Homework for Information Technology

profileJohnPadget4653
enterprise_security_plan_2.pptx

Enterprise Security Plan

Riordan Manufacturing

Agenda

Riordan Manufacturing’s History

Physical Vulnerabilities and control Measures

Network Security and Control Measures

Data Security and Control Measures

System Integration

Current

Future

Implementation

Riordan Manufacturing History

Physical Vulnerabilities & Control Measures

Vulnerability – Weak Authentication

Risk- Identity theft, unauthorized access to confidential information

Vulnerability – Improper training

Risk- Back ups not accomplished, confidential emails or data sent without proper security measures, missed security patches

Vulnerability – Hardware

Risk- Loss of programs and data. Customer banking information becoming lost or permanently

deleted. Power loss, system timing problems.

Its very important to ensure that your company is safe and secure and in order to do that you have to look past the security cameras and door locks and look into your actual IT security plan. Weak authentication, improper training and a lack of proper hardware usage can cause major risks and issues within your system that can potentially take down your entire enterprise. In order to to help mitigate this issues a Roll Based Access Control System (RBAC) can be implemented. This system helps divide access to systems across the board not allow one person to have total control and making it possible to restrict access to certain individuals. Ensuring that a proper training plan is in place and revisited by employees semi-annually can help keep security measures and practices fresh in their memory. Hardware will always be an issue that has to constantly be revisited. Since hardware becomes outdated so fast its important to stay on top of all updates and ensure that the correct hardware is used like power banks and back-ups to guarantee zero loss of data during power outages and such.

4

Network Security & Control Measures

Two Teams: Network & Security

Roles & Responsibilities

Separation of Duties

Access Control Lists

Network Devices  Network Team

Security Planning  Security Team

Access Controls

Identity Management

Authentication

Encryption

Firewalls

Physical Security

Redundant equipment

Training

Monitoring/Audits

The network allows access to all of the company’s resources, business operations, finances, and secrets. Riordan needs to create two teams for the network security to ensure that the network administration is carried out effectively by the network team who will not be able to alter the security implementations since they are administered by the security team. These two teams must collaborate and compile and execute a strategy to secure the network.

Each team should identify each member, as well as their roles and responsibilities to ensure that all tasks will have someone to hold accountable for the results. Once these roles and responsibilities are established, access control lists can be configured to manage who may access which resources and for what purpose(s).

Layered security, separation of duties, the principle of least privilege, access controls & lists, identity management, rapid threat containment, authentication, encryption, firewalls, physical security implementations, redundant equipment & backup resources, training, monitoring, and audit measures will help to prevent social engineering, lack of compliance, traffic interception, unguarded port exploits, single points of failure, malware, and unauthorized access, among other threats that might possibly leave the network vulnerable.

5

Data Security & Control Measures

Riordan Manufacturing will need to protect one of its most valuable assets, which would be its data.

Data allows Riordan Manufacturing to perform day to day functions of manufacturing.

Data allows Riordan to calculate company statistics and predict customer needs.

Data should be managed by security management. According to Mark Thomas, security management ensures security risk are:

Identified

Analyzed

Managed.

A risk assessment was performed to determine the risk and vulnerabilities that Riordan faces. The threats to data are:

Weak authentication

Protocol errors

Spoofing

Database inconsistencies

Access control to inventory management systems

Sub-standard key management

Lack of segregation

Weak authentication can lead to unauthorized access to data, which would allow the data to be stolen or altered.

Protocol errors can cause data to be lost or invalid.

Spoofing is an attack that can allow unauthorized access to data, which leads to data to be stolen or altered.

Database inconsistencies are caused by lost files and different save formats, which create false data.

Access control to inventory management systems creates inventory reports that can be inaccurately created if the data is corrupted, which could lead to theft. Sub-standard key management if weak can allow access to data.

A lack of segregation will allow a single person to have too much power and become a single point of failure. A single point of failure will allow unauthorized access to data. The logical threats to data have been identified and will allow the mitigation of the threats and risks to be named,

Riordan Manufacturing will need to protect one of its most valuable assets, which would be its data. Data allows Riordan Manufacturing to perform day to day functions of manufacturing. Data also allows Riordan to calculate company statistics and predict customer needs. Data should be managed by security management. According to Mark Thomas, security management ensures security risk are identified, analyzed, and managed. A risk assessment was performed to determine the risk and vulnerabilities that Riordan faces. The threats to data are legitimate threats which are threats that are system related. The legitimate threats are weak authentication, Protocol errors, spoofing, database inconsistencies, access control to inventory management systems, sub-standard key management, and lack of segregation. Weak authentication can lead to unauthorized access to data, which would allow the data to be stolen or altered. Protocol errors can cause data to be lost or invalid. Spoofing is an attack that can allow unauthorized access to data, which leads to data to be stolen or altered. Database inconsistencies are caused by lost files and different save formats, which create false data. Access control to inventory management systems creates inventory reports that can be inaccurately created if the data is corrupted, which could lead to theft. Sub-standard key management if weak can allow access to data. A lack of segregation will allow a single person to have too much power and become a single point of failure. A single point of failure will allow unauthorized access to data. The logical threats to data have been identified and will allow the mitigation of the threats and risks to be named,

6

Data Security & Control Measures

Riordan Manufacturing will need to mitigate the vulnerabilities and threats identified.

Weak authentication can be addressed by setting standards and policies for password requirements. Authentication programs will be established to require specific standards for passwords. Policies will need the password to be changed regularly.

Protocol errors will be controlled by using monitoring tools. Monitoring tools allow administrators to monitor the work of employees and ensure protocols are being met.

