ASSIGNMENT 2 FRONT SHEET Qualification BTEC Level 5 HND Diploma in Computing Unit number and title Unit 5: Security Submission date Date Received 1st submission Re-submission Date Date Received 2nd submission Student Name Phan Nguyen Dinh Trong Student ID GCD201526 Class GCD0905 Assessor name Tran Trong Minh Student declaration I certify that the assignment submission is entirely my own work and I fully understand the consequences of plagiarism. I understand that making a false declaration is a form of malpractice. Student’s signature Trong Grading grid P5 P6 P7 P8 M3 M4 M5 D2 D3 1 ❒ Summative Feedback: ❒ Resubmission Feedback: Grade: Assessor Signature: Date: Lecturer Signature: 1 Table of Contents P5. Discuss risk assessment procedures.1 Negative school: risk is considered unlucky,loss, danger .2 The neutral school.
Risk Identification Procedures. Risk assetment procedures. Explain data protection processes and regulations as applicable to an organisation.1 Assessment of network security risks.2 Raise awareness about data security for employees.3 Data security management.4 Troubleshooting and problem management.5 Configure the system securely.6 Ensure the network is divided into separate areas.7 Secure DN data by monitoring network security.9 Increased malware protection.10 Update patches regularly. The important of data protection regulations.
Design and implement a security policy for an organisation.Example of policy.The most and should that must exist while creating policy.1 Ensure that there is a policy on policies.2 Identify any overlap with existing policies.3 Don't develop the policy in a vacuum.4 Step back and consider the need.5 Use the right words so there is no misunderstanding intent.6 When possible, include an exceptions process.7 Allow some shades of gray.8 Define policy maintenance responsibility.9 Keep senior executives out of the routine when possible.10 Establish a policy library with versioning.The element of security policy.2 Security Policy Document.8 Threat and Risk Assessment.18 Areas of Coverage.19 Physical Security Policies.20 Network Security Policies.21 Host Security Policies.22 User Security Policies.23 Document Security Policies.25 Incident Handling Policies. The steps to design a policy. Step in policy development.35 P8 List the main components of an organisational disaster recovery plan, justifying the reasons for inclusion. The components of recovery plan.
Steps to Building a Disaster Recovery Plan.1 Conduct an asset inventory.2 Perform a risk assessment.3 Define criticality of applications and data.4 Define recovery objectives.5 Determine the right tools and techniques.6 Get stakeholder buy-in.7 Document and communicate your plan.8 Test and practice your DR plan.9 Evaluate and update your plan. The policies and procedures that are required for business continuity.11 Figure 3 Type of Threats.12 Figure 4 Risk assessment steps.18 Figure 6 Control of access.19 Figure 7 conduct an asset inventory.37 Figure 8 Perform a risk assessment.38 Figure 9 Define criticality of applications and data.38 Figure 10 Test and practice your DR plan.41 Figure 11 life cycle. Discuss risk assessment procedures 1.1 Negative school: risk is considered unlucky,loss, danger. Risk is unhealthy, bad, and unexpected.
Risk (synonymous with risk) is unfortunate. Risk is the ability to be in danger or suffer from pain. Risks are unforeseen uncertainties that develop in a company's business and production processes and have a negative impact on the company's ability to exist and grow. Briefly put, risk is defined by conventional wisdom as "damage, loss, danger, or factors linked with danger, difficulty, or uncertainty that can happen to a person.2 The neutral school Risk is uncertainty that can be quantified and is potentially linked to the occurrence of unanticipated events.
The risk's current value and outcome are uncertain. Risk assetment The process or procedure where you: +Identify hazards and risk factors that have the potential to cause harm is known as risk assessment (hazard identification). 7 +Examine and assess the risk connected to that danger (risk analysis, and risk evaluation). Determine the best strategies to remove the risk or, if that is not possible, to control the risk (risk control).
- A risk assessment is a detailed examination of your workplace to find any elements, circumstances, procedures, etc. that could be harmful, especially to humans. Following identification, you assess the risk's likelihood and seriousness. You can then decide what steps need to be taken to successfully eliminate or control the harm once this assessment has been made.
The following phrases are used in the CSA Standard Z1002 "Occupational health and safety - Hazard identification and elimination and risk assessment and control": Risk assessment: The total procedure of risk analysis, risk assessment, and hazard identification. Risk assessment: The entire process of hazard identification, risk analysis, and risk assessment. Risk analysis: A process for comprehending the nature of hazards and determining the level of risk. Risk evaluation: The process of comparing an estimated risk against given risk criteria to determine the significance of the risk.
Risk control: The process of comparing an es琀椀mated risk against given risk criteria to determine the signi昀椀cance of the risk. Asset A resource having economic worth that a person, business, or nation possesses or controls with the hope that it would someday be useful is referred to as an asset. In order to raise a company's value or benefit its operations, assets are acquired and recorded on the balance sheet of the company. Whether it's manufacturing equipment or a patent, an asset can be viewed of as anything that, in the future, can generate cash flow, lower expenses, or increase sales.
