icon
×

Cybersecurity Strategy and Response

Assignment 1

My company’s critical assets include information assets, software assets, services, and physical assets. Information assets such as databases and operational procedures may be attacked through unauthorized access to the company’s information system. Software assets, which include system and application software, may be attacked through malicious software propagated by system attackers. The company’s services, such as communication and computing services, may be attacked through Denial of Service (DoS) attacks. Physical assets such as communication equipment, computer equipment, and storage media may be attacked through vandalism or theft (Holt, Bossler, & Seigfried-Spellar, 2015).

The company’s critical partners can be categorized into internal and external partners. Internal partners include members of the IT leadership team and IT technicians. External partners include Internet Service Providers (ISPs), vendors, and IT consultants. Members of the IT leadership team play the role of supervising the use of IT resources. IT technicians maintain information systems for optimum performance. ISPs are responsible for providing the company with secure, reliable, and fast Internet services. Vendors supply the company with IT systems, including software and hardware. IT consultants provide guidance on the adoption and implementation of effective, secure, and robust information systems within the company. Both internal and external partners should collaborate to ensure that IT resources are effectively managed (Bulgurcu, Cavusoglu, & Benbasat, 2010).

Attack surface refers to the software environment that is predisposed to unauthorized access by system attackers. The attack surface specifically refers to points within the company’s information system through which attackers may maliciously gain entry or use to extract data. The company’s attack surface includes servers, open ports, online services, Internet access points, web forms, user interface, and employees who possess sensitive information. Weaknesses or loopholes in any of the components of the company’s attack surface predispose it to hacking or system attacks from either the internal or external environment (Yang, Geng, Du, Liu, & Han, 2011).

Place your order

The types of attackers the company should watch include internal and external attackers. Internal attackers include employees who may enter the company’s information system without being authorized or with malicious intent. External attackers include hackers into the system from the external environment who either seek to steal sensitive information or to compromise the integrity of the company’s information system (Holt et al., 2015).

The types of attacks the company may encounter include passive and active attacks. Passive attacks often target the company’s network. They include wiretapping, idle scan, and port scan. Active attacks aim at altering or affecting system operations. They include spoofing, DoS attacks, host attacks, and network attacks (Egele, Scholte, Kirda, & Kruegel, 2012).

The company should respond to system attacks by minimizing their severity. Security policies and procedures should also be implemented to ensure that the number of security attacks and incidents is minimized. Routine checks of network devices and computer systems should also be used to detect threats before they can compromise the whole information system. The company should also ensure that all security incidents are documented (Yang et al., 2011).

My company’s cybercrime risk strategy is the implementation of a comprehensive response plan. The plan is comprehensive as it entails creation of awareness on cybercrime, working with critical partners and leveraging on trusted IT resources.

Assignment 2

The forms of malware the company can detect include rootkits, Trojan horses, viruses, ransomware, adware, and spyware. Rootkits are concealed malicious programs installed in a system to alter the operating system. Trojan horses are malicious programs that are misinterpreted as useful software to persuade users to take installation actions. Viruses are hidden in other software and are used to execute malicious actions, such as destroying data. Ransomware is designed to hold a system captive until a ransom is paid. Adware delivers unwanted advertisements. Spyware is designed to investigate the activities of users without their knowledge (Holt et al., 2015).

Antimalware tools available to the company include AVG Antivirus, Avast Antivirus, Ad-Aware Internet Security, Microsoft Security Essentials, McAfee Virus Removal Tools, and Windows Defender. The company can also make use of antimalware resources such as File Verification, Online Virus Scanners, Malware News, and Malware Removal Help (Egele et al., 2012).

The security policies the company enforces include Enterprise Information Security Policy (EISP), Systems-Specific Policy, and Issue-Specific Security Policy (ISSP). The EISP sets the company’s strategic direction and scope of its security efforts. The Systems-Specific Policy provides procedures and standards that are applied in maintaining or configuring the company’s information system. The ISSP provides targeted and detailed guidelines that instruct users on how to secure the company’s technology systems. The security standards the company enforces are the ISO/IEC 27000 series of standards. These standards provide the company with guidelines for best practices in the management of information security (Disterer, 2013).

