Provide a (Problem Specification) for "Investigating Network Security Challenges and Solution to protecting data"
Added by Amy J.
Step 1
- State primary goals: improve data confidentiality, integrity, and availability; reduce incident response time; and provide auditable compliance with relevant regulations. - Identify the desired end-state: a robust, scalable security posture with measurable Show more…
Show all steps
Your feedback will help us improve your experience
Akash M and 77 other AP CS educators are ready to help you.
Ask a new question
Labs
Want to see this concept in action?
Explore this concept interactively to see how it behaves as you change inputs.
Key Concepts
Recommended Videos
You work for the head of the IT department at a small software company with 475 employees in two offices. The company does not have a formal data security plan, even though they perform many important security-related tasks. Your boss asks you to draft a plan and present it to him or her. Think about security and the type of information that may need to be included in a plan for a company of this size. Consider the following information: - Each employee uses one computer. - Employees are connected via a local area network. - The upper management team includes seven (7) individuals. - The finance team includes four (4) individuals. - The human resources (HR) department includes ten (10) individuals. - There are twenty-two (22) individuals on the customer service team. - There are twenty (20) individuals who are office support staff. - The remaining staff are designers, testers, programmers, and engineers. - In addition to one computer each, the designers, testers, programmers, and engineers share the use of several servers and dedicated computers to test the software they design. - The upper management, finance, and human resources team also use mobile devices to access company information. No one else is supposed to use mobile devices to connect to the company network or conduct company business. Write a data security plan of at least 1,000 words. Include the following sections: 1. Types of data used by individuals in the company (e.g., financial information, personnel data, customer details, correspondence) 2. List of individuals by team (e.g., finance team, HR team) with access to specific types of data 3. Physical location of the data, servers, and other system hardware. Include a description of physical security measures at these locations (e.g., locks on the doors, security personnel) 4. Number of computers, servers, and general layout of the system and network 5. Security settings for the computers and network (e.g., network firewall, password protection) 6. Backup procedures - which computers, how often, where the data is stored, how it is kept secure, and how long backups are retained Use your best judgment in defining each of these sections. The information you use does not have to match a real-world company, but it does need to be consistent within the entire security plan you create.
Akash M.
You are a cybersecurity specialist for a large oil and gas field services firm that frequently develops its own software. The company has over 150 locations globally and has outsourced a major portion of its IT and software development to India. All of these locations, including those in India, are on the same internal network for ease of access, even though many of them are contractors. You have been assigned the task of testing a new application to ensure that there are no security issues with it prior to go-live. Application details The purpose of the new application is to track the movement of all of the company’s trucks (semis) throughout the United States 24/7. Each truck will have a transponder that will report its location, speed, direction, and cargo (among other things). Users will be able to set a variety of filters based on what they’re looking for. The four main cargo types are all used in the hydraulic fracturing (aka “fracking”) process. They are wastewater, chemicals, explosives, and radioactive materials. The application will be hosted internally and will NOT be accessible via the Internet. However, any authenticated user on the internal network will be able to access it. A small number of employees will have admin privileges to it. Management is anxious to have this application go live so they can start saving money by making the routes more efficient. They see no issues with this application as it’s pretty simple in their eyes, so they are expecting you to provide the security approval fairly quickly. Here are the review tasks you must follow per company policy: 1. Create a test plan for testing this application a. Feel free to use the example included with this project as a template. 2. Create test cases 3. Create test cycles As you perform these tasks, be sure to include the following: ● Potential team members and what role they will play in the process. Don’t forget that some members may not be in IT. ● Accounts and access needed ● Specialized tools ● Documentation, and where it will reside ● Recording of results (how) ● Logging of bugs ● Justify why you chose a particular testing approach or methodology ● Identify risks associated with the design of the application, and recommend solutions. For example, if you believe that there is an access or authorization issue, then document the issue, the risk it poses, and recommendation(s) to fix it.
Web/FTP Business Domain Mail Server VPN Server Server Servers Controller Secondary Users Historian Workstations The Internet Corporate Network Control Network accessible Directly from business network Data Acquisition Database Server Primary Configuration Server Server Historian Workstations Users Control System Network Field Controllers Safety System Vendors AMI Terminal Server Field Devices Modem Bank
Recommended Textbooks
Computer Science and Information Technology
Introduction to Programming Using Python
Computer Science - An Overview
Transcript
Watch the video solution with this free unlock.
EMAIL
PASSWORD