Quiz 3 370

profileJohn_matt
replies_needed.docx

Please don’t give me a two to three sentence replies. It has to look burky. At least 7 to 8 sentences. Thank you

From this Section is very Important

Responded to discussion topic with well supported and outside research or assigned readings as appropriate, add value to the discussion, and demonstrate student’s understanding of concepts.

1. Practical Applications in Cybersecurity Management (Requires an answer)

Please use this conference to provide me your feedback on the courses. What were your experiences regarding the assignments? What did you learn in this class? What areas of the course do you think could be improved?

Reply needed 2

http://content.ebscohost.com/ContentServer.asp?T=P&P=AN&K=118506730&S=R&D=bth&EbscoContent=dGJyMMvl7ESeqLY4zOX0OLCmr06epq9Srq24SK%2BWxWXS&ContentCustomer=dGJyMPGqsE6yr7BQuePfgeyx43zx

My article is titled Threat and Challenges of Cyber-Crime and the Response By C. Alexander Hewes.  It gives a brief background of what cyber-crime is and how it has flourished throughout the years. The article also discusses the federal and state laws that have been enacted to help combat cyber-crime. It dives deeply into “Identifying the Perpetrators of Cyber- Crime” (Hewes, 2016).  He explains what cyber wise is out there that is attacking our network systems.  The article discusses liabilities and legality.  Also, what precautions can be taken to prevent cyber-crime. It also discusses the insurance coverage that could be purchased for businesses for this type of data loss and the strict requirements that must be met in order to be covered. 

So, what is Cyber Crime? Well in the broadest meaning Cyber Crime, “is criminal activity or a crime that involves the Internet, a computer system or computer technology.” (Hewes, 2016) Now this kind of criminal activity might: “ include 1) identity theft, 2) phishing schemes', 3) theft of corporate funds, assets, and computer resources, 4) disclosure, modification, or destruction of personally identifiable information (PII) or proprietary information, 5) abuse of computer resources for unauthorized purposes or to launch attacks on other systems, and 6) causing damage to networks and equipment.” (Hewes, 2016). Cyber Crime has grown steadily in the last several years. According to the “U.S. Computer Emergency Readiness Team (US-CERT) [cyber-crime has] increased from 5,503 in fiscal year 2006 to 67,168 in fiscal year 2014, an increase of 1,121%.1 2.” (Hewes, 2016) That is a significate increase in the reported successful attacks throughout the years.  The attack on “OPM’s database in 2014 occurred despite the established $4.5 billion National Cybersecurity and Protection System program and its centerpiece detection capability, named Einstein.” (Hewes, 2016). Just goes to show that sometimes despite our best efforts the bad guys profit.

This article outlined how many laws have been modified or changed or amended dealing with cyber-crime.  The number is vast, from the Computer Fraud and Abuse Act of 1984 to the National Cyber Security Protection Act of 2014.  It is not just the federal laws that have been evolving through the years it is also the state laws.  “47 states, the District of Columbia, Guam, Puerto Rico, and the Virgin Islands have enacted legislation requiring private or government entities to notify individuals of security breaches of information involving PII” (Hewes, 2016).

When seeking resolutions for such criminal enterprises it can become very difficult. Cyber-crime tends to have what is call “faceless” criminals.  These people can operate in the shadows of the internet and not be found. They can range from criminal groups to terrorists (Hewes, 2016).  Although it may have a faceless criminal pulling the strings that does not mean that the companies do not deal with a whole handful of liability issues ranging from  “1) loss or theft of corporate funds, assets, and computer resources, 2) disruption of critical operations that support critical network infrastructure, 3) damage to networks and equipment, 4) disclosure, modification, or destruction of PII or proprietary information, 5) damage to public confidence in an organization management’s ability to prevent and deal with cyber intrusions, 6) abuse of computer resources for unauthorized purposes or to launch attacks on other systems, 7) liability to customers and third parties for loss of confidential data, 8) liability to other organizations for business loss, and 9) the cost of repairs, replacements, new preventive steps, as well as legal fees.” (Hewes, 2016). With the company platform of liability issues expanding it is not hard to figure out that the “Legal Liability” (Hewes, 2016). With the growth and volume of large breaches this has led to class action law suits. Currently there are “70 class action lawsuits alone have been filed against Target by customers following its 2013 holiday season data breach” (Hewes, 2016). That data leaves out other breaches like OPM and Michael’s that have effected over 25 million individuals which also have class action lawsuits on file. (Hewes, 2016).

