting must be identified from current gaps in the company or by future desires moving forward. Looking at RCR’s current operations reveals several areas that require financial investment to improve security. Additionally, implementing and using a standardized method for responding to cyberattacks would provide the business with cost savings for future budgets. RCR needs to make budgeting for cybersecurity a priority now so there is no financial loss in the future.
RCR’s current environment has multiple areas that require financial investment. The first and one of the most important is a people investment at the role of the Chief Information Security Officer (CISO). The CISO is currently a dual-hatted role with responsibilities shared in Director of Information Technology Services (King, 2016). The CISO role should be an independent and single responsibility because of the depth area the positon covers (Florentine, 2016). Coupled with the fact that the current Director of ITS/CISO is also trying to catch up for the time the company did not have Director, due to a gap after the previous one retired, is leaving the company with a weakened security posture (King, 2016). How can the CISO be expected to operate at full capacity while managing two positions, one of which is involving a lot of catching up currently?
Another people investment the company should look into is similar to the CISO role issue with regards to the role of ISSO at field offices. The ISSO’s are currently dual-hatted as office managers as well. The ISSO should be an independent duty so the employee can devote their attention to information security needs full time. If an incident or event occurs at their field office, they need to be prepared to divert all attention and resources to mitigating the issue. As an office manager, they could be tied up taking care of more administrative duties when needed most. Furthermore, a technical investment the company should look into is the network topology of the field offices. While having the same network set-up is convenient for installation purposes, having identical networks at all offices is a security concern. If a malicious actor were to get into one network, they would now know how to get into any other as well.
An additional area requiring financial investment is a process investment and involves becoming fully compliant with ISO 27001/27002 standards. While the company has become compliant with parts of the standard, working towards full compliance would set RCR at a higher level of excellence in the information technology business environment. Another process investment the company needs to budget for is the start of the vulnerability management program which has already been brought up previously (King, 2016). The vulnerability management program should include some type of scanning and patching procedures for the company’s network which will require funds.
Moving forward, RCR should look into establishing a standard for cyberattack response to help lower future company costs. The best method for RCR would be to minimize exposure. By reducing networked machines, and minimizing the amount of sensitive data stored on machines, RCR can avoid future consequences for cybercrimes (Davis, Libicki, Johnson, Kumar, Watson, & Karode, 2016). With RCR, limiting the amount of systems containing HIPAA sensitive information would be a first step in this process. By limiting the storage of HIPAA sensitive information to only the operations center, house plans and blueprints could still be stored at the field offices. This way an exposure of data at a field office, while still costly to the business, would have less consequence than a breach of federally protected data.
As cybercrimes were estimated to be responsible for over $1 trillion in losses in 2010 (Pasquali, 2013), budgeting for cybersecurity now is a great way to save money. Unfortunately, many businesses don’t realize the need for cybersecurity budgeting until it is too late. By focusing on RCR’s current operations and planning for the future as well, the company can move forward with better protection against potential threats. The result of better protection will ultimately be money saved from data loss which could include legal litigation and federal fines in the case of HIPAA information (AMA, n.d.). The time to invest financially in cybersecurity for Red Clay Renovations is now.
References:
AMA. (n.d.). HIPAA Violations and Enforcement. Retrieved from http://www.ama-assn.org/ama/pub/physician-resources/solutions-managing-your-practice/coding-billing-insurance/hipaahealth-insurance-portability-accountability-act/hipaa-violations-enforcement.page?
Davis II, J. S., Libicki, M. C., Johnson, S. E., Kumar, J., Watson, M., & Karode, A. (2016). A framework for programming and budgeting for cybersecurity. Retrieved from http://www.rand.org/content/dam/rand/pubs/tools/TL100/TL186/RAND_TL186.pdf
Florentine, S. (2016, March 24). Why you need a CSO/CISO. Retrieved from http://www.cio.com/article/3048074/careers-staffing/why-you-need-a-cso-ciso.html
King, V. J. (2016, March 30). Red Clay Renovations. Retrieved from https://learn.umuc.edu/d2l/le/content/170374/viewContent/7213685/View
Pasquali, V. (2013, May 2). Cover: The untold cost of cybersecurity. Retrieved from https://www.gfmag.com/magazine/may-2013/cover-growing-threat-the-untold-costs-of-cybersecurity-
Follow-up replies needed 4
HI John,
Good opening paragraph with some solid information about the case study company. To complete your opening paragraph you could have informed the reader of what this briefing was about. Your second paragraph does inform me that this briefing is about vulnerabilities within the case study company. You do an excellent job of identifying the vulnerabilities and provide recommendations on how to fix them. Great introduction of the strategy you would use to reduce the costs associated with responding to cyber-attacks. To improve your briefing I would recommend that you use a section format and add a summery as a conclusion. A precise summery will help to remind the reader exactly what the briefing was about.
