370 (4)

profileJohn_matt
replies_needed.docx

Please don’t give me a two to three sentence replies. It has to look burky. At least 7 to 8 sentences. Thank you

From this Section is very Important

Responded to discussion topic with well supported and outside research or assigned readings as appropriate, add value to the discussion, and demonstrate student’s understanding of concepts.

Reply needed 1

VoIP (Voice over Internet Protocol) is growing in demand for many commercial and government organizations. There are many advantages to using VoIP systems. Cost is a major factor for any organization to make the switch to VoIP phones. When new construction begins on a building, cabling the offices for personnel is a factor. Many VoIP phones use Ethernet from category cabling to connect back to a Call Manager on the same network that provides a user their connectivity for internet access. These systems are integrated and are appealing because only one cable is needed for both. The user’s laptop or desktop system “piggy backs” off of the VoIP phones connection back to the switch. This cuts down on cabling and network hardware by half. Older systems would have separate phone switches and data switches, with separate cabling to each user from both. Using VoIP allows an organization to reduce the amount of equipment and cabling needed to do both. There are disadvantages to using this type of environment. Using a single cable creates a single point of failure for both voice and data to the user. If their phone goes down, the laptop will most likely drop as well. If the network switch that provides connectivity to both devices drops, the user is without a phone and network access as well. Connectivity speeds are also limited by the NIC on the VoIP phone. If your NIC on your laptop is a Gigabit connection, but the VoIP phone NIC is 100MBps, then your laptop is limited to the speed of the VoIP Phone. VoIP phones are also more expensive per device when compared to an analog POT (plain old telephone) phone.

Behl, A. (2012, September 07). Best Practices for Deploying Secure Cisco IP Telephony Solutions. Retrieved October 27, 2016, from http://www.ciscopress.com/articles/article.asp?p=1966660

Reply needed 2

The Concept of VoIP technology

According to Federal Communication Commission (n.d), Voice over Internet Protocol (VoIP) is a technology that allows a communication to be made using voice calls over a broadband Internet connection instead of a regular or analog phone line. Some VoIP services only allows communication to people using the same service while on the other hand, some can dial in to a telephone line including local, long distance, mobile, and international numbers.

The concept of VoIP is that it converts voice into a digital signal that travels over the internet. If the call is made to a telephone line, the signal is converted into a regular phone number.

Advantages Of VoIP

· It offers features and services that are not available with a traditional phone

· Caller can avoid paying for both a broadband connection and a traditional telephone line

· The communication provides high quality and reliability just as that of Internet connection.

Disadvantages Of VoIP

· VoIP is not available for everyone but for those who can afford it

· The stability of VoIP can be sporadic

· Single point of failure from electricity can cut the call off

· In case of emergency, some VoIP may not work effectively.

Trend of VoIP

VoIP witnessed full blown utilization in 2014. This was due to the advent of cloud services. Cloud communications have accorded VoIP the ability to be wide spread. However, due to the increase in the cloud services, the use of VoIP has widened the gap between people of different class.

According to Harris (2014), VoIP is becoming more viable in terms with respect to cost of use and the quality of service. In fact, mobility has been seen as a key contributor to growth. Meanwhile, VoIP is expected to continuously witness growth in the coming years due to cost effectiveness, improving network infrastructure across the globe and rising demand for smart devices and mobility among the corporate and individual consumers.

Reference

Harris, C. (2014): 2015 Will Require An Understanding Of VoIP Retrieved from https://www.shoretel.com/blog/2015-will-require-understanding-voip

The Hamilton Spectator (2015): The advantages and disadvantages of VoIP. Retrieved from  http://www.thespec.com/shopping-story/5785180-the-advantages-and-disadvantages-of-voip/

Federal Communication Commission (n.d): Voice Over Internet Protocol (VoIP) https://www.fcc.gov/general/voice-over-internet-protocol-voip

Reply needed 3

              I will be talking about VoIP (Voice over IP) technology for this discussion topic.In our shop when we are out at sea we use VoIP and VosIP (Voice over secure IP) technology often. A general explanation of VoIP is simply a technology that enables you to make phone calls using an internet connection. One big advantage of using VoIP is the fees are usually much lower the regular telephone providers, especially for long distance calls. Many people use VoIP technology on there cell phones nowadays to talk to friends and family who live a long distance away. Using the data on there cell phones is much cheaper than actually paying for a long distance phone calls. The connection for a VoIP call needs a High speed internet connection to be reliable, but other than that there are not many disadvantage of using VoIP technology.  VoIP technology has been trending for many years now, and different cell phone apps to use the technology are getting more and more popular, especially for people who live in a different country than the rest of there family.