So, what does a company do to protect themselves. Between the legal battle and the cost of the breach cleanup, a company could be billons in debt with just one cyber incident.   The first thing to do is categorize the major challenges. “Broad categories of concern can include 1) prevention, 2) detection, 3) legal compliance and timely notice to all stakeholders, 4) equipment and network repair, and 5) insurance liability coverage. By doing this companies can ask themselves questions and see where the most need lies for the least expense.  There are multiple ways for a company to protect themselves in case of a data breach, and security planning is just one idea at the top of most priority lists. Another possibility is to see if the business can quality for cyber-crime insurance. “The package policy known as the Business Owners Policy (BOP) that is often purchased by medium- and smaller- sized businesses usually includes coverage for electronic data loss” (Hewes, 2016). This could be of great help to those in need of some kind of safety net which could keep the business in tact in case of a data breach.

This article covered a wide range of topics starting with what is cyber-crime and ending with if your business could get insurance coverage for data breaches.  It was full of very insightful information and I encourage you all to take a look at it.

Hewes, C. A. (2016). Threat and Challenges of Cyber-Crime and the Response. SAM Advanced Management Journal , 4-10.

Reply needed 3

My article is called "Locky Ransomware Spreading Via Facebook, LinkedIn"

According to U.S. Attorneys (2016), Cybercrime is one of the greatest threats facing our country and has enormous implications for our national security, economic prosperity, and public safety. Cybercrimes are criminal offenses committed by means of the Internet and otherwise assisted by various forms of computer technology, such as the use of online social networks to bully others, online fraud, or identity theft. Victims may feel powerless and upset that their privacy has been violated.

Security researchers have discovered ransomware being spread through images and graphic files being shared on social networking sites including Facebook and LinkedIn (Evans, 2016). The threat actors figured out how to misuse a misconfiguration contained inside the design of these sites that could purposely constrain clients to download the noxious document. Among the malware being circulated is the scandalous Locky ransomware. Check Point analysts have named this new assault vector ImageGate. Late measurements from Check Point uncovered that Locky represented 5% of aggregate worldwide assaults spotted amid the month of October, making it the second most common piece of malware right now.

The head of Check Point’s Products Vulnerability Research said that given the ubiquity of social networking communication destinations like Facebook and LinkedIn, it is not astounding that threat actors are centering their endeavors to these sites. These threat actors comprehend these sites are normally 'white listed', and hence, they are consistently scanning for new methods to utilize web-based social networking as hosts for their malignant exercises.

Check Point included that it will discharge additional insights about the vulnerability once the influenced sites affirm they have settled the imperfection. Keeping in mind the end goal to better shield yourself from these sorts of assaults, users are warned to never download connections from individuals they do not know, or open connections that resemble a picture, however, contain an uncommon filename expansion.

 

Reference:

Evans, S. (2016). Locky Ransomware Spreading Via Facebook, LinkedIn. Infosecurity Magazine. Retrieved 30 November 2016, from http://www.infosecurity-magazine.com/news/locky-ransomware-facebook-linkedin/

U.S. Attorneys. (2016). Cyber Crime | USAO | Department of Justice. Justice.gov. Retrieved 30 November 2016, from https://www.justice.gov/usao/priority-areas/cyber-crime

Reply needed 4

We are implementing a new application where I work and this is how we have gone about it so far.

I work for a state run community college. We have recently been told we need to update the legacy ELS testing applications to a new application. As you can guess this has cause a lot of up roar. During a fall training, we were informed of the Switch to the legacy testing application.  We were told the testing center would be incorporating this application into our testing protocols and if we had questions, we needed to ask them now. Why? Because they were already doing the first round of testing on the application. After several questions where written down, we were told that we would get an in-depth training after fall finals were over and we had a short period of slow time. Then we were told the information would be incorporated into our winter training.  However, the new application, titled the Accuplacer, was going to start in the middle of December with or without training the staff. “training refers only to informing personnel of their roles and responsibilities within a particular IT plan and teaching them skills related to those roles and responsibilities.” (National Institute of Standards and Technology NIST, 2010) We began to feel we were not prepared for the switch for the new technology. “Training personnel on their roles and responsibilities before an exercise or test event is typically split between a presentation on their roles and responsibilities, and activities that allow personnel to demonstrate their understanding of the subject matter.” (National Institute of Standards and Technology NIST, 2010) According to this NIST definition the employees of the testing center had a right to be concerned.  

