Managing Security for Sunrise Bank
Managing Security for Sunrise Bank
STUDENT DETAILS
Given Name
Family Name
Enrolment Year 2019 Section N1
UNIT DETAILS
Unit Title
Security Unit Code K/615/1623
Assessor Name
Krishna Parajuli Issued Date 26 Aug 2019
Assignment Title Managing security for sunrise bank
Qualification Campus
Plagiarism
Plagiarism is a particular form of cheating. Plagiarism must be avoided at all costs and
students who break the rules, however innocently, may be penalized. It is your
responsibility to ensure that you understand correct referencing practices. As a
university level student, you are expected to use appropriate references throughout and
keep carefully detailed notes of all your sources of materials for material you have used
in your work, including any material downloaded from the Internet. Please consult the
relevant unit lecturer or your course tutor if you need any further advice.
Student Declaration
I certify that the assignment submission is entirely my own work and I fully understand the
consequences of plagiarism. I understand that making a false declaration is a form of
malpractice.
malpractice.
NEPAL
Scenario I
“Sunrise Bank", established in 2002, is a leading commercial bank in Nepal founded by reputed
entrepreneurs understanding the needs of a growing economy and is managed by a team of
professionals and experienced bankers. The main mission of the bank is to be leading Nepali bank,
delivering world class service through the blending of state-of-the-art technology and visionary
management in partnership with competent and committed staff, to achieve a sound financial
strength with sustainable value addition to all the stakeholders. The bank is committed to do this
mission while ensuring the highest levels of ethical standards, professional integrity, corporate
governance and regulatory compliance.
The bank is committed in providing quality service and planning to utilize all the technological
facilities that enhance quality service with high degree of compliance and risk management. The
bank has an IT department which is responsible to manage and implement all required IT
infrastructure. IT department has defined a policy that all of the branch office must connect to head
office through secure VPN. All other clients must be member of the centralized domain. User access
of the system has been managed via proper access control mechanism and the access control list, and
the service access has been managed via ports and services.
The bank has security policies for managing the security of all its assets, functions and the services.
VPN access has been managed for limited person of all branch office employees and IT
administration team of head office. Defense in depth approach is to be implemented in order to
confirm the IT security at various level of network infrastructure. IT infrastructure security design
including address translation, DMZ, VPN, firewall, antivirus and intrusion detection system are to be
implemented for internal and external security policy.
You have been working as an IT Officer for the bank. Your key role will be to manage, support and
implement a secure network infrastructure for banks LAN/WAN environment. In order to assess the
possibility, you have been assigned the following in which you have to demonstrate that you are able
to assess risks to IT security, describe different possible IT solutions, review mechanism to control
organizational IT Security and manage organizational security.
Part: 1
Before you start the implementation of the IT security measure for the organization, you need to
assess the IT security risks in the organization. You need to consider various aspects of risks such as
unauthorized access of the system and data, naturally occurring risks, host, application and network
risks etc. You are required to consider organizational security procedure such as business
continuance, backup/restoration, audits etc. and then produce a report for the CEO of Sunrise Bank
containing:
1. Identified security risk types to the organization along with description of organizational security
procedure.
2. Develop a proposal of a method to assess and treat IT security risks.
You would prefer to produce a more detailed document, so you will produce a comprehensive report
for fully functional secure system which will include identified risks and method to mitigate those
risks. Your manager would like a separate report on your assessment of the effectiveness of the
design in relation to user and system requirements.
Part: 2
Once the assessment of the risks and proposal for its remedy has been made you need to describe IT
security solution for the organization such as VPNs, firewall, DMZ with a suitable implementation
example. You need to:
1. Identify the potential impact to IT security using firewall and VPNs and make aware of the
repercussion of incorrect configuration of firewall policies and third-party VPNs.
2. Show through an example in simulated environment, how implementing a DMZ, Static IP ad
NAT in a network can improve Network Security.
3. Discuss how network monitoring systems can benefit the security of IT of the organization.
You need present at least three advantages.
4. Finally investigate how a 'trusted network' may be the part of an IT security solution.
Part: 3
Once you have identified IT risks and viable security solutions, you need to review the mechanisms
to control organizational security. Consider various aspects of network change management, audit
controls, disaster recovery plans, Data Protection Acts, Computer Misuse Act, ISO 3001 standards,
etc. You need to:
1. Discuss risk assessment procedures and explain data protection processes and regulations as
applicable to the organization.
2. Summarize the ISO 31000 risk management methodology and its application in IT security
and then discuss possible impacts to organizational security resulting from an IT security
audit.
3. Explain considering how IT security can be aligned with organizational policy, detailing the
security impact of any misalignment.
Part: 4
Lastly you will produce technical and user documentation which will be given to the company for
the management of organizational security. You have to design and implement a security policy for
the bank which will
1. List out the main components of an organizational disaster recovery plan, justifying the
reasons for inclusion.
2. Discuss the roles of stakeholders in the organization to implement security audit
recommendations.
3. And an evaluation of the suitability of the tools used in an organizational policy.
P2 Describe organizational
security procedures. LO1 & 2 D1 Investigate how
a ‘trusted network’ may be part of
LO2 Describe IT security solutions an IT security solution.
P3 Identify the potential impact
to IT security of incorrect
configuration of firewall policies M2 Discuss three benefits to
and third- party VPNs. implement network monitoring
systems with supporting reasons.
In order to pass the unit, the learner has to meet all the pass criteria. Tick each criteria awarded.
P1 P2 P3 P4 P5 P6 P7 P8 Pass Achieved / Not
In order to be awarded a Merit the learner has to meet all the pass criteria and all the merit criteria. Tick
the criteria awarded.
In order to be awarded a Distinction the learner has to meet all the pass merit criteria and all the Distinction
criteria. Tick the criteria awarded.
Note: Please access HN Global for additional resources support and reading for this unit. For further
guidance and support on report writing please refer to the Study Skills Unit on HN Global. Link to
[Link]
Note: Refer the unit details provided in your handbook when responding all the tasks above. Make
sure that you have understood and developed your response that matches the highlighted key words
in each task.
Other Requirements:
It should be the student’s own work – plagiarism is unacceptable.
Clarity of expression and structure are important features.
Your work should be submitted as a well presented, word-processed document with
headers and footers, and headings and subheadings, both in hard and soft copies.
You are expected to undertake research on this subject using books from the library, and
resources available on the Internet.
Any sources of information should be listed as references at the end of your document
and these sources should be referenced within the text of your document using Harvard
referencing style
Your report should be illustrated with screen-prints, images, tables, charts and/or graphics.
All assignments must be typed in Times New Roman, size 12, 1½ spacing.
The center policy is that you must submit your work within due date to achieve “Merit” and
“Distinction”. Late submission automatically eliminates your chance of achieving “Merit and
Distinction”. Also, 80% attendance is required to validate this assignment.
Assignment Prepared by: Signature: Date: 25 Aug 2019
Krishna Parajuli
I declare that all the work submitted for this assignment is my own work and I understand that if any
part of the work submitted for this assignment is found to be plagiarized, none of the work submitted
will be allowed to count towards the assessment of the assignment.
Table of Contents
Part: 1...................................................................................................................................................14
Introduction..........................................................................................................................................14
Environmental Risks............................................................................................................................15
Physical Risk........................................................................................................................................15
Phishing attack..................................................................................................................................16
Malware attack.................................................................................................................................16
SQL-Injection attack........................................................................................................................16
DDOS attack.....................................................................................................................................17
Virus attack.......................................................................................................................................17
Adware.............................................................................................................................................17
Data breach.......................................................................................................................................17
Hacker:.................................................................................................................................................18
Viruses:.................................................................................................................................................18
Misconfiguration:.................................................................................................................................18
Hardware security tools:......................................................................................................................18
Firewall.............................................................................................................................................19
Biometric security............................................................................................................................19
Security Procedure...............................................................................................................................19
Developing local policy, process and guidance:...............................................................................20
Authentication..............................................................................................................................20
Authorization................................................................................................................................21
Accountability..............................................................................................................................21
Risk Assessment...................................................................................................................................21
Risk assessment methodologies:......................................................................................................21
Security Audit...................................................................................................................................22
Vulnerability Assessment:................................................................................................................23
Penetration testing:...........................................................................................................................23
Security policies:..............................................................................................................................24
Monitoring tools:..............................................................................................................................24
Report:..............................................................................................................................................25
Conclusion............................................................................................................................................25
Part 2:...................................................................................................................................................27
Introduction..........................................................................................................................................27
Firewall.............................................................................................................................................27
Advantages of Firewall................................................................................................................28
Disadvantages of Firewall............................................................................................................28
Site-to-site VPN...........................................................................................................................29
Advantages of VPN..........................................................................................................................29
Disadvantages of VPN......................................................................................................................29
Advantages of DMZ.........................................................................................................................31
Disadvantages of DMZ.....................................................................................................................31
Advantages of NAT:.........................................................................................................................32
Disadvantages of NAT:.....................................................................................................................32
IP routing..........................................................................................................................................33
Static routing:...............................................................................................................................33
Wireshark.....................................................................................................................................36
SNMP server................................................................................................................................38
Trusted Network...................................................................................................................................39
Impacts of trusted network on IT security........................................................................................40
Conclusions..........................................................................................................................................42
Part: 3...................................................................................................................................................43
Introduction..........................................................................................................................................43
Risk assessment................................................................................................................................43
Risk Identification........................................................................................................................45
Risk Analysis................................................................................................................................46
Risk Evaluation............................................................................................................................46
Significance of DPA.....................................................................................................................48
Principle............................................................................................................................................50
Conclusion............................................................................................................................................55
Part: 4..................................................................................................................................................57
Introduction..........................................................................................................................................57
Purpose of bank security policy.......................................................................................................57
Router...............................................................................................................................................58
Switch...............................................................................................................................................59
Server................................................................................................................................................59
Networking cables............................................................................................................................59
Coaxial Cable...............................................................................................................................60
Pinging..............................................................................................................................................61
Attrib command:..........................................................................................................................64
Cipher command..........................................................................................................................64
Account policies...............................................................................................................................65
Local policies....................................................................................................................................68
NTFS security...................................................................................................................................69
Encryption........................................................................................................................................70
Quota system................................................................................................................................71
Group policy.....................................................................................................................................74
Firewall.............................................................................................................................................75
Secured servers:................................................................................................................................81
Backup Domain:...............................................................................................................................82
Backup DHCP:.................................................................................................................................82
Cloud Storage...................................................................................................................................83
Security Audits.................................................................................................................................83
Management:....................................................................................................................................85
Employee:.........................................................................................................................................85
Government:.....................................................................................................................................85
Part: 1
Before you start the implementation of the IT security measure for the organization, you need
to assess the IT security risks in the organization. You need to consider various aspects of risks
such as unauthorized access of the system and data, naturally occurring risks, host, application
and network risks etc. You are required to consider organizational security procedure such as
business continuance, backup/restoration, audits etc. and then produce a report for the CEO of
Sunrise Bank containing:
1. Identified security risk types to the organization along with description of organizational
security procedure.
