Unit 6 Assignment (4- to 6-pages)

Application: Web Servers and Security Development Life Cycle
Web servers often receive confidential customer information at the front end and store it at the back end. Attackers can gain access to such information by attacking the front end, the back end, or both. Both the front end applications and the back end database need to be secured. Intruders can cause serious damage to the customers whose information is stored in the server, and thus can result in causing damage to the organization.
The Microsoft Security Development Lifecycle (SDL) is an example of how an organization can develop applications in a secure way and ensure that code updates and newly discovered vulnerabilities are dealt with appropriately to manage risk. The SDL emphasizes making security an integral part of the software development lifecycle (SDLC).
Consider the following scenario: At your company, web servers on the Internet allow customers to access a consumer web application for retail purchases. The web servers run Microsoft IIS software and use a back-end SQL database that stores confidential, personally identifiable information about the users of the application. However, the company is not satisfied with the security of the current software and the database and wants to develop them in-house for enhanced security. Based on your reading and additional research, write a 4- to 6-page paper recommending security tools and processes to manage your company’s web application. Cover the following points:
• Explain two possible attack scenarios on the web servers. Explain the potential damages from each of the attacks.
• Clarify how and where your company can incorporate security measures into the SDLC to achieve these goals:
o Develop more secure applications
o Audit application security
o Keep applications secure in light of newly discovered vulnerabilities and threats

Unit 6 Learning Resources

This page contains the Learning Resources for this unit. Be sure to scroll down the page to see all of this unit’s assigned Learning Resources.
In Unit 6, you will use a variety of resources. This page outlines the resources that you will need to participate in the Discussion and to complete the Assignment.
Required Resources
Readings
• Stallings, W., & Brown, L. (2017). Computer security: Principles and practice (4th ed.). Upper Saddle River, NJ: Pearson.
o Chapter 5, “Database and Data Center Security”

In this chapter, you are introduced to the concept of database security. You will learn about the security issues involved with database systems, approaches to database access control, use of encryption in a database system, and security issues related to cloud computing.
o Chapter 11, “Software Security”

In this chapter, you are introduced to code vulnerabilities in software development. You will learn about detailing potential points of vulnerability in an abstract view of a program, defensive programming, and security concerns from the interaction between programs and O/S components.
o Chapter 19, “Legal and Ethical Aspects” (19.1–19.2)

In this chapter, you are introduced to the significant legal and ethical issues associated with computer security. You will learn about computer crimes, intellectual property, and privacy issues.
• Chebyshev, V., Sinitsyn, F., Parinov, D., Liskin, A., & Kupreev, O. (2018). IT threat evolution Q1 2018. Statistics. Retrieved from https://securelist.com/it-threat-evolution-q1-2018-statistics/85541/

This webpage provides statistics regarding different categories of security violation outbreaks and web threats.
• Microsoft. (2012). Microsoft security development lifecycle. Retrieved from http://www.microsoft.com/security/sdl/default.aspx

This webpage provides a brief definition of Security Development Life Cycle and provides links to pages explaining each stage of the Security Development Life Cycle.

Unit 7 Assignment (4- to 6-pages)

Application: Managing Electronic Transactions Through Mobile Devices
Mobile devices offer quick access to resources and enable electronic transactions from practically anywhere. The emergence and evolution of mobile devices have opened up a new domain of security concerns: mobile security. Mobile devices, if not properly secured, can cause great damage to the user and to the user’s organization.
Consider the following scenario: You are the manager of IT for a fast growing company. The company plans to take advantage of cutting edge technology as one of its competitive approaches to gain market share. It is planning to equip its sales people with mobile devices to take orders from customers. In addition, it is planning to enable its delivery and installation people to process credit card payments from customers upon delivery and installation of the systems, through a wireless credit card payment processing system.

The company recognizes that there are security issues related to electronic transactions using mobile devices. Every time an employee submits a transaction, the information is transferred from the mobile device to the appropriate department over an Internet connection. The company is also concerned that the personal use of company mobile devices will put them at greater risk of malware and other forms of compromise. Loss of sensitive consumer information can result in loss of reputation and potentially lead to legal actions against the company.

The Chief Information Officer (CIO) of the company has asked you to find a way to use mobile devices, in a secure way, to prevent data leakage.