Since I just reviewed and realized two other people discussed VoIP, I will also talk about PSTN. PSTN stands for the Public Switched Telephone Network (2016). This network is a circuit network that all major public telecommunication service companies use to provide proper telephonic communications around the world. Many different components make up this network, including telephone lines, fiber optics, cellular satellites, and much more. PSTN is a very convenient mean of communication and has been used for a long time. Making local calls is simple and easy. A big disadvantage is that making some long distance calls can be complicated to figure out, and also expensive, depending on what service provider you are going through. With the rise of VoIP, especially within cellular devices, is making PSTN less trendy. Some families don't even use a home phone anymore, and just rely on there cell phones to communicate. PSTN is not going away anytime soon, but it is not the main line of communication that it used to be in the past.

What is PSTN (public switched telephone network)? - Definition from WhatIs.com. (n.d.). Retrieved November 01, 2016, from http://searchnetworking.techtarget.com/definition/PSTN

-Chris

Reply needed 4

Upgrading a network is a difficult process to start because communicating requirements from all departments in an organization can be difficult to put into IT terms. Firstly I like to start with a tour of the facilities and look at their telecom rooms in the building. This gives me a gauge of their current physical infrastructure without relying on any one to correctly gather that information. Once a good picture of their current structure is painted, you can start to categorize what pieces are in need of upgraded and what is still usable.  I would compare the compatibility of each new system with the legacy systems and refine the replacement plan as new requirements crop up.

The total amount of users, their specific needs, and geographic location are all key factors. Categorize users as 100% mobile, 100% stationary or mixture in between. Each department head should submit a list of requirements (number of users, type of devices currently used, special software connectivity requirements). Some applications require static IP’s or ports to be open, these need to be identified so when any change over happens the downtime is mitigated. If time isn’t spent to painfully detail out all aspects of the network, the roll out of the new system is guaranteed to overlook something that has the potential to stop work for any particular department.

Hakala, D. (2013, January 18). 10 Important Questions to Ask When Considering a Network Upgrade. Retrieved October 27, 2016, from http://it.toolbox.com/blogs/itmanagement/10-important-questions-to-ask-when-considering-a-network-upgrade-54589

Reply needed 5

2. Choose a company or industry to examine risk for. If you currently are working, try and use your knowledge of your current company. Determine and list at least 3 risks, threats, vulnerabilities, and threat actions for your company of choice. For each risk, determine how you would mitigate the risk. Mitigation is attempting to lessen the impact or likelihood of a risk occurring.

When it comes to being a network security vulnerability technician within the military, there are a lot of vulnerabilities, which means there is a lot of risk. There are both internal and external risks. It just takes one disgruntled employee that knows there way around the network, to bring all kinds of problems. Simple things can cause a lot of harm to a network, including deleting important virtual servers and backups, wiping important files and drives, or mishandling classified documentation are a few of many things a disgruntled employee with the right clearance can do. External threats can be physical attacks overseas, and also hacking savvy people that want to exploit common vulnerabilities. Proper training of employees, and the proper implementation a networks security applications help mitigate a lot of the bigger threats. Everything from proper router configurations, network scanning, port security, and internal/external firewall settings can help mitigate the risks that come from a cyber attack. Giving employees the proper cyber training, and separating the duties of specific actions throughout the company help mitigate the risk of a disgruntled employee doing too much destruction to a network. Possible ways to mitigate physical attacks overseas is securing classified materials and servers behind complex safe combos and passwords, and also physical security to fend off intruders.

-Chris

Reply needed 6

The Navy and its systems are at risk to cyber security threats that exceed traditional information technology (IT) networks and computers to systems that affect nearly every aspect of the Navy's mission. Machinery control, weapons and navigation systems may be vulnerable, as well as the networks and computers commonly used by Navy personnel.