2. Develop a proposal of a method to assess and treat IT security risks.
Introduction
With the advent of basic banking and the widespread adoption of the Internet in the last century,
branch management has also completely changed. Some banks are also using a disabled strategy at
the moment; however, it is gradually being replaced by online technology. Sunrise Bank, established
in 2009, is one of Nepal's leading commercial banks, created by so-called business visionaries. When
they realized the need for an emerging economy, they created this bank and it is now overseen by a
group of experienced investors and experts. Currently, the main objective of this bank is to lead the
Nepal Bank, providing world-class benefits through a combination of innovative skills and visionary
management. By ensuring quality support for its client, the bank wants to use all innovative offices
that improve the quality of administration with a high level of consistency and risk management. The
bank has different security strategies to guarantee the security of each of its strengths, capacities and
administration, which are managed by a talented systems security engineer.
A security risk is a risk that surrounds an organization’s network because it can be of a different
nature. A security risk can affect the reputation of an organization, its partners and customers. There
are two types of safety risks: environmental and physical. Environmental risks are the types that arise
due to natural disasters, and physical risk are the type of risks that are caused by cyber-attacks,
vulnerabilities, etc. Both of these risks have a greater impact on data loss and corruption.
Organizational security procedures establish rules and guidelines for identifying, analyzing, and
applying policies to protect the organization's data and information. In this part, I am going to review
the security risks and its types as well as the organization’s security policy to understand the risks
and threats.
Environmental Risks
Environmental risks are the risks that an organization faces due to a natural disaster. For example,
one of the largest Maldives companies could be at risk from a tsunami as the country is covered by
the sea. There may be other risks, but the main danger is the tsunami, and companies need to avoid
server homes and domestic data backups. Listed below are other environmental risks that may affect
your organization:
Fire: Fire is naturally occurring risk that can destroy valuable documents and deplete everything.
Fire can destroy anything and all organizations experience this risk as it can occur anywhere and
the entire organization must be aware of it. The organization has a high probability of having a
fire risk when the organization is located near the industrial area where there is fire work in
businesses such as cement plant, noodle factory, metal factory etc.
Flood: Flood is a naturally occurring risk that affects the organization. For example: If this
organization is located in the Terai region of Nepal, it is a flat land in southern Nepal with a high
probability of flooding and we can see a history of large floods occurring every year. If a
company keeps servers, data and other valuable documents it can affect the organization.
Earthquake: This natural disaster can also affect the entire network system. This can destroy the
data center or lead to the loss of all information in the company. A few years ago, Nepal was hit
by a massive earthquake that destroyed many organizations and lost their data and valuable
documents, which can lead to enormous losses for organizations.
Extreme weather: The weather can be another factor that can affect the organization. Excessive
weather can have serious effects that can disturb the organization's network, leading to equipment
damage or malfunction. Some extreme thunderstorms are lightning, thunder, cyclones, etc.
Physical Risk
Physical risk is another factor affecting the organization and caused by human activities. Physical
risk arises from a human error or a deliberate attempt to take advantage of a system. In a company,
for example, a stranger or known person sends an email associated with a virus and employees are
unaware of this type of attack that affects the entire system. Sometimes data is hacked and sold to
make money. Some of the other human-causal factors are listed below:
Phishing attack
It is a social engineering attack used to steal user data, credit card numbers, social security numbers,
account numbers, passwords and other intellectual property. Phishing technology is a type of
technology used to obtain other intellectual property without permission. For example, ask the victim
to log in via a fake link and get all the data, such as username and password. These attacks can be
carried out anywhere on the internet. The most popular attack is sending an email with a fake link
and giving bank details about the remittance amount, claiming it has earned millions. In this way, the
attacker got all the information, hacked it and stole the money. Phishing attacks are the most popular
attacks on the internet.
Malware attack
Malware attacks are a way of attacking other computers or mobiles by using or installing software to
obtain organizational or personal information. It primarily injects viruses and damages the
organization's network. The attack is unconventional and unaware that your personal information has
been hacked. It also affects your organization's entire network and can bring down your entire server.
Cybercriminals can also transfer all financial information to their account, compromising the
financial status of an organization.
SQL-Injection attack
The database is an important part of the organization where you can save all the details of the
organization. SQL injection is a method of attacking devices using malicious code to obtain
information that is not shown to everyone. [ CITATION Glo19 \l 1033 ]The database is mainly
operated by the main server, so the organization data will not be leaked. But by using SQL injection,
attackers can easily find data like the financial status of the organization, employees and user lists,
etc. They can also remove the fixed table from the database, which can affect the entire organization
system and display it personal details. This attack affects the financial damage and reputation of the
organization.
DDOS attack
Distributed Denial of service for DDOS attacks. It is often used by cybercriminals. DDOS is a way
to create traffic that is not available to other online services, so that an attacker can take network
resources by shutting down the server. These attacks are also used to blackmail. You can easily take
all the confidential data of the company and use it for financial gain or to undermine the reputation of
the organization. [ CITATION jef18 \l 1033 ] With this attack, the attacker can take over the entire
organization system, where he can easily deal with different problems and loss that this organization
may face after the attack, which is a great disadvantage for the organization.[ CITATION Pid19 \l
1033 ]
Virus attack
Computer viruses are dangerous and attack our system if the system does not have the proper
protocol to ensure that the virus escapes. A computer virus is a piece of software designed to harm a
computer system using system resources and system memory. This type of program copies and
executes itself, interferes with the way the computer is run, and interferes with data theft, corrupting
files, or deleting them altogether, for any bank. That's a big problem. [ CITATION FTP18 \l 1033 ]
Some of the viruses found in the bank are boot sector viruses that directly affect the master boot
record and are difficult to remove. If this is attacked, the bank computer system needs a complete
system which is a big challenge for the bank as shaping this system causes huge loss of bank data.
Therefore, appropriate protocols should be put in place to protect computers from virus attacks. Ports
should be banned for use by unauthorized users.
Adware
As we know in this modern world we know, every company wanted their advertisement. But some of
the critical hackers use this process for retrieving data from user. [ CITATION FTP18 \l 1033 ].
When unusual ads start appearing on computer desktop, employee accidently download adware
through the medium while downloading the free software. While using the browser by the company
employee the hacker spreading adware collect critical data of bank without permission of user.
Data breach
Data breach is a kind of corporate data theft. There are two types of data breach: data breach inside
and outside data breach. Inside Data Breach is committed by an unethical employee of a company,
while an outsider’s data breach is committed by an unknown person or other related person. In either
case, they intend to steal data from the company, sell it to the other company and make money.
Within the data breach sometimes engage in mischievous activities on the account of other
employees, including: deleting files and other valuable documents to make someone else guilty or
sometimes for personal reasons.
Hacker:
Hackers are those who intent to break the others system and capture all the valuable data to gain the
financially and some does for the name and fame. They can exploit the system of the organization
and can even leak the data. They are very sensitive and can do anything.
Viruses:
Virus is software which is programmed such that it can destroy the computer system. Viruses usually
corrupt the files, damage the system or sometimes it duplicates all the files and hang the system. It
can be attached with the emails and if the email is opened then It can affect the system. There are
many types of viruses can be found which is harmful for any system.
Misconfiguration:
Misconfiguration is a configuration of the system incorrectly. It can happen knowingly or
unknowingly. While configuration any system, user should be conscious and focus to the work
because sometimes we may forget the right configuration and mislead the system. Some of the
mistake may lead the organization to the risk for example: if an administrator leaves a loophole in the
system, then hacker may catch it and easily get the access to the system. Sometimes administrator
unnecessarily click the services which is not required and may harm the system while assigning the
security policy and leads attackers to gain access to the system.
Firewall
Firewalls are security devices used to monitor systems. It monitors all incoming and outgoing traffic
in the system. It warns if there is a security breach in the system. For example: My system is attacked
by a virus, it immediately warns me in the form of information. We can set the firewall rules as the
desired network and it works according to this predefined rule. It is mainly used to protect the
network. And it filters all incoming and outgoing traffic and if there is any inconvenience to the
system. Firewall software is integrated into the system by Microsoft while hardware firewalls must
be installed separately. Compared to software firewall, hardware firewall is more powerful.
