Project 1: Security Models
Step 1: Review the Assigned Organization
All four projects for this course will be completed from the vantage point of a specific industry and an organization assigned to you by the instructor. If you do not know your assigned organization, contact your instructor immediately. If you want to use another organization than the one assigned you or one not listed, contact your instructor as well.
Familiarize yourself with the organization and breach your instructor has assigned by reviewing the details at https://www.databreaches.net/. The descriptions include an overview and key information about the organization on the internet, as well as information about a breach or attempted breach. For the purposes of this course, you will assume this organization is your employer.
You may wish to briefly research your assigned organization to gather additional information about the organization and its security posture.
Step 2: Write a Cybersecurity Background Summary
In Step 1, you familiarized yourself with your assigned organization. Now, it is time to write a cybersecurity overview. Write a three-page background summary that includes a general overview of cybersecurity and a section on enterprise cybersecurity.
Include the following items in the general overview of cybersecurity:
- Compare and contrast cybersecurity and computer security.
- Discuss data flows across networks. As part of this discussion, it may help to review the following topics: binary digits, nontextual data, ASCII, hexadecimal, computer networks, network devices and cables, and network protocols.
- Discuss basic cybersecurity concepts and vulnerabilities, including flaws that can exist in software. As part of this discussion, it may help to review the following topics: systems, utilities, and application software, software, interaction of software, and creating a program.
- Discuss common cybersecurity attacks. Helpful topics include protocols, web sessions, and security issues, servers and firewalls, a closer look at the World Wide Web and web markup language, cyberattacks, and attack vectors.
- Discuss penetration testing.
- Discuss how to employ network forensic analysis tools (NFAT) to identify software communications vulnerabilities.
Include the following items in the enterprise cybersecurity section:
- List and discuss the major concepts of enterprise cybersecurity, including confidentiality, integrity, and availability (CIA)
- Discuss the principles that underlie the development of an enterprise cybersecurity policy framework and implementation plan.
- List the major types of cybersecurity threats that a modern enterprise might face.
You will attach this cybersecurity background summary to the security assessment in a later project step.
Submit the cybersecurity background summary for feedback.
Step 3: Analyze Security Weaknesses
After writing the cybersecurity background summary, you are ready to analyze the security weaknesses of your assigned organization. When analyzing cybersecurity weaknesses, there are several areas to consider.
Analyze the organization’s security from the following perspectives:
- a technology perspective
- a people perspective
- a policy perspective
You will include this information in the security assessment. In the next step, you will consider risk factors.