 The employees of the testing center, along with the mid-level supervisor, met together, in their separate units, and arrived at the conclusion that staff did not want to be to be administering a test without the proper training. This conclusion sent all the mid-level supervisors back to the upper lever supervisor to have her reschedule the roll out of the New technology until after we were properly trained to administer the test.  The technology is now in a holding pattern until training can be accomplished.  In this case, upper management listened and reacted properly. 

National Institute of Standards and Technology NIST. (2010). Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities. Washington DC: NIST.

Reply 5 needed

Oracle Buys Dyn Despite Massive Recent DDoS Attack

Oracle reported this month, November 21, 2016, that it has consented to an arrangement to procure Dyn, the main cloud-based Internet Performance and DNS supplier that controls, monitors, and enhances Internet applications and cloud services to convey quicker access, decreased page slack times, and higher end-user fulfillment.

Dyn’s network was attacked last month in a Distributed Denial of Service (DDoS) attack that took down sites like Twitter, Spotify and CNN for millions of users. Even with an attack from threat actors, Dyn’s solutions will be integrated into Oracle’s Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) platforms (Blackmon, 2016).

Oracle expressed in an announcement that Dyn has a decent arrangement of significant worth to convey to the table and even with the attack the merger will go through. Dyn drives 40 billion traffic optimization decisions day by day for more than 3,500 venture clients, which incorporate computerized brands, for example, Netflix, Twitter, Pfizer and CNBC.

Thomas Kurian, President of Product Development has stated that Oracle already offers enterprise-class IaaS and PaaS for companies building and running Internet applications and cloud services (Blackmon, 2016). Dyn's immensely versatile and worldwide DNS is a critical center part and a characteristic expansion to Oracles cloud computing platform and despite the attack from threat actors the Dyn team brings significant knowledge and capabilities to Oracle and will further extend the value Oracle Cloud brings to market.

This arrangement between the two enterprises will meet end users' developing requests for customized applications that convey one of a kind client encounters, the capacity to construct responsive and completely associated applications and an arrangement of versatile, incorporated framework services.

With an open letter to customers and partners, Dyn’s global, scalable DNS will complement Oracle’s cloud computing offerings. End-users’ will be capable of accessing internet performance data to help optimize infrastructure costs, maximize application and website-driven revenue and manage risk. In reality, it is a one-stop shop for complete Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS).

Reference:

Blackmon, K. (2016). Oracle Buys Dyn Despite Massive Recent DDoS Attack. Thevarguy.com. Retrieved 30 November 2016, from http://thevarguy.com/information-technology-merger-and-acquistion-news/oracle-buys-dyn-despite-massive-recent-ddos-attack

Reply 6 needed

Based on what you've learned this week, what are three things that you could improve as you practice your interviewing skills?  Be specific and cite specific examples from your reading or the videos this week. Why do you think you struggle in those areas?

The biggest problem that I need to overcome is my nerves. It is something that I have always dealt with badly. I know that I need time to settle in I'm always extremity early person. I hate running late for things it drives me crazy when I'm late. The video was helpful to say find things to help you relax before the interview. For me I will listen to music and drink some caffeine before the interview.

The next is I need to be clear and detailed for my answer. I use little words as possible as I'm straight to the point type of communicator so I will need to expand my answers but still not be overly fluffy. Even in the classes I have taken I have always had a hard time expanding my answers to the word requirements.

The last is how I dress. I have not had to interview in 20 years and I need to get the right dress for this part as my NWU's will not be the correct choice.  

Lee

Reply 7 needed

The following are some of the areas I need to improve as I practice my interviewing skills:

· Research potential employer: Even though I have been aware for a while that it is good to research a potential employer prior to reporting for an interview, I did not attach too much importance to it. I have always thought if one shows up for an interview with the experience that match the job posting obviously, the person is interested in the job. But now, I know that not being equipped with the information would make me look like I am uniformed or even not quite interested in gaining the employment.

· Learn to apply information about the company in my responses during interviews: This is another aspect that I definitely need to practice. My reason for saying this is that since one would not necessarily know the questions that will be asked during an interview, the idea is to be prepared to think quickly and identify how to accurately incorporate findings as applicable in responses.

· Interview Stress Management: For some reason, immediately prior to and during interviews, I tend to experience nervousness. This is not good because the interviewer could interpreted it in multiple ways including as lack of confidence. I have to learn to stay calm including taking breathing exercise.  

Ngozi