Biometric security
Biometric security is a unique identity of an individual used for identification and authentication. The
person may have special features such as a person's fingerprint, iris print, hands, face, voice, etc.
These features are saved as a format of data and are used for immediate validation. For example, my
company has a fingerprint or iris printing system for attendance, and I need to access the system to
provide biometrics. Otherwise, it is impossible. You cannot trick the system into hacking or cracking
it. Only authorized persons can provide the data.
VPN: A virtual private network (VPN) is a secure network in which data is transmitted through a
highly secure tunnel that transmits data using encryption. It is a dedicated connection between host
and server computers. All data packets are encrypted through a secure tunnel. In Nepali context,
VPN services are provided by Internet Service Providers (ISPs).
Router: A router is a highly intelligent device used to transfer data packets between two different
networks. The best way to get data packets to the address, account, and destination is to forward
them to the destination IP. It works on the network layer (layer 3) of the OSI model. Sister Router,
Juniper, is an excellent router for security purposes. These routers are much safer than regular
routers. These types of routers provide better protection to your organization.
Security Procedure
Security procedures are detailed, step-by-step instructions on how the user or server manager should
enforce, enable, or enforce the security controls set out in bank policies. The following are some of
the security measures that can be implemented in a bank:
Developing local policy, process and guidance:
Creating a policy means setting rules and protocols within your organization. The banking
environment requires strong policies that include needs identification, information gathering,
drafting, reporting and analysis. This process takes place in several stages. These steps are
summarized below:
Identify needs
Identify who will take lead
Gather information and raw data
Drafting policies
Consulting with proper and trustful stakeholders
Approving policies
Authentication
Authentication is the process by which a machine or device can identify a user who is connected to a
network resource. This is usually the process of identifying an individual based on their username
and password. In a security system, authentication is different from authorization. Authorization is
the process of granting individual access to system objects based on their identity. In the field of
backing, this technique typically follows three steps. These steps identify each other, monitor
communications through the firewall, and restrict policies by username and password. Technologies
that work with authentication are firewalls such as Radius, WDS, LDAP, and token-based security.
Authorization
Authorization is a post-authentication process. This process helps secure banking transactions by
granting the appropriate permission granted by the administrator or security administrator. This
involves determining the rights / privileges of access to resources related to information security and
computer security in general and access control in particular.
Accountability
Accountability helps us ensure the required registration process, audit control function, data security
oversight, report writer, and most importantly, password protection on a networked system. This is
the responsibility of the organization.
Risk Assessment
Security Audit
Security auditing is a standard that certain types of organizations maintain. Banking sector security
clearance either follows the bank's standard security guidelines or does not. This helps in
harmonizing the security systems used in different sectors. A general overview generally assesses the
security of the physical configuration and security of the system, software, information handling
processes, and user procedures. The security audit examines whether mapping follows standard
security approaches and technique management. Security reviews cover the following solutions in
the banking scenario:
It evaluates the flow of data within the bank
It identifies vulnerable points and problem area.
It determines whether we must alter the security policies or not.
It recommends how to leverage information technology in banking sectors.
It delivers an in-depth analysis of internal and external system used in security system.
Vulnerability Assessment:
A vulnerability assessment provides an institution with the knowledge, awareness, and risk needed to
define, identify, classify and prioritize vulnerabilities in computer systems, applications and network
infrastructures and understand the threats to its environment and There is a process of answering
appropriately. Vulnerability assessment focusing on the detection of vulnerabilities in information
systems. As an IT manager, we need to highlight the vulnerability of Sunrise bank heads. To find the
weaknesses in the system, we need to perform various tests during the testing process.
Penetration testing:
One of the approaches to security assessment is that it involves security audits and vulnerability
assessment and demonstrates whether an attacker can successfully exploit vulnerabilities in the
system. This is also known as a penetration test. In fact, there are three types of penetration tests,
they are:
Black-Box testing
White-Box testing
Grey-Box testing
Security measures are actively analyzed to detect design weaknesses, technical flaws and defects. It
not only highlights vulnerabilities, but also records how weaknesses can be exploited.
Security devices:
Security devices Firewalls, Cisco routers, biometric devices, DMZs, etc., used to secure the network.
This type of device is used to detect and report unwanted traffic, such as intrusions, viruses, and
DDOS attacks. Hackers need to work hard to break devices so that the network is secure, which
helps to address security risks. For example: Facebook, Google and other big technologies use DMZ
to secure their network, where a hacker tries to break a firewall and even if he can break it there are
only proxy servers that can secure their real servers and how to get data and can manage.
Security policies:
Security Policies: This is a set of rules set out in the network where the users of this network follow
all the rules and instructions regarding the security of the data stored on the server. It also helps
protect against threats and viruses. It also reduces data breaches in the company and keeps the data
safe because the data can only be obtained by authorized users and unauthorized users are denied.
There are many users in a company and these users are different from the department and can only
access their data.
Monitoring tools:
In a network, there are many users and some have different intentions and they want to break the
policy and seize all the data. To avoid these types of threats, the company should be monitored and
this type of software always keeps a record of all users and computers and tracks the work of each
user in the network. All activities that are detected can be used during system auditing and can detect
system flaws. Monitoring tools are also called monitoring software and are very useful for securing
networks.
Report:
If there is any serious defect in the system, it should be reported to the Board members and other
concerned persons so that the system can be shut down immediately and data can be saved.
Reporting can sometimes help protect data because it has the potential to shut down servers.
Conclusion
Our organizations also have a variety of security risks, such as unauthorized ring access to the system
and data, naturally occurring threats, and threats to the host, network and application that can damage
the bank's entire network. Therefore, to minimize those risks, I have identified all the potential risks
that may be present in our system such as network, application, host, environmental risk, etc. Then I
discussed the security process and the various steps involved. The main purpose of the security
action is to ensure consistency in the implementation of security controls. When sanctions are
applied or business procedures related to security are followed. The main purpose of a security action
is to restrict access to the information of authorized users of an organization, protecting that
information against unauthorized modifications. There are many methods for assessing hazards but
best practices for assessing safety risks need to be implemented, and I have discussed the five steps
involved in risk treatment. Finally, I talked about the vulnerability assessment. It recognizes,
measures and classifies the security vulnerabilities of a computer system, network and
communication channels. Typically, a vulnerability assessment is performed to identify exploitable
weaknesses and predict the effectiveness of additional security measures to protect information
resources from attacks. Penetration testing is a methodological approach to security assessment that
includes security audits and vulnerability assessments and demonstrates whether attackers can
successfully exploit vulnerabilities in a system. At the same time, security measures are actively
scanned for design flaws, technical flaws, and vulnerabilities.
Part 2:
Identify the potential impacts to IT security using firewall and VPNs and make aware of the
repercussion of incorrect configuration of firewall policies and third-party VPNs.
Show through an example in simulated environment, how implementing a DMZ, static IP and
NAT in a network can improve Network Security.
Discuss how network monitoring system can benefits the security of IT of the organization.
You need to present at least three advantages.
Finally investigate how a ‘trusted network’ may be the part of an IT security solution.
Introduction
Each association, large or small, has its own unique security strategies, with the ultimate goal of
dealing with each of its advantages, capabilities and security of administration. Risk assessment and
penetration testing alone is not sufficient for a bank risk. Therefore, the IT Foundation security
configuration, including VPN, firewall, DMZ, must be factored in and out of the security mode. Our
clients are confidently focused on our association's security methodology to ensure that their data
and money related records are secure. These days, we cannot rely entirely on security reviews and
conditional checks, so cyber security systems are fundamental to keeping track of our bank and
customers' back and forth day in and day out. Our association has a powerful mechanism to create a
layered, defensive security approach that should integrate a variety of processes focused on our
bank’s innovations, personnel and processes. We can make various IT security answers to the bank
real, for example, VPN, Firewall, DMZ, which I described below.
Firewall
Firewall is a network security tool that monitors incoming and outgoing network traffic and
determines whether certain traffic is allowed or restricted based on specific security rules. Firewalls
are the first line of defense in network security for 25 years. They create a barrier between secure and
regulated internal networks that can be trusted and external networks such as the Internet. Firewalls
are the first line of defense in network security for 25 years. They create a barrier between secure and
regulated internal networks that can be trusted and external networks such as the Internet. Firewalls
are divided into two types: - Firewall or host-based firewall. Network firewalls play an important
role in filtering traffic between two or more networks and work on network devices.
There are five different types of firewalls used in bank for securing the network. Those firewalls are
listed below: -
Packet filtering firewalls
Circuit-level gateways firewall
Stateful inspection firewall
Application-level gateway firewall
Next-gen firewalls
Advantages of Firewall
A firewall is a software / hardware device that is easy to install and operate. No major technology is
required to use this tool. Privacy is paramount in this device, which is why it provides privacy to
incoming and outgoing packets. It uses its own rules to protect the system by dropping packets that
pose a threat to the system. It can easily monitor protocols from the data link layer to the application
layer. This tool is not expensive so it can be used for any type of organization as well as for personal
purposes.
Disadvantages of Firewall
The firewall only blocks an untrusted network, but it cannot prevent an internal security risk, such as
using malicious code from a website. It cannot be properly filtered at the application layer and can
pose a security risk. Network address and packet filters can be complicated and difficult to manage in
a large environment, as they are out of sync. It has no functions like user login, login, etc. so it does
not provide any user views.
Site-to-site VPN
The second major VPN implementation is through a bank, which can have two or more locations that
need to be securely connected (perhaps via the Internet) so that each location can communicate with
another location or locations. ۔Site-to-site VPNs traditionally use a combination of VPN technology
called IPSEC.