My company has IT security teams responsible for identifying and mitigating malware. The IT security teams are led by the Chief Security Officer (CSO). The members of the security teams include Information Security Analysts, Data Security Specialists, Information Security Managers and Data Security Assistants.

The company implements information security training and awareness programs meant to enable employees to engage in smart online behaviors. They include information sharing training, Internet security training, and email security training. Information sharing training enables employees to determine how to prevent the exposure of company information to the wrong people. Internet security training programs are implemented periodically to create awareness of the effective use of the Internet. The training programs provide employees with insights into the types of threats they are likely to encounter on the Internet and how to mitigate them. Email security training is designed to empower employees with skills and knowledge on how to safeguard their email accounts against emerging security threats (Yang et al., 2011).

My company partners with law enforcement agencies by reporting cybersecurity threats and attacks for legal action. It also partners with antimalware organizations in the purchase, updating, nd maintaining robust and reliable antimalware software.

Many latest malware information hubs and databases are accessible to the company. The malware information databases provide the company with information security intelligence that is used for identifying and mitigating innovative threats. Examples of the aforementioned databases include McAfee Labs Threat Center, Securelist, F-Secure Virus Description Database, and Symantec’s A-Z Listing of Threats and Risks (Daryabar, Dehghantanha, & Broujerdi, 2011).

Assignment 3

The Personally Identifiable Information (PII) that the company stewards includes information and data that distinguishes the identity of its employees, contractors, and customers. It includes names, email addresses, home addresses, credit card numbers, date of birth, telephone numbers, login details, and passport numbers. The processes of managing PII, including creation, storage, processing, and eradication, are implemented to protect the privacy of the owners of the data. For example, PII is stored in secure systems to ensure that it is not accessed by unauthorized people. The company specifically handles PII in line with legal and policy frameworks about privacy and confidentiality of data.

The company’s privacy policy is called the Personal Data Privacy Policy. The policy provides that holders of private data are notified during its collection. It also provides that PII is used only for intended reasons. Guidelines on obtaining consent from the data owner before disclosure are also provided within the Personal Data Privacy Policy. Furthermore, the policy provides guidelines on the security of PII, including access control and measures for ensuring accountability. The aforementioned provisions of the Personal Data Privacy Policy are summarized in the form of notes, which are provided to the company’s online data vendors and other stakeholders to ensure that they comply with requirements for privacy and confidentiality of PII.

The Intellectual Property assets of my company include trade secrets, copyrights, patents, innovative business ideas and trademarks. The company’s patents, copyrights and trademarks are protected through registration. Trade secrets and innovative business ideas are protected by keeping them confidential. The company also monitors the marketplace to ensure that its intellectual property is not illegally used by other companies. When the company’s intellectual property is infringed, it takes legal action through lawsuits to protect it.

Employees are instructed to implement effective email prevention mechanisms to mitigate phishing attacks. For example, employees protect against spam emails by exercising caution when handling emails from unrecognized sources. In addition, employees are instructed not to provide personal information on pop-up screens. The company also protects its computers through firewalls, anti-spyware, and spam filters to mitigate phishing attacks. The implementation of email security training programs is meant to train employees on how to detect spam emails and mitigate phishing attacks.

Cybercrime incidents at the company are reported to the National Cybercrime Unit (NCCU). The NCCU works with the Metropolitan Police Cyber Crime Unit (MPCCU) and Regional Organized Crime Units (ROCUs) to respond effectively to cybercrime threats and incidents (Guitton, 2013). The company has specific procedures for responding to suspected and actual cybercrime incidents. Employees are instructed to report cybercrime attacks to the Chief Security Officer, who then contacts the NCCU. The NCCU has investigative response mechanisms for dealing with cybercrime incidents. It also works with law enforcement agencies to ensure that perpetrators of cybercrime face appropriate legal actions (Wall & Williams, 2013).

The company is mandated to comply with legal frameworks on the protection of PII and sensitive data, such as health and financial information. The laws that protect PII in the United Kingdom include the Data Protection Act 1998, the Privacy and Electronic Communications Regulations 2003 and the Employers’ Data Protection Code of Practice (Wong, 2011).

