CSG3309 IT Security Management

  • Subject Code :  

    CSG3309

  • Country :  

    AU

  • University :  

    Edith Cowan University

Answer:

Introduction

The IT security management includes the processes for enabling the technology and the organizational structure for protecting the assets and the IT operations of the organization against the external and the internal threats, which can be unintentional or intentional (Soomro, Shah & Ahmed, 2016). The chosen organization for this study is JOHN DOUGH pizza, which has faced several issues related to IT and this study is conducted for selecting one of the complex security issues among the previously identified issues and to analyse the issue. The identified issue for the company JOHN DOUGH Pizza is the Ransomware attack.

This is very significant for the organization to identify the issue as this is very critical part of how the company manage the security issue of the company. Being able to identify the security issues in the organization will be very significant to prevent any further attack and money loss. Therefore, identifying the issue for JOHN DOUGH Pizza will be very vital to assess the risk and to implement the mitigation strategies before it causes huge loss. After the analysis of the security issue, this whitepaper will also present the state-of-the-art of the organization in order to mitigate the identified risk effectively. This paper also presents the analysis on the chosen security issue against the organization JOHN DOUGH Pizza as well as provides the set of recommendations, which need to be implemented as the improvements of future security.

JOHN DOUGH Pizza is the Perth based organization, which is struggling with the IT security. Their business has already faced several security incidents and the company is engaged the IT security consultancy, who provided the risk assessment for the company. However, the new appointed CISO has reviewed the assessment of the identified risks in the organization and decided that one of the vital security issues should be addressed as per the state-of-the-art of the organization. Therefore, the CISO aims to develop the whitepaper for exploring the risk as well as providing the proper risk mitigation strategies. This whitepaper and the recommendation including the mitigation strategies can be used by the organization for creating the internal process based on the analysis and the recommendations.

Problem Definition

One of the significant risks that the organization JOHN DOUGH Pizza had faced is the Ransomware attack. This is one of the complex and vital risks among all the of the risks that the organization faced. Ransomware attack in the company is one of the vital problems that the technology will aim to solve as well as protect the organization from potential attacks. The company stores several sensitive and confidential information regarding the business and the customer such as information of the customers and the information of the customer’s finance. However, those information were not properly secured and encrypted. Therefore, this makes that information very easy and makes the database easily accessible to steal. Once a hacker accessed to the company’s database, where all the information were stored and it was very easy for them to read and steal the data. With this, the database and the network of the company were not secure properly against the malware-based attacks and the illegal access.

This was very challenging for the company to restrict the illegal access to the network and the server. Again, a hacker got the access to their system of one employee through the exploitation of the network or stealing the password, the hacker encrypted the information and they then demanded ransom money. In this attack, the hacker encrypted all the significant files and information stored in the database of the company and then the information became inaccessible by the users of the organization. The for retrieving the information, the hacker was demanding huge amount of money.

This ransomware attack in the organization JOH DOUGH Pizza had faced several consequences as they never had proper backup of the data neither they had proper information security, which caused them data loss, which consists the sensitive and the confidential information of the customer including account credentials, bank details, card details, address etc. and the business process. Therefore, this is one of the significant IT security concerns for the company.

The ransomware is the type of the malware, which will prevent the organization from accessing the data until the company pays the attacker the ransom money for getting the information back. This can also be possible that the system in the organization can be infected with the other forms of the malware after the successful attacks (Kok et al., 2019). In this attack, the devices get infected when the victim user clicks any link, or visit any web pages or installs any program or application, which include the malicious code that is designed for downloading as well as installing the ransomware. It can occur in several ways such as:

Ways of attack

Description

Email attachments

Opening any email attachments and then enabling the malicious macros and downloading any documents embedded with the RAT (Remote Access Trojan) or downloading any zip file can contain malicious files.

Phishing email

When any user will click on any link that is embedded in the main can redirect to the malicious webpage and that webpage can look like original web page and user will not be able to understand (Wang, Li & Rao, 2016).