 

· Foreign Influence: Each month according to the Navy’s Cyber security division each month the navy’s receives 41 million attacks on its systems. Another example is the 2013 breach at the Pentagon. In this case, an employee clicked on a link in an email that appeared innocuous. That breach required the temporary shutdown of the DOD and Joint Chiefs of Staff networks, cost $10 million, and took four months to repair (CRF.org).

 

· Military Members: Its members are one of the biggest threat not that they would comment espionage but lack of training and know how is the big threat. In that today phishing scams and other methods are used everyday to gain access to the navy systems and it only takes one click of a mouse to allow a system to become infiltrated. It is crucial because the weakest link in our cyber defense is the individual Sailor. The Navy’s worst security breaches are usually the result of human error. It is, in fact, the cause of eighty percent of the DON’s PII breaches (Personally Identifiable Information) today. The Navy is bolstering its cyber security training to users and leaders because defending the Navy is not only the responsibility of the cyber security workforce; it is an all hands effort. Some examples of current annual training being provided to the general workforce include cyber security training that is required for all personnel

 

 

· Stolen Information: Stolen information can be used directly, to break a security code for example, or indirectly, as when Personally Identifiable Information (PII) is collected to impersonate a particular person. A targeted service member could have his or her online interactions including social media monitored in such a way that an enemy could steal his or her identity in order to breach security or compromise that person’s ability to work. Lastly, Sailors cannot forget to take the most obvious precautions to prevent the loss of information every year laptops containing sensitive information are stolen from vehicles, left in taxis or damaged by clumsiness, such as spilling a soda on one’s keyboard. CD’s and DVD’s containing sensitive information have been stolen outright or while in transit through the mail (ODCNOI 2015).

 

So in the end all of these threats lead to an increase in training everyone on what to look for in order to protect its systems .

 

References:

 

· Cyberattack on U.S. Infrastructure: A Highly Disruptive Cyberattack on U.S. Critical Infrastructure,” Global Con ict Tracker, Council on Foreign Relations Preventive Action, Center for. “Global Con ict Tracker.” CFR.org. Council on Foreign Relations, 2 Jan. 2014. Web. 29 Oct. 2015.

 

By Office of the Deputy Chief of Naval Operations for Information Dominance Navy Cybersecurity Division 2015 

Reply needed 7

Why are security policies important?

Security policies are important because they outline procedures or guidelines for personnel within a specific organization to follow. These guidelines offer a framework for decision making. Whenever a part project ran into a problem, a new policy would come out to prevent future instances of it from reoccurring. This creates a documented form of rules and possible consequences of not following them.

What happens without a security policy?

Without Security policies there is no documentation to reference when incidents arise. This is comparable to a nation without laws. There have to be general descriptions of the principles of each policy and list out by severity the consequences of not following them. Without that people can do as they want without regard for the detriment their actions cause others.

What are the elements that a good security policy should contain?

                A Good policy is comprehensive enough to detail each procedure but still leave some room for interpretation for when “special circumstances” arise. For example a user at a company is downloading games and is caught when trying to run an executable file that he shouldn’t. That user is probably in violation of a security policy and should be subject to the penalties of it. Another user is downloading a “add-in” application for a program they use to do work and is caught when trying to run an un-authorized executable. That user is trying to complete work and is in violation of a policy, but there wasn’t any malicious intent. There should be enough wiggle room in the policy to make sure the punishment matches the crime.

Ensuring that polices are known. Organizations that create these polices, need to ensure that they are known to the people they impact. Training or publishing those security polices in a manner that ensures they are comprehended by all constitutes a good policy in my opinion.

 

Putvinski, M. (2009, September 06). Information Security Best Practices: Checklist for Best Practice IT Security Program. Retrieved November 01, 2016, from http://corporatecomplianceinsights.com/information-security-best-practices/

Reply needed 8

1. Why are security policies important?

Information security is a very important aspect to any successful company. Without the right policies in place for every employee to follow, they will all have there own perception of how the information should be handled, and it may not be in compliance with the company. Security policies not in place  bring unnecessary risk to the company due to negligence and non compliance. Security policies take the guesswork out of how material and information should be handled.