Assignment 4

The company has a cybercrime strategy that provides a comprehensive framework on how to identify, address, and mitigate cybercrimes within its cyberspace. The cybercrime strategy stipulates the measures the company uses to overcome the main threats to its business: fraud, intellectual property theft, and data security. The strategy also contains guidelines for dealing with financial crimes, such as identity theft and online fraud. The governance of the company’s IT security resources is also provided for in its cybercrime strategy.

There are security policies for common kinds of cyber incidents within the company’s cyberspace. For example, the company implements the inappropriate-use policy to identify what constitutes improper use of internet resources. It also mandates contractors and employees to sign and comply with the acceptable-use policy. This policy ensures that contractors and employees use IT resources and the Internet by legal and policy frameworks that safeguard against cybercrime (Bulgurcu et al., 2010). The company also implements a corporate security policy, which provides for monitoring of Internet connections and carrying out regular security audits meant to protect against cybercrime.

There is a specific plan for addressing cyberstalking among peers or the company’s employees. The plan provides guidelines on how to collect and safeguard evidence of cyberstalking. It also stipulates how to report cyberstalking to law enforcement agencies. Suspected cases of cyberstalking among peers or employees are reported to IT security personnel. The Chief Security Officer leads investigations on cyberstalking incidents in collaboration with law enforcement officers. Perpetrators of cyberstalking face corporate punitive measures, such as suspension from work, and legal action.

My company does not have a forensic team for collecting evidence and investigating cyberstalking incidents. The management team maintains that it is cheaper to subcontract vendors for gathering evidence related to cybercrime. Notably, cybercrimes such as cyberstalking incidents in the company are not common and therefore do not require a full-time team of forensic investigators. When subcontracted, vendors gather evidence and information about he victim, the offender, the dynamics of the cybercrime, and the crime scene (Casey, 2011). The gathered evidence is then used to support legal action against perpetrators.

Some of the roles and skills required for effective handling of incidences of cybercrime have been identified in my company. The Chief Security Officer works with Information Security Managers in leading investigations into cybercrime within the company’s cyberspace. However, the company does not have cybercrime analysts, digital forensic investigators and cybercrime investigators to deal with cybercrime incidents. The roles and skills that have not been identified are played by subcontracted vendors.

Several resources on handling cybercrime are available to the company. Most of these resources are within online databases. They include National Fraud and Cybercrime Reporting Center, National Cyber Crime Agency’s Cyber Crime Assessment reports and Norton UK’s Cybercrime Resources. These resources provide useful information on identifying latest cyber threats, mitigating attacks, conducting investigations and reporting perpetrators to law enforcement agencies (Newburn, 2012).

Assignment 5

My company is adequately prepared for handling digital evidence about its cyberspace surface. For example, it has a guide designed for first responders and meant to provide them with information on responsibilities and roles regarding investigating cybercrime incidents. The company also has a strategy and a plan for handling digital evidence. The strategy provides guidelines for handling and preserving volatile data. The plan contains a framework for maintaining the integrity of digital evidence, adhering to the chain of custody, seeking specialist support, and working with law enforcement agencies. In addition, my company implements training programs on handling digital evidence. The training enables its IT staff to ensure that digital evidence is not lost along the chain of custody (Holt et al., 2015).

The company partners with outside vendors to ensure that forensics related to cybercrimes is conducted cost-effectively and appropriately. However, its IT staff supports and collaborates with subcontracted vendors to ensure that all processes of forensic audit and collection of digital evidence are carried out in a standardized manner. Outside vendors play the role of obtaining useful forensic information on the digital trail of perpetrators of cybercrimes. They also seize communication devices useful in supporting legal actions against perpetrators (Casey, 2011).

Forensic investigators are required to demonstrate a high level of competency through their skills. They should be able to track hacks, recover data, and preserve digital data. Forensic investigators should also be competent in working with electronic equipment and writing investigative reports. They should also have interpersonal and communication skills that enable them to work collaboratively with law enforcement officers and IT staff. More importantly, forensic investigators should have problem-solving and critical thinking skills (Ahmed, Obermeier, Naedele, & Richard, 2012). My company’s training plan does not provide for forensic investigation because it depends on subcontracted forensic investigators.

