370 (1)

profileJohn_matt
replies_needed_1.docx

Please don’t give me a two to three sentence replies. It has to look burky. At least 7 to 8 sentences. Thank you

Reply needed 1

What is the most useful characteristics associated with computer networks?

The characteristics of most all computer networks include sharing resources, storing, creating and access files over one or more networks which could include LANs, WANS, etc. The networks connect printers, scanners, faxes, mobile phones, ipads, as well as cloud applications. The computer network allow individuals both personal and business the access to communicating input and output of raw or other data from the end user.

What is the most negative characteristics associated with computer networks?

There are information security risks, access risk and other vulnerabilities -- there is now absolute secured network because of human error, hackers or thieves of network intrusions, privacy issues. We would go on  about the most negative characteristics of a computer network but, overall risks of information security and, now cybersecurity has it vulnerabilities because on the global internet of millions or more networks that cross or are connected to one another. Then you have the networks whereby the cable could be accidently cut by constructions works. This subject is extremely broad. Although, protection of data and networks are ever evolving there is still a huge list of vulnerabilities.

What is the relationship between the Internet and a home network?

The internet is connected by millions of networks both local and global. The internet is connected to extremely complex networks that trained professionals govern, maintain, created the networks. The home network is less complicated and, may have access to the internet but, is usually partitioned network for the use of the private owner.  

Reply needed 2

•What is the most useful characteristic associated with computer networks? Explain your response.

Collaboration and knowledge sharing is a useful characteristic associated with computer networks. By collaborating all data on a single network creates a centralized place for users and administrators of the system to retrieve information.  Networks allow organizations to reduce expenses and improve efficiency by sharing data and common equipment like printers for example

•What is the most negative characteristic associated with computer networks? Explain your response.

Congestion is one of the most negative characteristics associated with computer networking. As more people access computers on a network, efficiency of the network will decrease. Traffic congestion that overloads the freeway and network congestion over limited bandwidth both display negative network externalities

 

•What is the relationship between the Internet and a home network?

A home network is an internal network at your house that connects devises within the house to each other. Home networks can be used to share files, printers, and a single connection to the Internet between sets of computers. The Internet is the vehicle that the home network using to communicate outside the home network via a router with either wired or wireless connection.

 Reference

Reference for Business. COMPUTER NETWORKS. Retrieved from: http://www.referenceforbusiness.com/encyclopedia/Clo-Con/Computer-Networks.html

Reply needed 3

· What is the most useful characteristic associated with computer networks? Explain your response.

The ability to connect with anyone and anything around the world must be one of the most useful characteristics associated with computer networks. Using computer networks you can connect to different devices such as printers, phones, entertainment systems just by connecting through WiFi. You can not only share and transfer data with devices but you can do the same with other computer network users and that is what makes computer networks so amazing.

· What is the most negative characteristic associated with computer networks? Explain your response.

The network being vulnerable to malware and viruses is the most negative characteristic with computer networks. While browsing the web and downloading different things computers suffer a risk of being hacked. Even with checking their email the user can accidentally download a Trojan virus thus allowing the hacker to access their personal information such as saved credit cards, passwords, and possibly even the user's social security and birthdate and such. 

· What is the relationship between the Internet and a home network?

Two different networks that work together. A home network is a more private network used by one user or a few users in a small radius as opposed to the internet where you can connect with different users and devices around the world. The home network may use internet but very limited within a short radius. Internet can be used to connect to others with internet and even home networks. 

From this Section is very Important

Responded to discussion topic with well supported and outside research or assigned readings as appropriate,  add value to the discussion, and demonstrate student’s understanding of concepts.

