Bonanza Offer FLAT 20% off & $20 sign up bonus Order Now
ICTNWK502
AU
TAFE Queensland
Read the following scenario as background to the assessment tasks:
You are employed as a network administrator in the IT department of WSC educational institution. WSC delivers a variety of qualifications. It is a new business and is rapidly expanding. They currently have 30 staff, including management, academic staff, admin, support, IT department and trainers. Staff use desktops, laptops and printers to accomplish daily tasks.
WSC has asked you to implement secure encryption technologies. This will involve completing the following tasks:
Review the WSC Information Technology Security Policy, Procedures and Plan, and the WSC Authentication Policy in Appendix 1 for further relevant information.
You should also review the complete WSC IT policies and procedures document, the WSC ICT Inventory and WSC strategic plan (available in the student shared folder on the H drive) for further information and details about WSC and its network.
Based on the above and additional information that may be provided by your assessor complete the following tasks:
After thorough assessment of the information technology structure and the policies, the following are the security requirements:
1. Intranet (LAN) connection authentication using WPA2 for wireless networks.
2. Assigning every device a specific IP address to bar unassigned devices from connecting to the network.
3. Encryption for the data during transmission.
4. Encrypting stored data.
5. Securing the institutions website using secure socket layer.
6. Securing unused ports on connection hubs.
7. Securing the server room.
After a review of the security policies and procedures the following are the appropriate encryption methods that can be effectively applied:
1. Triple Data Encryption Standard (DES)
2. Rivest-Shamir-Adleman (RSA)
3. Advanced Encryption Standard (AES)
4. Two Fish
5. Blow Fish
Below is the review of encryption technologies and ranked according to how secure they are.
1. Advanced Encryption Standard (AES)
This is a symmetric encryption method where only the sender and receiver of the message know the secret key. Using the secret key the AES algorithm substitutes, transpose and mixes the bytes that make up the plain text in an iterative process, the number of iterations depend on the size of encryption key.
2. Rivest-Shamir-Adleman (RSA)
This is an asymmetric encryption method whereby there is a public key that is known by both users for the purpose of data encryption. Once the data has been encrypted using the public key and sent the receiver has a private key to which they use to decrypt the data. RSA leverages the fact that it is difficult to factorize large prime numbers to keep the encrypted data safe. The large prime number are the decryption key.
The above mentioned encryption methods, AES, RSA, Triple DES, Two Fish and Blow Fish, are all open source and therefore free for public use. The only cost incurred would be in the processing power and other resources of the computer like the RAM. Particularly the RSA method is computing power intensive when the encryption key and the plain text file is large. The AES is also computing power intensive as the encryption process is iterative, the larger the encryption key the more times it iterates.
Encryption method Cost
1. AES nil
2. RSA nil
3. Triple DES nil
4. Two fish nil
5. Blow fish nil
The following are open source encryption software based on the above technologies that can be used to secure the institution’s data;
Box cryptor (RSA)
Bit Locker (AES)
CryptoExpert (Blow fish)
Certain Safe (Triple DES)
The following are implemented to secure the information technology systems of the institution:
1. Data encryption software, Box cryptor that utilized RSA technology to encrypt data that needs to be sent.
2. Data encryption software, Bit Locker, that utilizes AES technology to encrypt the data locally stored in the laptops and desktops.
3. WPA authentication before connecting wirelessly.
4. Specific IP address assigned to each device in the network.
The effect on the responsibilities and roles to the staff with the introduction of the encryption technology include:
1. Ensuring the transmitted data is always encrypted.
2. Ensuring data stored locally is always encrypted.
The following are the results from the analysis of the new user responses.
1. The user is concerned about the added responsibilities.
2. The new user request for a seminar where they can learn the new technologies.
All the newly implemented technologies are observed to perform as expected in the task of encrypting both the locally stored data and that that is being transmitted. The encryption software have a user friendly interface and thus prone to few user induced errors.
A few users of the encryption system have experienced difficulties which have been recorded at the help desk.
1. A few users have had difficulty in using the browser add on for RSA encryption.
2. There has been difficulty in encrypting data using the public key and decrypting it using the private key, the users find it confusing.
The issues found after the review of the logs are:
1. Some users are still reluctant to use encryption technology on data that is locally stored.
2. The logs reveal that some data is being transmitted without first being encrypted.
3. The network of the institution is not properly secured from external attack.
Our team consists of PhD stalwarts who leave no stones unturned to deliver you perfect assignment writing services. The ghostwriters follow your university guidelines to ensure you get top-notch quality work irrespective of the topic. Our team has gone through rigorous training to meet your expectations with the utmost precision. We are familiar with all types of academic documents such as essays, academic posters, book reports, dissertations, homework, coursework and more. Whether you opt for our online exam help or assignment help, we provide individualised attention to your concern in each case.
Upload your Assignment and improve Your Grade
Boost Grades