Members of the IT team in my company use specific digital forensic tools for various purposes. For example, they use email analysis tools to identify threats to email communications. They also use registry analysis tools to determine the integrity of the company’s system software. Additionally, the IT staff uses data and disk capture tools to maintain the security of PII within the company’s computers. Furthermore, they use network forensics tools to detect threats to the company’s communication and computer networks. The specific digital forensic tools used in my company include the Digital Forensics Framework, Computer Aided Investigative Environment (CAINE), Registry Reco, and WindowsSCOPE.

My company applies an integrated strategy for mitigating anti-forensics attempts. The strategy entails a combination of a wide range of ge mechanisms for mitigating anti-forensics efforts. For example, the company uses encryption to ensure that forensic evidence is secured in encrypted disks. IT staff also use steganography to hide forensic evidence. Steganography involves hiding forensic evidence within other files (Cheddad, Condell, Curran, & McKevitt, 2010). File wiping utilities are also used to ensure that forensic evidence is removed from the operating system and secured.

Assignment 6

The Cyber Kill Chain Methodology is an innovative approach useful in network defense. The goal of applying the kill chain model is to understand the actions of a network intruder. Step 1 in the application of the kill chain model is to understand the intent of the intruder. In step 2, analyze the malware or the intruder’s weapons. Step 3 involves analysis of intrusion attempts or the medium through which the intruder delivers attack weapons. In step 4, increase the resilience of the system through user awareness training and penetration testing. In step 5, create robust endpoint mitigations. Step 6 entails the blocking of the intruder’s operations. The final step of the kill chain model is the gathering of forensic evidence to determine the extent of damage to network resources (Martin, 2017).

To implement dynamic defense against cyber attacks, it is necessary to make thereat intelligence operational. Dynamic defense begins with the collection of threat intelligence and determining its business value. This is followed by analysis of threat intelligence platforms. The third process is the implementation of defense mechanisms against multi-phased attacks. Finally, threat mitigation and threat intelligence are integrated to achieve the objectives of dynamic defense against cyber attacks.

The cyber kill chain procedure for mitigating a JavaScript Malware Attack is a little modified. It involves understanding the JavaScript Malware Attack process. The attack begins with reconnaissance, which entails gathering data on the target. Secondly, the attacker loads the weapons for the attack. Thirdly, the attacker delivers or launches the network intrusion. The fourth activity is the compromising of the target. Fifthly, the intruder engages in the installation of a persistent attack on the target. The sixth activity is the issuance of commands and control of the attack. Finally, the intruder takes action to achieve the objectives of the attack.

Assante & Lee (2015) assert that the cyber kill chain for defending an industrial control system against incidents requires an understanding that attacks occur in two stages. The first stage is like a structured and targeted attack. It has four phases. The first phase is planning and involves reconnaissance activities. The second phase is preparation and entails loading weapons of attack. The third phase of stage 1 is cyber intrusion, and it involves gaining initial access to the system. The final phase is management and enablement. It occurs when the intrusion has been successful. Stage 2 starts with the development and tuning of the attack. This is followed by validation or testing of attack capability. The final phase is the ICS Attack, and it involves the actual delivery of the attack.

The Critical Security Controls V6.0 was developed by the Center for Internet Security to provide a comprehensive security framework for measuring and monitoring its critical security controls. The continuous monitoring process of the Critical Security Controls V6.0 is based on the National Institute of Standards and Technology (NIST) model. The security framework is simplified and is effective and rapid in minimizing the impact of incidents based on meaningful security metrics.

Assignment 7

A group of hackers can form a team to share their skills for a successful and efficient attack on complex systems, such as the power grid. Such a team starts with reconnaissance to inform the development of a command that is sent to cut off the power supply. Teamwork enables skilled hackers to access and attack complex systems with speed because they divide tasks according to their skills and execute them in an efficient manner (Szoldra, 2016). The work of the team is executed as an operation of a small team within the armed forces. The divergent skill sets members bring to the hack team make their attack on a complex system both agile and smart. A hack team that is equipped with different skill sets makes it easily adaptable to emerging situations. This means that members of the team can pass through high-level defenses against cyber attacks.