2. What happens without a security policy?

Lack of security policy brings security incidents. If employees don't have a guideline to follow, they may not know how to properly handle certain materials or information within the company. "Staff will be unaware whether they are acting within the organization's risk appetite or not." (Micklefield, 2016)

3. What are the elements that a good security policy should contain?

There are many different vital elements that need to be within a security policy for it to be effective. You want to provide the purpose, scope, objective, authority and access control policies, classification of the data, and the responsibilities of the employees in relationship to materiel stated (Kostidinov, 2016). It should also state the importance of everyone to comply to the policy.

Kostidinov, D. (n.d.). Key Elements of an Information Security Policy. Retrieved November 02, 2016, from http://resources.infosecinstitute.com/key-elements-information-security-policy/

Micklefield, M. (n.d.). Why are IT Policies important? Retrieved November 02, 2016, from http://mpa.co.nz/problem-solved/professional-services/why-are-it-policies-important/

-Chris

Reply needed 9

An Information Technology (IT) Security Policy identifies the rules and procedures for all individuals accessing and using an organization's IT assets and resources. Effective IT Security Policy is a model of the organization’s culture, in which rules and procedures are driven from its employees' approach to their information and work.

 

A lack of security policies may involves the in ability to protect assets from unauthorized entities.

The IT Security Policy is a living document that is continually updated to adapt with evolving business and IT requirements. Institutions such as the International Organization of Standardization (ISO) and the U.S. National Institute of Standards and Technology (NIST) have published standards and best practices for security policy formation (Paquet 2013). As stipulated by the National Research Council, the specifications of any company policy should address (Paquet 2013):

 

· Objectives

· Scope

· Specific goals

· Responsibilities for compliance and actions to be taken in the event of noncompliance.

 

An organization’s security policy will play a large role in its decisions and direction, but it should not alter its strategy or mission. Therefore, it is important to write a policy that is drawn from the organization’s existing cultural and structural framework to support the continuity of good productivity and innovation, and not as a generic policy that impedes the organization and its people from meeting its mission and goals (Paquet 2013).

 

References:

 

Paquet C. (2013). Network Security Concepts and Policies Chapter is provided courtesy of Cisco Press.

_______________________________________________________________________________________

Reply needed 10

A CISO for a large private finance company is senior level executive that is responsible for maintaining and establishing the IT vision, strategy, and programs to ensure security and mitigate risks for the in the best interest of its customers and shareholders. A large part of that responsibility lies in industry and federal regulation compliance.  These compliance regulations are designed to ensure the security of sensitive customer data. This task is ever increasingly becoming more and more difficult in the current decentralized cyber environment (Schiff, 2014).

Cyber-compliance is a vast ocean of information in itself. A large private finance company will be required to follow many regulations listed below are just a few regulations possibilities.

· Gramm–Leach–Bliley Act (GLBA): also known as the Financial Services Modernization Act of 1999. Under the GLBA finance companies are required to provide customers with privacy notifications. This privacy notification is supposed to inform the customer of what data is being collected and how it is being collected, used, shared, stored, and protected (Federal Trade Commision, 2002).

· The Health Insurance Portability and Accountability Act of 1996 (HIPAA) HIPPA is historically a health care industry regulation. However with the passage of the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009 and the implementing regulations in 2010, requires Finance companies that provide medical lockboxes, medical banking services or other services which require access to and/or dissemination of protected health information (PHI) must be HIPPA complaint(Law360, 2011).

· Sarbanes-Oxley Act Of 2002 (SOX) SOX was created to protect investors from fraudulent accounting that ran rampant in the early 2000’s. In addition to financial requirements of like audits, accuracy, and controls SOX defines what records need to be stored and for how long. It does not define how just mandates that IT department is responsible for the secure storage of them (investopedia, n.d.).

Managing compliance can be tricky, many businesses find them self in an increasingly complex ecosystem of regulations. In order ensure compliance with regulations compliance tools can help manage that burden. Tools can provide a way to manage compliance controls and contract required controls Providing valuable information for effective and smart risk decisions (Search security, 2008).  These tools can also assist in:

· Authoring, distribute, and map policy and controls(Search security, 2008).

· Assess technical and non-technical operations controls(Search security, 2008).

· Mitigate/remediate areas where controls are insufficient(Search security, 2008).

