0% found this document useful (0 votes)
190 views91 pages

Managing Security for Sunrise Bank

This document contains an assignment for managing security at Sunrise Bank. It is divided into 4 parts. Part 1 involves assessing security risks to the bank's IT systems and producing a report identifying the risks and proposing a method to evaluate and mitigate the risks. Part 2 describes possible IT security solutions like VPNs, firewalls and DMZs, and provides an example implementation. Part 3 reviews mechanisms for controlling organizational security, including risk assessment procedures, data protection regulations, and aligning security with organizational policy. Part 4 involves producing technical and user documentation for managing the bank's security, including designing an organizational security policy and disaster recovery plan.

Uploaded by

achyut dhital
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
190 views91 pages

Managing Security for Sunrise Bank

This document contains an assignment for managing security at Sunrise Bank. It is divided into 4 parts. Part 1 involves assessing security risks to the bank's IT systems and producing a report identifying the risks and proposing a method to evaluate and mitigate the risks. Part 2 describes possible IT security solutions like VPNs, firewalls and DMZs, and provides an example implementation. Part 3 reviews mechanisms for controlling organizational security, including risk assessment procedures, data protection regulations, and aligning security with organizational policy. Part 4 involves producing technical and user documentation for managing the bank's security, including designing an organizational security policy and disaster recovery plan.

Uploaded by

achyut dhital
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Introduction
  • Environmental Risks
  • Physical Risk
  • Man in the Middle Attack
  • Virus Attack
  • Hacker
  • Biometric Security
  • Security Procedures
  • Risk Assessment Methodologies
  • Risk Treatment Methodologies
  • Security Audit
  • Methodology of Solving IT Security Risks
  • Conclusion
  • Introduction to Risk Assessment
  • Part 4: Security Devices
  • Components of Organizational Disaster Recovery Plan
  • Conclusion

Network Security 2019

MANAGEMENT & TECHNOLOGY

ASSIGNMENT COVER SHEET

STUDENT DETAILS

Student ID Reg No.

Given Name
Family Name
Enrolment Year 2019 Section N1

Semester Fourth Email Shuvechchha@[Link]

UNIT DETAILS
Unit Title
Security Unit Code K/615/1623
Assessor Name
Krishna Parajuli Issued Date 26 Aug 2019
Assignment Title Managing security for sunrise bank

Assignment No 01 Submission Date 17 June 2021

Qualification Campus

Shuvechchha Bhandari (HND / Second Semester)


1
Network Security 2019

STUDENT ASSESSMENT SUBMISSION AND


DECLARATION
When submitting evidence for assessment, each student must sign a declaration
confirming that the work is their own.

Student Name Shuvechchha Bhandari Assessor Name Krishna


Parajuli
Issue Date 26 Aug 2019 Submission Jun 17 2021
Date
Programme BTEC HND in Computing

Unit Name Security

Assignment Title Managing security for sunrise bank

Plagiarism
Plagiarism is a particular form of cheating. Plagiarism must be avoided at all costs and
students who break the rules, however innocently, may be penalized. It is your
responsibility to ensure that you understand correct referencing practices. As a
university level student, you are expected to use appropriate references throughout and
keep carefully detailed notes of all your sources of materials for material you have used
in your work, including any material downloaded from the Internet. Please consult the
relevant unit lecturer or your course tutor if you need any further advice.

Student Declaration
I certify that the assignment submission is entirely my own work and I fully understand the
consequences of plagiarism. I understand that making a false declaration is a form of
malpractice.
malpractice.

Pearson Education 2018


Higher Education Qualifications

INTERNATIONAL SCHOOL OF MANAGEMENT AND TECHNOLOGY


GAIRIGAUN, TINKUNE, KATHMANDU

Shuvechchha Bhandari (HND / Second Semester)


2
Network Security 2019

NEPAL

BTEC HND in Computing

Unit 5: Security Unit Code: K/615/1623

Session/Year: 2019 Assessment No: 01

Assignment Launch Date: 26 Aug 2019 Due Date: 26 Oct 2019

Assignment Title: Managing Security for Sunrise Bank

Teacher Name: Krishna Parajuli IV’s Name & Date:

Student Name: Pearson Reg No: Final Grade:

Assignment submission format


Each student has to submit their assignment as guided in the assignment brief. The students are
guided what sort of information is to produce to meet the criteria targeted. Some tasks might require
group work, but the student has to produce individual assignment.

Scenario I
“Sunrise Bank", established in 2002, is a leading commercial bank in Nepal founded by reputed
entrepreneurs understanding the needs of a growing economy and is managed by a team of
professionals and experienced bankers. The main mission of the bank is to be leading Nepali bank,
delivering world class service through the blending of state-of-the-art technology and visionary
management in partnership with competent and committed staff, to achieve a sound financial
strength with sustainable value addition to all the stakeholders. The bank is committed to do this
mission while ensuring the highest levels of ethical standards, professional integrity, corporate
governance and regulatory compliance.
The bank is committed in providing quality service and planning to utilize all the technological
facilities that enhance quality service with high degree of compliance and risk management. The
bank has an IT department which is responsible to manage and implement all required IT
infrastructure. IT department has defined a policy that all of the branch office must connect to head
office through secure VPN. All other clients must be member of the centralized domain. User access

Shuvechchha Bhandari (HND / Second Semester)


3
Network Security 2019

of the system has been managed via proper access control mechanism and the access control list, and
the service access has been managed via ports and services.
The bank has security policies for managing the security of all its assets, functions and the services.
VPN access has been managed for limited person of all branch office employees and IT
administration team of head office. Defense in depth approach is to be implemented in order to
confirm the IT security at various level of network infrastructure. IT infrastructure security design
including address translation, DMZ, VPN, firewall, antivirus and intrusion detection system are to be
implemented for internal and external security policy.
You have been working as an IT Officer for the bank. Your key role will be to manage, support and
implement a secure network infrastructure for banks LAN/WAN environment. In order to assess the
possibility, you have been assigned the following in which you have to demonstrate that you are able
to assess risks to IT security, describe different possible IT solutions, review mechanism to control
organizational IT Security and manage organizational security.
Part: 1
Before you start the implementation of the IT security measure for the organization, you need to
assess the IT security risks in the organization. You need to consider various aspects of risks such as
unauthorized access of the system and data, naturally occurring risks, host, application and network
risks etc. You are required to consider organizational security procedure such as business
continuance, backup/restoration, audits etc. and then produce a report for the CEO of Sunrise Bank
containing:
1. Identified security risk types to the organization along with description of organizational security
procedure.
2. Develop a proposal of a method to assess and treat IT security risks.

You would prefer to produce a more detailed document, so you will produce a comprehensive report
for fully functional secure system which will include identified risks and method to mitigate those
risks. Your manager would like a separate report on your assessment of the effectiveness of the
design in relation to user and system requirements.

Part: 2
Once the assessment of the risks and proposal for its remedy has been made you need to describe IT
security solution for the organization such as VPNs, firewall, DMZ with a suitable implementation
example. You need to:

Shuvechchha Bhandari (HND / Second Semester)


4
Network Security 2019

1. Identify the potential impact to IT security using firewall and VPNs and make aware of the
repercussion of incorrect configuration of firewall policies and third-party VPNs.
2. Show through an example in simulated environment, how implementing a DMZ, Static IP ad
NAT in a network can improve Network Security.
3. Discuss how network monitoring systems can benefit the security of IT of the organization.
You need present at least three advantages.
4. Finally investigate how a 'trusted network' may be the part of an IT security solution.

Part: 3
Once you have identified IT risks and viable security solutions, you need to review the mechanisms
to control organizational security. Consider various aspects of network change management, audit
controls, disaster recovery plans, Data Protection Acts, Computer Misuse Act, ISO 3001 standards,
etc. You need to:
1. Discuss risk assessment procedures and explain data protection processes and regulations as
applicable to the organization.
2. Summarize the ISO 31000 risk management methodology and its application in IT security
and then discuss possible impacts to organizational security resulting from an IT security
audit.
3. Explain considering how IT security can be aligned with organizational policy, detailing the
security impact of any misalignment.

Part: 4
Lastly you will produce technical and user documentation which will be given to the company for
the management of organizational security. You have to design and implement a security policy for
the bank which will
1. List out the main components of an organizational disaster recovery plan, justifying the
reasons for inclusion.
2. Discuss the roles of stakeholders in the organization to implement security audit
recommendations.
3. And an evaluation of the suitability of the tools used in an organizational policy.

Pass Merit Distinction


LO1 Assess risks to IT security

Shuvechchha Bhandari (HND / Second Semester)


5
Network Security 2019

P1 Identify types of security risks M1 Propose a method to assess


to organizations. and treat IT security risks.

P2 Describe organizational
security procedures. LO1 & 2 D1 Investigate how
a ‘trusted network’ may be part of
LO2 Describe IT security solutions an IT security solution.
P3 Identify the potential impact
to IT security of incorrect
configuration of firewall policies M2 Discuss three benefits to
and third- party VPNs. implement network monitoring
systems with supporting reasons.

P4 Show, using an example for


each, how implementing a DMZ,
static IP and NAT in a network
can improve Network Security.

LO3: Review mechanisms to control organizational IT security


D2 Consider how IT security can
P5 Discuss risk assessment M3 Summarize the ISO 31000
be aligned with organizational
procedures. risk management methodology policy, detailing the security
and its application in IT security. impact of any misalignment.
P6 Explain data protection
processes and regulations as M4 Discuss possible impacts to
applicable to an organization. organizational security resulting
from an IT security audit.

LO4: Manage organizational security


D3 Evaluate the suitability of the
P7 Design and implement a M5 Discuss the roles of
tools used in an organizational
security policy for an stakeholders in the organization policy.
to implement security audit
organization. recommendations.

P8 List the main components of


an organizational disaster
recovery plan, justifying the
reasons for inclusion.

To be used by the assessor.


Shuvechchha Bhandari (HND / Second Semester)
6
Network Security 2019

General feedback on the assignment:

In order to pass the unit, the learner has to meet all the pass criteria. Tick each criteria awarded.
P1 P2 P3 P4 P5 P6 P7 P8 Pass Achieved / Not

In order to be awarded a Merit the learner has to meet all the pass criteria and all the merit criteria. Tick
the criteria awarded.

M1 M2 M3 M4 M5 Merit achieved / Not

In order to be awarded a Distinction the learner has to meet all the pass merit criteria and all the Distinction
criteria. Tick the criteria awarded.

D1 D2 D3 Distinction Achieved / Not

Note: Please access HN Global for additional resources support and reading for this unit. For further
guidance and support on report writing please refer to the Study Skills Unit on HN Global. Link to
[Link]
Note: Refer the unit details provided in your handbook when responding all the tasks above. Make
sure that you have understood and developed your response that matches the highlighted key words
in each task.
Other Requirements:
 It should be the student’s own work – plagiarism is unacceptable.
 Clarity of expression and structure are important features.
 Your work should be submitted as a well presented, word-processed document with
headers and footers, and headings and subheadings, both in hard and soft copies.
 You are expected to undertake research on this subject using books from the library, and
resources available on the Internet.
 Any sources of information should be listed as references at the end of your document
and these sources should be referenced within the text of your document using Harvard
referencing style
 Your report should be illustrated with screen-prints, images, tables, charts and/or graphics.
 All assignments must be typed in Times New Roman, size 12, 1½ spacing.

Shuvechchha Bhandari (HND / Second Semester)


7
Network Security 2019

The center policy is that you must submit your work within due date to achieve “Merit” and
“Distinction”. Late submission automatically eliminates your chance of achieving “Merit and
Distinction”. Also, 80% attendance is required to validate this assignment.
Assignment Prepared by: Signature: Date: 25 Aug 2019
Krishna Parajuli

Brief Checked by: Signature: Date: 25 Aug 2019


Dhruba Babu Joshi

I declare that all the work submitted for this assignment is my own work and I understand that if any
part of the work submitted for this assignment is found to be plagiarized, none of the work submitted
will be allowed to count towards the assessment of the assignment.

Table of Contents
Part: 1...................................................................................................................................................14
Introduction..........................................................................................................................................14
Environmental Risks............................................................................................................................15
Physical Risk........................................................................................................................................15
Phishing attack..................................................................................................................................16

Man in the middle attack..................................................................................................................16

Malware attack.................................................................................................................................16

SQL-Injection attack........................................................................................................................16

DDOS attack.....................................................................................................................................17

Shuvechchha Bhandari (HND / Second Semester)


8
Network Security 2019

Virus attack.......................................................................................................................................17

Adware.............................................................................................................................................17

Data breach.......................................................................................................................................17

Hacker:.................................................................................................................................................18
Viruses:.................................................................................................................................................18
Misconfiguration:.................................................................................................................................18
Hardware security tools:......................................................................................................................18
Firewall.............................................................................................................................................19

Biometric security............................................................................................................................19

Security Procedure...............................................................................................................................19
Developing local policy, process and guidance:...............................................................................20

Authentication..............................................................................................................................20

Authorization................................................................................................................................21

Accountability..............................................................................................................................21

Risk Assessment...................................................................................................................................21
Risk assessment methodologies:......................................................................................................21

Risk treatment methodologies..........................................................................................................22

Security Audit...................................................................................................................................22

Vulnerability Assessment:................................................................................................................23

Penetration testing:...........................................................................................................................23

Group and security policy................................................................................................................23

Method of solving IT Security Risks:..................................................................................................24


Security devices:...............................................................................................................................24

Security policies:..............................................................................................................................24

Monitoring tools:..............................................................................................................................24

Training and Awareness:...................................................................................................................25

Report:..............................................................................................................................................25

Conclusion............................................................................................................................................25
Part 2:...................................................................................................................................................27

Shuvechchha Bhandari (HND / Second Semester)


9
Network Security 2019

Introduction..........................................................................................................................................27
Firewall.............................................................................................................................................27

Advantages of Firewall................................................................................................................28

Disadvantages of Firewall............................................................................................................28

Virtual Private Network (VPN)........................................................................................................28

Remote Access VPN....................................................................................................................29

Site-to-site VPN...........................................................................................................................29

Advantages of VPN..........................................................................................................................29

Disadvantages of VPN......................................................................................................................29

Access Control list (ACLs)..............................................................................................................29

Standard Access list......................................................................................................................30

Extended Access List........................................................................................................................30

Named Access List...........................................................................................................................30

Demilitarized Zone (DMZ):.............................................................................................................30

Advantages of DMZ.........................................................................................................................31

Disadvantages of DMZ.....................................................................................................................31

Network Address Translation (NAT)................................................................................................31

Advantages of NAT:.........................................................................................................................32

Disadvantages of NAT:.....................................................................................................................32

IP routing..........................................................................................................................................33

Static routing:...............................................................................................................................33

Network monitoring systems............................................................................................................34

Wireshark.....................................................................................................................................36

SNMP server................................................................................................................................38

Trusted Network...................................................................................................................................39
Impacts of trusted network on IT security........................................................................................40

Conclusions..........................................................................................................................................42
Part: 3...................................................................................................................................................43

Shuvechchha Bhandari (HND / Second Semester)


10
Network Security 2019

Introduction..........................................................................................................................................43
Risk assessment................................................................................................................................43

Risk assessment steps.......................................................................................................................44

Goal of risk assessments...................................................................................................................44

Risk Assessment in ISO 31000....................................................................................................45

Risk Identification........................................................................................................................45

Risk Analysis................................................................................................................................46

Risk Evaluation............................................................................................................................46

Data protection and its regulations...................................................................................................47

Network Change Management.........................................................................................................47

Data Protection Act (DPA):..............................................................................................................47

Significance of DPA.....................................................................................................................48

Computer Misuse Act.......................................................................................................................48

Significance of Computer Misuse Act.........................................................................................49

Data Protection Processes and Regulation in Nepal.........................................................................49

Summarization of ISO 31000 Risk Management.............................................................................49

Principle............................................................................................................................................50

Process and Framework:......................................................................................................................50


