370 (3)

profileJohn_matt
replies_needed.docx

Please don’t give me a two to three sentence replies. It has to look burky. At least 7 to 8 sentences. Thank you

From this Section is very Important

Responded to discussion topic with well supported and outside research or assigned readings as appropriate, add value to the discussion, and demonstrate student’s understanding of concepts.

Reply needed 1

2. When choosing network hardware, why would it be recommended to standardize at least some types of hardware? What are some disadvantages to hardware standardization? When would you recommend hardware standardization or would you recommend it at all?

Standardizing any technology is a double edged sword. Having fewer differing types of hardware and software allows an organization to reduce its need for interoperability. That means fewer frustrations, lower costs, and more functionality between devices. When things are designed from the ground up to work together, fewer problems arise during implementation. Conversely it is recommended to not “put all your eggs in one basket”. Using different manufactures and models reduces the risk of a complete work stoppage if a particular malfunction occurs with just that type of technology. There is no all-encompassing guiding principle of when to pick a single source and when to spread the wealth. An example of when to standardize is when the risk of total failure of that system is low and its impact if that does happen is also low. If any technology provides a key function to the continued success of an organization, I would ensure there are differing types of technology that can provide that and backups for emergencies.

 

In a particular case, if I had already existing CISCO brand VoIP phones and was upgrading my call manager and/or switch. I would probably lean towards choosing CISCO, because that VoIP phone hardware can lose its all or some of its functionality when using a Juniper brand call manager. Those functionalities could be call waiting, having multiple phone extensions per device, voice mail. Losing some of those utilities isn’t acceptable for any practical solution and would be the proverbial straw that breaks the back in that decision.

Standardizing Your IT Infrastructure. (n.d.). Retrieved November 1, 2016, from http://www.techsoupforlibraries.org/Cookbooks/Planning for Success/Buying and Deploying Technology/standardizing-your-it-infrastructure

-MAtt

Reply needed 2

1. Interoperability of hardware and software is an important consideration when conducting network planning. Why is interoperability important in network planning? 

Interoperability is a very important concept to keep in mind, especially when it comes out to planning an intricate network. You can buy all the top of the line hardware and software, but if it is not compatible with each other, it will be deemed useless. So when it comes to creating a network, you have to really plan out how everything is going to work with each other. If you are going to have both physical and virtual servers, will they all be compatible? If you have an entire server dedicated to a firewall, it needs to be able to provide security services to everything else on your network. Sometimes hardware and software will work with each other, but not at maximum capability, which can bring issues over time to your entire network if no solution is found. I personally have seen many issues within networks where interoperability has been a problem, servers will crash, files will be corrupted, and actual hardware will not want to function properly.

-Chris

Reply needed 3

Several definitions have been proposed for the term interoperability. The Oxford English Dictionary (OED) defines the component parts as: inter - "mutually, reciprocally, together; between or among themselves; with each other" operable - "capable of being accomplished; capable of being actually used". Lynch (1993) defines it as "the ability of one machine . . . to interact usefully with other machines on a casual, ad hoc basis, without the prior planning or negotiation between the organizations operating those machines" . Lynch (1993) define it as occurring when "components of a system…communicate with one another effectively, correctly, and provide the expected services to the user".

 

A possible working definition. Interoperability can be defined as: the ability of different types of computers, networks, operating systems, and applications to work together effectively, without prior communication, in order to exchange information in a useful and meaningful manner.

 

References :

 

Lynch, Clifford. (1993, March Interoperability: the standards and challenges for the 1990s. Wilson Library Bulletin 67(7)

Reply needed 4

3. Email is a powerful communications medium, but is also one of the top methods for introducing malware into a network. Why (and how)?

Email has vulnerabilities because it’s a communication technology that doesn’t completely discriminate incoming messages. Spam blocker and other tools that help filter out junk e-mail do help, but they aren’t full proof. Many forms of cyber breaches begin with some pathway into a network. Phishing is an example of an e-mail attack that is still very prevalent in today’s cyber environment. A hacker will send out thousands upon thousands of e-mails to potential targets with malicious code embedded or attached. It only takes one of those e-mails to gain entry or deliver a virus. Even with such a low return on how many e-mails are sent, it costs these hackers very little time or money to do so.