Reply needed 4

Telecommunications is important for all IS managers or any level of IT support personnel to understand. There are many standards in telecom that are used nationally and internationally for the purpose of intuitive design, backwards compatibility and not making things proprietary. Telecom is about distance communication and if a technician on the distant end doses something a different way, it won’t work. Understanding these standards and why they were introduced, helps a manager or engineer plan out infrastructure projects that utilize cabling or wireless backbones. You need to know how much connectivity you need as a base for any IT project and then double it.

http://ecmweb.com/basics/basics-structured-cabling

-Matt

Reply needed 5

An information systems manager is responsible for the computer systems within a company. The manager needs to have broad knowledge in technical support or operations of the company. There is no way an IT manager can be effective without the use of telecommunication for the business. He or she needs to understand the kind of information that can be shared via telecommunication. He should consider adequate security of the company’s communication lines. When it comes to disaster and adverse incidence in the company, how much telecommunication lines should the company have? This determination will be made by the manager. The kind of voice-over line used and the effectiveness of the telecom line will enhance the overall business goal, however, the manager should be well knowledgeable.

http://www.newenglandcollegeonline.com/resources/computer-science/computer-and-information-systems-manager-job-description-and-salary/#.WAbUmFQrLcs

Reply needed 6

"Telecommunications, also known as telecom, is the exchange of information over significant distances by electronic means and refers to all types of voice, data and video transmission. This is a broad term that includes a wide range of information transmitting technologies such as telephones (wired and wireless), microwave communications, fiber optics, satellites, radio and television broadcasting, the internet and telegraphs."

Based on the above information an Information Systems Manager needs to be aware of the different types of telecommunications that are available to the business. Utilizing these different types of communications services are vital to business and the strategies that they hold. A manager that is well versed in several forms of communication can effectively utilize this knowledge to run the business efficiently. 

Refences:

http://searchtelecom.techtarget.com/definition/telecommunications

Reply needed 7.

The top four IT security controls, as explained by Valladares (2014), are:

- Inventory of authorized and unauthorized devices

                “Actively manage (inventory, track, and correct) all hardware devices on the network so that only authorized devices are given access, and unauthorized and unmanaged devices are identified and prevented from gaining access” (SANS, 2016).

- Inventory of authorized and unauthorized software

                As expressed by Center for Internet Security (2016), ‘devise a list of authorized software and version that is required in the enterprise for each type of system, including servers, workstations, and laptops of various kinds and uses. This list should be monitored by file integrity checking tools to validate that the authorized software has not been modified.

- Secure configurations for hardware and software on mobile devices, laptops, workstations, and servers

                As stated by SANS (2016), “establish, implement, and actively manage (track, report on, and correct) the security configuration of laptops, servers, and workstations using a rigorous configuration management and change control process in order to prevent attackers from exploiting vulnerable services and settings”. 

- Continuous vulnerability assessment and remediation

                “Run automated vulnerability scanning tools against all systems on the network on a weekly or more frequent basis and deliver prioritized lists of the most critical vulnerabilities to each responsible system administrator along with risk scores that compare the effectiveness of system administrators and departments in reducing risk” (Center for Internet Security, 2016).

I believe policies that are enforced are a “true” safeguard to your company because it will basically cover the dos and don’t of your company by explaining the rules, why they have been set in place, the consequences if not followed, when these rules apply, etc…  Some benefits of policies and procedures, as expressed by Pacific Crest Group (n.d), are as follows:

- Employees understand the constraints of their job without using a ‘trial and error’ approach, as key points are visible in well-written policies and procedures.

- Policies and procedures enable the workforce to clearly understand individual and team responsibilities, thus saving time and resources. Everyone is working off the same page; employees can get the “official” word on how they should go about their tasks quickly and easily.

- Clearly written policies and procedures allow managers to exercise control by exception rather than ‘micro-manage’ their staff.

- They send a “We Care!” message. ‘The company wants us to be successful at our jobs.’

- Clearly written policies and procedures provide legal protection. Juries apply the ‘common person’ standard. If written clearly so that outsiders understand, the company has better legal footing if challenged in court.

References:

Center for Internet Security. (2016). Center for Internet Security. Retrieved October 19, 2016, from https://www.cisecurity.org/critical-controls.cfm

Pacific Crest Group. (n.d.). Are Your Policies and Procedures a Barrier To Growing Your Company? Retrieved October 19, 2016, from www.pcg-services.com/are-your-policies-and-procedures-a-barrier-to-growing-your-company/

SANS. (2016). Critical Security Controls V6.0. Retrieved October 19, 2016, from https://www.sans.org/media/critical-security-controls/critical-controls-poster-2016.pdf

Valladares, C. (2014, February 19). The Top 4 Controls. Retrieved October 19, 2016, from http://www.tripwire.com/state-of-security/wp-content/uploads/2014/02/Top4SecurityControls_Tripwire.pdf

Reply needed 8.