A skilled team of hackers can access and control an entire network of a power company. The team uses inside intelligence and clever social engineering tactics to ensure that an attack command reaches the target within 24 hours (Szoldra, 2016). Notably, cyberspace is becoming increasingly dangerous because skilled teams of hackers can cause thousands of homes to lose power. They are also capable of attacking healthcare facilities and even military bases. Therefore, attackers can deny people access to healthcare and change the outcomes of war.

According to the International Telecommunication Union (2017), Computer Incident Response Teams (CIRTs) should be created by organizations to overcome the increasing risk of attack in cyberspace. Organizations should follow specific stages to ensure that they create an effective CIRT. The creation of a CIRT should start from the establishment of a mission and vision statement. The mission statement provides a clear framework of services and policies that are important in protecting systems from security attacks and minimizing damage. A vision statement indicates the ultimate goal that a CIRT seeks to achieve. The second stage is the creation of the constituency of the CIRT. It entails establishing the organization or group of organizations that the CIRT will work for. Creation of a constituency also involves determining the kind of security incidents that the CIRT will defend against.

The third stage in the formation of a CIRT is the determination of the place of the defense team within the organization. This involves clarifying the roles the CIRT will play within the organization. The Fourth stage is the creation of relationships, which can be both domestic and international. The fifth stage is the determination of the services the CIRT will provide in the context of cybersecurity. The mechanisms for providing services are also established. Finally, he   RT created and rendered operational in mitigating cyber attacks (International Telecommunication Union, 2017).

 

References

Ahmed, I., Obermeier, S., Naedele, M., & Richard, G. G. (2012). SSCADAsystems: Challenges for forensic investigators. Computer, 45(12), 44-51.

Assante, M. J., & Lee, R. M. (2015, October ). The Industrial Control System Cyber Kill Chain. SANS.

Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness. MIS quarterly, 34(3), 523-548.

Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the internet. Academic Press.

Cheddad, A., Condell, J., Curran, K., & McKevitt, P. (2010). Digital image steganography: Survey and analysis of current methods. Signal processing, 90(3), 727-752.

Daryabar, F., Dehghantanha, A., & Broujerdi, H. G. (2011). Investigation of malware defense and detection techniques. International Journal of Digital Information and Wireless Communications (IJDIWC), 1(3), 645-650.

Disterer, G. (2013). ISO/IEC 27000,27, 001, and  7002 for information security management. Journal of Information Security, 4(02), 92.

Egele, M., Scholte, T., Kirda, E., & Kruegel, C. (2012). A survey on automated dynamic malware-analysis techniques and tools. ACM computing surveys (CSUR), 44(2), 6.

Guitton, C. (2013). Cyber insecurity as a national threat: overreaction from Germany, France, and the UK?. European Security, 22(1), 21-35.

Holt, T. J., Bossler, A. M., & Seigfried-Spellar, K. C. (2015). Cybercrime and digital forensics: An introduction. Routledge.

International Telecommunication Union. (2017).CIRT Creation Stages.

Martin, L. (2017). Gaining the Advantage: Applying Cyber Kill Chain Methodology to Network Defense.

Newburn, T. (2012). Handbook of policing. Routledge.

Szoldra, P. (2016). We watched a team ofhackers fullyy compromise a power company in less than 24 hours. Business Insider.

Wall, D. S., & Williams, M. L. (2013). Policing cybercrime: networked and social media technologies and the challenges for policing.

Wong, R. (2011). Data protection: The future of privacy. Computer law & security review, 27(1), 53-57.

Yang, G., Geng, G., Du, J., Liu, Z., & Han, H. (2011). Security threats and measures for the Internet of Things. Journal of Tsinghua University Science and Technology, 51(10), 1335-1340.

Write My Essay Now
GET A PRICE
$ 0 .00

Ratings


Be Awesome - Share Awesome

img