Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, 31 March 2014

Discussion Question 10: A bank in California has 13 branches spread throughout northern California, each with its own minicomputer where its data are stored. Another bank has ten branches spread throughout California, with the data being stored on a mainframe in San Francisco. Which system do you think is more vulnerable to unauthorized access? Excessive losses from disaster?

Discussion Question 15: An organization’s internal audit department is usually considered an effective control mechanism for evaluating the organization’s internal control structure. Birch Company’s internal auditing function reports directly to the controller. Comment on the effectiveness of this organizational structure.

Problem 2 INTERNAL CONTROL Required: Identify the control weaknesses present and make a specific recommendation for correcting each of the control weaknesses.

CLICK HERE to get this paper!!

Problem 5 DISASTER RECOVERY PLAN:
Required:
a. Describe the computer security weaknesses present at Hill Crest Corporation that made it possible for a disastrous data loss.
b. List the components that should have been included in the disaster recovery plan at Hill Crest Corporation to ensure computer recovery within 72 hours.
c. What factors, other than those included in the plan itself, should a company consider when formulating a disaster recovery plan?

Problem 6: Per the article The Kiss of Identity Theft – Password Simplicity and Redundancy, which of the following statements is true?
I. Hackers who use powerful computers can break passwords containing dictionary words 100 times faster.
II. Adding just one capital letter and one asterisk would change the processing time (for a hacker) from 2.4 days to 2.1 centuries.

Both are true.
Neither are true.
I.
II.

CLICK HERE to get this paper!!

Review Question 1: Why is human behavior considered one of the biggest potential threats to operating system integrity?

Review Question 2: Why would a systems programmer create a back door if he or she has access to the program in his or her day- to- day tasks?

Chapter 16 Problem 4 INTERNAL CONTROL AND FRAUD
Required:
a. What weaknesses in the organization’s control struc-ture must have existed to permit this type of embez-zlement?
b. What specific control techniques and procedures could have helped prevent or detect this fraud?

Chapter 16 Problem 6 PREVENTIVE CONTROLS Listed here are five scenarios. For each scenario, discuss the possible damages that can occur. Suggest a pre-ventive control.
a. An intruder taps into a telecommunications device and retrieves the identifying codes and personal identification numbers for ATM cardholders. ( The user subsequently codes this information onto a magnetic coding device and places this strip on a piece of cardboard.)
b. Because of occasional noise on a transmission line, electronic messages received are extremely garbled.
c. Because of occasional noise on a transmission line, data being transferred is lost or garbled.
d. An intruder is temporarily delaying important strategic messages over the telecommunications lines.
e. An intruder is altering electronic messages before the user receives them

Wednesday, 19 February 2014

Implementation plan for your organization

Resource: Implementation Plan Template

Create an implementation plan for your organization, one of the Virtual Organizations, or a project from the websites such as challenge.gov or a state RFP site.

Include the following:

⦁ Business strategies for implementation
⦁ Both technology- and human-based safeguards used for information systems
⦁ Information comparing security requirements of out-sourcing and in-sourcing
⦁ Comparison of technical, user, and system training documentation
⦁ Timelines and the need for their accuracy
⦁ Reference page


Implementation Plan Template
Use the following template to create your implementation plan in Week Four.

Project Name or Identification: 

Project Stakeholders
· Names
· Titles or roles
· Contact information 

Project Description 

· Background
· Description of the challenge or opportunity
· Overview of the desired impact

Measurable Organizational Value (MOV)

· Project’s overall goal and measure of success

· What elements of the project provide value to the organization?

· ROI (return on investment) and cost versus benefit

· Statement or table format 

CLICK HERE to get this paper!!

Project Scope

· What will be included in the scope of this project?

· What will be considered outside the scope of this project?

· What are the project’s main deliverables?

· Provide a statement and description.

Project Schedule Summary

· Project start date

· Project end date

· Timeline of project phases and milestones

· Project reviews and review dates

CLICK HERE to get this paper!!