Advantages of VPN
Nowadays, online is an important part of our life, which is why VPN helps in making our identity
anonymous. There are many online hackers on the Internet, so it is helpful to hide our IP address so
that these hackers cannot see our data. It also helps us use the Internet more securely or privately so
that nothing leaks from our devices. Firewalls have some guidelines so we cannot go through them,
but VPN helps to avoid that firewall by hiding our IP address. VPNs are important to personalize our
Internet or network systems so that it can prevent attacks.
Disadvantages of VPN
Many are not reliable VPNs, so it is important to know more about VPNs before using them. This
could easily compromise our privacy as trusted VPNs cannot protect our IP addresses and online
hackers could easily access our details which could interfere with the necessary data and
information. Quality VPN is expensive and difficult to maintain. VPN also affects the speed of our
devices. This often slows down our devices and requires a good CPU as well as powerful bandwidth.
Advantages of DMZ
DMZ helps to separate your public server from the rest of your LAN.
This increases the security of your LAN.
It is used to reduce and control access to those systems from outside the organization.
Disadvantages of DMZ
It is very difficult to use.
If the attacker enters into the firewall, they can easily access the DMZ.
large private network. Public IP address in the private network. It helps to improve the security of the
network by only sending valid external networks. Here are the ways we can configure and example
of the NAT:
Advantages of NAT:
It helps in privacy because the IP address is kept hidden also the transmission between internal
and external traffic also are kept hidden.
This helps avoid using the same IPV4 address.
It also helps you to use your own private IPV4 address and improves network security.
Disadvantages of NAT:
It consumes many system processes and memory.
End-to-end IP traceability can be lost.
Some applications will not work if NAT is enabled.
IP routing
IP routing is a set of guidelines that allow data packets to travel across a variety of networks,
following a secure route provided by the administrator. The router is used to send data from source to
destination. There are three types of IP routing:
1. Default IP routing
2. Static IP routing
3. Default IP routing
Static routing: Static IP is a permanent address that does not change and is provided by Internet
service providers for device configuration. This is done manually to configure the IP address on any
device, mainly routers. It provides better security for a fixed route and helps improve network
security, and it is used by the network administration to allow them to access the routing path,
making it more secure to transmit data. Below is the configuration:
We have to ping to know whether it share data or not. To ping we need IP address for device
[Link] and for router [Link]
Advantages of Static IP
Administrator choose the router network path that’ why it is very secure connection and the speed
of connection is very high.
It is easy to use for small networks as well as bandwidth is not use to update the routers.
Disadvantages of Static IP
It is complex for large network so network administration must handle it properly because it can
be messy.
There will be difficult to add extra network in static IP because the configuration has to done in
each router which becomes tedious.
It is hard and difficult to maintain if there will occur problem in network.[ CITATION tec191 \l
1033 ]
There are several benefits of using network monitoring system. Some of the major benefits of using
this network monitoring are as shortly explained below:
software provide complete visibility into a complex ecosystem that helps network operator teams
easily track data moving between devices and resolve issues faster.
where to use valuable network resources. With this information, you can anticipate future capacity
requirements, benchmark current performance, upgrade network elements to improve performance,
and stay one step ahead of the competition.
Wireshark
Wireshark has been around since 1998, when it was invented by Gerald Combs and called Ethereal.
Over the years it has received gargantuan amounts of community support and patches, and is widely
accepted as the de facto network protocol analyzer available today.
Wireshark runs on all the major and most minor operating systems, including the usual Linux distros,
Windows, OS X, FreeBSD, NetBSD, and OpenBSD. The program is free software, licensed GPL,
and is thus free to use, share, and modify.[ CITATION wir16 \l 1033 ] Wireshark is the world's
leading network traffic analyzer and an indispensable tool for any security expert or system
administrator. This free software allows you to analyze network traffic in real time and is often the
best tool for troubleshooting your network. Wireshark is a powerful tool that requires extensive
network knowledge. It helps filter the traffic, which makes it especially useful. Collection filters only
collect the types of traffic that you are interested in, and display filters help you grow the traffic that
you want to investigate. The Network Protocol Analyzer provides search tools, including regular
expressions and highlighting, to make it easier to find what you are looking for. Example: For most
modern businesses, this means understanding the TCP / IP stack, reading and interpreting packet
headers, and how routing, port forwarding, and DHCP work.
SNMP server
SNMP (Simple Network Management Protocol) is a network management protocol used almost
exclusively on TCP / IP networks. SNMP provides a means of monitoring and controlling network
devices, and managing configurations, statistics, performance, and security on a network.
[ CITATION Tho20 \l 1033 ] SNMP-based management enables the use of third-party solutions that
include products such as HP OpenView and CA Uncenter. Network management stations run
management applications that monitor and control the managed nodes. Managed nodes are devices
such as hosts, gateways, etc. that have management agents that are responsible for performing
management functions requested by management stations. SNMP is used to communicate
Shuvechchha Bhandari (HND / Second Semester)
37
Network Security 2019
management information between management stations and agents. The SNMP agent on these
servers offers the following functions:
Event management
Inventory management
Sensor and system state monitoring
SP configuration monitoring
Trusted Network
A trusted network is controlled by a network manager or network administrator. Basically, it is the
network administrator who tries to define and define the security parameters. Therefore, it can also
be said that reliable networks are within the limits of security. Computers using trusted networks are
more secure and confidential due to stronger firewalls. Allows only open and secure data transfers to
authorized users. Unreliable networks are beyond the control of the security community and the
network administrator. They can even be private or shared networks. Consider security policies and
access to the levels you can use to secure the network.
To monitor incoming and outgoing traffic, we set up a firewall and set out some rules for exchanging
two-way packets on a firewall server. After we start configuring for the firewall, all the network
behind the firewall is in a reliable network. As far as VPNs are concerned, they transfer data to
unreliable networks and are still considered trusted networks because the source of the packet is in a
trusted network. Virtual Private Network (VPN) programming is the creation of a less secure
network, such as a secure and confidential connection to the public Internet. In the early days of the
Internet, VPNs were developed to provide branch office employees with access to corporate
applications and data, cheaply and securely.
Authentication: Authentication takes place in two stages. Level and machine level visible to the
user. Human-level visual authentication is a simple login where you provide a network ID and
password to access it. However, machine-level authentication is more complex and involves a
predefined ID and password that are only known to the machine authorized to access the network.
This can occur when a user attempts to access a computer or node network after completing the
initial human visualization. The router or server, in this case, the machine is authorized to access the
network, and the machine attempting to connect must provide its identity (IP address or MAC
address) and the secret key that accompanies it to prove its authorization. Access the network.
Encryption- Network encryption is the process of encrypting or encoding data and messages sent or
communicated over a computer network. It is an extensive process consisting of various tools,
techniques, and standards to make messages unreadable while transferring between two or more
network nodes. Network cryptography is implemented primarily in an OSI-like network layer.
Network encryption implements one or more encryption algorithms, processes, and standards for
encrypting data / messages / packets sent over the network. Cryptographic services are usually
provided through cryptographic software or cryptographic algorithms integrated with network
devices and / Orin software.
Advantage of using encryption technology:
1. Encryption Provides Security for Data at All Times
2. Encrypted Data Maintains Integrity
3. Encryption Protects Privacy
4. Encryption is Part of Compliance
5. Encryption Protects Data across Devices
Firewall: Computers and servers on trusted networks must have hardware, such as a firewall, which
is a software program or hardware that helps verify security.
Private networks: Computers and servers in trusted networks must be equipped with software such
as virtual private networks (VPNs).
lot extra proof against interference and snooping from logical or bodily assault, so there's more self-
assurance in the ones techniques than in techniques that execute on a regular computing engine.
In a traditional platform with a traditional crypto co-processor, the co-processor protects all its
capabilities from logical and bodily assault however does not defend processing at the regular CPU.
A Trusted Platform presents logical and bodily safety for secrets and techniques and logical safety
for the statistics included through the one’s secrets and techniques (that is processed on one of the
primary CPUs). The TPM acts as a traditional co-processor for secrets and techniques, and the
integrity mechanisms save you the discharge of secrets and techniques to irrelevant processing
environments and allow a nearby or far off consumer or pc to affirm the trustworthiness of a platform
earlier than interacting with that platform. So, a Trusted Platform protects a bigger wide variety of
techniques than a traditional platform with a traditional crypto co-processor: A essential few
techniques—handling secrets and techniques—are included through a minimalist crypto co-
processor. Other techniques on statistics that makes use of secrets and techniques are much less
included than they might be internal a crypto co-processor. This is due to the fact no bodily safety
exists, for example, in opposition to deletion. But they may be higher included than regular
techniques outdoor a crypto co-processor due to the fact the confidentiality and integrity of the
statistics are included.
Specifically, a Trusted Platform presents hardware safety for keys and different secrets and
techniques, which might typically be used to encrypt documents or benefit get right of entry to
servers or different networks. The TPM prevents the discharge of secrets and techniques till
presentation of an authorization fee and/or the presence of a specific TPM and/or the presence of a
specific software program nation in the platform. The TPM prevents irrelevant get right of entry to
encrypted documents and community assets through, for example, snooping round a difficult disk,
shifting a difficult disk to any other platform, or loading software program to listen in on different
techniques.
