joi, 24 decembrie 2015

IT 380 Final Project

http://tidd.ly/ba60f346 Get through airport security without standing in line!
http://newstudentoffortune.com/products/it-380-final-project IT 380: Final Project Guidelines and Rubric Overview The final project for this course is the creation of a risk assessment and mitigation strategy for a fictional airport that includes four distinct organizations. Based on a provided scenario, you will develop a report for the management team that includes personnel recommendations for IT team members, a comprehensive assessment of IT security risks, and suggested strategies and approaches for minimizing the identified risks. The project includes two milestones, submitted in Modules Three and Five. The final project is submitted in Module Seven. Prompt The Scenario: You have been hired as a consultant to conduct a comprehensive risk assessment and provide a risk assessment and mitigation report for an airport. The airport has four different organizations: Airport authority Four flight service providers (four airlines) Airport restaurant Guests The airport authority maintains a system that handles the flight management controls. This system is made up of a database server, an application server, and a web server. The four flight service providers have only back-end access to their own dedicated server in the airport authority network and not to any other provider's back-end systems. Each flight service provider has a system made up of a database server, an application server, and a web server that allows patrons to reserve and purchase tickets. The restaurant provides food for both airport employees as well as travelers. The restaurant's systems are used to maintain customer transactions, human resource functions (payroll and benefits information), and vendor ordering. Guest users have wireless access to a high-speed internet connection, which is also shared among all the users in all organizations. The wireless access uses a common password. Guest users should not have access to the other organizations within the airport. The users obtain IP addresses automatically. The airport authority has 27 users, and the flight service providers have 85 users. The maximum number of guests is estimated to be 100. Software updates that address security vulnerabilities are assessed by the airport security team. The team verifies whether the vulnerability is applicable to their environment. If it is, they analyze the circumstances under which vulnerabilities could be exploited and the possible business impact on organizational assets and business continuity. After the evaluations are complete, the security team works with the configuration management administrator to manage software updates. The administrator reviews the security team's list of critical security updates and runs a report to see how many computers on the network are potentially vulnerable to the exploit addressed in the security update. The organization has a content-filtering firewall in place; however, there are currently no filtering rules. There has been some discussion in the past to mitigate this, but the organization is looking for recommendations on how this should be configured. Critical Elements: Your 8- to 10-page risk assessment and mitigation strategy must include the following critical elements: 1. Team Information a. Identification of all stakeholders. b. Job Description. Create a job description for the chief security officer the airport plans to hire. Include desired qualifications and experiences, as well as responsibilities and daily tasks. c. Security Certification Recommendations. Recommend certifications for the current IT staff. Provide a brief rational for your recommendations.

Niciun comentariu:

Trimiteți un comentariu