Security Audit.......................................................................................................................................52
Importance of Security Audit in Organization.................................................................................53

Aligning IT Security with Organizational Policy.............................................................................53

Misalignment of IT Security Policy with Organizational Policy.....................................................55

Conclusion............................................................................................................................................55
Part: 4..................................................................................................................................................57
Introduction..........................................................................................................................................57
Purpose of bank security policy.......................................................................................................57

Major devices that are used in a network.............................................................................................58


Modem..............................................................................................................................................58

Shuvechchha Bhandari (HND / Second Semester)


11
Network Security 2019

Router...............................................................................................................................................58

Switch...............................................................................................................................................59

Server................................................................................................................................................59

Networking cables............................................................................................................................59

Coaxial Cable...............................................................................................................................60

Shielded Twisted Pair (STP) Cable..............................................................................................60

Fiber Optic Cable.........................................................................................................................60

Unshielded Twisted Pair...............................................................................................................60

Pinging..............................................................................................................................................61

Active Directory Domain Services (AD DS)...................................................................................62

Technical and User Documentation:.................................................................................................62

Access Control Policy..................................................................................................................63

Attrib command:..........................................................................................................................64

Cipher command..........................................................................................................................64

Local Security Policies.....................................................................................................................64

Account policies...............................................................................................................................65

Local policies....................................................................................................................................68

NTFS security...................................................................................................................................69

Encryption........................................................................................................................................70

Quota system................................................................................................................................71

Group policy.....................................................................................................................................74

Firewall.............................................................................................................................................75

Components of organizational disaster recovery plan:........................................................................80


Create a disaster recovery team........................................................................................................80

Identify and assess disaster risks......................................................................................................80

Earthquake resistance buildings:......................................................................................................81

Secured servers:................................................................................................................................81

Shuvechchha Bhandari (HND / Second Semester)


12
Network Security 2019

Data backup in data warehouse:.......................................................................................................81

Backup Domain:...............................................................................................................................82

Backup DHCP:.................................................................................................................................82

RAID (Redundant Array of Independent Disks)..............................................................................82

Cloud Storage...................................................................................................................................83

Test and maintain the DRP...............................................................................................................83

Security Audits.................................................................................................................................83

Roles of the stakeholders:....................................................................................................................84


Customer:.........................................................................................................................................84

Management:....................................................................................................................................85

Investors & shareholders:.................................................................................................................85

Employee:.........................................................................................................................................85

Government:.....................................................................................................................................85

Suitability of the tools used in organization policy:.............................................................................86


Conclusion............................................................................................................................................87
References............................................................................................................................................88

Part: 1
Before you start the implementation of the IT security measure for the organization, you need
to assess the IT security risks in the organization. You need to consider various aspects of risks
such as unauthorized access of the system and data, naturally occurring risks, host, application
and network risks etc. You are required to consider organizational security procedure such as
business continuance, backup/restoration, audits etc. and then produce a report for the CEO of
Sunrise Bank containing:
1. Identified security risk types to the organization along with description of organizational
security procedure.
2. Develop a proposal of a method to assess and treat IT security risks.

Introduction
With the advent of basic banking and the widespread adoption of the Internet in the last century,
branch management has also completely changed. Some banks are also using a disabled strategy at

Shuvechchha Bhandari (HND / Second Semester)


13
Network Security 2019

the moment; however, it is gradually being replaced by online technology. Sunrise Bank, established
in 2009, is one of Nepal's leading commercial banks, created by so-called business visionaries. When
they realized the need for an emerging economy, they created this bank and it is now overseen by a
group of experienced investors and experts. Currently, the main objective of this bank is to lead the
Nepal Bank, providing world-class benefits through a combination of innovative skills and visionary
management. By ensuring quality support for its client, the bank wants to use all innovative offices
that improve the quality of administration with a high level of consistency and risk management. The
bank has different security strategies to guarantee the security of each of its strengths, capacities and
administration, which are managed by a talented systems security engineer.
A security risk is a risk that surrounds an organization’s network because it can be of a different
nature. A security risk can affect the reputation of an organization, its partners and customers. There
are two types of safety risks: environmental and physical. Environmental risks are the types that arise
due to natural disasters, and physical risk are the type of risks that are caused by cyber-attacks,
vulnerabilities, etc. Both of these risks have a greater impact on data loss and corruption.
Organizational security procedures establish rules and guidelines for identifying, analyzing, and
applying policies to protect the organization's data and information. In this part, I am going to review
the security risks and its types as well as the organization’s security policy to understand the risks
and threats.

Environmental Risks
Environmental risks are the risks that an organization faces due to a natural disaster. For example,
one of the largest Maldives companies could be at risk from a tsunami as the country is covered by
the sea. There may be other risks, but the main danger is the tsunami, and companies need to avoid
server homes and domestic data backups. Listed below are other environmental risks that may affect
your organization:
 Fire: Fire is naturally occurring risk that can destroy valuable documents and deplete everything.
Fire can destroy anything and all organizations experience this risk as it can occur anywhere and
the entire organization must be aware of it. The organization has a high probability of having a
fire risk when the organization is located near the industrial area where there is fire work in
businesses such as cement plant, noodle factory, metal factory etc.

Shuvechchha Bhandari (HND / Second Semester)


14
Network Security 2019

 Flood: Flood is a naturally occurring risk that affects the organization. For example: If this
organization is located in the Terai region of Nepal, it is a flat land in southern Nepal with a high
probability of flooding and we can see a history of large floods occurring every year. If a
company keeps servers, data and other valuable documents it can affect the organization.

 Earthquake: This natural disaster can also affect the entire network system. This can destroy the
data center or lead to the loss of all information in the company. A few years ago, Nepal was hit
by a massive earthquake that destroyed many organizations and lost their data and valuable
documents, which can lead to enormous losses for organizations.

 Extreme weather: The weather can be another factor that can affect the organization. Excessive
weather can have serious effects that can disturb the organization's network, leading to equipment
damage or malfunction. Some extreme thunderstorms are lightning, thunder, cyclones, etc.

Physical Risk
Physical risk is another factor affecting the organization and caused by human activities. Physical
risk arises from a human error or a deliberate attempt to take advantage of a system. In a company,
for example, a stranger or known person sends an email associated with a virus and employees are
unaware of this type of attack that affects the entire system. Sometimes data is hacked and sold to
make money. Some of the other human-causal factors are listed below:

Phishing attack
It is a social engineering attack used to steal user data, credit card numbers, social security numbers,
account numbers, passwords and other intellectual property. Phishing technology is a type of
technology used to obtain other intellectual property without permission. For example, ask the victim
to log in via a fake link and get all the data, such as username and password. These attacks can be
carried out anywhere on the internet. The most popular attack is sending an email with a fake link
and giving bank details about the remittance amount, claiming it has earned millions. In this way, the
attacker got all the information, hacked it and stole the money. Phishing attacks are the most popular
attacks on the internet.

Shuvechchha Bhandari (HND / Second Semester)


15
Network Security 2019

Man in the middle attack


The man of the middle attack is a way of disrupting the communication between the two sides and
the information between being human. Cybercriminals hacked the computers of employees of the
same company and their associates using their public IP addresses or Wi-Fi, and he would be the
middle man who gathers information from the people of the organization. This can also be done
through online forms such as phishing attacks. This attack can easily harm the organization because
as a man in the middle he knows everything about the bank and the organization so he can encrypt
the data and use this data for financial gain and it can also attack many viruses on the network
system. [ CITATION Com18 \l 1033 ]

Malware attack
Malware attacks are a way of attacking other computers or mobiles by using or installing software to
obtain organizational or personal information. It primarily injects viruses and damages the
organization's network. The attack is unconventional and unaware that your personal information has
been hacked. It also affects your organization's entire network and can bring down your entire server.
Cybercriminals can also transfer all financial information to their account, compromising the
financial status of an organization.

SQL-Injection attack
The database is an important part of the organization where you can save all the details of the
organization. SQL injection is a method of attacking devices using malicious code to obtain
information that is not shown to everyone. [ CITATION Glo19 \l 1033 ]The database is mainly
operated by the main server, so the organization data will not be leaked. But by using SQL injection,
attackers can easily find data like the financial status of the organization, employees and user lists,
etc. They can also remove the fixed table from the database, which can affect the entire organization
system and display it personal details. This attack affects the financial damage and reputation of the
organization.

DDOS attack
Distributed Denial of service for DDOS attacks. It is often used by cybercriminals. DDOS is a way
to create traffic that is not available to other online services, so that an attacker can take network
resources by shutting down the server. These attacks are also used to blackmail. You can easily take
all the confidential data of the company and use it for financial gain or to undermine the reputation of

Shuvechchha Bhandari (HND / Second Semester)


16
Network Security 2019

the organization. [ CITATION jef18 \l 1033 ] With this attack, the attacker can take over the entire
organization system, where he can easily deal with different problems and loss that this organization
may face after the attack, which is a great disadvantage for the organization.[ CITATION Pid19 \l
1033 ]

Virus attack
Computer viruses are dangerous and attack our system if the system does not have the proper
protocol to ensure that the virus escapes. A computer virus is a piece of software designed to harm a
computer system using system resources and system memory. This type of program copies and
executes itself, interferes with the way the computer is run, and interferes with data theft, corrupting
files, or deleting them altogether, for any bank. That's a big problem. [ CITATION FTP18 \l 1033 ]
Some of the viruses found in the bank are boot sector viruses that directly affect the master boot
record and are difficult to remove. If this is attacked, the bank computer system needs a complete
system which is a big challenge for the bank as shaping this system causes huge loss of bank data.
Therefore, appropriate protocols should be put in place to protect computers from virus attacks. Ports
should be banned for use by unauthorized users.

Adware
As we know in this modern world we know, every company wanted their advertisement. But some of
the critical hackers use this process for retrieving data from user. [ CITATION FTP18 \l 1033 ].
When unusual ads start appearing on computer desktop, employee accidently download adware
through the medium while downloading the free software. While using the browser by the company
employee the hacker spreading adware collect critical data of bank without permission of user.

Data breach
Data breach is a kind of corporate data theft. There are two types of data breach: data breach inside
and outside data breach. Inside Data Breach is committed by an unethical employee of a company,
while an outsider’s data breach is committed by an unknown person or other related person. In either
case, they intend to steal data from the company, sell it to the other company and make money.
Within the data breach sometimes engage in mischievous activities on the account of other
employees, including: deleting files and other valuable documents to make someone else guilty or
sometimes for personal reasons.

Shuvechchha Bhandari (HND / Second Semester)


17
Network Security 2019

Hacker:
Hackers are those who intent to break the others system and capture all the valuable data to gain the
financially and some does for the name and fame. They can exploit the system of the organization
and can even leak the data. They are very sensitive and can do anything.

Viruses:
Virus is software which is programmed such that it can destroy the computer system. Viruses usually
corrupt the files, damage the system or sometimes it duplicates all the files and hang the system. It
can be attached with the emails and if the email is opened then It can affect the system. There are
many types of viruses can be found which is harmful for any system.

Misconfiguration:
Misconfiguration is a configuration of the system incorrectly. It can happen knowingly or
unknowingly. While configuration any system, user should be conscious and focus to the work
because sometimes we may forget the right configuration and mislead the system. Some of the
mistake may lead the organization to the risk for example: if an administrator leaves a loophole in the
system, then hacker may catch it and easily get the access to the system. Sometimes administrator
unnecessarily click the services which is not required and may harm the system while assigning the
security policy and leads attackers to gain access to the system.

Hardware security tools:


The physical devices which are used for the securing the network system is known as hardware
security tools. It helps to enhance the security of the network and works as a security guard to the
system. Some of them are discussed below:

Firewall
Firewalls are security devices used to monitor systems. It monitors all incoming and outgoing traffic
in the system. It warns if there is a security breach in the system. For example: My system is attacked
by a virus, it immediately warns me in the form of information. We can set the firewall rules as the
desired network and it works according to this predefined rule. It is mainly used to protect the
network. And it filters all incoming and outgoing traffic and if there is any inconvenience to the
system. Firewall software is integrated into the system by Microsoft while hardware firewalls must
be installed separately. Compared to software firewall, hardware firewall is more powerful.

Shuvechchha Bhandari (HND / Second Semester)


18
Network Security 2019

Biometric security
Biometric security is a unique identity of an individual used for identification and authentication. The
person may have special features such as a person's fingerprint, iris print, hands, face, voice, etc.
These features are saved as a format of data and are used for immediate validation. For example, my
company has a fingerprint or iris printing system for attendance, and I need to access the system to
provide biometrics. Otherwise, it is impossible. You cannot trick the system into hacking or cracking
it. Only authorized persons can provide the data.

VPN: A virtual private network (VPN) is a secure network in which data is transmitted through a
highly secure tunnel that transmits data using encryption. It is a dedicated connection between host
and server computers. All data packets are encrypted through a secure tunnel. In Nepali context,
VPN services are provided by Internet Service Providers (ISPs).

Router: A router is a highly intelligent device used to transfer data packets between two different
networks. The best way to get data packets to the address, account, and destination is to forward
them to the destination IP. It works on the network layer (layer 3) of the OSI model. Sister Router,
Juniper, is an excellent router for security purposes. These routers are much safer than regular
routers. These types of routers provide better protection to your organization.

Security Procedure
Security procedures are detailed, step-by-step instructions on how the user or server manager should
enforce, enable, or enforce the security controls set out in bank policies. The following are some of
the security measures that can be implemented in a bank:
Developing local policy, process and guidance:
Creating a policy means setting rules and protocols within your organization. The banking
environment requires strong policies that include needs identification, information gathering,
drafting, reporting and analysis. This process takes place in several stages. These steps are
summarized below:
 Identify needs
 Identify who will take lead
 Gather information and raw data
 Drafting policies
 Consulting with proper and trustful stakeholders
 Approving policies

Shuvechchha Bhandari (HND / Second Semester)


19
Network Security 2019

 Consider whether procedure is required


 Implementation of those policies
 Finally, monitor, review and revise the policies.

Design of network and user authentication strategy (authentication, authorization, and


accountability)
By designing the right network system, we create a better and more secure network strategy. By
implementing authentication, authorization and accountability techniques, we can implement various
authentication strategies. By adding these three methods to the design of a network system, we can
create a secure system for the bank that is more reliable for illegal activities and that reduces the risk
of the banking system's data. I will now briefly describe the AAA technique.

Authentication
Authentication is the process by which a machine or device can identify a user who is connected to a
network resource. This is usually the process of identifying an individual based on their username
and password. In a security system, authentication is different from authorization. Authorization is
the process of granting individual access to system objects based on their identity. In the field of
backing, this technique typically follows three steps. These steps identify each other, monitor
communications through the firewall, and restrict policies by username and password. Technologies
that work with authentication are firewalls such as Radius, WDS, LDAP, and token-based security.

Authorization
Authorization is a post-authentication process. This process helps secure banking transactions by
granting the appropriate permission granted by the administrator or security administrator. This
involves determining the rights / privileges of access to resources related to information security and
computer security in general and access control in particular.

Accountability
Accountability helps us ensure the required registration process, audit control function, data security
oversight, report writer, and most importantly, password protection on a networked system. This is
the responsibility of the organization.

Risk Assessment

Shuvechchha Bhandari (HND / Second Semester)


20
Network Security 2019

“A risk assessment is a thorough examination of your workplace to identify elements, situations,


processes, etc. that can cause damage. Once identified, it analyzes and evaluates the probability and
severity of the risk.[ CITATION Com18 \l 1033 ] Once that decision is made, you can decide what
steps to take to effectively eliminate or prevent the damage from occurring. In risk assessment, we
need to identify the risk factors that can cause harm and analyze, assess the risks associated with this
(risk analysis and risk assessment).