Follow-up replies needed 5
John,
Good job on your discussion, I think you did a great job in addressing how the minimize exposure strategy could be used in the planning and programming phases of budget preparation. You were very detailed in your analysis and you utilized appropriate resources to cite your work. However, I do have a couple suggestions that I think will improve the other sections of your discussion such as your introduction, information about the audience, and your summary. In your introduction, although you stated the fact that Red Clay Renovations stores sensitive information about its projects and clients, you didn’t really mention the financial aspect of cyber-defense strategies that would be necessary to implement to protect the personal data from being exposed. This information could serve to be the purpose of your post, which would help improve the structure and content of your introduction section. Additionally, the instructions stated that our discussion is targeted at the company’s senior leadership and corporate board. As such, it can be helpful to include how the stated facts would impact these executives so that they understand their role in maintaining the company’s secure operations. For example, you could have stated that the planning process is typically the responsibility of senior leadership and the corporate board which is why this discussion pertains to them. In other words, they must understand the significance of devising a strategy which would help reduce the costs associated with responding to cyber-attacks as they are the designated officials to do so. Lastly, I thought your summary could have been extended; this extension is necessary as the rubric requires us to mention at least three key points within our conclusion. I liked that you mentioned the fact that a way Red Clay Renovations minimizes exposure is by preventing contract employees from bringing in their personal devices to work as this reduces the number of networked machines (King, 2016, p. 12). However, to add on to the summary, you could have also mentioned the way in which Red Clay Renovations could reduce the number of access points on networked machines or how it could minimize the amount of sensitive data stored on networked machines (Davis et al., 2013, p. 13).
Follow-up replies needed 6
John,
A legal review may benefit the company to identify the cost association with the sensitive information storage. Legal teams cost money and it would be a big investment, but may steer the security offensive for RCR. This discussion was three parts, but I felt everyone focused on identifying the vulnerabilities. What do you think? Hardly anyone selected a strategy for reducing the costs associated with responding to cyberattacks from the Rand report. People referenced the report, but did not select a strategy,a and then they did not discuss how the strategy could be used in planning. I recommend the "neutralizing attacks" strategy and empathizing auditing through NIST 800-55 to measure the effectiveness of the framework in conjunction with cyber defense investments according to the budget.
Respectfully,
Replies needed 6
I often explain technology in terms of a library. If you look at a single bookshelf, you can think of that as your hard disk drive, while a book that you pull down from the shelf would be your monitor, what is on the screen, or RAM. How quickly your eyes can scroll across the page and read the material is your processing speed. If you can read 2 books at the same time, your are multi-tasking. Some material, such as mathematical formulas or detailed drawings, take more time to digest that a novel or the newspaper. The same is true for a computer.
So if the number of books you can open at once, or read simultaneously, is determined by your RAM, then being able to ready more should simply be a matter of adding more RAM, right? Well, a sophomoric answer might be “Yes”, but a more professional answer might be “maybe”.
For example, would you have trouble reading a book if its print was smudged? What is the text was haphazard, or jumbled. What is another book’s material was inserted intermittently into its pages -- could you follow it then? And what if your reading glasses were dirty?
Before you go spend hard-earned dollars on more RAM, first take a look at other options that can increase processing speed or a computer, often at a no cost at all:
1 Viruses. Verify that you have the latest set of anti-virus components for your virus checker and make sure your system is clean.
2 Malware. If you have a malware-checker, run it. Same rules about latest version as with a virus-checker.
3 Operating system. Make sure that your operating system is running the latest version. Many security upgrades come in each upgrade, include security attacks that slow down your PC. Run any updates you have missed.
4 Browser history. Make sure you only keep what you need. Many browsers keep everywhere you have ever visited, by default. This is a huge drag on browser resources. Delete all of it. What is really needed will be rebuilt.
5 Disable browser add-ons. While you are in your browser, disable add-ons. Only keep the one you really need.
6 Hard drive space. Make sure you have emptied trash and have sufficient room on you hard drive as a temporary memory space. You can run Disk Cleanup Tool to clear Internet cache space, empty the Recycling Bin.
7 Delete unused applications. Many of us have lots of applications or utilities that we never or rarely use. Delete them. Your system can use the extra space to speed things up.
8 Buy more RAM. Finally, if you have done all the above and are still happy with your computer’s performance, consider more RAM. But before you spend your money, consider carefully if your PC is slow in general, or mostly with graphics or streaming of video or games. If it is slow in graphics, look at the RAM attached to your graphics card itself, and consider a graphics
9 Go big. When you do purchase more RAM, make it worthwhile. I was running 2 GB of RAM and upgraded to 16GB, and never looked back.