· Assist in building metrics and measures for quantifiable analysis of risk management(Search security, 2008).

If were a CISO I would definitely make use of compliance tools. If for nothing else than to use them to track and easily show proof of compliance in a standardized way. Using standardized tools and methods make has many advantages. There are many tools out there it is vital to assess each tool to find the one that fits your companies requirements best.

Reply needed 11

To develop a successful IT compliance management program, one must first understand what laws and regulations are relevant to their company. After identifying the relevant laws and regulations, one can begin to analyze the details and create a compliance schedule that describes the goal of compliancy and an estimate date of completion. The compliancy details of each law and regulation should consist of guidelines and best practices that once implemented will bring the company to an acceptable level of compliance. It is important to note that the details of compliance will vary from company to company as needs differ greatly. It is up to the company to decide how to best implement security controls and processes that are tailored to their specific needs.

Financial institutions are subject to a variety of laws and regulations. A few of these are the Sarbanes-Oxley Act, Gramm-Leach-Bliley Act 1999, and the Federal Financial Institutions Examination Council. Sarbanes-Oxley protects customers from fraudulent activities of companies and organizations. Gramm-Leach-Bliley regulates how financial institutions handle the private information of individuals. "Federal Financial Institutions Examination Council specifies that the organization's Board of Directors is responsible for ensuring that a comprehensive BC plan has been implemented." (Geminare)

I would certainly consider the use of a compliance tool. "The MetricStream IT Compliance Management App provides a common framework to manage and monitor compliance with a range of IT regulations and standards. The App scales across the enterprise, streamlining and automating IT compliance workflows, while consolidating compliance and controls data in a central repository." (Metricstream) As for a justification for the expenses, using a IT compliance management tool can increase productivity and effectiveness of compliance preparation measures. The saved time and manpower spent preparing for an audit can then be put back towards business activity.

Geminare. (n.d.). An Overview of U.S. Regulations Pertaining to Business Continuity. Retrieved November 7, 2016, from http://www.geminare.com/pdf/U.S._Regulatory_Compliance_Overview.pdf

Metricstream. (n.d.). IT Compliance Management App. Retrieved November 07, 2016, from http://www.metricstream.com/apps/it-compliance-management.htm

Reply needed 12

The Wachovia’s case study is a very interesting story that exemplifies the challenges of interoperability of legacy systems. Designing a new system from the ground up in today’s cyber-aware environment is relatively simple in comparison to securely getting to legacy systems to interoperate together. Nearly any systems can be merged together and work given unlimited resources, however, that concept is unrealistic. When Wachovia merged with First Union in 2001 the two companies had very different processes for operations. Both Wachovia and First Union had grown individually through acquisitions, therefore inherited different content and repositories across their many business groups. Some of this content was stored physically other content was digital. Making matters even worse is that the digital repositories were a result of heterogeneous mix of data formats, applications, and APIs. Unifying them would be impractical because of cost and resources required. Therefore, the WIT group would implement middleware that would serve as a bridge to approach content integration (Walter, 2004).

A middleware interoperability enterprise system is a gift that would continue to give in future mergers and acquisitions. A middleware enterprise system could merge the current legacy content providing a needed solution and allow for contentment mergers in the future at a fourth of the cost of manually unifying them. Additionally, a middleware bridge could do this at much quicker rate than a complete tear down and rebuild (Walter, 2004).

Another challenge WIT group face was integrating First Unions content and its loan-servicing staff. First Union stored loan records in paper only. This meant that for any staff to access First Union commercial loan records it had to be done physically. This was unfeasible for security, staffing, and practicality reasons. Furthermore, Wachovia Corporation had digitized its loan documents, the application was slow and limited in access and availability. This left the management to decide between:

· Scan and load First Unions physical paper records into Wachovia ImagePlus platform that was not very functional;

· or design and build a new platform then scan and load First Union’s documents and ingrate that platform with the existing Wachovia ImagePlus database.

This concept has the following results:

Spend less now and more later down the road to continue using a un-functional platform (ImagePlus) or;

Spend a little more now and create flexible platform that could easily integrate additional content and repositories from future acquisitions.