Feedback about Trust to the User: By interacting with trusted platforms using smart cards or
handheld computers such as Personal Digital Assistants (PDAs), users can choose to trust a computer
or IT infrastructure. A smart card or other handheld computer can be programmed to query a secure
platform (local or remote), retrieve identity information and integrity metrics, and compare identity
and integrity metrics against expected values. If they disagree, a smart card or handheld user may
refuse to communicate with a trusted platform because it is the wrong computer or in a bad
condition. Inappropriate software and its intended use are unreliable. It allows users to access an
Trustworthy Digital Signatures: Digital signatures become more important as they gain more
legitimacy, and trusted platforms can help and enhance the use of digital signatures. Users realize
these benefits in the following ways:
The trusted platform protects signature keys using TPM, TPM never exposes these keys to the
outside, and the data stored in TPM uses such keys to digitally sign.
The trusted platform enhances digital signatures by adding integrity metrics that indicate the state
of the software platform when data is signed.
Depending on the implementation of the TPM, a reliable platform can add signatures, ensuring
that what the signatory sees is consistent.
Therefore, the main advantages of having a trust network in the organization is that it has many
advantages and positive effects on the organization. A trust network helps increase performance in
the organization and boost a sense of security and safety in the organization.
Conclusions
Different types of security solutions are described such as firewall, VPN, NAT, DMZ, static IP, etc. to
improve the security of the organization's network. The firewall is used to avoid unnecessary data
packets and the VPN is also used to secure the network connection within the organization. It also
shows that incorrect VPN and firewall settings can be dangerous for the organization. DMZ is used
to prevent attacks from untrusted networks, NAT is used to give a private IP to the bank, and a static
IP is used as the best route to give devices. These security solutions help prevent risks and provide
better security for the organization. For making trusted network part of our IT security solution first
we should know about the factors of trusted network. In this way while doing research first I found
out the factors of trusted network like Authentication, Encryption, Firewall and Private Network.
Part: 3
Once you have identified IT risks and viable security solutions, you need to review the
mechanisms to control organizational security. Consider various aspects of network change
management, audit controls, disaster recovery plans, Data Protection Acts, Computer Misuse
Act, ISO 3001 standards, etc. You need to:
1. Discuss risk assessment procedures and explain data protection processes and regulations as
applicable to the organization.
2. Summarize the ISO 31000 risk management methodology and its application in IT security
and then discuss possible impacts to organizational security resulting from an IT security
audit.
3. Explain considering how IT security can be aligned with organizational policy, detailing the
security impact of any misalignment.
Introduction
“A risk assessment is a thorough look at your workplace to identify those things, situations,
processes, etc. that may cause harm. After identification is made, you analyze and evaluate how
likely and severe the risk is. When this determination is made, you can next, decide what measures
should be in place to effectively eliminate or control the harm from happening.”[ CITATION
nd154 \l 1033 ]
Risk assessment is the ability to identify, analyze, and assess a threat before it poses a threat to the
entire network system. ISO 31000 is an international method of risk management guidance for risk
control. The ISO 31000 risk assessment is broken down into several conditions, namely, risk
identification, analysis and evaluation. Data protection procedures and regulations are rules that
apply to the organization to discipline those who misuse sensitive data and information and enforce
risk-taking measures. There are many laws that can be applied to data protection processes, such as:
B. Network Change Management, Data Protection Act, Computer Abuse Act, etc. In this section I
cover risk assessment and the process of data protection to control this risk.
Risk assessment
Risk assessment identifies risks that could negatively affect a firm's ability to run a business. These
reviews provide actions, processes and controls to identify these inherent business risks and mitigate
the impact of these risks on business processes. Surveying risk assessment is fundamental for
deciding how advantageous a speculation is and the best procedures to relieve chance. It displays the
upside compensate contrasted with the risk assessment profile. It likewise decides the rate of return
important to influence a specific venture to succeed. Companies can use the Risk Assessment
Framework (RAF) to prioritize and distribute assessment details, including any risks to Innovation
Technology (IT) infrastructure. RAF helps the organization identify potential risks and any business
assets at risk from these risks, as well as the potential consequences if these risks are effective. In
large businesses, risk assessment is usually done by the Chief Risk Officer (CRO) or Chief Risk
Manager.
Step 5: Regularly review and update your risk assessment. The potential dangers, risks and
associated controls can change quickly in today's business environment. It is important that
companies regularly update their risk assessments to adapt to these changes.
There are three stages engaged with ISO 31000 risk assessment appraisal strategy which are
talked about underneath:
Risk Identification
The first stage of ISO 31000 risk assessment is the identification stage. You need to identify,
understand and explain the risks. Remember, risk is seen as something that can hinder, prevent, or
even help an organization achieve its strategic goals. During the risk identification phase, it is
important to use the latest information available. Realistic, timely and accurate statistics will enable
you to develop highly relevant strategies. Factors to consider identifying potential threats to your
organization may include: material and non-material sources, causes / events, threats and
opportunities (also important to assess positive risks), risk management opportunities and Changes in
the context of any risk such as changes in available external resources, the nature and value of the
risk
the likelihood of the risk and the likelihood and consequences of the risk (knowledge), Experience
and Stakeholder Assumptions Risk Assessment. When identifying a risk, it is important to note the
consequences of multiple risks.
Risk Analysis
The risk analysis phase enables decisions regarding risk treatment and the determination and
determination of the organization’s risk tolerance. The type, amount and probability of occurrence of
the risk as well as detailed factors such as available resources and internal / external influences are
taken into account. A risk incident can have several consequences that can affect other risks. The
domino effect of risk should also be seen in relation to the goals of the organization. The methods
used to analyze risk are many and the organization must determine which ones to use. Some of these
are discussed in Section 6.3 as the context of the risk management strategy includes the definition of
risk criteria and measurability. You can use a qualitative, semi-quantitative, or quantitative approach,
or a combination of all three, to determine the risk analysis. Remember that the risk is very
subjective. While communication with key stakeholders is critical during the development and
implementation of a risk management strategy, an approach that somehow reduces bias must be
followed. One person may rate the risk as very likely and severe, while another person may rate the
risk as moderately likely and less severe. Your organization needs to determine how the measurement
of risk level is defined and this will affect your risk measurement and analysis.
Risk Evaluation
The final step in the risk assessment process is risk assessment. The idea behind the assessment is to
make it easier for organizations to prioritize risk handling and risk mitigation.
Risk Assessment to Determine Steps for Risk Criteria and Risk Analysis:
Effectiveness of Defining Criteria What are the Highest Priority Risks?
How to approach the next step (risk handling) The results of a risk assessment can lead to many
actions. Further analysis should be assigned, existing controls should be maintained,
the purpose of the risk strategy should be revisited in conjunction with the purpose of the
organization.
Regular assessments allow you to address changes in risk factors, impacts, consequences, and
objectives within a reasonable time frame, allowing you to develop a comprehensive and mature risk
management strategy.
Along these lines risk assessment can be evaluated in ISO 31000 risk assessment appraisal
philosophy, in spite of the fact that we can't utilize ISO 31000 for affirmation reason yet it gives
direction to us and utilizing it we can contrast association's dangers administration rehearses and
another worldwide benchmark. Risk assessment administration 31000 isn't finished in itself and
requires ceaseless change.
in sequence do not bypass government control of information. Some members of the association use
system change administration as an approach to robotically reduce downtime and comply with
government regulations, and streamline the backup and restore of gadget designs. It helps to make
organization in robotize approach as well as it also reduces in network downtime and saving each
and
every data and information of organization without any faulty configuration.
Significance of DPA
Data protection is the best practice for any organization as it provides rules and regulations that can
be followed to gain the trust of customers, partners, etc. It helps to protect the personal data of the
individual by applying its principle. The law also punishes those who do not follow or disobey these
rules. The law protects all types of data and also prioritizes ethnic background, health, criminal
history, etc. There are many cybercriminals today, so this law provides strict security for data and
data sharing. With this act, an organization can properly manage data and maintain data quality. It
analyzes, stores, backs up and retrieves this data with appropriate roles and responsibilities. For
example, after our customers provide us with their information, we need to make sure that the
information is used in a particularly expressive way, that it is no longer placed where it is needed,
that it is only meaningful. I use it, that is, to keep it safe, etc. In the remote possibility that we do not
do what is stated, our association may be rejected as stated by law. It is important to follow the
information safety net to prevent cybercrime, while ensuring that subtle elements are protected from
misrepresentation.
Identifying risks: Recognize what may prevent you from achieving your goals.
Risk analysis: Understand the causes and causes of identified risks. Investigation of probabilities
and outcomes given appropriate controls to determine the level of residual risk.
Risk assessment: Compare the results of risk analysis with risk criteria to determine if residual risk
is acceptable.
Risk handling: Change the magnitude and likelihood of results, both positive and negative, to
achieve a net increase in profits.
Establishing Context: This activity, which was not included in the previous description of the risk
management process, consists of defining the framework of the risk management process, defining
the purpose of the organization, and establishing risk assessment criteria. The contexts include
external elements (regulatory environment, market conditions, stakeholder expectations) and internal
elements (governance, culture, organizational standards and rules, skills, existing contracts,
employee expectations, information systems, etc.)
Monitoring and Review: This task involves measuring the performance of risk management against
indicators, which are reviewed from time to time to ensure their relevance. This includes verifying
deviations from the risk management plan, verifying whether the framework, policy and risk
management plan is still appropriate, taking into account the external and internal context of the
organization, reporting on risks, progress of the risk management plan and quality risk management
policy. The effectiveness of the risk management framework is monitored and reviewed.
Communication and Consulting: This function helps to understand stakeholder interests and
concerns, verifies that the risk management process is focusing on the right elements, and also helps
explain the rationale for decisions and alternatives to deal with particular risks.
