Security Systems

Submitted by: Submitted by

Views: 44

Words: 726

Pages: 3

Category: Science and Technology

Date Submitted: 03/17/2015 07:49 PM

Report This Essay

BCIS 6370.27 Assignment 4 (30 Pts)

Due at 10:00 PM Central (LMS)

Topics: Risk Management

Answer (with detailed responses and substantial rationale) the following 4 questions. If an organization must evaluate the following three information assets for risk management, which vulnerability should be evaluated first for additional controls? Which should be evaluated last? o Switch L47 connects a network to the Internet. It has two vulnerabilities: it is susceptible to hardware failure at a likelihood of 0.2, and it is subject to an SNMP buffer overflow attack at a likelihood of 0.1. This switch has an impact rating of 90 and has no current controls in place. You are 75 percent certain of the assumptions and data. o Server WebSrv6 hosts a company Web site and performs e-commerce transactions. It has a Web server version that can be attacked by sending it invalid Unicode values. The likelihood of that attack is estimated at 0.1. The server has been assigned an impact value of 100, and a control has been implanted that reduces the impact of the vulnerability by 75 percent. You are 80 percent certain of the assumptions and data. o Operators use an MGMT45 control console to monitor operations in the server room. It has no passwords and is susceptible to unlogged misuse by the operators. Estimates show the likelihood of misuse is 0.1. There are no controls in place on this asset; it has an impact rating of 5. You are 90 percent certain of the assumptions and data.

-

What is risk management? Why is the identification of risks and vulnerabilities to assets so important in risk management? According to Sun Tzu, what two key understandings must you achieve to be successful in battle? Who is responsible for risk management in an organization? Which community of interest usually takes the lead in information security risk management?

-

-

© Dr. Isaac Gang – Assignment 4

Case Exercise As Charlie wrapped up the meeting, he ticked off a few key reminders...