Even penetration testers preforming an analysis on behalf of an organization will use phishing attempts to have unwitting users click on something they shouldn’t have. Many users today have become aware through training or constant exposure, that some e-mails have something off about them. Hyperlinks look like they are not using a correct address or they receive an e-mail from a user they do not know asking for information you wouldn’t typically give out. It is important to stay aware of newer styles of attacks and how to avoid them. Even if you as a user had no malicious intent to be an unwitting participant in a security breach, many organizations still hold users accountable.

 

Spam & Phishing. (n.d.). Retrieved November 1, 2016, from https://staysafeonline.org/stay-safe-online/keep-a-clean-machine/spam-and-phishing

Reply needed 5

2. Patching systems is an important aspects of the maintenance phase. What are the best ways to patch systems? What are the risk involved with patching systems?

Patching systems (especially within an enterprise network) is one of the most time intensive, but also one of the most important tasks to keep your network healthy. There are many different areas of a network that need to work together to properly perform patching. You should have a proper network scanner to first scan your network for vulnerabilities that need to be taken care of. Many big companies use programs like WSUS to automatically push updates/patches to there systems. Once you are done scanning and fixing the vulnerabilities that you find, you want to scan your network again to make sure that the patches have been implemented. There is always risk involved when patching a system. Recently Cox Cable company pushed a patch to some of there netgear routers that they did not do proper testing on. Every single router that received the patch needed to be swapped out for a new one because none of the customers could access the internet. Just one update cost the company loads of money to fix. So before applying any patches to a network, they should be properly tested just to make sure you aren't doing more damage than good. 

-Chris

Reply needed 6

3. Email is a powerful communications medium, but is also one of the top methods for introducing malware into a network. Why (and how)?

Hurcombe (2014) stated that significant spike in malicious spam emails containing links, as attackers move away from attachments in their efforts to spread Downloader.Ponik and Downloader.Upatre. Email is a powerful communications medium because it enables fast and easy communication between two or more people in fact, all businesses have domain name registered to them for both internal and external communication. Sharing of security files and business transactions are carried out using emails.

However, with the increasing use of email, it is also one of the top methods for introducing malware into a network. The primary cause of falling into the captivity of malware is lack of training (unintentional) and exploitation of vulnerability (intentional by insider threats). Malware is an abbreviation for "malicious software." It includes viruses, worms, and Trojan horses that intentionally perform malicious attacks on computer systems. Malware is usually in form of code and so it is referee to malicious code. An attacker will trick an authorized user to click on a link in the email or on an attachment and from there seize the control of the computer and escalate privilege from there. Some will even involve ransomware – demanding for money before they release the use of the computer. 

Reference

Hurcombe, J. (2014): Malicious links: Spammers change malware delivery tactics. Retrieved from https://www.symantec.com/connect/blogs/malicious-links-spammers-change-malware-delivery-tactics

Reply needed 7

What do you think about their privacy policy?

My thoughts when it comes to the data that I have provided and that a company has collected for use of their services should be regulated to that specific site.  If a company wants to use the data that I provide and that is collected during the use of the services to profile or target me, I should be provided an option to opt out.  If the company doesn’t provide a means for opting out then they should offer a transparent picture of what your online profile for them looks like, in order for you to better understand how the data collected is being used and portrayed, as well as any unintentional PII that may have been collected.  With all of the data breaches that have been happening with companies in the past few years it seems like having a complete profile of your users is a prime target for hackers.  I know that a lot of my friends are not allowed to have social media accounts due to the nature of their jobs.  Unfortunately, even without a social media presence our personal lives have become so entwined with technology it’s hard not to have some sort of digital footprint and policies like this one from google create a larger footprint.

How would it impact an organization that is contemplating using Google as its enterprise communication platform?

There shouldn’t be any major impact an organization contemplating using Google as its enterprise communication platform.  An article from PCworld, discusses how the Google Apps suites for business, government, and education already link services across their platforms. Another point the article makes that Google wouldn’t establish or link a user’s business account and personal account (Gross & Perez, 2012).

What social media services that Google provides would you allow your employees to use, and what type of policy would you recommend the company adopt for the use of Google services?

If Google is not linking a user’s business profile with their personal profile, then an employee can use which ever social media service they want.  With that being said, the employee would still be subjected to the companies AUP, and network monitoring, so they should use them at their own risk. 

What security risks do you foresee using Google Cloud services? 

InfoWorld produced an article discussing an RSA Conference on the top 12 cloud computing threats.  While the number 1 threat was data breaches, what caught my eye was number 12, shared technology, shared dangers.  This fell right in line with googles new privacy policy.  Since google is now sharing data over multiple platforms, infrastructures, and applications, they need to ensure that every layer is protected.  If any one of the sharing items has a simple misconfiguration or vulnerability, it could lead to the whole sharing suite being compromised (Rashid, 2016).