Security Audit
Network security audit is a key component of the firm's ongoing risk mitigation strategy. Whether
the audit is performed by an internal team or an external auditing company, the process includes a
measurable assessment of your firm's security policy and management details. The term "audit" may
indicate that such an assessment is unexpected, but in most cases cyber security audits are conducted
with the full knowledge and cooperation of the company. Will be made. Security auditing is a
complete process and may take some time to complete. This is because auditors consider not only the
technical aspects of network security (firewalls, system configurations, etc.) but also the
organizational and human aspects of security policies. In addition to investigating IT systems and
historical data, conduct personal interviews and review documentation to ensure that information
security procedures meet relevant compliance standards. This is followed routinely and has to be
done.
IT security with hierarchical arrangements Hierarchical preparation security. The head of the IT
department of our financial institution needs to study the near contemporary security status of all the
facts and conditions of the hotspot destination without problems to sustain the financial institution
reforms, along with the footprints they leave for new workers. Pinnacle Management bodies can
make financial institutions almost a fame in IT security. Behind the techniques of our financial
institution, if sometimes the upper management body of workers expressed such readiness, that they
may not be happy with the help of the IT department to use the IT workplace on that factor, they
should know. And the processes can be updated.
Therefore, there are basically seven key chapters that are all interrelated and related to improving
business consistency, and are summarized below: -
Culture: Develop an organizational tradition wherein users, managers and IT experts all make
exact selections approximately statistics risk.
Planning: The strategy and strategy planning activities of an information security firm provide
ample opportunity to tailor outcome plans and tasks to actual business needs. For example,
controlling the principles of enterprise architecture in security planning practices is an important
strategy.
Action: Adopting a strategic action approach, as defined by ISO 27001 for the ISMS Security
Management Program. Instead of enforcing the control baseline "fits all in one size", it
establishes the ability for businesses to evaluate, develop, and implement security solutions when
needed.
Communication: The main objective should be to develop a security level service level metrics
that can be incorporated into regular service level agreements (SLAs) between IT, service
providers and the consumer sector.
Qualifications: Business alignment generally does not require information security expertise
skills such as architectural practice, personal communication, business information and
marketing skills.
Technology: The way that security technologies are used can have a major impact on the
perception of security of technology users. The success of an integrated IT service delivery
strategy, such as that required by ITIL v3, will depend on how security controls are technically
integrated with IT services.
Relationships: The significance of organizing and retaining powerful relationships with different
roles and people with inside the organization. Alignment relies upon at the cooperation and assist
of key influencers, selection makers, and different stakeholders.
Alignment is a challenge that cannot be met in pieces. Organizations need to spend their time and
resources on a comprehensive strategy to improve business integrity. The actions and plans that
result from this strategy should be carried out collectively, not in place of an existing security plan.
Conclusion
The risk and threats which is seen in the organization should be identified, analyzed and evaluate
according to the risk assessment procedure and it can be mitigated using the ISO 31000 guidelines.
The process and the regulation that should be used to protect the data in the organization which is
one of the most valuable things of any organization. Data can be used for different use like it can
help to predict the future. It can used for market research and so on. The security audit that should be
done time to time to protect the data and information and their impacts are explained. It is important
for every organization to write policy to support continuity of organization business and while
designing it there should be included head member of IT security department so that after
implementing policy all the organization’s department can handle those policy effectively. Alignment
of IT security policy with organizational policy is important for all the organizations to smoothly run
all functions of organizations.
Part: 4
Lastly you will produce technical and user documentation which will be given to the company
for the management of organizational security. You have to design and implement a security
policy for the bank which will.
1. List out the main components of an organizational disaster recovery plan, justifying the
reasons for inclusion.
2. Discuss the roles of stakeholders in the organization to implement security audit
recommendations.
3. And an evaluation of the suitability of the tools used in an organizational policy.
Introduction
A security policy is a written document that describes how a company protects a company's physical
and information technology assets. This security policy never expires. That is, it is updated as
technology and employee requirements change. Companies should always focus on training their
employees on how to protect their assets, such as valuable data. The company's physical and
informational assets are so important to its survival in the market that it needs to plan for recovery in
the event of a disaster or emergency. A natural disaster recovery plan is a method designed to recover
your organization's data as quickly as possible in the event of a natural disaster. All of this plan
should be considered with high-impact stakeholders such as employees, board members,
management and managers. Stakeholders are individuals who are interested in the company and who
have the potential to influence or influence the business.
Modem
Modem is short for modulator-demodulator. It is a hardware component that allows a computer or
other device, such as a router or switch, to connect to the Internet. It converts or "modulates" the
analog signal of a telephone or cable wire into digital data (ones and zeros) that the computer can
recognize. Similarly, it converts digital data from a computer or other device into an analog signal
that can be sent over standard telephone lines. The first modems were "dial-up", meaning they had to
dial a phone number to connect to an Internet service provider. These modems operated on standard
analog telephone lines and used the same frequencies as telephone calls, limiting their maximum
data rate to 56 kbps. Dial-up modems also require full use of the local phone line, meaning that voice
calls interrupted the Internet connection. Modern modems are usually DSL or cable modems, which
are considered "broadband" devices. DSL modems operate over standard telephone lines, but use a
wider frequency range. It provides faster data transfer rates than dial-up modems and does not
interfere with phone calls. Cable modems send and receive data over standard cable TV lines, which
are usually coaxial cables. Most modern cable modems support DOCSIS (Data over Cable Interface
Specification), which provides an efficient way to transmit TV, cable Internet and digital phone
signals over the same cable line. [ CITATION Com19 \l 1033 ]
Router
The Advanced Research Project Agencies Network (ARPANET), based on projects developed in the
1960s, was created in 1969 by the United States Department of Defense. This early network design
was based on circuit switching. The first device to function as a router were the interface message
processors that made up the ARPANET and formed the first packet data network. The original idea
for a router, then called a gateway, came from a group of computer networking researchers who
formed an organization called the International Networking Working Group, which in 1972 became a
subcommittee of the International Federation for Information Processing. The first true router was
developed, and by 1976 three PDP-11-based routers were being used to prototype an experimental
version of the Internet. From the mid-1970s to the 1980s, minicomputers were used as routers.
Today's high-speed routers are actually very specialized computers with additional equipment for fast
forwarding of data packets and specialized security features like encryption. A router is a device that
analyzes the content of data packets sent over a network or another network. Routers determine
whether the source and destination are on the same network or whether data is to be transferred from
one type of network to another, which requires encapsulating the data packet with the routing
protocol header information for the new one. network type. When multiple routers are used in a
collection of interconnected networks, they exchange and analyze information and then create a table
of routes and preferred rules to determine routes and destinations for that data. As network interfaces,
routers convert computer signals from one standard protocol to another that is more suitable for the
destination network. Large routers determine interconnectivity within a business, between businesses
and the Internet, and between different Internet Service Providers (ISPs); Small routers determine
interconnectivity for home or office networks. ISPs and major companies exchange routing
information using the Border Gateway Protocol (BGP).
Switch
In the context of networks, a switch is a high-speed device that receives incoming data packets and
sends them to their destination in the local area network (LAN). A LAN switch works on the network
layer of the Data Link Layer (Layer 2) or OSI model and thus supports all types of packet protocols.
The layer 2 switch is sometimes called a bridge: its function is to send frames with data packets
between nodes or layers of the network. In short, switches are a simple local area network traffic
police. Describes the tractor as units of data for switching frames and how data is transferred from
one area of the network to another. Routing, on the other hand, takes place on layer 3, where data is
sent between networks or from one network to another.
Server
A server is a computer program or device that serves another computer program and its users (also
known as clients). In a data center, the physical computer on which the server program runs is often
referred to as the server. This machine can be a dedicated server or used for other purposes. In the
client / server programming model, server programs expect and meet requirements from client
programs that can run on the same computer or on different computers. Certain applications on your
computer can act as clients of service requests from other programs and as servers for requests from
other programs.
Networking cables
A network cable serves as a means of transferring information from one network device to another.
The type of cable chosen for your network depends on its size, topology, and process. Various types
of network cables act as the backbone of the network infrastructure. Choosing the right type of
network cable can impact a variety of business operations as corporate network administrators adopt
new technologies. The type of network cable used in any network infrastructure is one of the most
important aspects of networking in various industries.
Coaxial Cable
There is only one copper conductor between them. The plastic layer provides insulation between the
braided metal shell and the center conductor. The metal shells block outside interference from
motors, fluorescent lights, and other computers. Coaxial cabling is extremely resistant to signal
barriers, although it is complicated to install. It can handle longer cable lengths between network
devices than twisted pair cable. The two types of coaxial cables are thin coaxial and thick coaxial.
Shielded Twisted Pair (STP) Cable
This is a special type of copper telephone wiring used in business installations. An outer shield that
acts as a ground is attached to a slightly twisted pair of telephone wires. If you want to place the
cable in an area where there is current interference and threat in the UTP, a twisted pair of shields
may be the answer. Shield cables also help to widen the gap between the cables.
Fiber Optic Cable
Fiber optic cable consists of a central glass core surrounded by several layers of protective material.
It overcomes the problem of electrical interference by transmitting light instead of electronic signals.
This makes them perfect for certain environments that contain large amounts of electrical noise. It
has become the standard for connecting networks between buildings due to its light and moisture
resistance.
Unshielded Twisted Pair
It is the world's most admired network cable. UTP cable is used for traditional telephone and
computer networks.
Different wiring schemes for UTP:
CAT1, which is used for telephone cables. CAT2 supports speeds of up to 4 Mbps and is widely
used in token ring networks.
Both CAT3 and CAT4 are used for token ring networks for high network speed.
The CAT5 cable is now being replaced by CAT5e architectures, offering an improved crosstalk
specification that allows it to support speeds of up to 1 Gbps. This is the most used network cable
specification in the world.