Spoofing can be countered by end user training, email filtering, User and network behavior analysis tools, and file and folder modification notification tools.

Database inconsistencies can be reduced by running the DBCC CHECKDB which checks and corrects for database inconsistencies.

Access control to inventory management systems can be monitored by maintaining the access control. The access control can audit validity of accesses and the impact to the overall system.

Sub-standard key management and lack of segregation can both be addressed by introducing Role-Based Access Control or RBAC. RBAC identifies key functions as roles. The roles are given specific permissions and accesses which are then assigned to employees. In addition to these steps, additional precautions can be taken.

The "TechRepublic" (2006) there are additional steps to protect data. Those being:

Back up data early and often

Password-protect documents

Use Encrypting File System

Use disk encryption

Protect data in transit with Internet Protocol Security

secure wireless transmissions

The Security Team will need to create policies and set standards with the full support of upper management.

Riordan Manufacturing will need to mitigate the vulnerabilities and threats identified. Weak authentication can be addressed by setting standards and policies for password requirements. Authentication programs will be established to require specific standards for passwords. Policies will need the password to be changed regularly. Protocol errors will be controlled by using monitoring tools. Monitoring tools allow administrators to monitor the work of employees and ensure protocols are being met. Spoofing can be countered by end user training, email filtering, User and network behavior analysis tools, and file and folder modification notification tools. Database inconsistencies can be reduced by running the DBCC CHECKDB which checks and corrects for database inconsistencies. Access control to inventory management systems can be monitored by maintaining the access control. The access control can audit validity of accesses and the impact to the overall system. Sub-standard key management and lack of segregation can both be addressed by introducing Role-Based Access Control or RBAC. RBAC identifies key functions as roles. The roles are given specific permissions and accesses which are then assigned to employees. In addition to these steps, additional precautions can be taken. The "TechRepublic" (2006) there are additional steps to protect data. Those being Back up data early and often, password-protect documents, Use Encrypting File System, use disk encryption, Protect data in transit with Internet Protocol Security, and secure wireless transmissions. The Security Team will need to create policies and set standards with the full support of upper management. Using these additional measures in conjunction with standards and policies will allow RIORDAN Manufacturing to mitigate the risk to their data.

7

Wan

Wan

Wan

Wan

System Incompatibilities

Each location has a different

setup

Not all processing is automated

Each location maintains paper files

Historical storage is in many disparate databases

System Integration –

Current Environment

Riordan Manufacturing's current operating systems consist of three entities; Georgia, Michigan, California and a joint venture in the People's Republic of China

Company files are a combination of data files, paper files, conversion of records from other sources and minimal automated storage for historical data

The organization is unable to achieve a secure environment across all networks

The current environment does not allow for communication across all locations

As a result vulnerabilities cannot be managed effectively and processes are labor intensive and costly

8

Headquarters

San Jose

Plastic Beverage Container

Albany, GA

Custom Plastic Parts

Pontiac, MI

Plastic Fan Plant

China

Future Environment

Cloud Storage

Technology provides a variety of options for integrating multiple systems, like in the case of Riordan Manufacturing, are not set up to work together

Enterprise Resource Planning is one of the most popular processes that manages and integrates areas of a business such as sales, marketing, finance and accounting, human resources and purchasing

Each department has its' optimized system unique to that line of companies tasks

The implementation of ERP would allow Riordan Manufacturing to link information about all areas of the business for all locations.

Enterprise Resource Planning would provide opportunities for the organization to track sales and marketing results, maintain all employee records and payroll information, and manage production and inventory controls across all locations through interconnected dashboards

Cloud solution would allow the storage of current and historical data that is assessable to those who need to see it.

9

Implementation Plan

Establish Security Team

Control Assets

Assess Threats, Vulnerabilities and Risks

Security Controls

Conduct Training

Conduct Audits

Implementation of an Enterprise Security Plan for Riodan will include a few steps. The first step is establishing a security team. This is generally led by a CSO, CISO, or director of security. Which one that is decided is typically determined by the size of the company. Riodan should have a director of Security. The next step is control of assets. This can be accomplished by Riodan by various means. Another step that should be done by Riodan is assessing threats vulnerabilities, and risks. Implementation of security controls is important and must be done by Riodan once the Risks, Vulnerabilities, and threats. Conducting training and then audits will be the last step in the plan.

10

References

Apollo Group, Inc. (2013). Virtual Organizations. Retrieved from http:// ecampus.phoenix.edu/secure/aapd/CIST/VOP/index.html

Investopedia. (n.d.). Enterprise Resource Planning - ERP. Retrieved from http:// www.investopedia.com/terms/e/erp.asp

Rouse, M. (n.d.). ERP (enterprise resource planning). Retrieved from http:// www.searchsap.techtarget.com/definitions/ERP

TechRepublic. (2006). Retrieved from http://www.techrepublic.com/article/10-things-you-can-do-to-protect-your-data/

The University of Phoenix. (2014). ITIL Foundations with Mark Thomas. Retrieved from University of Phoenix, CMGT430-ENTERPRISE SECURITY website.

Cisco.com. (n.d.). Retrieved from http://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html

Dattatreya, Y. (1994-2016). CIO.com. Retrieved from http:// www.cio.com/article/2432981/risk-management/building-an-enterprise-security-program-in-ten-simple-steps.htm

TechTarget. (2000-2016). Retrieved from http:// searchsecurity.techtarget.com/answer/How-should-security-and-networking-groups-manage-the-firewall

University of Phoenix. (2013). Virtual Organization: Riordan Manufacturing. Retrieved from University of Phoenix, All website.

References

12