For this Assignment, based on your readings and through additional research, prepare a 4- to 6-page proposal that describes and evaluates applicable security management solutions for the company. Include the following points:
• Explain the security threats the employees’ mobile devices may be subjected to. For threats pertaining to electronic transactions, explain countermeasures.
• Based on the best practices for mobile security, describe which of these countermeasures you believe would be most effective. Justify your choices.
• Propose a security management solution that meets the business requirements. Include tools, processes, and policies required to implement the solution

Unit 7 Learning Resources

This page contains the Learning Resources for this unit. Be sure to scroll down the page to see all of this unit’s assigned Learning Resources.
In Unit 7, you will use a variety of resources. This page outlines the resources that you will need to participate in the Discussion and to complete the Assignment.
Required Resources
Readings
• Glynn, F. (2012). A CISO’s guide To application security – Part 1: Defining AppSec. Retrieved from https://threatpost.com/cisos-guide-application-security-part-1-defining-appsec-041012/76421/

In this article, the author prescribes different measures to combat mobile malware threats.
• Juniper Networks. (2012). Security intelligence center. Retrieved from http://www.juniper.net/us/en/security/

In this webpage, you come across small news reports about a few aspects of mobile threats.
• Lai, E. (2010, December 20). Forrester’s top 20 mobile device management best practices for enterprises. ZDNet. Retrieved from http://www.forbes.com/sites/sap/2010/12/20/forresters-top-20-mobile-device-management-best-practices-for-enterprises/

In this blog article, the author suggests some important prescriptive measures to combat against mobile threats.
• Lookout Mobile Security. (2011, August). Mobile threat report. Retrieved from https://www.lookout.com/resources/reports/mobile-threat-report

In this report, you are presented with a detailed analysis of different categories of current mobile threats and potential future trends.
• McAfee. (2018). McAfee Labs Threats Reports: Insights into malware, ransomware, and other cybersecurity threats from the McAfee threat research team. Retrieved from https://www.mcafee.com/enterprise/en-us/threat-center/mcafee-labs/reports.htm

Unit 8 Assignment (4- to 6-pages)

Application: Incident Response

Even with the best security system, an organization’s information systems are never fully safe from outside attacks or malicious activities from insiders. As a result, an organization must be prepared to take curative measures when an incident occurs. As a security professional, you should have knowledge and expertise in incident response and should be able to explain the necessity of incident response systems to the higher management.
For this Assignment, select an arbitrary organization. You may choose one with which you are familiar, but you do not need to disclose its identity. Assume you are the IT security manager. You frequently find traffic to and from suspicious websites which could indicate malware, a configuration problem, or misuse. You think that, as a starting point, having an incident response plan in place would be beneficial. You decide to submit a proposal to your CEO.

Based on your readings and through additional research write a 4- to 6-page proposal to the CEO. Use this as an outline for your proposal:
Begin your proposal by briefly describing the organization and its nature of functions. Again, if it is one with which you are familiar, you do not need to identify it.

Your proposal should include the following sections:
1. Incident Response Plan Details:
• Explain the benefits of an incident response plan.
• Identify and explain with reasonable details the steps to isolate, respond, and recover after an attack (incident) is discovered.
• Identify the teams that should be involved in the incident response process. Explain their roles.
2. Incident Communication Requirements:
• Identify and explain the type of communication and reporting to different internal stakeholders that will be necessary after you have discovered an attack.
• What are the legal, ethical, and other considerations if personal customer data has been stolen?
• Considering the breach laws in your home country, at which point would you disclose such a breach to law enforcement and communicate with customers?

Unit 8 Learning Resources

This page contains the Learning Resources for this unit. Be sure to scroll down the page to see all of this unit’s assigned Learning Resources.
In Unit 8, you will use a variety of resources. This page outlines the resources that you will need to participate in the Discussion and to complete the Assignment.
Required Resources
Readings
• Stallings, W., & Brown, L. (2017). Computer security: Principles and practice (4th ed.). Upper Saddle River, NJ: Pearson.
o Chapter 8, “Intrusion Detection”

In this chapter, you are introduced to the concept of “Intrusion”: the act of trespassing into a system. You will examine the intruders and the different intrusion detection principles and methods.
o Chapter 9, “Firewalls and Intrusion Prevention Systems” (9.6–9.9)

In this chapter, you are introduced to the concept of firewalls. You will explore the need for firewalls, their characteristics, and their functions as security solutions.
o Chapter 18, “Security Auditing”

In this chapter, you are introduced to the concept of security auditing. You will examine security audit architecture, security audit trails, and considerations when implementing security logging.
• Global Justice Information Sharing Initiative Security Working Group. (2004). Applying security practices to justice information sharing. Retrieved from https://it.ojp.gov/documents/200404_ApplyingSecurityPractices_v_2.0.pdf
o Chapter 2, “Security Disciplines” (Objective 3: Detection and Recovery)

In this article, the author discusses in detail the concepts of Intrusion Detection Systems, Critical Incident Response, Security Auditing, and Disaster Recovery.
• Sayana, S. A. (2003). Approach to auditing network security. Information Systems Audit and Control Association, 5.

In this article, the author provides an overview of network vulnerabilities, control mechanisms, important considerations for auditing network security, and evaluation of protection mechanisms.

Did you know that effective analysis of concepts requires professionalism in handling academic research Papers? Do no compromise on your grade choose professional Research writers at elitetutorslab.com

error: Content is protected !!