This was all done in the early 2000s meaning cyber security was not as much of a concern as it is in today’s challenging environment. Meaning this integration was challenging then and would be even more so today. However, the processes and architecture WIT group used would pay dividends in future operations. WIT took a one step at a time concept evaluating the challenges as a whole and tackle each one at a time. their model was successful and would enable interoperability of different content and repositories seamlessly into a single user interface that is both more secure and shields both end users from specific locations, software, content repositories.   

Reply needed 13

1       “Workflow and Imaging Technologies (WIT)” (Walter, 2015) This is a team of 40 individuals that evaluate the work place environment to come up with workplace solutions. One of the reasons I consider them an important concept because they operate together to create innovative technologies.  Additionally, as a team they can bounce ideas off each other to solve problems. This teams is vital in this study, because they could develop a technology which allowed the banks to merge 3 of their most important divisions without needing to build an entirely new infrastructure.  The process the team created saved thousands of dollars.  Additionally, they are able to commercialize the products in the successful integration of the IT capabilities is because the combined input from and entire team, allows for creative and profitable inventions. 40 minds is better than one.

2       “WIT took a Hybrid approach. They decided to leave the images in an application called ImagePlus but, to migrate the ImagePlus indexes over to the FileNet application.  This design enables a single application to manage security when accessing the documents, rather than write a point-to-point integration with ImagePlus, for viewing the actual images, Wachovia built a simple bridge (retrieve and view) to ImagePlus.” (Walter, 2015)  The second concept I believe that helped Wachovia, was the WIT teams Hybrid approach itself.  This project showed the employees of both organizations employees they were valued. Giving full access to all areas of both repositories by “building a simple bridge” (Walter, 2015) that would “(retrieve and view) to ImagePlus” (Walter, 2015) The WIT built good will between the employees.  The design was a cost saving measure.  The WIT team believed eventually, other areas in the company could use this bridge as well, pay to use it, generating revenue for the company.

3       “WIT proposed using DB2 II Content Edition to separate ImagePlus from the desktop client. This approach would make it easier to integrate the accounting system. Also, should the need arise in the future, it could, if necessary, to plug the desktop application into other back-end repositories.  The Commercial Loan division wanted the integration capability right away, but WIT could see that other divisions in the business units would want it use the application as well. It didn’t make sense to build the product five or six times if we could build it once in a way that other groups could leverage.” (Walter, 2015) This was a harder decision.  ImagePlus was ending its life cycle soon, and the company would have to invest further in renewing the application. So, instead the company took a gamble and changed tactics.  WIT believed the employees wanted to be more effective and efficient in their jobs, and the WIT approach. The WIT team had many considerations, but they chose to develop a new application. They created a workable solution, which was better than the older application, and in doing so, made an innovative, and marketable product.  

4       “Commercial Loans agreed to fund the initial enterprise implementation of the Content Integration Technology. In Wachovia’s case, “enterprise implementation” meant that WIT would take ownership and responsibility for operating and maintaining the content-integration technology, but that the business unit would be charged for its construction and on-going use. In return for giving up some control, the business unit would receive a financial benefit: as other groups, could make use of the infrastructure that Commercial Loans paid for. Wachovia will spread the service charge across all users, thereby lowering the amount that Commercial Loans pays to “rent” the technology for its own purpose.” (Walter, 2015) This is an interesting interaction and concept because a it allows for growth in areas that can now and then piggyback off the growth, by essentially paying rent which essentially lowers the cost of the areas that is doing the growing.

5       “Recognizing the common thread across all of the projects, WIT sensed that it needed to find a way to pull information in a seamless way from a variety of sources without affecting back-end operations and systems. Yet each project that WIT undertakes for a line-of-business client has its own success criteria and ROI analyses that are tied to the business unit’s objectives and performance.” (Walter, 2015) Sometimes looking everywhere and collecting as much data as necessary is the important piece of the puzzle. WIT realized the bridge would help at Wachovia. WIT began to look for one department to own the application and then other departments within Wachovia who could use the product.  These departments rent the application use, and the revenue goes back to the department who owns it.  The revenue is then applied to the cost of the application creation.   

Walter, M. (2015, November 15). http://gilbane.com. Retrieved from http://gilbane.com: http://gilbane.com/case_studies_pdf/CTW_Wachovia_Final.pdf#_Toc88022904.