Risk assessment methodologies:


This is the process of identifying, analyzing and evaluating risk. It's the only way to ensure that the
cybersecurity controls you choose are appropriate for the risks your organization faces. It is also a
test of the capabilities of a system or application, including various attacks on the system. There are
several ways to do this check on your system. This main objective of risk assessment is to recognize,
measure and classify security risk assessments in various environments in the banking sector, such as
computer systems, computer networks and even the communication channels used for
communications. The various phases of the methodology used in the risk assessment are shown in
the table below and are also presented below:
 Phase1: Acquisitions: -In this phase, separate interviews are conducted with customers and
employees involved in the design and administration of the system architecture. This is followed
by an explicit documentation that collects technical information about all the network
components used in networked systems.
 Phase2: Identification: -The line includes various interviews with customers and employees
associated with system architecture design and administration. After that, explicit documentation
is done to collect technical information about all network components used in the network.
 Phase3: Analyzing: - After identifying the hazards, system experts review the information
collected from the identification. At this stage, various security risks are analyzed. At this stage,
the effectiveness of existing safety guidelines is examined.
 Phase4: Evaluation: - This step determines the potential exploitation of security risks and
measures various gaps in existing security systems. This step helps to identify identified security
risks and update system requirements for full functionality.
 Phase5: Generating Report: - After all the above phase, this phase is the final phase for
generating the report of cause, control and method of system failure and risks. The draft report is
made which contain essential point. Which are given below: -
 Task rendered by each team member

Shuvechchha Bhandari (HND / Second Semester)


21
Network Security 2019

 Method used and finding


 General and specific recommendations
 Terms used and their definition
 Information collected from all the phases

Risk treatment methodologies


Risk treatment is a risk control measure. The risk management processes include all steps for
identifying, assessing and dealing with risks. In its simplest form, risk treatment involves a process
of changing a risk by changing the consequences or likelihood of them. This process requires
creative consideration of options and detailed design, both of which are required in order to find and
select the best risk treatment.

Security Audit
Security auditing is a standard that certain types of organizations maintain. Banking sector security
clearance either follows the bank's standard security guidelines or does not. This helps in
harmonizing the security systems used in different sectors. A general overview generally assesses the
security of the physical configuration and security of the system, software, information handling
processes, and user procedures. The security audit examines whether mapping follows standard
security approaches and technique management. Security reviews cover the following solutions in
the banking scenario:
 It evaluates the flow of data within the bank
 It identifies vulnerable points and problem area.
 It determines whether we must alter the security policies or not.
 It recommends how to leverage information technology in banking sectors.
 It delivers an in-depth analysis of internal and external system used in security system.

Vulnerability Assessment:
A vulnerability assessment provides an institution with the knowledge, awareness, and risk needed to
define, identify, classify and prioritize vulnerabilities in computer systems, applications and network
infrastructures and understand the threats to its environment and There is a process of answering
appropriately. Vulnerability assessment focusing on the detection of vulnerabilities in information
systems. As an IT manager, we need to highlight the vulnerability of Sunrise bank heads. To find the
weaknesses in the system, we need to perform various tests during the testing process.

Shuvechchha Bhandari (HND / Second Semester)


22
Network Security 2019

Penetration testing:
One of the approaches to security assessment is that it involves security audits and vulnerability
assessment and demonstrates whether an attacker can successfully exploit vulnerabilities in the
system. This is also known as a penetration test. In fact, there are three types of penetration tests,
they are:
 Black-Box testing
 White-Box testing
 Grey-Box testing
Security measures are actively analyzed to detect design weaknesses, technical flaws and defects. It
not only highlights vulnerabilities, but also records how weaknesses can be exploited.

Group and security policy


Groups and Security Policy Group Policy operations are a feature of the Operation Microsoft
Windows NT family of operating that controls the working environment of user accounts and
computer. Group Policy Provides centralized management and configuration of operating systems,
applications, and user settings in the Active Directory environment. A set of group policy
configurations is known as a Group Policy Object (GPO). Security policy settings are ruling that
administrator manage on a computer or multiple devices to protect devices or network resources. You
can use the Security Settings extension of the Local Group Policy Editor snap-in to define security
settings as part of the Group Policy object (GPO). Group and security policies reduce the risk of data
leakage or damage and protect the company from malicious external and internal users. It sets
guidelines and best practices for use and ensures adequate compliance, which encourages the
organization to take an active stance on legal issues. An effective IT security policy system ensures
that only people with sensitive customer data and appropriate access data can access secure systems
and databases. IT departments implementing security management systems must ensure that access
to such systems is controlled at an organizational level and that system activities are documented in
such a way that they can be traced back to their source.

Method of solving IT Security Risks:


Some of the methods to treat IT security risks are given below:

Shuvechchha Bhandari (HND / Second Semester)


23
Network Security 2019

Security devices:
Security devices Firewalls, Cisco routers, biometric devices, DMZs, etc., used to secure the network.
This type of device is used to detect and report unwanted traffic, such as intrusions, viruses, and
DDOS attacks. Hackers need to work hard to break devices so that the network is secure, which
helps to address security risks. For example: Facebook, Google and other big technologies use DMZ
to secure their network, where a hacker tries to break a firewall and even if he can break it there are
only proxy servers that can secure their real servers and how to get data and can manage.

Security policies:
Security Policies: This is a set of rules set out in the network where the users of this network follow
all the rules and instructions regarding the security of the data stored on the server. It also helps
protect against threats and viruses. It also reduces data breaches in the company and keeps the data
safe because the data can only be obtained by authorized users and unauthorized users are denied.
There are many users in a company and these users are different from the department and can only
access their data.

Monitoring tools:
In a network, there are many users and some have different intentions and they want to break the
policy and seize all the data. To avoid these types of threats, the company should be monitored and
this type of software always keeps a record of all users and computers and tracks the work of each
user in the network. All activities that are detected can be used during system auditing and can detect
system flaws. Monitoring tools are also called monitoring software and are very useful for securing
networks.

Training and Awareness:


Not all users may have any IT experience, so user training on software threats and security should be
provided from time to time. For example, a well-known bank received an email from a well-known
user and the system got damaged. This is due to less information about the attack. Unbeknownst to
users, viruses can be attached to mail, sent so that a hacker can break into the network or even
disable servers. All users must be trained and aware of threats to the company and the network. All
users should be asked to check their mail before opening it and to change their password frequently
so that others cannot guess it. Users should always be logged out/locked out when they are not using
the computer and hence security measures should be followed at all times to keep the system secure.

Shuvechchha Bhandari (HND / Second Semester)


24
Network Security 2019

Report:
If there is any serious defect in the system, it should be reported to the Board members and other
concerned persons so that the system can be shut down immediately and data can be saved.
Reporting can sometimes help protect data because it has the potential to shut down servers.

Conclusion
Our organizations also have a variety of security risks, such as unauthorized ring access to the system
and data, naturally occurring threats, and threats to the host, network and application that can damage
the bank's entire network. Therefore, to minimize those risks, I have identified all the potential risks
that may be present in our system such as network, application, host, environmental risk, etc. Then I
discussed the security process and the various steps involved. The main purpose of the security
action is to ensure consistency in the implementation of security controls. When sanctions are
applied or business procedures related to security are followed. The main purpose of a security action
is to restrict access to the information of authorized users of an organization, protecting that
information against unauthorized modifications. There are many methods for assessing hazards but
best practices for assessing safety risks need to be implemented, and I have discussed the five steps
involved in risk treatment. Finally, I talked about the vulnerability assessment. It recognizes,
measures and classifies the security vulnerabilities of a computer system, network and
communication channels. Typically, a vulnerability assessment is performed to identify exploitable
weaknesses and predict the effectiveness of additional security measures to protect information
resources from attacks. Penetration testing is a methodological approach to security assessment that
includes security audits and vulnerability assessments and demonstrates whether attackers can
successfully exploit vulnerabilities in a system. At the same time, security measures are actively
scanned for design flaws, technical flaws, and vulnerabilities.

Shuvechchha Bhandari (HND / Second Semester)


25
Network Security 2019

Part 2:
Identify the potential impacts to IT security using firewall and VPNs and make aware of the
repercussion of incorrect configuration of firewall policies and third-party VPNs.
Show through an example in simulated environment, how implementing a DMZ, static IP and
NAT in a network can improve Network Security.
Discuss how network monitoring system can benefits the security of IT of the organization.
You need to present at least three advantages.
Finally investigate how a ‘trusted network’ may be the part of an IT security solution.

Introduction

Shuvechchha Bhandari (HND / Second Semester)


26
Network Security 2019

Each association, large or small, has its own unique security strategies, with the ultimate goal of
dealing with each of its advantages, capabilities and security of administration. Risk assessment and
penetration testing alone is not sufficient for a bank risk. Therefore, the IT Foundation security
configuration, including VPN, firewall, DMZ, must be factored in and out of the security mode. Our
clients are confidently focused on our association's security methodology to ensure that their data
and money related records are secure. These days, we cannot rely entirely on security reviews and
conditional checks, so cyber security systems are fundamental to keeping track of our bank and
customers' back and forth day in and day out. Our association has a powerful mechanism to create a
layered, defensive security approach that should integrate a variety of processes focused on our
bank’s innovations, personnel and processes. We can make various IT security answers to the bank
real, for example, VPN, Firewall, DMZ, which I described below.

Firewall
Firewall is a network security tool that monitors incoming and outgoing network traffic and
determines whether certain traffic is allowed or restricted based on specific security rules. Firewalls
are the first line of defense in network security for 25 years. They create a barrier between secure and
regulated internal networks that can be trusted and external networks such as the Internet. Firewalls
are the first line of defense in network security for 25 years. They create a barrier between secure and
regulated internal networks that can be trusted and external networks such as the Internet. Firewalls
are divided into two types: - Firewall or host-based firewall. Network firewalls play an important
role in filtering traffic between two or more networks and work on network devices.
There are five different types of firewalls used in bank for securing the network. Those firewalls are
listed below: -
 Packet filtering firewalls
 Circuit-level gateways firewall
 Stateful inspection firewall
 Application-level gateway firewall
 Next-gen firewalls

Advantages of Firewall
A firewall is a software / hardware device that is easy to install and operate. No major technology is
required to use this tool. Privacy is paramount in this device, which is why it provides privacy to
incoming and outgoing packets. It uses its own rules to protect the system by dropping packets that

Shuvechchha Bhandari (HND / Second Semester)


27
Network Security 2019

pose a threat to the system. It can easily monitor protocols from the data link layer to the application
layer. This tool is not expensive so it can be used for any type of organization as well as for personal
purposes.

Disadvantages of Firewall
The firewall only blocks an untrusted network, but it cannot prevent an internal security risk, such as
using malicious code from a website. It cannot be properly filtered at the application layer and can
pose a security risk. Network address and packet filters can be complicated and difficult to manage in
a large environment, as they are out of sync. It has no functions like user login, login, etc. so it does
not provide any user views.

Virtual Private Network (VPN)


A virtual private network (VPN) is a point-to-point connection that connects users to private
networks in different locations. Basically, a VPN is used to establish a secure connection to the
Internet. Building a point-to-point connection from a public Wi-Fi connection to a private Wi-Fi
connection in a VPN company or corporate building works as if you were directly connected to the
network. The generally accepted definition of a network is fairly common and generally accepted
throughout the business. VPN technology was developed to give remote users and branch offices
secure access to applications and other resources. Now using in the banking scenario, we need to use
VPN because it is secure for accessing the bank system. VPN used while securing the bank are
introduced below: -

Remote Access VPN


Remote access VPN allows individual users to establish a secure connection to a remote computer
network. Some users may need to establish a VPN connection from their personal computer to their
headquarters (or destination). Remote access VPNs can use IPsec or Secure Shell (SSL) technology
for VPNs.

Site-to-site VPN
The second major VPN implementation is through a bank, which can have two or more locations that
need to be securely connected (perhaps via the Internet) so that each location can communicate with
another location or locations. ‫ ۔‬Site-to-site VPNs traditionally use a combination of VPN technology
called IPSEC.

Shuvechchha Bhandari (HND / Second Semester)


28
Network Security 2019

Advantages of VPN
Nowadays, online is an important part of our life, which is why VPN helps in making our identity
anonymous. There are many online hackers on the Internet, so it is helpful to hide our IP address so
that these hackers cannot see our data. It also helps us use the Internet more securely or privately so
that nothing leaks from our devices. Firewalls have some guidelines so we cannot go through them,
but VPN helps to avoid that firewall by hiding our IP address. VPNs are important to personalize our
Internet or network systems so that it can prevent attacks.

Disadvantages of VPN
Many are not reliable VPNs, so it is important to know more about VPNs before using them. This
could easily compromise our privacy as trusted VPNs cannot protect our IP addresses and online
hackers could easily access our details which could interfere with the necessary data and
information. Quality VPN is expensive and difficult to maintain. VPN also affects the speed of our
devices. This often slows down our devices and requires a good CPU as well as powerful bandwidth.

Access Control list (ACLs)


Access control lists (ACLs) directly determine who can access a particular sensitive area of your
network. In general, there are many. Allows general access to the network, including sensitive
information about company policies and operations. For computer file systems, there is a list of
permissions attached to the object. ACLs specify which users or system processes are allowed access
to an object and what operations are allowed on that particular object. Each entry in a typical ACL
specifies a subject and operation. Access list statements are basically packet filters that compare,
classify, and process packets.

Standard Access list


Standard list access lists are the oldest type of access lists, beginning with version 8.3 of the Cisco
iOS Software. Standard lists control access list traffic by comparing the source address of packets
with the address configured in the standard access list. The standard ACL uses only the source IP
address in the IP packet as proof of condition. All decisions in the standard list access list are based
on the default IP address. This means that the standard list access list basically allows or does not
allow a full set of protocols.

Shuvechchha Bhandari (HND / Second Semester)


29
Network Security 2019

Extended Access List


ACLs are used to control network access or define traffic that should work on a number of features.
An extended ACL is made up of one or more access control entries (ACEs). Each ACE specifies a
source and destination for the relevant traffic. You can identify the parameters in the access list
command, or you can create objects or groups of objects to use in ACL.

Named Access List


Designated access lists are created and referenced differently than standard and extended access lists,
but are still functionally similar. With named access lists, we can use names to create and implement
standard or advanced access lists. Named access lists are configured differently than normally
counted lists.

Demilitarized Zone (DMZ):


A demilitarized zone is a secure route where an internal local area network (LAN) is isolated from an
untrusted network (usually the public Internet). The DMZ acts as an external network and
communicates with external servers. Therefore, the external network cannot connect to the internal
network. The firewall checks for interactions between internal and external networks before going
through the DMZ due to restricted access to the internal network. It provides an additional layer that
helps protect the internal network of the system behind the firewall, and untrusted networks can only
connect to exposed networks in the DMZ.

Shuvechchha Bhandari (HND / Second Semester)


30
Network Security 2019

Fig: - Network Simulation in Cisco Packet Tracer

Advantages of DMZ
 DMZ helps to separate your public server from the rest of your LAN.
 This increases the security of your LAN.
 It is used to reduce and control access to those systems from outside the organization.

Disadvantages of DMZ
 It is very difficult to use.
 If the attacker enters into the firewall, they can easily access the DMZ.

Network Address Translation (NAT)


Network Address Translation (NAT) is a method of changing another IP address space by changing
the network address information in a packet's IP header while the packet is being forwarded to one
traffic routing device. NAT is the process by which a network device (usually a firewall) provides a
public address to computers (or groups of computers) in a private network. This is similar to CIDR.
The most common form of network translation is large, using addresses in the private range ([Link]
to [Link], [Link] to [Link], or 192.168.0 0 to [Link]). It includes a

Shuvechchha Bhandari (HND / Second Semester)


31
Network Security 2019

large private network. Public IP address in the private network. It helps to improve the security of the
network by only sending valid external networks. Here are the ways we can configure and example
of the NAT:

Advantages of NAT:
 It helps in privacy because the IP address is kept hidden also the transmission between internal
and external traffic also are kept hidden.
 This helps avoid using the same IPV4 address.
 It also helps you to use your own private IPV4 address and improves network security.