Tim
References:
Boutin, P. (2011). 5 Ways to Fix a Slow PC. Gadgetwise. Retrieved from http://gadgetwise.blogs.nytimes.com/2011/10/21/5-ways-to-fix-a-slow-pc/
Keene (2014). Fix a Sluggish, Slow PC. CmdrKeene’s Blog. Retrieved from http://cmdrkeene.com/fix-sluggish-slow-pc
Mohanty, P. (2013). My windows 8 suddenly is running very slow, long time to load program. Microsoft Community. Retrieved from http://answers.microsoft.com/en-us/windows/forum/windows_8-performance/my-windows-8-suddenly-is-running-very-slow-long/3485cf0e-d6f8-479b-9bc9-f9b7c2d24fb0?auth=1
Norem, J. (n.d.). Speed up a slow PC without buying new hardware. Answer Line. Retrieved from http://www.pcworld.com/article/2058086/speed-up-a-slow-pc-without-buying-new-hardware.html
Reply needed 7
The family desktop PC is running slowly. Specifically, it is taking a long time to bring up and switch between applications. Your neighbor tells you all you need to do is buy more memory (RAM).
10 What should you do and why?
11 What other components should you consider upgrading? Why?
12 Is it possible to have more memory than the PC can handle? Why or why not?
The first thing you should do is check the usage rate of your available RAM. If the computer is being used for what your family would consider “normal” and the usage rate is high, your neighbor may have a good point. However, if the usage rate is low then more RAM isn’t going to solve the issue of the computer running slowly.
RAM horror story: My 2012 Macbook pro that was purchased with 4 GB of RAM started running significantly slower almost overnight about 6 months ago. I upgraded to more RAM (16 GB) and the issue still wasn’t fixed. I checked my RAM usage rate before the upgrade and it was around 3.5 GB of the total 4 Gigs. What fixed my issue after much searching around was a bad HDD cable, my computer was having an issue loading programs into the RAM and that’s why it became slower, the issue had nothing to do with the available RAM. Based on the information usage rate I should have known more RAM would not solve the issue.
If your computer is running slowly you can check the state of your hard drive, your computer may have trouble saving files from RAM or loading programs from the hard drive to RAM. This would cause the specific problem mentioned in the question above. An upgrade to a solid state device might solve your problem if you are currently using a traditional hard drive.
Upgrading your CPU can give you more computational power which in turn would be able to process information faster and show a decrease in wait times while using the computer.
In my opinion it is impossible for a computer to have too much memory when it comes to Hard drives, I say this because as long as there is a physical address for the computer to write too, it will. RAM however is governed by the capacity of the motherboard so there is such a thing as too much memory for the PC to handle (Ung, 2015).
Reply needed 8
When the family desktop PC is running slowly. and is specifically taking a long time to bring up and switch between applications, I would take the recommendation from my neighbor.
Since the use of multiple applications and programs slows processes down, increasing RAM would help speed up the computer instead of the system reverting to the hard drive and slowing things down. Therefore, I would recommend adding more memory. By upgrading since accessing the internet requires us of browsers, adding more RAM or upgrading the system will allow the system to handle the capacity and usage of the system. PCs can only handle a certain amount of memory. When too many programs and applications are in use as I recently experienced with my system, the system not only slows down, freezes or continues to heat up. Once applications and programs are closed, the systems runs faster and it cools off. Continued use of the system with too little memory may put the system in a continual cycle of fluctuating temperature and slow or locked up which will definitely affect the speed and life of the system. Checking the memory and applications in use will help to make a decision to determine if it's time to purchase and add RAM.
Monckton, P. (n.d.). Should I boost my PC's memory? Retrieved October 07, 2016, from http://www.pcadvisor.co.uk/how-to/pc-upgrades/should-i-boost-my-pcs-memory-3464779/
H. (2013). How Does RAM Works (Computer Memory). Retrieved October 07, 2016, from https://www.youtube.com/watch?v=TMV_Dwsd8dI
less
Reply needed 9
If the desktop PC is running slowly, the first thing I will do is to check why it's running slow. This could be from programs that start up automatically when the PC comes on. If there are programs that we know we don't need to have start up automatically, remove them. Also, checking how much free space is left on the hard drive can help as well. If the drive has less space that you wanted it to have, perform a disk clean-up to make up more space by deleting the temporary files and so forth. If there is a program that is not needed anymore after you finish, close it. Having multiple programs up at one time can immediate slow time for a PC. Lastly, check to see if your PC have the right specifications for certain applications to perform well on. For example, and application on Windows 8 will not as well on Windows XP because of the recommended specifications that software needs to run properly.
Other componets that would be upgrades is the CPU or buy another motherboard to handle they heavy usuage for the PC. I wouldn't say this its possible to have more memory than a PC can handle but I can say its for some PCs because of the motherboard cause motherboard can only hold so much ram before its at its limit.