Q.
1 Password Policy:
The password policy for the company must be improved to prevent such incidents from taking
place. One preventive strategy is to improve the strength of the passwords. The company must
require each staff member to update their passwords every month. The passwords must expire,
and must be changed every month. This is a type of administrative control. Technical control
must also be implemented, for example, a user must only be able to enter an incorrect password
three times. After this, the account must get locked. This is a type of detective control.
To secure critical information, user access privileges must be set. Information should be
accessible only on a need to know basis. Every user must not have the same access rights.
Moreover, the IT department must learn a lesson from this incident, every time an employee’s
employment is terminated; his access rights must be revoked. The user’s credentials must be
removed from the system immediately, making sure they cannot access the system again.
Q.2 Physical Security Policy:
The physical security policy has to differ for the different locations and their specific needs.
Following is the list of proposed solutions for each of the potential vulnerabilities:
The warehouses have multiple controlled pharmaceuticals that must be logged when
received and shipped out.
o Tag controlled pharmaceuticals with radiofrequency tags, like items in a
superstore. Unless the pharmaceutical has been logged in the DBMS, the security
alarms should go off.
Each warehouse has a separate room for highly regulated narcotics.
o CCTV Cameras on the possible entrances/exits for this room. Access must be
restricted with the use of a biometric system.
The main office has a public lobby and conference rooms for guests and prospective
clients.
o One human security guard. Biometric security systems must be installed,
prohibiting the access of visitors to sensitive areas. Visitors must also be issued
cards that read “VISITOR”, and policy should be implemented requiring
everyone to wear their badges. This way, it will be possible for security personnel
to make sure visitors do not wander off to restricted areas.
One of the regional offices is in an urban area that has been suffering from an increase in
vandalism and petty crime.
o Simple RFID system can be implemented that does not allow anyone without
registered RFID to enter. CCTV system should be installed at entrances/exits.
Security personnel should be present to monitor the CCTV footage at real time,
and to guard the entrances. Burglar alarm system may also be installed.
The data center is located at the main office. There are two doors, one from the Network
Admin’s office and one from the main hallway between the IT department and the
Finance department.
o The datacenter must not be accessible from the main hallway. Access to this room
must only be possible only through the Network Admin’s office. In addition, there
must be a security system (it can either be RFID or biometric) on the door, that
only allows access to certain personnel. This access must be given on a need-to-
have basis again. For example, if Network Admin and IT department needs to
access the data center, then only these personnel’s cards or finger prints must be
allowed to unlock the door.
Q.3 Projects for the Next Year:
In light of the recent ransom ware attack, the most suitable project is implementing new
firewalls, NIDS appliance, jump servers for remote access and RSA tokens for remote
employees. This is the appropriate choice, as unprotected remote access and penetrable firewall
is what allowed the attack in the first place. To make sure that the company is safe from such an
attack, and data and information can be made secure, this is the first step, and so this must be the
first project as well.
Q.4 Evidence:
The evidence gathered must be accurate complete and authentic. Timestamps can be used as a
means of making sure the data is accurate and authentic. The incident report must be complete,
accurate and authentic. The in house IT team can be involved to make sure that the report covers
everything.
From the IT services company, a detailed incident report must be requested; this is a part of
Tracking phase in the Incidence Handling process. Once the incident and its source are
documented, only then can the team apply lessons learned to prevent such an incident from
taking place in the future.
Q.5 Ports and Protocols:
The information in the incident report provides evidence that the attackers gained access on one
of the training computers by running port scan. The protocols for such an attack are TCP or
UDP. If the attacker was able to gain access through remote desktop, the ports must have been
TCP / UDP Ports 3389.
References
"How to change the listening port for Remote Desktop". Microsoft. January 31, 2007. Retrieved June 18,
2017. Microsoft KB article 306759, revision 2.2.