Disadvantages of NAT:
 It consumes many system processes and memory.
 End-to-end IP traceability can be lost.
 Some applications will not work if NAT is enabled.

Shuvechchha Bhandari (HND / Second Semester)


32
Network Security 2019

IP routing
IP routing is a set of guidelines that allow data packets to travel across a variety of networks,
following a secure route provided by the administrator. The router is used to send data from source to
destination. There are three types of IP routing:
1. Default IP routing
2. Static IP routing
3. Default IP routing

Static routing: Static IP is a permanent address that does not change and is provided by Internet
service providers for device configuration. This is done manually to configure the IP address on any
device, mainly routers. It provides better security for a fixed route and helps improve network
security, and it is used by the network administration to allow them to access the routing path,
making it more secure to transmit data. Below is the configuration:

We have to ping to know whether it share data or not. To ping we need IP address for device
[Link] and for router [Link]

Shuvechchha Bhandari (HND / Second Semester)


33
Network Security 2019

Advantages of Static IP
 Administrator choose the router network path that’ why it is very secure connection and the speed
of connection is very high.
 It is easy to use for small networks as well as bandwidth is not use to update the routers.

Disadvantages of Static IP
 It is complex for large network so network administration must handle it properly because it can
be messy.
 There will be difficult to add extra network in static IP because the configuration has to done in
each router which becomes tedious.
 It is hard and difficult to maintain if there will occur problem in network.[ CITATION tec191 \l
1033 ]

Network monitoring systems


Network monitoring is the efficient push of a PC system to distinguish moderate or flickering parts
of the system, as there are basically three types of system observing devices. These are run screens,
finger points, account observations. System watch applications are expected to use a powerful route
to check the status of the system we are using. Generally, network monitoring is done with the help
of sudden software applications and tools. These network monitoring services are used to determine
if the specified web server is working and connected properly. Some of the system monitoring
devices I have used in the bank are described below along with their importance in the bank.

There are several benefits of using network monitoring system. Some of the major benefits of using
this network monitoring are as shortly explained below:

Better visibility of network elements:


"With so many network elements, it's hard to know which elements support which business-critical
services" is a common problem faced by most network administrators today. With technological
innovation and the increase in the number of connected devices, today's computer networks are
becoming increasingly large and complex. Whether you're dealing with a software-defined network,
migrating to the cloud, or migrating to IPv6, you need reliable tools to help you control all of your
network assets and keep your business running smoothly. CA and Broadcom network monitoring

Shuvechchha Bhandari (HND / Second Semester)


34
Network Security 2019

software provide complete visibility into a complex ecosystem that helps network operator teams
easily track data moving between devices and resolve issues faster.

Intuitive insights into infrastructure planning:


Network Monitoring Software provides you with historical reports that can predict the future
performance of your infrastructure. Analyzing historical data helps you determine whether the
current system landscape can be measured to meet business needs or whether you should invest in
new technologies. For example, if network administrators are trying to convince their management
that the current infrastructure needs to be upgraded, intuition alone is not enough. The historical
record of how the instrument has performed over the past few months with reliable forecasts for the
future is much stronger.

Easily identify pending outages:


The most basic function of network monitoring software is to indicate whether a device (such as a
router, switch, server, database, etc.) is working or not. As a network administrator, you don't want to
wait for your clients to start experiencing performance problems. You prefer to take a proactive
approach and stay ahead of breakdowns. Predictive network monitoring displays network
performance metrics in an easy-to-read format, helping you identify network outages that will affect
the user experience.

Increase your bottom line and productivity:


Network monitoring software helps your NetOps teams to become more efficient by saving time in
network management while reducing operating costs. By minimizing manual intervention in
resolving recurring problems, our monitoring tools allow you to work on more complex projects.
Thus, giving immediate ROI. Also, since you are aware of the problems you are facing, a reduction
in business means less productivity and efficiency.

Understand capacity and boost performance:


The needs of application users are constantly changing. This makes it difficult for NetApp to predict
how network resources will be used in the future. As network usage grows, it may be necessary to
plan additional infrastructure to meet demand. By proactively tracking the status of devices and
applications, network monitoring software helps administrators and users understand when and

Shuvechchha Bhandari (HND / Second Semester)


35
Network Security 2019

where to use valuable network resources. With this information, you can anticipate future capacity
requirements, benchmark current performance, upgrade network elements to improve performance,
and stay one step ahead of the competition.

Wireshark
Wireshark has been around since 1998, when it was invented by Gerald Combs and called Ethereal.
Over the years it has received gargantuan amounts of community support and patches, and is widely
accepted as the de facto network protocol analyzer available today.
Wireshark runs on all the major and most minor operating systems, including the usual Linux distros,
Windows, OS X, FreeBSD, NetBSD, and OpenBSD. The program is free software, licensed GPL,
and is thus free to use, share, and modify.[ CITATION wir16 \l 1033 ] Wireshark is the world's
leading network traffic analyzer and an indispensable tool for any security expert or system
administrator. This free software allows you to analyze network traffic in real time and is often the
best tool for troubleshooting your network. Wireshark is a powerful tool that requires extensive
network knowledge. It helps filter the traffic, which makes it especially useful. Collection filters only
collect the types of traffic that you are interested in, and display filters help you grow the traffic that
you want to investigate. The Network Protocol Analyzer provides search tools, including regular
expressions and highlighting, to make it easier to find what you are looking for. Example: For most
modern businesses, this means understanding the TCP / IP stack, reading and interpreting packet
headers, and how routing, port forwarding, and DHCP work.

Fig: Wireshark main view

Shuvechchha Bhandari (HND / Second Semester)


36
Network Security 2019

Fig: documentation of Wireshark

SNMP server
SNMP (Simple Network Management Protocol) is a network management protocol used almost
exclusively on TCP / IP networks. SNMP provides a means of monitoring and controlling network
devices, and managing configurations, statistics, performance, and security on a network.
[ CITATION Tho20 \l 1033 ] SNMP-based management enables the use of third-party solutions that
include products such as HP OpenView and CA Uncenter. Network management stations run
management applications that monitor and control the managed nodes. Managed nodes are devices
such as hosts, gateways, etc. that have management agents that are responsible for performing
management functions requested by management stations. SNMP is used to communicate
Shuvechchha Bhandari (HND / Second Semester)
37
Network Security 2019

management information between management stations and agents. The SNMP agent on these
servers offers the following functions:
Event management
Inventory management
Sensor and system state monitoring
SP configuration monitoring

Trusted Network
A trusted network is controlled by a network manager or network administrator. Basically, it is the
network administrator who tries to define and define the security parameters. Therefore, it can also
be said that reliable networks are within the limits of security. Computers using trusted networks are
more secure and confidential due to stronger firewalls. Allows only open and secure data transfers to
authorized users. Unreliable networks are beyond the control of the security community and the
network administrator. They can even be private or shared networks. Consider security policies and
access to the levels you can use to secure the network.
To monitor incoming and outgoing traffic, we set up a firewall and set out some rules for exchanging
two-way packets on a firewall server. After we start configuring for the firewall, all the network
behind the firewall is in a reliable network. As far as VPNs are concerned, they transfer data to
unreliable networks and are still considered trusted networks because the source of the packet is in a
trusted network. Virtual Private Network (VPN) programming is the creation of a less secure
network, such as a secure and confidential connection to the public Internet. In the early days of the
Internet, VPNs were developed to provide branch office employees with access to corporate
applications and data, cheaply and securely.

Shuvechchha Bhandari (HND / Second Semester)


38
Network Security 2019

Authentication: Authentication takes place in two stages. Level and machine level visible to the
user. Human-level visual authentication is a simple login where you provide a network ID and
password to access it. However, machine-level authentication is more complex and involves a
predefined ID and password that are only known to the machine authorized to access the network.
This can occur when a user attempts to access a computer or node network after completing the
initial human visualization. The router or server, in this case, the machine is authorized to access the
network, and the machine attempting to connect must provide its identity (IP address or MAC
address) and the secret key that accompanies it to prove its authorization. Access the network.

Encryption- Network encryption is the process of encrypting or encoding data and messages sent or
communicated over a computer network. It is an extensive process consisting of various tools,
techniques, and standards to make messages unreadable while transferring between two or more
network nodes. Network cryptography is implemented primarily in an OSI-like network layer.
Network encryption implements one or more encryption algorithms, processes, and standards for
encrypting data / messages / packets sent over the network. Cryptographic services are usually
provided through cryptographic software or cryptographic algorithms integrated with network
devices and / Orin software.
Advantage of using encryption technology:
1. Encryption Provides Security for Data at All Times
2. Encrypted Data Maintains Integrity
3. Encryption Protects Privacy
4. Encryption is Part of Compliance
5. Encryption Protects Data across Devices

Firewall: Computers and servers on trusted networks must have hardware, such as a firewall, which
is a software program or hardware that helps verify security.
Private networks: Computers and servers in trusted networks must be equipped with software such
as virtual private networks (VPNs).

Impacts of trusted network on IT security


Hardware-Based Security: Processes that execute on expert safety hardware are better included
than techniques that execute on regular computing engines. These included capabilities are an awful

Shuvechchha Bhandari (HND / Second Semester)


39
Network Security 2019

lot extra proof against interference and snooping from logical or bodily assault, so there's more self-
assurance in the ones techniques than in techniques that execute on a regular computing engine.
In a traditional platform with a traditional crypto co-processor, the co-processor protects all its
capabilities from logical and bodily assault however does not defend processing at the regular CPU.
A Trusted Platform presents logical and bodily safety for secrets and techniques and logical safety
for the statistics included through the one’s secrets and techniques (that is processed on one of the
primary CPUs). The TPM acts as a traditional co-processor for secrets and techniques, and the
integrity mechanisms save you the discharge of secrets and techniques to irrelevant processing
environments and allow a nearby or far off consumer or pc to affirm the trustworthiness of a platform
earlier than interacting with that platform. So, a Trusted Platform protects a bigger wide variety of
techniques than a traditional platform with a traditional crypto co-processor: A essential few
techniques—handling secrets and techniques—are included through a minimalist crypto co-
processor. Other techniques on statistics that makes use of secrets and techniques are much less
included than they might be internal a crypto co-processor. This is due to the fact no bodily safety
exists, for example, in opposition to deletion. But they may be higher included than regular
techniques outdoor a crypto co-processor due to the fact the confidentiality and integrity of the
statistics are included.
Specifically, a Trusted Platform presents hardware safety for keys and different secrets and
techniques, which might typically be used to encrypt documents or benefit get right of entry to
servers or different networks. The TPM prevents the discharge of secrets and techniques till
presentation of an authorization fee and/or the presence of a specific TPM and/or the presence of a
specific software program nation in the platform. The TPM prevents irrelevant get right of entry to
encrypted documents and community assets through, for example, snooping round a difficult disk,
shifting a difficult disk to any other platform, or loading software program to listen in on different
techniques.

Feedback about Trust to the User: By interacting with trusted platforms using smart cards or
handheld computers such as Personal Digital Assistants (PDAs), users can choose to trust a computer
or IT infrastructure. A smart card or other handheld computer can be programmed to query a secure
platform (local or remote), retrieve identity information and integrity metrics, and compare identity
and integrity metrics against expected values. If they disagree, a smart card or handheld user may
refuse to communicate with a trusted platform because it is the wrong computer or in a bad
condition. Inappropriate software and its intended use are unreliable. It allows users to access an

Shuvechchha Bhandari (HND / Second Semester)


40
Network Security 2019

arbitrary computing platform in an organization or public space, or on an unauthorized server, and


privately without users' permission to determine if it is trusted to work on private information and
not disclose information.

Trustworthy Digital Signatures: Digital signatures become more important as they gain more
legitimacy, and trusted platforms can help and enhance the use of digital signatures. Users realize
these benefits in the following ways:
 The trusted platform protects signature keys using TPM, TPM never exposes these keys to the
outside, and the data stored in TPM uses such keys to digitally sign.
 The trusted platform enhances digital signatures by adding integrity metrics that indicate the state
of the software platform when data is signed.
 Depending on the implementation of the TPM, a reliable platform can add signatures, ensuring
that what the signatory sees is consistent.
Therefore, the main advantages of having a trust network in the organization is that it has many
advantages and positive effects on the organization. A trust network helps increase performance in
the organization and boost a sense of security and safety in the organization.

Conclusions
Different types of security solutions are described such as firewall, VPN, NAT, DMZ, static IP, etc. to
improve the security of the organization's network. The firewall is used to avoid unnecessary data
packets and the VPN is also used to secure the network connection within the organization. It also
shows that incorrect VPN and firewall settings can be dangerous for the organization. DMZ is used
to prevent attacks from untrusted networks, NAT is used to give a private IP to the bank, and a static
IP is used as the best route to give devices. These security solutions help prevent risks and provide
better security for the organization. For making trusted network part of our IT security solution first
we should know about the factors of trusted network. In this way while doing research first I found
out the factors of trusted network like Authentication, Encryption, Firewall and Private Network.

Shuvechchha Bhandari (HND / Second Semester)


41
Network Security 2019

Part: 3
Once you have identified IT risks and viable security solutions, you need to review the
mechanisms to control organizational security. Consider various aspects of network change
management, audit controls, disaster recovery plans, Data Protection Acts, Computer Misuse
Act, ISO 3001 standards, etc. You need to:
1. Discuss risk assessment procedures and explain data protection processes and regulations as
applicable to the organization.
2. Summarize the ISO 31000 risk management methodology and its application in IT security
and then discuss possible impacts to organizational security resulting from an IT security
audit.
3. Explain considering how IT security can be aligned with organizational policy, detailing the
security impact of any misalignment.

Introduction
“A risk assessment is a thorough look at your workplace to identify those things, situations,
processes, etc. that may cause harm. After identification is made, you analyze and evaluate how
likely and severe the risk is. When this determination is made, you can next, decide what measures
should be in place to effectively eliminate or control the harm from happening.”[ CITATION
nd154 \l 1033 ]
Risk assessment is the ability to identify, analyze, and assess a threat before it poses a threat to the
entire network system. ISO 31000 is an international method of risk management guidance for risk
control. The ISO 31000 risk assessment is broken down into several conditions, namely, risk
identification, analysis and evaluation. Data protection procedures and regulations are rules that
apply to the organization to discipline those who misuse sensitive data and information and enforce
risk-taking measures. There are many laws that can be applied to data protection processes, such as:

Shuvechchha Bhandari (HND / Second Semester)


42
Network Security 2019

B. Network Change Management, Data Protection Act, Computer Abuse Act, etc. In this section I
cover risk assessment and the process of data protection to control this risk.

Risk assessment
Risk assessment identifies risks that could negatively affect a firm's ability to run a business. These
reviews provide actions, processes and controls to identify these inherent business risks and mitigate
the impact of these risks on business processes. Surveying risk assessment is fundamental for
deciding how advantageous a speculation is and the best procedures to relieve chance. It displays the
upside compensate contrasted with the risk assessment profile. It likewise decides the rate of return
important to influence a specific venture to succeed. Companies can use the Risk Assessment
Framework (RAF) to prioritize and distribute assessment details, including any risks to Innovation
Technology (IT) infrastructure. RAF helps the organization identify potential risks and any business
assets at risk from these risks, as well as the potential consequences if these risks are effective. In
large businesses, risk assessment is usually done by the Chief Risk Officer (CRO) or Chief Risk
Manager.

Risk assessment steps


Step 1: Identify the hazards. The first step in the risk assessment is to identify any potential hazards
which, if encountered, could negatively affect the organization's ability to conduct its business.
Potential hazards that can be considered or identified during a risk assessment include natural
disasters, power outages, cyber-attacks, and power outages.
Step 2: Determine what or who might be injured. After identifying the hazards, the next step is to
determine which business assets will be adversely affected if the risk materializes. Business assets
considered to be exposed to these threats can include critical infrastructure, IT systems, business
operations, corporate reputation, and even employee security.
Step 3: Assess the risks and develop controls. Risk analysis can help determine how hazards will
affect business assets and the actions that can be taken to minimize or eliminate the impact of those
hazards on business assets. Potential dangers include property damage, business disruption, financial
loss, and lawsuits.
Step 4: Save the results. The results of the risk assessment should be recorded by the company and
filed as easily accessible official documents. Records should include details of potential hazards,
associated risks, and hazard prevention plans.