References

Gross, G., & Perez, J. (2012, February 24). Google: New Privacy Policy to Have Little Impact on Enterprise. Retrieved from Pcworld.com: http://www.pcworld.com/article/250605/google_new_privacy_policy_to_have_little_impact_on_enterprise.html

Rashid, F. (2016, March 11). The dirty dozen: 12 cloud security threats. Retrieved from InfoWorld: http://www.infoworld.com/article/3041078/security/the-dirty-dozen-12-cloud-security-threats.html

Reply needed 8

Google new privacy policy is a great read. I feel that Google was using a similar combination before this announcement for its ad sharing services. Now Google is stating they will combine their services and even use location data for add placement. User must understand that many existing applications are already location based such as Yelp and foursquare (Mazumder, 2016). This announcement by Google is just confirming that the technology giant will attempt to follow suit with other developers and streamline its services much like the Apple experience. I am not for or against this move simply because I use Google’s location services on my Android to power my location based applications already. Opting out of certain services is not optional before this change because opt out selection often stops the application for many products.

        For any organization considering Google as its enterprise communication platform this could present issues. When using google services for organizational data transfer you are trusting google with the security of your data forever. For some organizations this may not be an issue but institutions such as financial and medical have federal compliance that is mandatory. Organizations should be concerned about the legal issues usage of google services will provide (Kotsios, 2015). Releasing control of sensitive information is often not a good idea for compliance reasons. Privacy considerations must be made before deciding to release data.

        I would allow employees to use many google services. Hangouts of great for conferencing and comes at a cost savings to other offerings. Google + is not overly used and can present a unique opportunity for collaboration.  I would adopt a shadow IT policy that clearly defines what can be moved from company control and what cannot. Employees must ensure they are not sending confidential information to their personnel mail and cloud accounts (Gmail and Google drive). While this method provides ease of use it also releases data form company control.   

Reference

Kotsios, A. (2015). Privacy in an augmented reality. International Journal Of Law & Information

               Technology, 23(2), 157-185. doi:10.1093/ijlit/eav003.

Mazumder, S. (2016). LANet: An Enriched Knowledgebase for Location-aware Activity Recommendation

Reply needed 9

IT architecture is important for a variety of reasons. The IT architecture provides the roots of the organization by connecting end users with data and applications (Lutz, 2016). Architecture should involve with the organization and changes to technology to ensure continued service to the customer base. A poorly designed architecture will not maintain the ability to support and grow with the organization.  

Technology is ever changing and business technology must change also. Legacy systems are meant to be phased out of existing business architecture. When systems become legacy they are no longer considered during new application and system design, therefore they will not be supported by new because they will no longer be supported. Files systems that are not supported within the architecture cost the company time and money to develop a solution to access necessary data. Poorly designed architecture also leads to redundant data and interfaces. The more data that exist on the network the more difficult it becomes to control.

Security architecture and IT architecture are complementary disciplines. IT and security design both possess elements that are necessary for each to accomplish their intended goals. Organizations should care about architecture because it is the foundation of business operations. Security must be considered from the inception of design along with ensuring architecture aligns with current and future business needs. It is more cost effective to design and build an agile framework for the start than attempt to turn implement vast changes during operations.

References

Lutz, R. (2016). Security and Privacy in Future Internet Architectures - Benefits and Challenges

of Content Centric Networks.

Reply needed 10

An effective IT architecture is crucial for a business success and survival and an efficient way of achieving competitive advantage through Information Technology. Any organization CEO and managerial staff understand very well that IT architecture is the main ingredient for business development and achievement. The architecture is fundamental to constant improvement and change in business to satisfy customers and employees’ needs. The two main important reasons of IT architecture are:

1. To provide a detailed, formal and described plan of guide in the business and that help a company to achieve its goal

2. To provide different structures interrelationships and principles and it presented a way of governing and designing them.

A security architecture technical architecture is to achieve essential system-wide features of interoperability of security. Security Architecture is the design artifacts that describe how the security controls and security countermeasures are positioned and how they relate to the overall systems architecture.

Reference

opengroup.org. (2016). The Business Executive's Guide . Retrieved from /www.opengroup.org: http://www.opengroup.org/public/arch/p1/oview/