Social media

When a user will click to any legitimate advertising site on the social media that site can be seeded with the malicious code.

TDS (Traffic Distribution Systems)

When the users click of the link on the legitimate gateway web page that will redirect that user to the malicious site and the hacker will then track their geo location and other details such as operating system, browser and other details (Kosenko et al., 2017).

Drive by infections

This type of malware attacks can be occurred by visiting any fake, suspicious or unsafe web site or opening any pop-up notification. Any legitimate website will be compromised if the malicious JavaScript codes are injected into the content of that web page.

Malvertising

Such malware attack can occur when any user clicks to any legitimate advertising web site, which is seeded with the malicious content (Dwyer & Kanguri, 2017).

Self-propagation

This can occur by spreading the malicious content or the code to the devices of the organization through the USB drives or the network.

Infected programs

This type of malware attack can occur by installing any program or application, which contains the malicious codes or contents.

After any device is exposed to any malicious code, the attack follows seven stages as shown in the below image.

Solution of the Risk

The organization JOHN DOUGH Pizza can use the Big Data technology for resolving the issue. Big Data can be used by the organization for recognizing, preventing as well as protecting their business data and other vital assets of the company from the ransomware attack. This technology will help JOHN DOUGH for gaining the more in-depth understandings and knowledge of the landscape of the current threat and will also help in determining the effective security strategies as well as the solution for preventing the data breach and protecting the sensitive and confidential information. The big data technology will also help them to understand the need of preparing as well as protecting against the threats by facilitating them to get to know about the financial impact of the ransomware attack. Big data technology can help them to foresee the intensity and class of the ransomware threats. This technology will also allow JOHN DOUGH Pizza to use the historical and current data for getting statistical understandings of the acceptable and non-acceptable security trends.

Several ways are also there to mitigate ransomware attack among which some of the measures, which the company should take instantly for reducing the impact of the ransomware attack such as:

Isolate the infected system: The most and the first significant thing that the organization needs to do is to isolate the infected system from the other system and the network. The organization must disconnect from network immediately as well as they must consider powering off the machine (Humayun et al., 2020). The last thing that the organization can do for preventing the spreading of the attacks to the other devices is to take other steps to reduce the further damage without creating any chaos with the malware.

Get the cyber security insurance: No matter how strong and good the cybersecurity program of the organization is, JOHN DOUGH Pizza still can be compromised or hacked. Therefore, purchasing the high quality of the cyber insurance plan, which will include the overage for the ransomware and other attacks will save the organization and their huge amount of money (Trang, 2017). The quality of the cyber insurance may vary significantly, therefore, the organization should consult a specialist and get quotes before purchasing any plan and they need to ensure that they must read the fine print of the coverage of the insurance.

Contact the incident response experts: The ransomware attacks are increasing every year. If the organization becomes the victim of the attack and even the organization isolates the infected system from other devices and network then still there will be risk. Therefore, the organization must contact the cyber security experts, who can help them in removing the malicious content from the IT infrastructure as well as they must ensure that the IT system are strongly protected and safe to use (Kumar & Ramlie, 2021). The company also follow the instruction given by the incident response professionals for reducing the effect of the attacks and to prevent future attacks.

Incorporate the lesson learned: After any security incident or cyber attacks, which have been resolved in the organization, the company JOHN DOUGH Pizza must incorporate the lesson learned for ensuring that the company can respond to the security issues more effectively. The company must conduct a meeting and sit down with the internal team members and the third party organization, who will help in responding to the security incident. They must work together for developing the plan of the actions for preventing the potential malware attacks. When any future security issue occurs, then the organization will be able to be prepared for dealing with the security incident effectively.

Business Benefits

Investing in the cybers security or the technology for giving security is one of the vital factors for the businesses. The damaging impacts of the ransomware can be alarming for the organization and the organization may face huge loss again by paying ransom to the attacker to by losing valuable data (Hallman et al., 2021). This is difficult sometimes for quantifying the returns of the cyber security in JOHN DOUGH Pizza, however, the organization must take the preventive measures and they must calculate the return of investment of the investment on cyber security. The ROI should be calculated based on the returns on the cost. This will also help the organization to get the positive results like revenue enhancement or cost saving in cyber security.