Shuvechchha Bhandari (HND / Second Semester)


43
Network Security 2019

Step 5: Regularly review and update your risk assessment. The potential dangers, risks and
associated controls can change quickly in today's business environment. It is important that
companies regularly update their risk assessments to adapt to these changes.

Goal of risk assessments


 Develop a risk profile that provides quantitative analysis of the types of threats the business
faces.
 Develop an accurate inventory of IT assets and data assets.
 Justify the cost of security measures to mitigate risks and vulnerabilities.
 Develop an accurate inventory of IT assets and data assets.
 Identify, prioritize and document the risks, threats and known weaknesses in the company's
production infrastructure and facilities.
 Determine budgeting to address or mitigate identified risks, threats, and vulnerabilities.
 Understand the return on investment, whether funds are invested in infrastructure or other
operational assets to offset potential risks.

Risk Assessment in ISO 31000


ISO 31000 is an international standard that was published in 2009 and provides principles and
guidelines for effective risk management. It describes a general approach to risk management that
can be applied to different types of risk (financial, security, project risk) and used by any type of
organization. The standard offers a uniform vocabulary and concepts for discussing risk
management. It provides guidelines and principles that can help you to critically analyze the risk
management process in your company. The standard does not contain detailed instructions or
requirements for dealing with specific risks or recommendations with regard to a specific scope; it
remains at the general level. We can't utilize ISO 31000 for confirmation reason yet it gives direction
to us and utilizing it we can contrast association's dangers administration hones and another global
benchmark. This procedure is intended to be iterative, communitarian and efficient with the goal that
coordinated risk assessment administration system can be created.

There are three stages engaged with ISO 31000 risk assessment appraisal strategy which are
talked about underneath:

Shuvechchha Bhandari (HND / Second Semester)


44
Network Security 2019

Risk Identification
The first stage of ISO 31000 risk assessment is the identification stage. You need to identify,
understand and explain the risks. Remember, risk is seen as something that can hinder, prevent, or
even help an organization achieve its strategic goals. During the risk identification phase, it is
important to use the latest information available. Realistic, timely and accurate statistics will enable
you to develop highly relevant strategies. Factors to consider identifying potential threats to your
organization may include: material and non-material sources, causes / events, threats and
opportunities (also important to assess positive risks), risk management opportunities and Changes in
the context of any risk such as changes in available external resources, the nature and value of the
risk
the likelihood of the risk and the likelihood and consequences of the risk (knowledge), Experience
and Stakeholder Assumptions Risk Assessment. When identifying a risk, it is important to note the
consequences of multiple risks.

Risk Analysis
The risk analysis phase enables decisions regarding risk treatment and the determination and
determination of the organization’s risk tolerance. The type, amount and probability of occurrence of
the risk as well as detailed factors such as available resources and internal / external influences are
taken into account. A risk incident can have several consequences that can affect other risks. The
domino effect of risk should also be seen in relation to the goals of the organization. The methods
used to analyze risk are many and the organization must determine which ones to use. Some of these
are discussed in Section 6.3 as the context of the risk management strategy includes the definition of
risk criteria and measurability. You can use a qualitative, semi-quantitative, or quantitative approach,
or a combination of all three, to determine the risk analysis. Remember that the risk is very
subjective. While communication with key stakeholders is critical during the development and
implementation of a risk management strategy, an approach that somehow reduces bias must be
followed. One person may rate the risk as very likely and severe, while another person may rate the
risk as moderately likely and less severe. Your organization needs to determine how the measurement
of risk level is defined and this will affect your risk measurement and analysis.

Risk Evaluation
The final step in the risk assessment process is risk assessment. The idea behind the assessment is to
make it easier for organizations to prioritize risk handling and risk mitigation.

Shuvechchha Bhandari (HND / Second Semester)


45
Network Security 2019

Risk Assessment to Determine Steps for Risk Criteria and Risk Analysis:
Effectiveness of Defining Criteria What are the Highest Priority Risks?
How to approach the next step (risk handling) The results of a risk assessment can lead to many
actions. Further analysis should be assigned, existing controls should be maintained,
the purpose of the risk strategy should be revisited in conjunction with the purpose of the
organization.
Regular assessments allow you to address changes in risk factors, impacts, consequences, and
objectives within a reasonable time frame, allowing you to develop a comprehensive and mature risk
management strategy.
Along these lines risk assessment can be evaluated in ISO 31000 risk assessment appraisal
philosophy, in spite of the fact that we can't utilize ISO 31000 for affirmation reason yet it gives
direction to us and utilizing it we can contrast association's dangers administration rehearses and
another worldwide benchmark. Risk assessment administration 31000 isn't finished in itself and
requires ceaseless change.

Data protection and its regulations


"Data protection is the process of protecting important information against corruption, compromise
or loss."[ CITATION Ric18 \l 1033 ] Data protection describes operational personal data backup and
business continuity / disaster recovery. It is a strategy developed in two lines: data availability and
data management. Data protection is also an important task that must be done to run a business. Data
is a valuable asset that is used for a variety of purposes. The data company needs to keep data safe
and secure to protect it. Data must be safely restored if it is lost or damaged. Every organization have
different data protection process and regulation that’s why these data protection process should meet
your business policies. There are some of the acts related to data protection process:

Network Change Management


Network Change Management is the growing technology for configuration and change management.
If there any changes take place in network then it can lead to error or faults which can also leads to
vulnerabilities activities so to minimize these types of faulty configuration Network Change
Management helps to configure properly those network activities. It helps to execute method like
changing or updating network as well as also in different government act use by the organization.
Mapping Devices and System Validation urges the Gadgets Association to ensure that all steps taken

Shuvechchha Bhandari (HND / Second Semester)


46
Network Security 2019

in sequence do not bypass government control of information. Some members of the association use
system change administration as an approach to robotically reduce downtime and comply with
government regulations, and streamline the backup and restore of gadget designs. It helps to make
organization in robotize approach as well as it also reduces in network downtime and saving each
and
every data and information of organization without any faulty configuration.

Data Protection Act (DPA):


The Data Protection Act 1998 is a law of the United Kingdom Parliament. The Act defines the UK's
data processing law for identifiable living persons (see Checklist: "Program of Action to Respect
Data Protection Act"). All UK companies that hold personal information about third parties
(customers) must comply with data protection law. The Data Protection Act is a national law that
supplements European Union's General Data Protection Regulation and updates information security
laws in UK. The Data Protection Act 2018 is actualized in seven sections which are delineated in
Section 1. The principles of the law are as follows (write down all tasks completed):
 This act has right to manage the personal data of individual
 Managing personal data is related to GDPR
 Part 2 supplements the GDPR and applies a broadly equivalent regime to certain types of
processing to which the GDPR does not apply.
 Part 3 makes provision about the processing of personal data by competent authorities for law
enforcement purposes and implements the Law Enforcement Directive.
 Part 4 gives right to managing personal data to intelligence services.
 Part 5 makes deliver about the Information Commissioner.
 Part 6 makes deliver about the enforcement of the data protection legislation.
 Part 7 makes supplementary arrangement, including delivering about the application of this Act
to the Crown and to Parliament.[ CITATION gen18 \l 1033 ]

Significance of DPA
Data protection is the best practice for any organization as it provides rules and regulations that can
be followed to gain the trust of customers, partners, etc. It helps to protect the personal data of the
individual by applying its principle. The law also punishes those who do not follow or disobey these
rules. The law protects all types of data and also prioritizes ethnic background, health, criminal
history, etc. There are many cybercriminals today, so this law provides strict security for data and

Shuvechchha Bhandari (HND / Second Semester)


47
Network Security 2019

data sharing. With this act, an organization can properly manage data and maintain data quality. It
analyzes, stores, backs up and retrieves this data with appropriate roles and responsibilities. For
example, after our customers provide us with their information, we need to make sure that the
information is used in a particularly expressive way, that it is no longer placed where it is needed,
that it is only meaningful. I use it, that is, to keep it safe, etc. In the remote possibility that we do not
do what is stated, our association may be rejected as stated by law. It is important to follow the
information safety net to prevent cybercrime, while ensuring that subtle elements are protected from
misrepresentation.

Computer Misuse Act


The main purpose of the Computer Misuse Act (CMA) was to combat cybercrime by making it
illegal to access and modify computer data. The law represents the first major legislation to address
cyber threats and criminalize hacking, viruses, malware and spyware. The purpose of the Computer
Misuse Act was to regulate the growing world of computers, which, in 1990, was simply not
adequately protected by law. The compatibility of the current legal framework for computers was
highlighted in the 1987 case of Steve Gold and Robert Schaefer, who gained unauthorized access to
the BT service, which eventually led to their e-mail account in Dunk of Edinburgh. Accessed. His
sentence was overturned on appeal under the Counterfeiting and Counterfeiting Act 1981 because the
circumstances of the case did not correspond to any criminal offense under applicable law. With the
rise of the Internet, smartphones and social media for decades, the vast digital environment continues
to be regulated, following the royal approval of the Computer Misuse Act.[ CITATION cyf17 \l 1033
] This act gives proper punishment to those criminals who tried to hack or who considered to attack
other parties. In organization also, there can be attack of many malicious activities like password
changing, data modifying, email attack etc. so this act helps to take proper legal battle to those cyber
criminals.
Significance of Computer Misuse Act
For all types of organizations, the Computer Data Abuse Act is required to ensure that personal data
and information is protected from hacking and viruses. The act helps in gaining the trust of
customers, partners, individuals etc. and also help in strengthening the reputation of the organization.
Enforcing this law helps the organization to avoid unnecessary unauthorized access and misuse of
PCs. It is not easy to attack hackers if they know that this rule applies to any organization.

Shuvechchha Bhandari (HND / Second Semester)


48
Network Security 2019

Data Protection Processes and Regulation in Nepal


The data protection process and guideline are to protect people's data. Nepal is slower in information
technology than other countries, but it provides the same facilities or regulations to the entire
organization. Data protection means backing up data, reviewing data, managing data without loss,
loss or leakage, which must be implemented fairly and legally. The organization should protect the
data without sharing any data and without any other intention so that people can be confident that the
organization will provide its data. In Nepal, there is an electronic transaction law that helps secure
every electronic data or information. This law helps to regulate those who access or hack into another
PC without permission. The law helps bring legal charges to cybercriminals who illegally take other
data and information. The organization should enforce this code to protect the data of clients,
partners and individuals.

Summarization of ISO 31000 Risk Management


Risk Management - Provides guidelines, principles, framework and process for risk management. It
can be used by any organization, regardless of its size, activity or industry. Using ISO 31000 can
help organizations increase their chances of achieving goals, improve the identification of
opportunities and threats, and help them effectively deploy and use resources for risk treatment.
However, ISO 31000 is not used for certification purposes, but it does guide internal or external
accounting programs. Organizations that use this can compare their risk management practices to the
internationally recognized standard that provides solid principles for effective management and
corporate governance.
Principle
The ISO 31000 principle deals with the basic idea, principle or truth about an article. “ISO 31000
serves as a risk principle, a risk management framework and a guide for its implementation, method,
logic, design and implementation. impose the administration of the danger, transmit its esteem and
clarify its object and reason.[ CITATION Mic \l 1033 ] The standards are the establishment of risk
monitoring and are taken into account during the development of the association's risk management
system and procedures. These should enable an association to cope with the impacts of vulnerability
targets. If opportunities management is to be convinced, the association must meet the following
criteria at all levels:
 creating and maintaining risk management values.
 Risk management is an integral part of all organizational processes.
 Risk management is part of decision making.

Shuvechchha Bhandari (HND / Second Semester)


49
Network Security 2019

 Risk management clearly addresses uncertainty.


 Risk management is systematic, structured and timely.
 Risk management is based on the best available information.
 Risk management is tailor-made.
 Risk management takes human and cultural factors into account.
 Risk management is transparent and inclusive.
 Risk management is dynamic, iterative and responsive to change.
 Risk management allows the organization to continually improve.

Process and Framework:


ISO 31000 provides guidance on risk management. It can be used by any organization, regardless of
size, activity or area. It helps improve the organization by identifying potential hazards and risks, and
provides guidance on how to reduce or eliminate all of these risks. This framework helps the risk
management process to manage risk effectively at different levels and in specific contexts of the
organization. This framework ensures that information about the risk is communicated as a result of
the risk management process and that it helps in making decisions for the appropriate levels of the
organization. The ISO 31000 application process establishes an internal and external context to
ensure the objectives and interests of the interested parties while developing the risk criteria and
helps identify all opportunities to achieve project or business objectives. After understanding the
internal and external context, a risk management process is established in which all the goals,
objectives and methods for risk assessment are defined.

Fig: Process of ISO 31000 Risk management

Shuvechchha Bhandari (HND / Second Semester)


50
Network Security 2019

Identifying risks: Recognize what may prevent you from achieving your goals.
Risk analysis: Understand the causes and causes of identified risks. Investigation of probabilities
and outcomes given appropriate controls to determine the level of residual risk.
Risk assessment: Compare the results of risk analysis with risk criteria to determine if residual risk
is acceptable.
Risk handling: Change the magnitude and likelihood of results, both positive and negative, to
achieve a net increase in profits.
Establishing Context: This activity, which was not included in the previous description of the risk
management process, consists of defining the framework of the risk management process, defining
the purpose of the organization, and establishing risk assessment criteria. The contexts include
external elements (regulatory environment, market conditions, stakeholder expectations) and internal
elements (governance, culture, organizational standards and rules, skills, existing contracts,
employee expectations, information systems, etc.)
Monitoring and Review: This task involves measuring the performance of risk management against
indicators, which are reviewed from time to time to ensure their relevance. This includes verifying
deviations from the risk management plan, verifying whether the framework, policy and risk
management plan is still appropriate, taking into account the external and internal context of the
organization, reporting on risks, progress of the risk management plan and quality risk management
policy. The effectiveness of the risk management framework is monitored and reviewed.
Communication and Consulting: This function helps to understand stakeholder interests and
concerns, verifies that the risk management process is focusing on the right elements, and also helps
explain the rationale for decisions and alternatives to deal with particular risks.

Shuvechchha Bhandari (HND / Second Semester)


51
Network Security 2019

Fig: Framework of ISO 31000 Risk management


Framework are defined as real or conceptual structures and are intended to serve as support or
guidance for building something further. That is, it extends the structure to something useful. If a
company wants to manage risk consistently and effectively, it must first make sure that the company
has nine key management functions. The standard identifies these skills as three basics and six
organizational precautions.

Security Audit
Network security audit is a key component of the firm's ongoing risk mitigation strategy. Whether
the audit is performed by an internal team or an external auditing company, the process includes a
measurable assessment of your firm's security policy and management details. The term "audit" may
indicate that such an assessment is unexpected, but in most cases cyber security audits are conducted
with the full knowledge and cooperation of the company. Will be made. Security auditing is a
complete process and may take some time to complete. This is because auditors consider not only the
technical aspects of network security (firewalls, system configurations, etc.) but also the
organizational and human aspects of security policies. In addition to investigating IT systems and
historical data, conduct personal interviews and review documentation to ensure that information
security procedures meet relevant compliance standards. This is followed routinely and has to be
done.

