04.10.2016 Views

SEC 280 Principles of Information Systems Security Case Studies

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>SEC</strong> <strong>280</strong> <strong>Principles</strong> <strong>of</strong> <strong>Information</strong> <strong>Systems</strong> <strong>Security</strong> <strong>Case</strong><br />

<strong>Studies</strong><br />

https://hwguiders.com/downloads/sec-<strong>280</strong>-principles-<strong>of</strong>-information-systems-security-case-studies/<br />

EC <strong>280</strong> <strong>Principles</strong> <strong>of</strong> <strong>Information</strong> <strong>Systems</strong> <strong>Security</strong> <strong>Case</strong> <strong>Studies</strong><br />

<strong>SEC</strong> <strong>280</strong> Week 1:<br />

Your boss has just heard about some nefarious computer activities called ping sweeps and port<br />

scans. He wants to know more about them and what their impact might be on the company.<br />

Write a brief description <strong>of</strong> what they are, and include your assessment <strong>of</strong> whether the activities<br />

are something to worry about or not. This assignment requires two to three pages, based upon the<br />

APA style <strong>of</strong> writing.<br />

<strong>SEC</strong> <strong>280</strong> Week 2:<br />

You are the <strong>Information</strong> <strong>Security</strong> Officer at a medium-sized company (1,500 employees). The<br />

CIO asks you to explain why you believe it is important to secure the Windows and Unix/Linux<br />

servers from known shortcomings and vulnerabilities. Explain to your CIO what you can do to<br />

make sure the network infrastructure is more secure.


<strong>SEC</strong> <strong>280</strong> Week 3:<br />

ABC Institute <strong>of</strong> Research has sensitive information that needs to be protected from its rivals.<br />

The Institute has collaborated with XYZ Inc. to research genetics. The information must be kept<br />

top secret at any cost. At ABC Institute, the researchers are unsure about the type <strong>of</strong> key<br />

(asymmetric or symmetric) to use. Please formulate a possible solution, and describe the<br />

advantages and disadvantages <strong>of</strong> any solution employed.<br />

<strong>SEC</strong> <strong>280</strong> Week 4:<br />

Computer security is not an issue for organizations alone. Anyone whose personal computer is<br />

connected to a network or the Internet faces a potential risk <strong>of</strong> attack. Identify all the potential<br />

security threats on a personal computer. Identify some <strong>of</strong> the techniques an attacker might<br />

employ to access information on the system.<br />

<strong>SEC</strong> <strong>280</strong> Week 5:<br />

You have just been hired as an <strong>Information</strong> <strong>Security</strong> Engineer for a large, multi-international<br />

corporation. Unfortunately, your company has suffered multiple security breaches that have<br />

threatened customers’ trust in the fact that their confidential data and financial assets are private<br />

and secured. Credit-card information was compromised by an attack that infiltrated the network<br />

through a vulnerable wireless connection within the organization. The other breach was an inside<br />

job where personal data was stolen because <strong>of</strong> weak access-control policies within the<br />

organization that allowed an unauthorized individual access to valuable data. Your job is to<br />

develop a risk-management policy that addresses the two security breaches and how to mitigate<br />

these risks.


<strong>SEC</strong> <strong>280</strong> Week 6:<br />

Gem Infosys, a small s<strong>of</strong>tware company, has decided to better secure its computer systems after<br />

a malware attack shut down its network operations for 2 full days. The organization uses a<br />

firewall, three file servers, two Web servers, one Windows 2008 Active Directory server for user<br />

access and authentication, ten PCs, and a broadband connection to the Internet. The management<br />

at Gem needs you to formulate an incident-response policy to reduce network down time if<br />

future incidents occur. Develop an incident-response policy that covers the development <strong>of</strong> an<br />

incident-response team, disaster-recovery processes, and business-continuity planning.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!