However, the company should response to the risks ideally, which must be designed for protecting the availability, integrity and confidentiality of the data, services, system and network while ensuring the usability of the measures. The usability of the digital services can take the precedence over cyber security of the devices and the contents. However, the usability and security will not be necessarily exclusive mutually. The measures taken by the organization must include those, which aims to establish the identity of the users for preventing the unauthorized access to the data, services and systems.

Recommendations

Proper strategies and preparation regarding the IT security will efficiently reduce the impact and the cost of any ransomware attack. Following some best practices in the organization will help JOHN DOUGH Pizza in reducing the exposure of the organization to the ransomware attack as well as reducing the impacts. Followings are some of the best practices, which JOHN DOUGH Pizza can follow to make their protection and security stronger:

  • Continuous data backups: Ransome always refers that this is the malware design for making this so that paying the ransom pay will be the only way for restoring the encrypted data that is hacked by the hackers. Therefore, protected and automated data backups will enable the organization for recovering from the attack with the minimum loss of data without paying any ransom money (Thomas & Galligher, 2018). Maintaining the regular backups of the data as the routine process will be very significant practice for preventing the data loss and for being able in receiving this in the incident of disk hardware malfunction or corruption. The functional backups will help JOHN DOUGH Pizza to recover from the ransomware attacks.
  • Cyber awareness education and training: Ransomware is spread mostly using the phishing emails. Therefore, training the users in the organization on how to identify as well as avoid any potential ransomware attack is very vital. As most of the cyber-attacks nowadays start with the targeted emails, which does not contain the malware, however, the socially engineered email encourages the victim for clicking on the malicious links (Thomas, 2018). Therefore, the user’s education on the security will be considered as the most significant defence that a company can deploy.
  • User authentication: Accessing the services such as RDP with the stolen credentials of the users will be the most preferable technique or method for the ransomware attackers. The use of the strong and secured user authentication will make this harder for the attackers for making the use of the stolen or guessed passwords (Ami, Elovici & Hendler, 2018).
  • Conduct of regular penetration testing: Pen test will involve having the outside party trying to breach the network for checking for any vulnerabilities. By engaging the third party for conducting the regular pen test, the organization will be able to identify the weaknesses before the malicious attackers do so (Nicholson, 2019). Regular penetration testing will also provide the valuable and significant lesson on where the cyber security of the organization will need to improve.
  • Utilize the endpoint security: The antivirus software will not only be perfect for preventing the malicious software. If the organization does not have any antivirus software, then the organization must consider switching to the advance endpoint security strongly (Kharraz & Kirda, 2017). The advance security of the endpoint will use the Artificial Intelligence and Machine Learning technology for identifying the attacks, where the conventional antivirus software will be mixed. The organization must invest in the next generation endpoint security.

Conclusion

This can be concluded from this study that the IT security management tries to ensure thee availability, integrity and confidentiality off the computing system and the components. The principles parts of the information system are subject to attack the data, software and hardware. These principles and communication among the three principles are vulnerable to the computer security and computer system. The systems and the people, which are interested in compromising the system can attack the system, which exploit the vulnerabilities. The IT security management can help the organization to defend the components of the information system, which includes the networks, hardware, software, application and data.

The security team of JOHN DOUGH Pizza will be responsible to have the defence strategy as well as making the decisions in the timely manner by considering the defence and the security. The successful mitigation strategy must include the detection, deterrence, containment of the risks and prevention of the issues including compliance, awareness, recovery and correction. The security attack on the target company can occurred due the inability of the management for acting as per the alerts of the potential breach. The company JOHN DOUGH Pizza must be prepared for preventing as well as detecting however, there can be chances of failure in containing the risk as well as recover to fix the issue. As the company JOHN DOUGH Pizza has faced ransomware including other several issues, the company must ensure that they are following the security strategies and policies properly in order to prevent such risk in future.