Shuvechchha Bhandari (HND / Second Semester)


52
Network Security 2019

Importance of Security Audit in Organization


There are many ways that security audits add value to an organization. In many cases, they need to
start a viable business in the first place. If a company cannot demonstrate that it has the proper
controls in place to reduce risk and protect data, it will be difficult to find vendors willing to work
with them or customers willing to entrust them with their data. In that sense, an IT security audit
should be considered critical in the business sense.
Even after the initial audit is complete, organizations must continually update their security audit
checklists to ensure ongoing compliance. But the benefits of security audits go beyond the "table
right" of meeting compliance standards. Network security is a worrying and dynamic field, and
failing to keep up with the latest developments and cyber threats can weaken the organization even if
its information security policies have been effective in the past. Cybersecurity audits can identify
vulnerabilities and problem areas in the IT system and show where policies and controls need to be
changed to address them.
For example, if a software security update has been performed recently, but only a few people in the
organization are aware of those changes and have not made any corresponding documentation
updates to reflect them, this lack of knowledge could put the data in risk. The security audit is also
important because it establishes a baseline for the security posture of the company. This database
makes it easy to diagnose problems if they arise after the audit. If the audit process finds that policies
and controls are sufficient to mitigate risk, subsequent security events are the result of someone not
adhering to established procedures, rather than explicit oversight on network security.

Aligning IT Security with Organizational Policy


There is no single strategy or strategy that guarantees success in improving business alignment in
security. Instead, several different but interrelated functions need to be identified and implemented to
improve alignment over time. Different corporates are generally suitable for different corporate
cultures and business environments. Even after making the schemes official laws, they can declare
the processes difficult to complete without IT security, and in such a situation, the bank's clients may
also face issues that may affect the integrity of the bank. We can modify computer security
hierarchically on specific routes, for example, to improve the correspondence between them. Since
all official procedures are done intentionally with the help of access to the board of members, talk to
them about that factor, existing prerequisites for improvement, and specific requirements, e.g., for
example, chance administration, performing security review in association can assist us with aligning

Shuvechchha Bhandari (HND / Second Semester)


53
Network Security 2019

IT security with hierarchical arrangements Hierarchical preparation security. The head of the IT
department of our financial institution needs to study the near contemporary security status of all the
facts and conditions of the hotspot destination without problems to sustain the financial institution
reforms, along with the footprints they leave for new workers. Pinnacle Management bodies can
make financial institutions almost a fame in IT security. Behind the techniques of our financial
institution, if sometimes the upper management body of workers expressed such readiness, that they
may not be happy with the help of the IT department to use the IT workplace on that factor, they
should know. And the processes can be updated.
Therefore, there are basically seven key chapters that are all interrelated and related to improving
business consistency, and are summarized below: -
 Culture: Develop an organizational tradition wherein users, managers and IT experts all make
exact selections approximately statistics risk.
 Planning: The strategy and strategy planning activities of an information security firm provide
ample opportunity to tailor outcome plans and tasks to actual business needs. For example,
controlling the principles of enterprise architecture in security planning practices is an important
strategy.
 Action: Adopting a strategic action approach, as defined by ISO 27001 for the ISMS Security
Management Program. Instead of enforcing the control baseline "fits all in one size", it
establishes the ability for businesses to evaluate, develop, and implement security solutions when
needed.
 Communication: The main objective should be to develop a security level service level metrics
that can be incorporated into regular service level agreements (SLAs) between IT, service
providers and the consumer sector.
 Qualifications: Business alignment generally does not require information security expertise
skills such as architectural practice, personal communication, business information and
marketing skills.
 Technology: The way that security technologies are used can have a major impact on the
perception of security of technology users. The success of an integrated IT service delivery
strategy, such as that required by ITIL v3, will depend on how security controls are technically
integrated with IT services.
 Relationships: The significance of organizing and retaining powerful relationships with different
roles and people with inside the organization. Alignment relies upon at the cooperation and assist
of key influencers, selection makers, and different stakeholders.

Shuvechchha Bhandari (HND / Second Semester)


54
Network Security 2019

Alignment is a challenge that cannot be met in pieces. Organizations need to spend their time and
resources on a comprehensive strategy to improve business integrity. The actions and plans that
result from this strategy should be carried out collectively, not in place of an existing security plan.

Misalignment of IT Security Policy with Organizational Policy


The policies and procedures of every employee working in any organization are called organizational
policies. Each organization must have its own organizational policies and maintain a security system.
In a bank or other organization, the benefits come when the security is aligned with the organization's
policies. But if there is a misunderstanding, it has security implications for the organization. When
security is combined with organizational policies, security is strengthened which helps reduce risks
and risks in the company. But when misrepresented, it creates a huge problem. Risk and risk will
increase in the company. Data breaches are more likely because security failures such as some
employees' login times are not properly enforced then they can access the system and also use the
system and retrieve data. The company will be more likely to acquire valuable information. If port-
like permissions are not properly blocked, they can easily retrieve data using a pen drive, external
HHD, etc. If NTFS security is not implemented properly, conflicts will arise in the company and may
lead to data breach. If you use the folder of another department, then there will be more trouble.
There are several implications that can be seen if there is a misunderstanding between an
organization's policy and security. The main implications that have been observed due to security
misunderstandings in the system are the disclosure of intelligence that will make a big difference to
the company. This malpractice can undermine the security of the system and may even break the
company. There will be a breach of both internal and external data which will make the company
worthless. Both misalignment and misalignment can be reasons for the company which will bring
down the company.

Conclusion
The risk and threats which is seen in the organization should be identified, analyzed and evaluate
according to the risk assessment procedure and it can be mitigated using the ISO 31000 guidelines.
The process and the regulation that should be used to protect the data in the organization which is
one of the most valuable things of any organization. Data can be used for different use like it can
help to predict the future. It can used for market research and so on. The security audit that should be
done time to time to protect the data and information and their impacts are explained. It is important
for every organization to write policy to support continuity of organization business and while

Shuvechchha Bhandari (HND / Second Semester)


55
Network Security 2019

designing it there should be included head member of IT security department so that after
implementing policy all the organization’s department can handle those policy effectively. Alignment
of IT security policy with organizational policy is important for all the organizations to smoothly run
all functions of organizations.

Part: 4

Shuvechchha Bhandari (HND / Second Semester)


56
Network Security 2019

Lastly you will produce technical and user documentation which will be given to the company
for the management of organizational security. You have to design and implement a security
policy for the bank which will.
1. List out the main components of an organizational disaster recovery plan, justifying the
reasons for inclusion.
2. Discuss the roles of stakeholders in the organization to implement security audit
recommendations.
3. And an evaluation of the suitability of the tools used in an organizational policy.

Introduction
A security policy is a written document that describes how a company protects a company's physical
and information technology assets. This security policy never expires. That is, it is updated as
technology and employee requirements change. Companies should always focus on training their
employees on how to protect their assets, such as valuable data. The company's physical and
informational assets are so important to its survival in the market that it needs to plan for recovery in
the event of a disaster or emergency. A natural disaster recovery plan is a method designed to recover
your organization's data as quickly as possible in the event of a natural disaster. All of this plan
should be considered with high-impact stakeholders such as employees, board members,
management and managers. Stakeholders are individuals who are interested in the company and who
have the potential to influence or influence the business.

Purpose of bank security policy


 It helps in understanding the threats and threats related to an organization.
 It helps to control those risks and dangers.
 This network security helps to implement physical and logical security to protect the system.
 It helps to prevent risk by having periodic tests and evaluations.
 It helps to keep data and information secure and allows periodic updates and regular review of
that data.

Major devices that are used in a network

Shuvechchha Bhandari (HND / Second Semester)


57
Network Security 2019

Modem
Modem is short for modulator-demodulator. It is a hardware component that allows a computer or
other device, such as a router or switch, to connect to the Internet. It converts or "modulates" the
analog signal of a telephone or cable wire into digital data (ones and zeros) that the computer can
recognize. Similarly, it converts digital data from a computer or other device into an analog signal
that can be sent over standard telephone lines. The first modems were "dial-up", meaning they had to
dial a phone number to connect to an Internet service provider. These modems operated on standard
analog telephone lines and used the same frequencies as telephone calls, limiting their maximum
data rate to 56 kbps. Dial-up modems also require full use of the local phone line, meaning that voice
calls interrupted the Internet connection. Modern modems are usually DSL or cable modems, which
are considered "broadband" devices. DSL modems operate over standard telephone lines, but use a
wider frequency range. It provides faster data transfer rates than dial-up modems and does not
interfere with phone calls. Cable modems send and receive data over standard cable TV lines, which
are usually coaxial cables. Most modern cable modems support DOCSIS (Data over Cable Interface
Specification), which provides an efficient way to transmit TV, cable Internet and digital phone
signals over the same cable line. [ CITATION Com19 \l 1033 ]

Router
The Advanced Research Project Agencies Network (ARPANET), based on projects developed in the
1960s, was created in 1969 by the United States Department of Defense. This early network design
was based on circuit switching. The first device to function as a router were the interface message
processors that made up the ARPANET and formed the first packet data network. The original idea
for a router, then called a gateway, came from a group of computer networking researchers who
formed an organization called the International Networking Working Group, which in 1972 became a
subcommittee of the International Federation for Information Processing. The first true router was
developed, and by 1976 three PDP-11-based routers were being used to prototype an experimental
version of the Internet. From the mid-1970s to the 1980s, minicomputers were used as routers.
Today's high-speed routers are actually very specialized computers with additional equipment for fast
forwarding of data packets and specialized security features like encryption. A router is a device that
analyzes the content of data packets sent over a network or another network. Routers determine
whether the source and destination are on the same network or whether data is to be transferred from
one type of network to another, which requires encapsulating the data packet with the routing
protocol header information for the new one. network type. When multiple routers are used in a

Shuvechchha Bhandari (HND / Second Semester)


58
Network Security 2019

collection of interconnected networks, they exchange and analyze information and then create a table
of routes and preferred rules to determine routes and destinations for that data. As network interfaces,
routers convert computer signals from one standard protocol to another that is more suitable for the
destination network. Large routers determine interconnectivity within a business, between businesses
and the Internet, and between different Internet Service Providers (ISPs); Small routers determine
interconnectivity for home or office networks. ISPs and major companies exchange routing
information using the Border Gateway Protocol (BGP).

Switch
In the context of networks, a switch is a high-speed device that receives incoming data packets and
sends them to their destination in the local area network (LAN). A LAN switch works on the network
layer of the Data Link Layer (Layer 2) or OSI model and thus supports all types of packet protocols.
The layer 2 switch is sometimes called a bridge: its function is to send frames with data packets
between nodes or layers of the network. In short, switches are a simple local area network traffic
police. Describes the tractor as units of data for switching frames and how data is transferred from
one area of the network to another. Routing, on the other hand, takes place on layer 3, where data is
sent between networks or from one network to another.

Server
A server is a computer program or device that serves another computer program and its users (also
known as clients). In a data center, the physical computer on which the server program runs is often
referred to as the server. This machine can be a dedicated server or used for other purposes. In the
client / server programming model, server programs expect and meet requirements from client
programs that can run on the same computer or on different computers. Certain applications on your
computer can act as clients of service requests from other programs and as servers for requests from
other programs.

Networking cables
A network cable serves as a means of transferring information from one network device to another.
The type of cable chosen for your network depends on its size, topology, and process. Various types
of network cables act as the backbone of the network infrastructure. Choosing the right type of
network cable can impact a variety of business operations as corporate network administrators adopt

Shuvechchha Bhandari (HND / Second Semester)


59
Network Security 2019

new technologies. The type of network cable used in any network infrastructure is one of the most
important aspects of networking in various industries.
Coaxial Cable
There is only one copper conductor between them. The plastic layer provides insulation between the
braided metal shell and the center conductor. The metal shells block outside interference from
motors, fluorescent lights, and other computers. Coaxial cabling is extremely resistant to signal
barriers, although it is complicated to install. It can handle longer cable lengths between network
devices than twisted pair cable. The two types of coaxial cables are thin coaxial and thick coaxial.
Shielded Twisted Pair (STP) Cable
This is a special type of copper telephone wiring used in business installations. An outer shield that
acts as a ground is attached to a slightly twisted pair of telephone wires. If you want to place the
cable in an area where there is current interference and threat in the UTP, a twisted pair of shields
may be the answer. Shield cables also help to widen the gap between the cables.
Fiber Optic Cable
Fiber optic cable consists of a central glass core surrounded by several layers of protective material.
It overcomes the problem of electrical interference by transmitting light instead of electronic signals.
This makes them perfect for certain environments that contain large amounts of electrical noise. It
has become the standard for connecting networks between buildings due to its light and moisture
resistance.
Unshielded Twisted Pair
It is the world's most admired network cable. UTP cable is used for traditional telephone and
computer networks.
Different wiring schemes for UTP:
 CAT1, which is used for telephone cables. CAT2 supports speeds of up to 4 Mbps and is widely
used in token ring networks.
 Both CAT3 and CAT4 are used for token ring networks for high network speed.
 The CAT5 cable is now being replaced by CAT5e architectures, offering an improved crosstalk
specification that allows it to support speeds of up to 1 Gbps. This is the most used network cable
specification in the world.
 CAT6 supports speeds of up to 1 Gbit / s up to 100 meters and up to 10 Gbit / s up to 55 meters.
Organizations using CAT6 cables should use a dedicated cable analyzer to request a full test
report to ensure that CAT6 guidelines and standards are followed during installation.
 The CAT 7 is a new copper cable model that supports 10 Gbps speeds and 100 meters in length.

Shuvechchha Bhandari (HND / Second Semester)


60
Network Security 2019

Pinging
The ping command sends a data packet to a specific IP address on the network, and can then tell you
how long it took for that data to transmit and receive a response. It's a handy tool that you can use to
quickly test different points of your network. Ping comes from the term used in sonar technology to
send out vibrations of sound, and then it listens for the echo to come back. On computer networks,
most operating systems have a ping tool built in that works the same way. You issue a ping command
with a specific URL or IP address. Your computer sends several packets of information to that
device, and then waits for a response. When it receives a response, the ping tool shows you how long
it took for each packet to go round - or tells you there's no reply. It sounds easy, and it is. But you can
use it to good effect. You can check if your computer can access another device, such as your router,
or any other device on the Internet - on your local network. This will help you determine if there is a
network problem on or near your local network. By the time you take packets to return, you may be
slow to recognize the connection or you may experience packet loss. And it doesn't matter what
operating system you're using. Pull out a terminal or command prompt window, and you can use ping
on any OS version, Linux, or any version of Windows.

Shuvechchha Bhandari (HND / Second Semester)


61
Network Security 2019

Active Directory Domain Services (AD DS)


Active Directory Domain Services (ADDS) is Microsoft's directory server, which stores all
information and manages user interaction with your domain. The server computer running Active
Directory is called a domain controller. Domain controllers are used for network centralization.
Easily create and manage users and groups in your organization. In addition, you can create and
manage security policies to authenticate and authorize all users and computers on your network. A
domain controller is the main server computer that controls all activities within a domain, such as
security authentication. A directory service such as Active Directory Domain Services (AD DS)
provides ways to store directory information and disclose this information to network administrators
and users. For example, AD DS stores information about user accounts, such as names, passwords,
phone numbers, etc., and allows other authorized users of the same network to access this
information. Active Directory uses the built-in data storage to organize the logical classification of
directory information. This data store, also called a directory, contains information about Active
Directory items. These items typically include shared resources such as servers, volume, printers, and
user and computer accounts on the network. For more information about Active Directory data
storage, see Directory Data Storage. Integrates with Active Directory through security login
authentication and access to directory items. With a single sign-on, administrators can manage
directory and organization data on their network, and users of authorized network networks can
access resources. Policy-based management simplifies the management of even the most complex
networks.
Technical and User Documentation:
Technical documentation refers to any type of the documentation that describes handling,
functionality and architecture of technical product and the user documentation refers to the service
that is provided to the end users about how the system is used and sometimes is it called
guide/assistance. Here, I have presented technical and user documentation which will help the end
user in order to maintain and secure the organizational security.