CAT6 supports speeds of up to 1 Gbit / s up to 100 meters and up to 10 Gbit / s up to 55 meters.
Organizations using CAT6 cables should use a dedicated cable analyzer to request a full test
report to ensure that CAT6 guidelines and standards are followed during installation.
The CAT 7 is a new copper cable model that supports 10 Gbps speeds and 100 meters in length.
Pinging
The ping command sends a data packet to a specific IP address on the network, and can then tell you
how long it took for that data to transmit and receive a response. It's a handy tool that you can use to
quickly test different points of your network. Ping comes from the term used in sonar technology to
send out vibrations of sound, and then it listens for the echo to come back. On computer networks,
most operating systems have a ping tool built in that works the same way. You issue a ping command
with a specific URL or IP address. Your computer sends several packets of information to that
device, and then waits for a response. When it receives a response, the ping tool shows you how long
it took for each packet to go round - or tells you there's no reply. It sounds easy, and it is. But you can
use it to good effect. You can check if your computer can access another device, such as your router,
or any other device on the Internet - on your local network. This will help you determine if there is a
network problem on or near your local network. By the time you take packets to return, you may be
slow to recognize the connection or you may experience packet loss. And it doesn't matter what
operating system you're using. Pull out a terminal or command prompt window, and you can use ping
on any OS version, Linux, or any version of Windows.
The number given indicates the management department of sunrise bank, i.e., the personnel
department, the marketing department, the IT department, the credit department and the customer
department as well as the employees of these departments. The figures given show how a bank works
with different service providers and a banking team is needed to provide a service. The banking
industry is now globalizing so we can send and receive money using electronic services and the
Internet. Using the internet is made easy for everyone, but on the other hand there are hackers who
can hack into the account and steal the money. Therefore, the bank now needs a secure network in
which hackers can no longer steal money. Services need to be secure and trustworthy. For this
reason, sunrise bank wants a secure and trustworthy network so that users of the bank can trust that
they are using their account securely. In order to create the best safe and reliable banking network, I
have implemented many policies and safeguards on the banking network, which are listed below:
of authorized clients, controlling the client's attempt to acquire assets by the client. Our framework
takes up some space after effective verification by bank customers or our employees, yet our
framework requires a great deal of mental control. This strategy is also linked to how approvals are
formed in our bank as approvals sometimes reflect the structure of our bank, while also working well
with different report levels and levels. Level users are getting. Those archives of the banking system.
Attrib command:
Attrib command are the command which can read write and hide the files and folders. This command
helps to protect the file because it doesn’t show any file until and unless it is removed from hidden. It
helps to prevent risk.
Cipher command
In bank, we may face different kinds of risk that’s why it is necessary to encrypt the data that’s why
cipher command is used. Cipher command helps to encrypt and decrypt the data. This command
gives protection to the data.
To secure the system we need to define the entire local security policy, so first type [Link] in
RUN then it will open another window of local security policy where all this policy is described. ۔
Local Security Policy window where we can define various policies such as account policy, local
policies, etc.
Account policies
Accounting policies are specific statements and procedures used by the company's management to
prepare financial statements. This includes any accounting methods, measurement systems and
disclosure methods. Accounting policies differ from the accounting principles that contain the
accounting rules, and the policies are the company's way of enforcing these rules. Accounting
policies are a set of standards that govern how a company prepares its financial statements. These
policies are typically used for complex monetization methods such as amortization methods,
identification of goodwill, research and development preparation (research and development) costs,
inventory pricing, and financial statement stability. These policies may vary from company to
company, but all accounting policies generally comply with accepted Accounting Principles (GAAP)
and / or International Financial Reporting Standards (IFRS). Accounting principles can be seen as the
framework in which a company is expected to operate. However, the structure is somewhat flexible,
and the company's management can choose specific accounting policies that are beneficial to the
company's financial statements. Because accounting principles are sometimes slow, specific
company policies are important.
The first local security policy is an account policy where an administrator can set a policy to stop
data leaks, data breaches, unwanted logins to other users' accounts. And here in this account policy
image, we can determine the password age, password length and even password complexity, for
example, a request to include an uppercase letter, a number and a special character.
Set the minimum age of the password because the password must be changed after the age is
completed.
If the password is simple then anyone can guess the password, then there may be some security error
in the system. Some may try to lock data and get data so that enabling password complexity meets
system requirements and can help maintain better security.
Password must meet complexity requirements When this policy is enabled, the password must meet
the following minimum requirements: At least six characters long Contain at least three of the
following characters: uppercase letter, lowercase letter, Numbers, symbols (punctuation marks) not
included in the username or screen name of the user.
The account policy, which is another important parameter of the security policy, where we will set an
account lockout policy to prevent unauthorized use of the system.
Account lockout policy is more popular in the banking industry because unauthorized access can
cause problems for the bank. An account lockout threshold is enabled on bank computers, and it also
stores data about login attempts and helps discover it during an audit. This will help you know how
many times this system has been hacked. If this policy is locked, the real password will not be able to
open the system either. It must be unblocked by the administrator.
Local policies
To set the permissions, go to the local policy, then assign the user permissions and turn off the
system for some users, such as those who gave permissions to administrators and users.
Local policies allow you to set user permissions such as shutdown options. To give some users
permission to shut down the system. You can set it as a requirement by going to the local policy,
clicking Assign User Privilege, and setting the privilege on the shutdown system.
NTFS security
A file system is a way of organizing a drive, showing how data is stored on the drive and what kind
of information can be attached to files, such as file names and permissions. NTFS (NT File System)
stands for New Technology File System (NTFS).[ CITATION Cin21 \l 1033 ] NTFS is the latest file
system used by the Windows NT operating system to store and retrieve files. Before NTFS, the File
Allocation Table (FAT) file system was the primary file system in older Microsoft operating systems
and was designed for small disks and simple folder structures. In the given figure, the root folder is
allowed to users with full control over the folder and they can use this folder on a network. They
have the ability to change, read, and write to the file. NTFS security helps ensure that the correct
users are using the correct folder. We can even give permission to specific users of a network and it is
very useful when bankers are working because the IT department can access the file from the IT
domain but not from the finance department and others, so the authorization is separate and now
there will be no more conflicts between users and data is safe and secure.
Encryption
Encryption is a tool for securing digital data using one or more mathematical techniques, as well as a
"key" used to encrypt passwords or information. The process of encryption translates information
using algorithms that cannot read the actual information. For example, this process is called basic
text, which can be converted to an alternative form called cipher text. When authorized users need to
read data, they can decrypt the data using the binary key. It converts side text into plain text so that
authenticated users can access basic information. Encryption is an important way for individuals and
companies to protect sensitive information from hacking. For example, websites that transfer credit
card and bank account numbers should always keep this information confidential to avoid identity
theft and fraud. The study of mathematics and the application of sketching is called cryptography.
The figures below show that we can protect data and encrypt information and once encrypted they
are ineligible, so a password is required to decrypt data and information. We can encrypt files and
folders by right-clicking the folder and clicking the folder properties. The general section then has a
preset that leads to advanced features, where we can enable the checkbox to encrypt the content, to
secure the data on OK.
After the encryption process we can go back to the folder location and the folder name will turn
green which means the folder is encrypted and now it is safe.
Quota system
The disk quota system allows system administrators to control the number of files and blocks of data
that can be assigned to users or groups. The amount of file storage space is based on disk space and
the type of computer available on the ECS file server. The account you have. Each computer account
has both strict and soft fees. The soft fee is the point at which you are warned that you are
approaching the hard fee. The strict quota is the absolute maximum amount of disk space that the
system grants to your account. Do not exceed the strict quota. If you do this, bad things will happen.
The system cannot do anything with an account that needs to use additional disk space. You cannot
create a new file. Also, the file you are trying to edit may be corrupted. Strict quotas take effect as
soon as they are exceeded. There is no grace period. Soft fees are less than strict ones. Heed this
warning, as exceeding the strict quota can have serious consequences. If you exceed the soft fee for 7
days or more, it will automatically convert to the strict fee. This quota management can be used in
the system in the following ways: Go to run and type [Link], then select the disk and right
click on it, then go to the properties and there we can find the quota tab where we can manage the
space.
Another way is to go to this computer and then select the drive and right click on it, then go to the
properties and select the quota tab.
1. To start assigning a quota, right-click the drive in Explorer, then select the Properties menu. On the Quota
tab, click the View Quota Settings button.
2. Select the Enable quota management and also deny storage space to users who exceed the quota
limit check box. Click the Limit disk space to radio button and enter a value for the maximum
amount of disk space the user can use. In the example below, I've set the disk space limit to 10
GB and the warning level to 8 GB. To keep track of when users exceed the limit, select the check
boxes in the event log boxes.
3. Finally, click on the OK or Apply button to activate the changes. A warning dialog will appear
stating that Windows may take a few minutes to scan the drive before it can update the disk usage
statistics.
4. Click OK and once the quota limit is activated you should see the traffic light green.
Group policy
Group Policy is a tiered infrastructure that enables network administrators to apply specific
configurations to users and computers in the Active Directory of Microsoft. This helps keep the
system safe and secure. It allows administrators to determine what options users can do on the
network. For example: what files and folders and applications they can use. It is a collection of
systems and users centrally controlled by the administrator.
We can representative policies from the system to Gin, by admin. To set policies, press win + R to
launch RUN and type [Link] to open the Group Policy window. First select Control Panel then
go to User Configuration in the Group Policy Editor and then click on Admin Templates. To prevent
users from accessing Control Panel and PC settings, we can enable this option so that no user can
change any settings on the Control Panel to help keep the system safe.
