2. (25 points)
Classify each of the following acts (not necessarily related to computing infrastructures) as a violation of confidentiality, integrity, authenticity, or availability, or some combination thereof:
Hint: Answers may not be unique. Explain your answers as well as possible!
a. A hacker obtains millions of Facebooks passwords.
Answer:
b. Bob accidentally cuts the electricity from the server room.
Answer:
c. The National Security Agency (NSA) that is in charge of cryptographic and communications intelligence and security, finds an efficient method to break Advanced Encryption Standard (AES).
Answer:
d. Hanna registers the domain name “JohnSmith.com” and refuses to let John Smith buy or use the domain name.
Answer:
e. Ransomware attacks victim’s hard drive by locking with a secret key, and a criminal asks for a ransom to decrypt it.
Answer:
f. The NSA wiretaps the cell phone of a suspect in a criminal investigation.
Take into consideration that, according to Executive Order 12333 (EO 12333), NSA is prohibited the collection, retention, or dissemination of information about U.S. persons except pursuant to procedures established by the head of the agency and approved by the Attorney General.
Answer:
g. A foreign state actor finds a zero-day vulnerability for voting machines used in the US.
A zero-day vulnerability is a vulnerability in a software that exists and maybe known to the vendor, or developer, or a hacker, but there is no “patch” for it yet.
Answer:
h. A result of Tom’s college admission test was sent to Tim.
Answer:
3. (15 points)
Read the following scenarios, provide the analysis of the situations and described what you would do. Justify your answers.
a. A friend sends an electronic greeting card (e-card) to your work email. You need to click on the attachment to see the card. What should you do? Justify.
Answer:
b. Your supervisor is very busy and asks you to log into the HR Server using her user-ID and password to retrieve some reports. What should you do? Justify.
A: It’s your boss, so it’s okay to do this.
B: Ignore the request and hope she forgets.
C: Decline the request and remind your supervisor that it is against your policy.
Answer:
c. You receive an email from your bank telling you there is a problem with your account. The email provides instructions and a link so you can log in to your account and fix the problem. What should you do? Justify.
Answer:
4. (5 points)
What is the difference between information security strategy and information security policy?
Answer:
5. (20 points)
a. (10 points)
Why having an information security strategy is important for an organization? Be sure to describe how having an information security strategy supports your ideas.
Answer:
b. (10 points)
List at least four (4) “high level” items with descriptions that should be part of a security strategy. A high level item is an item that would represent a major area or topic that you would include in a security strategy.
Answer:
6. (20 points)
a. (10 points)
a. Why having an information security policy is important for an organization? Be sure to describe how having an information security policy supports your ideas.
b. Answer:
b. (10 points)
a. List at least four (4) “high level” items with descriptions that should be part of a security policy. A high level item is an item that would represent a major area or topic that you would include in a security policy.
Answer:
7. (10 points)
The notes (week 2) enumerate several information system assets. While these assets are important to an organization they are not the most important assets to a company or organization. What do you consider to be the top two (2) assets to an organization? Note that the information assets enumerated in the notes are NOT the correct answers to this problem. This question is asking for the most important assets, which means they may extend beyond the notion of information assets. Explain your reasoning for the assets you have selected.
Answer:
Compelling correspondence is essential to the achievement all things considered but since of the changing idea of the present working environments, successful correspondence turns out to be more troublesome, and because of the numerous impediments that will permit beneficiaries to acknowledge the plan of the sender It is restricted. Misguided judgments.In spite of the fact that correspondence inside the association is rarely completely open, numerous straightforward arrangements can be executed to advance the effect of these hindrances.
Concerning specific contextual analysis, two significant correspondence standards, correspondence channel determination and commotion are self-evident. This course presents the standards of correspondence, the act of general correspondence, and different speculations to all the more likely comprehend the correspondence exchanges experienced in regular daily existence. The standards and practices that you learn in this course give the premise to additionally learning and correspondence.
This course starts with an outline of the correspondence cycle, the method of reasoning and hypothesis. In resulting modules of the course, we will look at explicit use of relational connections in close to home and expert life. These incorporate relational correspondence, bunch correspondence and dynamic, authoritative correspondence in the work environment or relational correspondence. Rule of Business Communication In request to make correspondence viable, it is important to follow a few rules and standards. Seven of them are fundamental and applicable, and these are clear, finished, brief, obliging, right, thought to be, concrete. These standards are frequently called 7C for business correspondence. The subtleties of these correspondence standards are examined underneath: Politeness Principle: When conveying, we should build up a cordial relationship with every individual who sends data to us.
To be inviting and polite is indistinguishable, and politeness requires an insightful and amicable activity against others. Axioms are notable that gracious “pay of graciousness is the main thing to win everything”. Correspondence staff ought to consistently remember this. The accompanying standards may assist with improving courtesy:Preliminary considering correspondence with family All glad families have the mystery of progress. This achievement originates from a strong establishment of closeness and closeness. Indeed, through private correspondence these cozy family connections become all the more intently. Correspondence is the foundation of different affiliations, building solid partners of obedient devotion, improving family way of life, and assisting with accomplishing satisfaction (Gosche, p. 1). In any case, so as to keep up an amicable relationship, a few families experienced tumultuous encounters. Correspondence in the family is an intricate and alluring marvel. Correspondence between families isn’t restricted to single messages between families or verbal correspondence.
It is a unique cycle that oversees force, closeness and limits, cohesiveness and flexibility of route frameworks, and makes pictures, topics, stories, ceremonies, rules, jobs, making implications, making a feeling of family life An intelligent cycle that makes a model. This model has passed ages. Notwithstanding the view as a family and family automatic framework, one of the greatest exploration establishments in between family correspondence centers around a family correspondence model. Family correspondence model (FCP) hypothesis clarifies why families impart in their own specific manner dependent on one another ‘s psychological direction. Early FCP research established in media research is keen on how families handle broad communications data. Family correspondence was perceived as an exceptional scholastic exploration field by the National Communications Association in 1989. Family correspondence researchers were at first impacted by family research, social brain science, and relational hypothesis, before long built up the hypothesis and began research in a family framework zeroed in on a significant job. Until 2001, the primary issue of the Family Communication Research Journal, Family Communication Magazine, was given. Family correspondence is more than the field of correspondence analysts in the family. Examination on family correspondence is normally done by individuals in brain science, humanism, and family research, to give some examples models. However, as the popular family correspondence researcher Leslie Baxter stated, it is the focal point of this intelligent semantic creation measure making the grant of family correspondence special. In the field of in-home correspondence, correspondence is normally not founded on autonomous messages from one sender to one beneficiary, yet dependent on the dynamic interdependency of data shared among families It is conceptualized. The focal point of this methodology is on the shared trait of semantic development inside family frameworks. As such, producing doesn’t happen in vacuum, however it happens in a wide scope of ages and social exchange.
Standards are rules end up being followed when performing work to agree to a given objective. Hierarchical achievement relies significantly upon compelling correspondence. So as to successfully impart, it is important to follow a few standards and rules. Coming up next are rules to guarantee powerful correspondence: clearness: lucidity of data is a significant guideline of correspondence. For beneficiaries to know the message plainly, the messages ought to be sorted out in a basic language. To guarantee that beneficiaries can without much of a stretch comprehend the importance of the message, the sender needs to impart unmistakably and unhesitatingly so the beneficiary can plainly and unquestionably comprehend the data.>