Shuvechchha Bhandari (HND / Second Semester)


62
Network Security 2019

The number given indicates the management department of sunrise bank, i.e., the personnel
department, the marketing department, the IT department, the credit department and the customer
department as well as the employees of these departments. The figures given show how a bank works
with different service providers and a banking team is needed to provide a service. The banking
industry is now globalizing so we can send and receive money using electronic services and the
Internet. Using the internet is made easy for everyone, but on the other hand there are hackers who
can hack into the account and steal the money. Therefore, the bank now needs a secure network in
which hackers can no longer steal money. Services need to be secure and trustworthy. For this
reason, sunrise bank wants a secure and trustworthy network so that users of the bank can trust that
they are using their account securely. In order to create the best safe and reliable banking network, I
have implemented many policies and safeguards on the banking network, which are listed below:

Access Control Policy


In an organization, there is a lot of information and data that is the main priority of the users. These
data need to be protected, so we need to implement an access control policy. Access control policy
refers to the control of the system by an authorized person only. The management system that
manages the organizational system sets certain conditions for accessing this information and data.
Access control policies can be used to control the hassle of data and information by controlling
complex passwords outside of central software, as well as redundant data and network boundaries.
These access control policies require authentication, authentication and permission for users to enter.
Sunrise Bank also has an access control policy. In order to handle this data, we create situations
where only those users can access this data. This approach has to do with judging the legitimate ways

Shuvechchha Bhandari (HND / Second Semester)


63
Network Security 2019

of authorized clients, controlling the client's attempt to acquire assets by the client. Our framework
takes up some space after effective verification by bank customers or our employees, yet our
framework requires a great deal of mental control. This strategy is also linked to how approvals are
formed in our bank as approvals sometimes reflect the structure of our bank, while also working well
with different report levels and levels. Level users are getting. Those archives of the banking system.

Attrib command:
Attrib command are the command which can read write and hide the files and folders. This command
helps to protect the file because it doesn’t show any file until and unless it is removed from hidden. It
helps to prevent risk.

Cipher command
In bank, we may face different kinds of risk that’s why it is necessary to encrypt the data that’s why
cipher command is used. Cipher command helps to encrypt and decrypt the data. This command
gives protection to the data.

Local Security Policies


A local security policy defines various security settings on a local computer. This may include
password and account lockout policies, monitoring policies and user rights assignments. Domain
security policies override local security policies, so caution should be exercised when local policies
apply to a domain. In this policy, computers or users may be banned to avoid unnecessary use. There
are many local security policies that can help the bank improve its security system. For example, if
employees use the computer for their personal use in excess of office hours, we may use the Local
Security Policy, which is the login policy times, which automatically log in to the computer after the
login time expires. Helps to lock. And if the user voluntarily accesses files and folders, we can set up
NTFS security for the files and folders and only specify specific users in that field. If someone
guesses other users' passwords and tries to steal data, we may use an account policy that locks the
computer after a certain effort.

Shuvechchha Bhandari (HND / Second Semester)


64
Network Security 2019

To secure the system we need to define the entire local security policy, so first type [Link] in
RUN then it will open another window of local security policy where all this policy is described. ‫۔‬
Local Security Policy window where we can define various policies such as account policy, local
policies, etc.

Account policies
Accounting policies are specific statements and procedures used by the company's management to
prepare financial statements. This includes any accounting methods, measurement systems and
disclosure methods. Accounting policies differ from the accounting principles that contain the
accounting rules, and the policies are the company's way of enforcing these rules. Accounting
policies are a set of standards that govern how a company prepares its financial statements. These
policies are typically used for complex monetization methods such as amortization methods,

Shuvechchha Bhandari (HND / Second Semester)


65
Network Security 2019

identification of goodwill, research and development preparation (research and development) costs,
inventory pricing, and financial statement stability. These policies may vary from company to
company, but all accounting policies generally comply with accepted Accounting Principles (GAAP)
and / or International Financial Reporting Standards (IFRS). Accounting principles can be seen as the
framework in which a company is expected to operate. However, the structure is somewhat flexible,
and the company's management can choose specific accounting policies that are beneficial to the
company's financial statements. Because accounting principles are sometimes slow, specific
company policies are important.
The first local security policy is an account policy where an administrator can set a policy to stop
data leaks, data breaches, unwanted logins to other users' accounts. And here in this account policy
image, we can determine the password age, password length and even password complexity, for
example, a request to include an uppercase letter, a number and a special character.

The following steps are followed by the password guide:


Specify the minimum length of the password and the password combination must be at least 6
characters.

Shuvechchha Bhandari (HND / Second Semester)


66
Network Security 2019

Set the minimum age of the password because the password must be changed after the age is
completed.

Shuvechchha Bhandari (HND / Second Semester)


67
Network Security 2019

If the password is simple then anyone can guess the password, then there may be some security error
in the system. Some may try to lock data and get data so that enabling password complexity meets
system requirements and can help maintain better security.
Password must meet complexity requirements When this policy is enabled, the password must meet
the following minimum requirements: At least six characters long Contain at least three of the
following characters: uppercase letter, lowercase letter, Numbers, symbols (punctuation marks) not
included in the username or screen name of the user.

The account policy, which is another important parameter of the security policy, where we will set an
account lockout policy to prevent unauthorized use of the system.
Account lockout policy is more popular in the banking industry because unauthorized access can
cause problems for the bank. An account lockout threshold is enabled on bank computers, and it also
stores data about login attempts and helps discover it during an audit. This will help you know how
many times this system has been hacked. If this policy is locked, the real password will not be able to
open the system either. It must be unblocked by the administrator.

Local policies
To set the permissions, go to the local policy, then assign the user permissions and turn off the
system for some users, such as those who gave permissions to administrators and users.

Shuvechchha Bhandari (HND / Second Semester)


68
Network Security 2019

Local policies allow you to set user permissions such as shutdown options. To give some users
permission to shut down the system. You can set it as a requirement by going to the local policy,
clicking Assign User Privilege, and setting the privilege on the shutdown system.

NTFS security
A file system is a way of organizing a drive, showing how data is stored on the drive and what kind
of information can be attached to files, such as file names and permissions. NTFS (NT File System)
stands for New Technology File System (NTFS).[ CITATION Cin21 \l 1033 ] NTFS is the latest file
system used by the Windows NT operating system to store and retrieve files. Before NTFS, the File
Allocation Table (FAT) file system was the primary file system in older Microsoft operating systems
and was designed for small disks and simple folder structures. In the given figure, the root folder is
allowed to users with full control over the folder and they can use this folder on a network. They
have the ability to change, read, and write to the file. NTFS security helps ensure that the correct
users are using the correct folder. We can even give permission to specific users of a network and it is
very useful when bankers are working because the IT department can access the file from the IT
domain but not from the finance department and others, so the authorization is separate and now
there will be no more conflicts between users and data is safe and secure.

Shuvechchha Bhandari (HND / Second Semester)


69
Network Security 2019

Encryption
Encryption is a tool for securing digital data using one or more mathematical techniques, as well as a
"key" used to encrypt passwords or information. The process of encryption translates information
using algorithms that cannot read the actual information. For example, this process is called basic
text, which can be converted to an alternative form called cipher text. When authorized users need to
read data, they can decrypt the data using the binary key. It converts side text into plain text so that
authenticated users can access basic information. Encryption is an important way for individuals and
companies to protect sensitive information from hacking. For example, websites that transfer credit
card and bank account numbers should always keep this information confidential to avoid identity
theft and fraud. The study of mathematics and the application of sketching is called cryptography.
The figures below show that we can protect data and encrypt information and once encrypted they
are ineligible, so a password is required to decrypt data and information. We can encrypt files and
folders by right-clicking the folder and clicking the folder properties. The general section then has a
preset that leads to advanced features, where we can enable the checkbox to encrypt the content, to
secure the data on OK.

Shuvechchha Bhandari (HND / Second Semester)


70
Network Security 2019

After the encryption process we can go back to the folder location and the folder name will turn
green which means the folder is encrypted and now it is safe.

Quota system
The disk quota system allows system administrators to control the number of files and blocks of data
that can be assigned to users or groups. The amount of file storage space is based on disk space and
the type of computer available on the ECS file server. The account you have. Each computer account
has both strict and soft fees. The soft fee is the point at which you are warned that you are
approaching the hard fee. The strict quota is the absolute maximum amount of disk space that the
system grants to your account. Do not exceed the strict quota. If you do this, bad things will happen.
The system cannot do anything with an account that needs to use additional disk space. You cannot
create a new file. Also, the file you are trying to edit may be corrupted. Strict quotas take effect as
soon as they are exceeded. There is no grace period. Soft fees are less than strict ones. Heed this
warning, as exceeding the strict quota can have serious consequences. If you exceed the soft fee for 7
days or more, it will automatically convert to the strict fee. This quota management can be used in
the system in the following ways: Go to run and type [Link], then select the disk and right
click on it, then go to the properties and there we can find the quota tab where we can manage the
space.

Shuvechchha Bhandari (HND / Second Semester)


71
Network Security 2019

Another way is to go to this computer and then select the drive and right click on it, then go to the
properties and select the quota tab.

1. To start assigning a quota, right-click the drive in Explorer, then select the Properties menu. On the Quota
tab, click the View Quota Settings button.

2. Select the Enable quota management and also deny storage space to users who exceed the quota
limit check box. Click the Limit disk space to radio button and enter a value for the maximum
amount of disk space the user can use. In the example below, I've set the disk space limit to 10
GB and the warning level to 8 GB. To keep track of when users exceed the limit, select the check
boxes in the event log boxes.

Shuvechchha Bhandari (HND / Second Semester)


72
Network Security 2019

3. Finally, click on the OK or Apply button to activate the changes. A warning dialog will appear
stating that Windows may take a few minutes to scan the drive before it can update the disk usage
statistics.

4. Click OK and once the quota limit is activated you should see the traffic light green.

Shuvechchha Bhandari (HND / Second Semester)


73
Network Security 2019

Group policy
Group Policy is a tiered infrastructure that enables network administrators to apply specific
configurations to users and computers in the Active Directory of Microsoft. This helps keep the
system safe and secure. It allows administrators to determine what options users can do on the
network. For example: what files and folders and applications they can use. It is a collection of
systems and users centrally controlled by the administrator.
We can representative policies from the system to Gin, by admin. To set policies, press win + R to
launch RUN and type [Link] to open the Group Policy window. First select Control Panel then
go to User Configuration in the Group Policy Editor and then click on Admin Templates. To prevent
users from accessing Control Panel and PC settings, we can enable this option so that no user can
change any settings on the Control Panel to help keep the system safe.

Shuvechchha Bhandari (HND / Second Semester)


74
Network Security 2019

The figure above prohibits access to the control panel and enables PC settings. This prevents users
from accessing the control panel and protects against unauthorized access and changes to the system.

Firewall
A firewall is a system designed to prevent unauthorized access to or from private networks. Firewalls
can be implemented in the form of hardware or software, or a combination of both.[ CITATION
Pro20 \l 1033 ] Firewalls prevent unauthorized Internet users from accessing private networks
connected to the Internet, especially intranets. All messages entering and leaving the intranet (the
local network that you connect to) must go through a firewall. The firewall examines each message
and blocks messages that do not meet specified security standards. Firewalls carefully analyze
incoming traffic according to pre-established rules and filter traffic from suspicious or unsafe sources
to prevent attacks. Firewalls protect traffic at computer entry points called ports. This entry point
exchanges information with external devices. For example, "The source address [Link] can reach
the destination [Link] through port 22." Think of the IP address as the house and the port number
as the room within the house. Only trusted people (sender addresses) can enter. All houses
(destination addresses): additional filtering, allowing access only to specific rooms (destination
ports), depending on whether the person in the house is the owner, a child or a guest. Owners are
allowed Children and guests can enter a particular set of rooms (a particular port), but can move to
any room (any port).

Shuvechchha Bhandari (HND / Second Semester)


75
Network Security 2019

[Link] in Run Command opens a new window for Windows Defender Firewall. Microsoft has a
number of firewall functions that we can use to protect the system, such as blocking the port in the
system and preventing vulnerabilities in the system. If we block the weak port, we can keep the
system safe and secure.

Shuvechchha Bhandari (HND / Second Semester)


76
Network Security 2019

Stopping a weak port can protect the system so that we can block the port in the system through
advanced firewall settings, where we can set the port to outbound and outbound rules, help the
firewall monitor these ports. And if blocked, a blocked port is found in this rule. To create the rules
that need to be configured are given below:

Shuvechchha Bhandari (HND / Second Semester)


77
Network Security 2019

In the above data we can select the next port and set the rules for TCP or UDP as required. Then
select the block connection and then create the appropriate name for the port and that's okay.

Shuvechchha Bhandari (HND / Second Semester)


78
Network Security 2019

Shuvechchha Bhandari (HND / Second Semester)


79
Network Security 2019

Finally, the port is blocked and now the vulnerable ports can be blocked in this way so to keep secure
the network. It is the most helpful ways to keep the system safe in the public network.

We can see the rules which we have recently created and the port is now successfully blocked. If
there are any threats coming from this port then firewall will detect it before reaching to the system
and it won’t allow the port to interact with the system and we can set this rule in both inbound and
outbound rules to keep the system more secure.

Components of organizational disaster recovery plan:


Disaster is an event that disturbs the normal state of existence and causes superficial distress in any
organization beyond its capacity. Disaster cannot be predicted, so any organization has a backup plan
to return soon. For example: In the 2015 Nepal earthquake, many companies collapsed and some
came back fast but some of them completely collapsed and never came back. Therefore, the company

Shuvechchha Bhandari (HND / Second Semester)


80
Network Security 2019

needs a better organizational disaster recovery plan for every situation it faces. No one knows where
and when a catastrophe like the one caused by the 2011 fire could occur. Therefore, before setting up
a company, they need to go into every aspect of geographical location, region, location of the country
and much more. If the company is located in the Maldives, there is a possibility of a tsunami or
flood. An organization should always be aware of this disaster so that if they keep their data safe,
maintain server rooms in earthquake, resistance buildings in most places, fire alarms and fire
extinguishers they can control the fire. Disaster can happen at any time, which is why a recovery
plan contains a recovery plan for data and features to get the organization going as quickly as
possible. A natural disaster or any other disaster is unpredictable, so the organization must be
prepared every day. A disaster can result in huge losses for an organization, so before a disaster hits
an organization it needs to have a recovery plan, and some of the plans I have prepared for upstream
banking are listed below:

Create a disaster recovery team


The disaster recovery team is responsible for developing, implementing and maintaining a disaster
recovery plan (DRP). The DRP should identify team members, define each member's responsibilities
and provide their contact information, and specify who to contact in the event of a disaster or
emergency. All employees must be informed about and understand the DRP and their responsibilities
in the event of a disaster.

Identify and assess disaster risks


The disaster recovery team must identify and assess the risks to the organization. This step should
include elements related to natural disasters, man-made emergencies and technology-related
incidents. This will help the group identify recovery strategies and resources required to recover from
disasters within a given and acceptable timeframe.

Earthquake resistance buildings:


Earthquake is an unpredictable and inevitable disaster that can blow up everything in seconds, so an
organization must be prepared. Earthquake preparedness is not about leaving the site, but an
organization must have a qualified engineer and worker to build earthquake resistant buildings to
withstand a disaster. I can say that "Caution is better than cure" because before any disaster strikes, if
the organization is well prepared, it will not affect the company. Therefore, I recommend Sunrise
bank for earthquake resistant buildings to keep you and your company safe. Since an earthquake

Shuvechchha Bhandari (HND / Second Semester)


81
Network Security 2019

resistant building can reduce risk and damage, and building construction will be a priority, they can
withstand a major earthquake.

Secured servers:
Servers and data are critical in any business. The servers must be secure, so they must be kept in a
safe room to protect them from disasters such as earthquakes, floods, and fires. Server rooms or data
centers are places or buildings that contain all the data and information of an organization. Therefore,
our bank servers must be kept in a separate room and building so that they are safe and secure.
Employees are made aware of the various hazards in the workplace and are given the necessary
knowledge. Thief alarm systems are installed under each employee's desk so that they can inform the
entire bank in the event of an emergency or other hazard. We use laptops and desktop computer locks
to protect computers in our bank.