One of the most important security controls is the configuration and hardening of computer systems. This is important because if the system is misconfigured then it leaves basic vulnerabilities open. This would make it relatively simple for a hacker to get into the network. The second important control is the centralized collection and management of security events. A centralized logging system is the only way to ensure that no important events within the security framework are not missed. This also allows for a more concentrated focus on security logs, by delegating the controls to a centralized section exclusively focused on the logs. The third control is to establish a vulnerability management program. The sooner you detect a vulnerability, the sooner you can work to close that vulnerability and protect your network. Finally the last important control is the restriction of the access and distribution of sensitive data. Controlling this access is the best way to secure that data is to ensure that it is limited to only the required people. 

References

Zaltser, L. (n.d.). Which Information Security Controls Are Most Important? Retrieved October 21, 2016, from https://zeltser.com/important-information-security-controls/  

Reply needed 9

Cisco’s StealthWatch Security Solution

       Thursday, October 20th, I worked at the 2016 Cyber Maryland Event where many vendors were sharing information about their company and new technologies had to offer. The one vendor, to no surprise, sparked my interest is Cisco. Maybe with having a Cisco Certified Network Associate (CCNA) certification creates some bias, but I honestly believe Cisco has a lot to offer when it comes to security solutions.  Their Stealth Watch System is the latest of what Cisco has to offer, it improves threat defenses by providing a comprehensive network visibility across internal and distributed networks.

       StealthWatch’s main core component is the FlowCollector, which draws on telemetry data such as (NetFlow, IPFX, sFlow, JFlow, etc.) from your existing infrastructure (Cisco, 2016). StealWatch’s network telemetry collects and analyzes this data from the router, switches, and firewalls monitoring network and user behavior.  One capability it has is with its context-aware security analysis, this is used to detect attacks such as insider threats, which by the way, to me as being the most concerned threat for today’s companies and organizations.  As with most monitoring solutions, it monitors traffic going in and out the network, but also includes lateral (east-west) traffic inside the network used to identify these insider threats (Cisco, 2016).

       As many know working in the cyber community, social engineering trends have shown, employees are increasingly becoming insider threats to today’s company networks.  Cisco’s StealthWatch is compared to other monitoring solutions that use full packet capture, although due to its extremely high cost and complexity can only be deployed in limited areas of the network.  This presents dangerous security gaps that StealthWatch can fill (Cisco, 2016).  Last, but not least, this technology can be used as either a physical or virtual appliances.

References

Cisco (2016). StealthWatch Improves Threat Defenses with Pervasive Network Visibility and Security Solution Overview. Retrieved from   http://www.cisco.com/c/en/us/products/collateral/security/stealthwatch/solution-overview-c22-736505.html

--Ronald

Reply needed 10

Insider threat involves an individual with legitimate access to company information systems intentionally or accidentally using their power to cause damage to company confidentiality, integrity, or availability. It is important to remember that insider threat is not purely a technological issue. Steps can and should be taken to mitigate the "people-centric problem." (Gelles & Mitchell, 2015) Such steps include separation of duties, policies, and training, especially awareness training. (Gelles & Mitchell, 2015) As for the technological solution, mitigating insider threat attacks involve monitoring user activity, creating behavioral norms, and detecting anomalies. "The Securonix Platform is a purpose-built advanced security analytics technology that mines, enriches, analyzes, scores and visualizes customer data into actionable intelligence on the highest risk threats from within and outside their environment." (Securonix, 2016) This security technology enables real-time data mining, automated correlation, detection, and mitigation based on analysis of user behavior and against peers. (Securonix, 2016) Data from all is formatted and visualized in efficient continuous reports. (Securonix, 2016) In addition to Securonix's security features, it also provides scalability as well as integration with previously deployed technologies. I believe that by implementing these two solutions that insider threat can be successfully managed. Gelles, M. G., & Mitchell, K. (2015). Top 10 considerations for building an insider threat mitigation program. Journal Of Threat Assessment And Management, 2(3-4), 255-257. doi:10.1037/tam0000059 Securonix. (2016, April 17). Securonix Security Analytics Platform. Retrieved October 24, 2016, from http://www.securonix.com/security-intelligence/