The figure above prohibits access to the control panel and enables PC settings. This prevents users
from accessing the control panel and protects against unauthorized access and changes to the system.
Firewall
A firewall is a system designed to prevent unauthorized access to or from private networks. Firewalls
can be implemented in the form of hardware or software, or a combination of both.[ CITATION
Pro20 \l 1033 ] Firewalls prevent unauthorized Internet users from accessing private networks
connected to the Internet, especially intranets. All messages entering and leaving the intranet (the
local network that you connect to) must go through a firewall. The firewall examines each message
and blocks messages that do not meet specified security standards. Firewalls carefully analyze
incoming traffic according to pre-established rules and filter traffic from suspicious or unsafe sources
to prevent attacks. Firewalls protect traffic at computer entry points called ports. This entry point
exchanges information with external devices. For example, "The source address [Link] can reach
the destination [Link] through port 22." Think of the IP address as the house and the port number
as the room within the house. Only trusted people (sender addresses) can enter. All houses
(destination addresses): additional filtering, allowing access only to specific rooms (destination
ports), depending on whether the person in the house is the owner, a child or a guest. Owners are
allowed Children and guests can enter a particular set of rooms (a particular port), but can move to
any room (any port).
[Link] in Run Command opens a new window for Windows Defender Firewall. Microsoft has a
number of firewall functions that we can use to protect the system, such as blocking the port in the
system and preventing vulnerabilities in the system. If we block the weak port, we can keep the
system safe and secure.
Stopping a weak port can protect the system so that we can block the port in the system through
advanced firewall settings, where we can set the port to outbound and outbound rules, help the
firewall monitor these ports. And if blocked, a blocked port is found in this rule. To create the rules
that need to be configured are given below:
In the above data we can select the next port and set the rules for TCP or UDP as required. Then
select the block connection and then create the appropriate name for the port and that's okay.
Finally, the port is blocked and now the vulnerable ports can be blocked in this way so to keep secure
the network. It is the most helpful ways to keep the system safe in the public network.
We can see the rules which we have recently created and the port is now successfully blocked. If
there are any threats coming from this port then firewall will detect it before reaching to the system
and it won’t allow the port to interact with the system and we can set this rule in both inbound and
outbound rules to keep the system more secure.
needs a better organizational disaster recovery plan for every situation it faces. No one knows where
and when a catastrophe like the one caused by the 2011 fire could occur. Therefore, before setting up
a company, they need to go into every aspect of geographical location, region, location of the country
and much more. If the company is located in the Maldives, there is a possibility of a tsunami or
flood. An organization should always be aware of this disaster so that if they keep their data safe,
maintain server rooms in earthquake, resistance buildings in most places, fire alarms and fire
extinguishers they can control the fire. Disaster can happen at any time, which is why a recovery
plan contains a recovery plan for data and features to get the organization going as quickly as
possible. A natural disaster or any other disaster is unpredictable, so the organization must be
prepared every day. A disaster can result in huge losses for an organization, so before a disaster hits
an organization it needs to have a recovery plan, and some of the plans I have prepared for upstream
banking are listed below:
resistant building can reduce risk and damage, and building construction will be a priority, they can
withstand a major earthquake.
Secured servers:
Servers and data are critical in any business. The servers must be secure, so they must be kept in a
safe room to protect them from disasters such as earthquakes, floods, and fires. Server rooms or data
centers are places or buildings that contain all the data and information of an organization. Therefore,
our bank servers must be kept in a separate room and building so that they are safe and secure.
Employees are made aware of the various hazards in the workplace and are given the necessary
knowledge. Thief alarm systems are installed under each employee's desk so that they can inform the
entire bank in the event of an emergency or other hazard. We use laptops and desktop computer locks
to protect computers in our bank.
overload. The RODC load is considered balanced when the DC is healthy and also acts as a backup
domain if the domain does not work. The organization can have a Child Domain Controller (CDC) in
the branch office so that they can work in a different domain and contact DC at any time. This will
make the branch work freely and easily and will reduce the burden of DC as CDC works like a child
of DC so it will be beneficial for big companies.
Backup DHCP:
DHCP is the most dedicated server in the organization and provides the fastest functionality to
manage all IPs in the workspace automatically and you don't have to go to all computers for
administrators to configure IP manually. This saves time for the devices to use the Internet that
require IP, which is why DHCP is one of the useful servers, which automatically assigns the IP
according to the rules defined on the server. If the DHCP server is down, no workspaces are running
and this affects the business, so it can be cloned and DHCP relay servers can be used to avoid DHCP
failures. Relay servers are often used to provide different IP addresses in the same company so if
they use relay servers it can be useful for the company and they can keep this server as a backup
server and it works the same as DHCP servers. I recommend that Sunrise Bank use DHCP and
DHCP Relay Server to continue the workflow.
Cloud Storage
Cloud storage is an online place you can use to store your data. Cloud storage provides a secure way
to remotely store your important data. Online storage solutions are usually delivered using a large
network of virtual servers that come with tools to manage files and organize virtual storage space. It
is managed and managed by hosting companies on storage servers built on virtualization technology,
and their service providers are responsible for making and accessing their data and protecting and
running their physical environment. User, person or organization that requires backup storage due to
the storage capacity from the provider to collect the data of the organization.
Security Audits
Security audits are an extensive and formal overview of your organization's security systems and
processes. Auditing is an extensive and detailed analysis of physical attributes such as networks,
firewalls and equipment, as well as other areas such as policies and standard operating procedures. In
addition to scanning existing systems, it looks at all aspects of your organization's security. This
process occurs when your organization's technology team conducts reviews to ensure that the
correctly updated processes and infrastructure are in place. It also includes a series of tests to ensure
that information security meets all the expectations and requirements of your organization.
Performing a security audit can answer the question of how to ensure the confidentiality, integrity,
and availability of your bank's information. All organizations should perform regular security audits
to ensure that their data and assets are protected. This audit determines if your plan complies with
your organization's internal policies and external rules and standards. It also identifies gaps and
weaknesses at any stage of maintenance. Once the audit is complete, you should update your
business continuity plan to reflect the necessary changes identified during the audit.
Customer:
The customer is one of the stakeholders of many companies and has less interest but more influence.
Due to their high impact, they also have a special role in maintaining the value of the organization as
they take advantage of the organization and in return, they give feedback to the organization which I
think has a security audit. The role of the client. For example: We say that Sunrise has provided an
online service to its users using a mobile application. The user uses the app and can review the
product and its function and talk about the quality and future requirements and the failure of the app
and much more. This will help the bank to fix the services and can perform system audit or security
audit if there is any serious problem in the system. The bank may be an indirect model for
conducting security audits in the organization.
Management:
The management team of the organization can be considered as the working team of the
organization. The bank also has its own working team with high strength and high interest. In order
to get multiple views from customers, the management team needs to be implemented in the
company so that they can collect all the feedback and make changes. It is very important to
strengthen the security system in the bank as the bank is online as well as physically sensitive. If the
bank's security system is weak, then it can cause serious problems. The management team will be the
working mechanism of the company so it will gather all the feedback and help in choosing the best
option to strengthen the security system and conduct security audit in the organization.
Employee:
An employee or worker is an actor with greater power and greater interest in the organization
because it is the first effect on the employee of the company if there is any change. These
stakeholders begin work after shareholders and investors pass security audits, and the Audit Officers
and IT division is the most important working group that has the greatest impact on security audits.
They need to check all components of the network for threats and vulnerabilities in the system. And
finally, they implement the necessary changes in the organization.
Government:
Government is one of the most important stakeholders in any organization. It has high power and
low interest. The role of government is to take care of the organization and ensure that the company
is compliant. Make sure all organizations are working legally. It acts as a wall on the way for the
company to go illegal. It is important to implement the reputable and recommended safety measures
during the audit process. If done the right way, it is considered legal, otherwise it is considered
illegal. Before conducting a security audit, you should consider the roles of all involved parties.
Everyone involved has a unique role. All changes are made to keep your data safe. Auditing during
this period is much more powerful because it collects all the data without leaving a trace. Banks have
daily transactions and workers work every day. Some mistakes are made unknowingly, while others
are intentional, and banks perform this check many times to help organizations move forward and
stay safe. need to do it.
Biometrics uses real-time data and matches the database. Biometrics uses individually identifiable
parts of the human body such as fingerprints, iris, retina, face, etc. Many organizations use these
biometrics for attendance. This helps prevent unauthorized access. Group Policy is also used to
maintain security in the system. Password policy, account logout policy, invalid login attempts and
much more. Every tool used to create a secure system has its own function and its strength is security
in organizational policy. It helped the bank to strengthen the security of the organization and
maintain its institutional policy.
Conclusion
In summary, information is the most valuable thing of an organization that needs to be safe and
secure under all conditions. Therefore, the organization should use services like data warehouse or
keep them safe and secure by backing up data to the cloud or other location. The organization should
create a backup plan for a natural disaster so that the company can return after a certain time. The
recommendation should be implemented whenever possible and security review should be done from
time to time in collaboration with the appointees. Various policies are used to keep data safe and
secure and to strengthen the security of the organization through the use of tools such as Firewall,
Encryption, Group Policy and Local Policy. These tools are more appropriate for improving
organizational policy and taking more action. When conducting a security audit, it is important to
ensure that the parties involved play their role effectively with the audit group in bilateral
communication, as the parties involved play an important role in the security review to express the
audit expectations of audit team.
References
Nadeau, T. D., 2020. MPLS Network Management. 2003 ed. s.l.:Morgan Kaufmann.