Project Budget Summary

· Total project budget

· Budget broken down by phase

Quality Issues

· Specific quality requirements

Resources Required

· People

· Technology

· Facilities

· Other

· Resources to be provided

o Resource

o Name of resource provider

o Date to be provided


CLICK HERE to get this paper!!
Assumptions and Risks

· Assumptions used to develop estimates

· Key risks, probability of occurrence, and impact

· Organizational or time constraints

· Risks of not doing this project

· Assess dependencies on other projects or areas within or outside the organization

· Assessment project’s impact on the organization

· Outstanding issues

· Formulation of key project risk mitigation strategies

Project Administration

· Communications plan

· Scope management plan

o The change control process

· Quality management plan

o Testing procedures related to the implementation

· Change management plan

· Human resources plan 

CLICK HERE to get this paper!!

Implementation and Continued Maintenance and Project Closure Plan

· What data or existing format will need to be changed?

· What production systems will be handled?

· What downtime will be needed?

· How will the integration be communicated?

· How will the new system be deployed (pilot, phased, parallel, plunge, and so on)?

· Support and maintenance

o Technical, user, and system training documentation

o System support roles and functions

· Project closure

Acceptance and Approval

· Names, signatures, and dates for approval

· The implementation plan approval processes associated with sponsors and stakeholders 

References

Terminology or Glossary

Appendices (as necessary)

Friday, 14 February 2014

CIS-505 WEEK10 DISCUSSION 2

Computer Security. Please respond to the following:
From the e-Activity, discuss two security issues related to the researched technologies.
Select a Wi-Fi device you are familiar with and analyze the security protection currently implemented on the device. Speculate whether the protection on the selected device is sufficient for the data it contains.


CLICK HERE to get this paper!!

CIS-505 WEEK 10 DISCUSSION 1

CIS-505 WEEK 10 DISCUSSION 1

Employee Monitoring. Please respond to the following:
Take a position on the ethical concerns raised by employees who are upset about organizations monitoring their email or Internet access for security purposes. Assess whether you believe it is fair for an employee to undergo this type of surveillance.
Suggest an alternative approach for an organization to control security without monitoring employee actions.

Assignment 3: Cybersecurity

Due Week 9 and worth 50 points

Cybersecurity is such an important topic today and understanding its implications is paramount in the security profession. Compliance, certification, accreditation, and assessment are critical in understanding the legal and ethical procedures to follow as a security professional. In support of cybersecurity initiatives, the National Initiative for Cyber Security Education (NICE) has published several initiatives in regard to protecting national security. The following document titled, “National Initiative for Cybersecurity Education”, located at , will be used to help you complete the assignment.

CLICK HERE to get to this paper!!

Write a three to five (3-5) page paper in which you:
Examine the National Initiative for Cyber Security Education and describe the initiative.
Assess the value of the NICE framework. Discuss the importance of this framework in regard to the security profession and individual organizations.
Suggest three (3) examples that illustrate the importance of the National Initiative for Cyber Security Education initiative.
Describe the expected outcomes of this initiative.
Evaluate how organizations can implement the NICE framework to prevent internal and external attacks.
Determine how the NICE framework addresses the legal and ethical issues in the field of information security.
Use at least three (3) quality resources outside of the suggested resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources.

Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; citations and references must follow APA or school-specific format. Check with your professor for any additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the professor’s name, the course title, and the date. The cover page and the reference page are not included in the required assignment page length.
The specific course learning outcomes associated with this assignment are:

CLICK HERE to get to this paper!!

Evaluate and explain from a management perspective the industry-standard equipment, tools, and technologies organizations can employ to mitigate risks and thwart both internal and external attacks.
Describe the legal and ethical issues inherent in information security.
Use technology and information resources to research issues in security management.
Write clearly and concisely about the theories of security management using proper writing mechanics and technical style conventions.