An asset is a resource having economic worth that a person, organization, or nation owns or manages with the hope that it may someday be useful. Assets are disclosed on a company's balance sheet and are acquired or produced in order to raise a company's value or improve the operations of a company. An asset can be anything that, in the future, can increase sales, lower costs, or generate cash flow, whether it's a patent or manufacturing equipment. Understanding Assets: 8 An asset represents a financial resource for a business or access that other people or companies do not have.
A right or other access is legally enforceable, so it can be used however the corporation sees fit and its usage can be restricted or prohibited by the owner. A corporation must have a right to an asset as of the date of the financial statements in order for it to be present. A scarce resource with the capacity to increase financial inflows or decrease cash outflows is considered an economic resource. Short-term (or current) assets, fixed assets, financial investments, and intangible assets are some basic categories for assets.
Personal Assets: Personal assets are items with current or potential worth that belong to an individual or family. Personal assets frequently comprise the following: Cash and cash equivalents, CDs, checking and savings accounts, money market accounts, tangible cash, and Treasury notes are all examples of financial instruments. Real estate, including any building permanently affixed to it. Personal property includes boats, collectibles, furniture, jewelry, and automobiles.
Investments include equities, bonds, mutual funds, annuities, pensions, and life insurance policy cash values. By deducting your liabilities from your assets, you may determine your net worth. In essence, your liabilities are all of your debts, and your assets are everything you own. If you have a positive net worth, your assets are worth more than your liabilities; if you have a negative net worth, your liabilities are more than your assets (in other words, you are in debt) Business Assets: Assets are valuable items for businesses that support production and expansion.
Assets for a firm might include tangibles like machinery, real estate, raw materials, and inventory as well as intangibles like royalties, patents, and other forms of intellectual property. The balance sheet outlines the assets of a firm and details how those assets are financed, including whether debt or stock issuance is used. A company's balance sheet gives a quick overview of how effectively its management is managing its resources. The two categories of assets that typically appear on a balance sheet are.
Current Assets: 9 Assets that can be turned into cash within one fiscal year or one operating cycle are referred to as current assets. Expenses and investments related to daily operations are made possible by current assets. Examples of current assets include: Cash and cash equivalents: Cash, certificates of deposit, and Treasury bills. Marketable securities: debt-related securities or liquid equity.
Accounts receivables: Customer debt that needs to be settled soon. Inventory: Raw resources or marketed products. Fixed Assets: Non-current assets, or fixed assets, are those that a business utilizes to produce goods and services and have a longer useful life. Fixed assets are shown as property, plant, and equipment on the balance sheet (PP&E).
Fixed assets are long-term investments that are categorized as tangible (i., touchable) assets because they are. Examples of fixed assets include: Vehicles (such as company trucks) Office furniture Machinery Buildings Land Non-current assets (like fixed assets) cannot be easily converted to cash to cover immediate operational costs or investments, which is one of the two main contrasts between personal assets and corporate assets. In contrast, it is anticipated that present assets will be liquidated within one fiscal year or one operating cycle. Vulnerability A vulnerability is a gap or a weak point in the application—it could be an implementation error or a design flaw—that allows an attacker to harm the application's stakeholders.
The owner of the application, application users, and other organizations that rely on the application are stakeholders. Threat Define: A potential for violation of security, which exists when there is an entity, circumstance, capability, action, or event that could cause harm Cyber threats and vulnerabilities can occasionally be mistaken for one another. The word with the most definitions is "potential." The threat is not a security issue with an organization or implementation. As opposed to that, it is anything that could compromise security.
This is comparable to a vulnerability, which is a genuine weakness that can be used against the system. Without respect to any precautions, the threat constantly exists. However, there are ways to reduce the likelihood that it will come to pass. Types of threats According to the NIST definition above, a threat might be an occurrence or a state of affairs.
Natural disasters, fires, and power outages are all considered events in this context. It is a pretty broad idea. In the field of cybersecurity, dangers including viruses, Trojan horses, and denial-of-service attacks are more frequently discussed. Phishing emails provide a social engineering risk that may result in the loss of sensitive data such as passwords, credit card numbers, and other personal information.
Data loss in terms of confidentiality, integrity, or availability can result from threats to information assets. The CIA triumvirate is another name for this. The STRIDE threat model is built on the CIA triad and three additional well-known security ideas. It is convenient to start with an established classification when listing potential dangers.
The most well-known categorization is STRIDE, which was suggested by Microsoft in 1999. Because the name is derived from the first letters of the several categories, it is also simpler to recall them. Data protection Data protection is the process of defending sensitive information against loss, tampering, or corruption. As data is created and stored at previously unheard-of rates, the significance of data protection grows.
Additionally, there is limited tolerance for downtime that can prevent access to crucial information. As a result, a key component of a data protection plan is making sure that data can be swiftly restored after any loss or damage. Other essential elements of data protection include safeguarding data privacy and preventing data breach. Data protection You must specify precisely the data your company needs to secure before investing in data security.
Businesses frequently only partially or incorrectly understand what data has to be safeguarded.1 Assessment of network security risks Once your organization has all the data it needs, you must examine the threats that your corporate data may face: - In case of a network security problem. - In case of incidents of natural natural disasters such as fires, earthquakes, etc.