References

Ami, O., Elovici, Y., & Hendler, D. (2018, April). Ransomware prevention using application authentication-based file access control. In Proceedings of the 33rd Annual ACM Symposium on Applied Computing (pp. 1610-1619).

Dwyer, C., & Kanguri, A. (2017). Malvertising-a rising threat to the online ecosystem. Journal of Information Systems Applied Research, 10(3), 29.

Hallman, R. A., Major, M., Romero-Mariona, J., Phipps, R., Romero, E., Slayback, S. M., ... & San Miguel, J. M. (2021). Determining a Return on Investment for Cybersecurity Technologies in Networked Critical Infrastructures. International Journal of Organizational and Collective Intelligence (IJOCI), 11(2), 91-112.

Humayun, M., Jhanjhi, N. Z., Alsayat, A., & Ponnusamy, V. (2020). Internet of things and ransomware: evolution, mitigation and prevention. Egyptian Informatics Journal.

Kharraz, A., & Kirda, E. (2017, September). Redemption: Real-time protection against ransomware at end-hosts. In International Symposium on Research in Attacks, Intrusions, and Defenses (pp. 98-119). Springer, Cham.

Kok, S., Abdullah, A., Jhanjhi, N., & Supramaniam, M. (2019). Ransomware, threat and detection techniques: A review. Int. J. Computer Science and Network Security, 19(2), 136.

Kosenko, V., Persiyanova, E., Belotskyy, O., & Malyeyeva, O. (2017). Methods of managing traffic distribution in information and communication networks of critical infrastructure systems. Innovative technologies and scientific solutions for industries, (2 (2)), 48-55.

Kumar, P. R., & Ramlie, R. E. B. H. (2021, January). Anatomy of Ransomware: Attack Stages, Patterns and Handling Techniques. In International Conference on Computational Intelligence in Information System (pp. 205-214). Springer, Cham.

Nicholson, S. (2019). How ethical hacking can protect organisations from a greater threat. Computer Fraud & Security, 2019(5), 15-19.

Soomro, Z.A., Shah, M.H. & Ahmed, J. (2016). Information security management needs more holistic approach: A literature review. International Journal of Information Management, 36(2), pp.215-225.

Thomas, J. (2018). Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks. Thomas, JE (2018). Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks. International Journal of Business Management, 12(3), 1-23.

Thomas, J., & Galligher, G. (2018). Improving backup system evaluations in information security risk assessments to combat ransomware. Computer and Information Science, 11(1).

Trang, M. N. (2017). Compulsory corporate cyber-liability insurance: Outsourcing data privacy regulation to prevent and mitigate data breaches. Minn. JL Sci. & Tech., 18, 389.

Wang, J., Li, Y., & Rao, H. R. (2016). Overconfidence in phishing email detection. Journal of the Association for Information Systems, 17(11), 1.

Are you stuck with an overly convoluted assignment based on a particular subject matter? Are you looking for a dedicated team of subject matter experts to help you through the hurdle? Take a look here. MyAssignmenthelp.co.uk is right here to back you up with the following services and beyond. 

So, get in touch with us right away, place your order and have the best SME by your side to provide you with impeccable assignment help online. 

Why Student Prefer Us ?
Top quality papers

We do not compromise when it comes to maintaining high quality that our customers expect from us. Our quality assurance team keeps an eye on this matter.

100% affordable

We are the only company which offers qualitative and custom assignment writing services at low prices. Our charges will not burn your pocket.

Timely delivery

We never delay to deliver the assignments. We are very particular about this. We assure that you will receive your paper on the promised date.

Round the clock support

We assure 24/7 live support. Our customer care executives remain always online. You can call us anytime. We will resolve your issues as early as possible.

Privacy guaranteed

We assure 100% confidentiality of all your personal details. We will not share your information. You can visit our privacy policy page for more details.

Upload your Assignment and improve Your Grade

Boost Grades