Data backup in data warehouse:


Data is the most valuable thing in a company. In a bank, this is of great importance, as the bank
provides loans, accepts deposits, exchanges checks and many other services, so all data is valuable,
and if the data is lost, the company will be left with nothing. is, and it can also be rolled up, therefore
data security should be given top priority for data security. Sunrise Bank needs to keep the data
secure so that it can help its customers as well as help the market bounce back in the event of a
disaster. A company should use a data warehouse to store the data so that the data can be kept for
future use and also to keep the data safe. Data warehouse also contains many tools, for example, it
will ensure data security, and data analysis can be done for market research and can somehow predict
the future. All data can do a lot to help both the customer and the company, which is why the
company should store the data in multiple places so that a disaster doesn't affect the company. I
personally recommend Sunrise Bank to keep the data secure and store the data in multiple
warehouses so that the company can reach the market as soon as possible.
Backup Domain:
Domains are the most dedicated servers of an organization because all workstation servers consist of
computers. The company cannot operate without a server and will have to stop working if the
domain or other server fails to work. I recommend Sunrise Bank to set up RED on the Domain
Controller (RODC) so that the RODC backup domain and (DC) as the domain controller can easily
run the company. To work This will help the company maintain workflow and services. The domain
is also secure and RODC helps in running load balances and operating the company without

Shuvechchha Bhandari (HND / Second Semester)


82
Network Security 2019

overload. The RODC load is considered balanced when the DC is healthy and also acts as a backup
domain if the domain does not work. The organization can have a Child Domain Controller (CDC) in
the branch office so that they can work in a different domain and contact DC at any time. This will
make the branch work freely and easily and will reduce the burden of DC as CDC works like a child
of DC so it will be beneficial for big companies.

Backup DHCP:
DHCP is the most dedicated server in the organization and provides the fastest functionality to
manage all IPs in the workspace automatically and you don't have to go to all computers for
administrators to configure IP manually. This saves time for the devices to use the Internet that
require IP, which is why DHCP is one of the useful servers, which automatically assigns the IP
according to the rules defined on the server. If the DHCP server is down, no workspaces are running
and this affects the business, so it can be cloned and DHCP relay servers can be used to avoid DHCP
failures. Relay servers are often used to provide different IP addresses in the same company so if
they use relay servers it can be useful for the company and they can keep this server as a backup
server and it works the same as DHCP servers. I recommend that Sunrise Bank use DHCP and
DHCP Relay Server to continue the workflow.

RAID (Redundant Array of Independent Disks)


RAID refers to a redundant array of independent disks. RAID storage uses multiple disks to provide
fault tolerance, improve overall performance, and increase storage capacity in the system. This is in
contrast to the older storage device that uses only one disk drive to store data. This allows us to store
the same data redundantly (in multiple stages) in a balanced way to improve overall performance.
RAID drives are often used in servers, but they are not usually necessary for personal computers. It
is used to improve the performance and reliability of data storage in the organization. The system
consists of two or more drives operating in parallel and these drives can be hard drives, but there is
also a trend to use solid state drive technology. RAID consists of different levels, each level
customized for a particular situation. Our bank uses RAID level 5. This is to provide byte-level data
striping and stripe error correction information for good performance and good fault tolerance. RAID
5 in banks allows you to mirror data to one or more disks in a single array. If one disk fails, the data
will be saved on the other disk. It also offers the option to read or write to multiple disks to improve
storage performance. RAID devices use different architectures called tiers, depending on the desired
balance between performance and fault tolerance.

Shuvechchha Bhandari (HND / Second Semester)


83
Network Security 2019

Cloud Storage
Cloud storage is an online place you can use to store your data. Cloud storage provides a secure way
to remotely store your important data. Online storage solutions are usually delivered using a large
network of virtual servers that come with tools to manage files and organize virtual storage space. It
is managed and managed by hosting companies on storage servers built on virtualization technology,
and their service providers are responsible for making and accessing their data and protecting and
running their physical environment. User, person or organization that requires backup storage due to
the storage capacity from the provider to collect the data of the organization.

Test and maintain the DRP


DRP (Disaster Recovery plan) disaster recovery plan is an ongoing process, as disasters and
emergencies are always changing. The organization will regularly review the DRP to assess the
effectiveness and efficiency of the documentation process in the project. The recovery team should
periodically update the DRP to change the evolution of business processes, technology, and
catastrophic risks.

Security Audits
Security audits are an extensive and formal overview of your organization's security systems and
processes. Auditing is an extensive and detailed analysis of physical attributes such as networks,
firewalls and equipment, as well as other areas such as policies and standard operating procedures. In
addition to scanning existing systems, it looks at all aspects of your organization's security. This
process occurs when your organization's technology team conducts reviews to ensure that the
correctly updated processes and infrastructure are in place. It also includes a series of tests to ensure
that information security meets all the expectations and requirements of your organization.
Performing a security audit can answer the question of how to ensure the confidentiality, integrity,
and availability of your bank's information. All organizations should perform regular security audits
to ensure that their data and assets are protected. This audit determines if your plan complies with
your organization's internal policies and external rules and standards. It also identifies gaps and
weaknesses at any stage of maintenance. Once the audit is complete, you should update your
business continuity plan to reflect the necessary changes identified during the audit.

Roles of the stakeholders:

Shuvechchha Bhandari (HND / Second Semester)


84
Network Security 2019

A stakeholder is either an individual, a group, or an organization that is affected by the outcome of a


project. You are involved in the success of the project and can be inside or outside the organization
sponsoring the project. The stakeholder makes a great contribution to the organization and
stakeholders who have a great interest in the organization and are severely affected have a role in the
organization. The security audit is a process for assessing the security of the organization. The role of
the stakeholder varies depending on the organization and the particular project being developed or
decided upon. They can be the employees of the company, suppliers, vendors or any partner. They all
have an interest in the organization. Stakeholders can also be an investor in the company and their
actions determine the outcome of the company. Such stakeholder plays an important role in defining
the future of the company as well as its day-to-day workings. After assessing the security of the
company, an audit is required, which documents the entire security system of the organization and
speaks about the weak point of the network system. It is also helpful to know whether or not it is
beneficial and effective to use the security system and to recommend the best option to make the
system safe and secure. However, in order to conduct a security audit in the organization, it must be
authorized by the company's stakeholders. Therefore, there are many roles for the stakeholder in the
company, regardless of whether they give permission or not. Each stakeholder is closely involved in
this task and therefore has their own roles. Each stakeholder contributes to the implementation of the
security audit recommendation. Some of the roles of stakeholders are shown below:

Customer:
The customer is one of the stakeholders of many companies and has less interest but more influence.
Due to their high impact, they also have a special role in maintaining the value of the organization as
they take advantage of the organization and in return, they give feedback to the organization which I
think has a security audit. The role of the client. For example: We say that Sunrise has provided an
online service to its users using a mobile application. The user uses the app and can review the
product and its function and talk about the quality and future requirements and the failure of the app
and much more. This will help the bank to fix the services and can perform system audit or security
audit if there is any serious problem in the system. The bank may be an indirect model for
conducting security audits in the organization.

Management:
The management team of the organization can be considered as the working team of the
organization. The bank also has its own working team with high strength and high interest. In order

Shuvechchha Bhandari (HND / Second Semester)


85
Network Security 2019

to get multiple views from customers, the management team needs to be implemented in the
company so that they can collect all the feedback and make changes. It is very important to
strengthen the security system in the bank as the bank is online as well as physically sensitive. If the
bank's security system is weak, then it can cause serious problems. The management team will be the
working mechanism of the company so it will gather all the feedback and help in choosing the best
option to strengthen the security system and conduct security audit in the organization.

Investors & shareholders:


Investors and shareholders are the core members of the organization, they have a lot of power and a
lot of interest in it. They take decisions in the company and if possible, make changes as per the
requirements of the management. The management team will now present the best option received
from the client. After clarification from management, it is decided to make any changes and proceed
for security audit.

Employee:
An employee or worker is an actor with greater power and greater interest in the organization
because it is the first effect on the employee of the company if there is any change. These
stakeholders begin work after shareholders and investors pass security audits, and the Audit Officers
and IT division is the most important working group that has the greatest impact on security audits.
They need to check all components of the network for threats and vulnerabilities in the system. And
finally, they implement the necessary changes in the organization.

Government:
Government is one of the most important stakeholders in any organization. It has high power and
low interest. The role of government is to take care of the organization and ensure that the company
is compliant. Make sure all organizations are working legally. It acts as a wall on the way for the
company to go illegal. It is important to implement the reputable and recommended safety measures
during the audit process. If done the right way, it is considered legal, otherwise it is considered
illegal. Before conducting a security audit, you should consider the roles of all involved parties.
Everyone involved has a unique role. All changes are made to keep your data safe. Auditing during
this period is much more powerful because it collects all the data without leaving a trace. Banks have
daily transactions and workers work every day. Some mistakes are made unknowingly, while others

Shuvechchha Bhandari (HND / Second Semester)


86
Network Security 2019

are intentional, and banks perform this check many times to help organizations move forward and
stay safe. need to do it.

Suitability of the tools used in organization policy:


An organizational policy is a set of guidelines and best practices put in place to protect the company,
employees, and customers. Organizational policy is made in any organization for working in a
standard way. It defines what is or is not permitted within the organization.
There are many types of the policy that an organization may develop, for example:
• Security policy
• Health and safety policies
• Employee discount policies
• e-policies
The purpose of the organizational policies are as follows:
• provide clear definition of boundaries within which to work
• define what is acceptable and unacceptable behavior
• provides guidelines for dealing with inappropriate behavior
• set customer expectations
Various tools are used in the security of corporate policies, and they are NTFS security, which allows
a particular employee to access files, and access IT-related files and folders, such as the IT
department. Can be used to provide specific exposure to. Access to other folders such as finance is
granted. NTFS security is a high level of security and is useful for both local users and networks.
This is permission-based security that controls all files and folders according to the rules. Other
devices are firewalls and VPNs. Firewalls contain software and hardware. Both have the same
procedure, which filters all packets coming and going on the network and helps prevent malicious
packets and alerts the administrator. It helps protect the network. Virtual Private Network (VPN) is a
technology that creates secure and confidential connections to less secure networks such as the
Internet This allows users to use this technology remotely. It is often used to contact the branch office
for secure access to corporate applications and other resources. Most banks are using this technology
to connect branches and offices.
VPN helps transmit data information using VPN tunnel where all the data is encrypted and a better
way is found as well as it hides the real IP and Indicates fake IP. This fake IP can be seen and if the
hacker tries to hack the VPN, the hacker cannot reach the real IP which makes it safe and secure.
Other security tools that fit into the organization's policy are biometrics, a popular security tool.

Shuvechchha Bhandari (HND / Second Semester)


87
Network Security 2019

Biometrics uses real-time data and matches the database. Biometrics uses individually identifiable
parts of the human body such as fingerprints, iris, retina, face, etc. Many organizations use these
biometrics for attendance. This helps prevent unauthorized access. Group Policy is also used to
maintain security in the system. Password policy, account logout policy, invalid login attempts and
much more. Every tool used to create a secure system has its own function and its strength is security
in organizational policy. It helped the bank to strengthen the security of the organization and
maintain its institutional policy.

Conclusion
In summary, information is the most valuable thing of an organization that needs to be safe and
secure under all conditions. Therefore, the organization should use services like data warehouse or
keep them safe and secure by backing up data to the cloud or other location. The organization should
create a backup plan for a natural disaster so that the company can return after a certain time. The
recommendation should be implemented whenever possible and security review should be done from
time to time in collaboration with the appointees. Various policies are used to keep data safe and
secure and to strengthen the security of the organization through the use of tools such as Firewall,
Encryption, Group Policy and Local Policy. These tools are more appropriate for improving
organizational policy and taking more action. When conducting a security audit, it is important to
ensure that the parties involved play their role effectively with the audit group in bilateral
communication, as the parties involved play an important role in the security review to express the
audit expectations of audit team.

References

Shuvechchha Bhandari (HND / Second Semester)


88
Network Security 2019

Anon., 2016. [Link]. [Online]


Available at: [Link]
[Accessed dec 2020].

Anon., 2017. cyfor. [Online]


Available at: [Link]
[Accessed 2020].

Anon., 2020. Protech. [Online]


Available at: [Link]
[Accessed 2020].

camcode, 2017. Camcode. [Online]


Available at: [Link]
[Accessed 18 March 2019].

Castagna, R., 2018. techtarget. [Online]


Available at: [Link]
[Accessed dec 2020].

FTP, 2018. FTP today. [Online]


Available at: [Link]
company

general data, 2018. wiki. [Online]


Available at: [Link]
[Accessed 12 jan 2020].

Glosbe, n.d. Glosbe. [Online]


Available at: [Link]
[Accessed 3 March 2019].

HN, C., 2018. HN computing. [Online]


Available at: [Link]
[Accessed 20 08 2018].

Shuvechchha Bhandari (HND / Second Semester)


89
Network Security 2019

hope, C., 2019. Computerhope. [Online]


Available at: [Link]
[Accessed 2020].

Liebowitz, M., n.d. [Link]. [Online]


Available at:
[Link]

melnick, j., 2018. cyber attackks. [Online]


Available at: [Link]
[Accessed 12 jan 2020].

n.d, 2015. hse. [Online]


Available at: [Link]
[Accessed 12 August 2018].

Nadeau, T. D., 2020. MPLS Network Management. 2003 ed. s.l.:Morgan Kaufmann.

NG, C., 2021. Varonis. [Online]


Available at: [Link]
[Accessed 2021].

Pidoco, n.d. Pidoco,n.d. [Online]


Available at: [Link]
[Accessed 1 March 2019].

Quora, 2018. Quora. [Online]


Available at: [Link]
[Accessed 6 March 2019].

Studytonight, 2016. Studytonight. [Online]


Available at: [Link]
[Accessed 2 March 2019].

Techopedia, 2016. Techopedia. [Online]


Available at: [Link]
[Accessed 19 March 2019].

Shuvechchha Bhandari (HND / Second Semester)


90
Network Security 2019

techopedia, 2019. techo. [Online]


Available at: [Link]
ip-address
[Accessed 12 jan 2020].

Techopedia, n.d. Techopedia. [Online]


Available at: [Link]
[Accessed 2 March 2019].

Techterms, 2017. Techterms. [Online]


Available at: [Link]
[Accessed 19 March 2019].

[Link], 2016. [Link]. [Online]


Available at: [Link]
[Accessed 1 March 2019].

[Link], 2016. [Link]. [Online]


Available at: [Link]
[Accessed 20 March 2019].

[Link], 2016. [Link]. [Online]


Available at: [Link]
[Accessed 15 March 2019].

[Link], 2016. [Link]. [Online]


Available at: [Link]
[Accessed 9 March 2019].

Shuvechchha Bhandari (HND / Second Semester)


91

Network Security
2019
MANAGEMENT & TECHNOLOGY 
 
 
 
ASSIGNMENT COVER SHEET 
  
STUDENT DETAILS
Student ID 
 
Reg No. 
 
Fami
Network Security
2019
 
STUDENT ASSESSMENT SUBMISSION AND 
DECLARATION 
When  submitting  evidence  for  assessment,  each  s
Network Security
2019
NEPAL 
 
BTEC HND in Computing  
 
Unit 5: Security 
 
 
 
 
 
 
        Unit Code:  K/615/1623 
 
Sess
Network Security
2019
of the system has been managed via proper access control mechanism and the access control list, and
the
Network Security
2019
1. Identify the potential impact to IT security using firewall and VPNs and make aware of the
repercuss
Network Security
2019
 
 
 
 
 
LO1 & 2 D1 Investigate how 
a ‘trusted network’ may be part of
an IT security solution. 
P1 I
Network Security
2019
General feedback on the assignment:
In order to pass the unit, the learner has to meet all the pass cri
Network Security
2019
The center policy is that you must submit your work within due date to achieve “Merit” and
“Distinction
Network Security
2019
Virus attack...........................................................................................
Network Security
2019
Introduction...........................................................................................

You might also like