SEC301 Introduction to Cyber Security

  • Subject Code :  

    SEC301

  • Country :  

    US

  • University :  

    University of San Francisco

Answer:

Introduction

This paper in focused on providing intensive discussion on qualitative risks assessment and quantitative risk assessment concerning the Ruskin Hospital system.

The system designed to withstand and recover from security attack is suitable to be developed  for the hospital, Ruskin Hospital Content System is not just a system, it’s a sosphicated hybrid topology system whose different departments are interconnected. With initial set up of 21 desktop computers, 7 switches, 6 servers, 3 routers, connected to cloud technology, 1 laptop and 7 printer machines we can not turn the blind eye to security threats from unstructured, structured and internal this kind of system will be exposed to.  Those risks are numerous which can only be assessed quantitatively and qualitatively.

Qualitative Risk Assessment

Ruskin Hospital System is mostly exposed to three kind of security threats; unstructured security threats, structured security threats and internal security threats.  Unstructured security threat comes from script kiddies who might be Information Technology who are always available in the facility, furthermore it could doctor and other who accidently can cause unfocused assault on network systems.  The interruption of network will cause malfunction of the other since our network is independent on other sub networks.

Additionally, structured security threats are present.  With facility having employed experts from different sort of backgrounds its difficulty to tell the motive of some. For this reason, I cannot assume the possibility of structured attack (Cherdantseva et al, 2016).  From the intelligence gathered the facility is best among region therefore some employees can be comprised to sabotage its operation.  Furthermore, this kind of system offers a powerful platform for some Information Communication to showcase their technical skills such curiosity mostly costs the company a lot of resources to recover in case malfunction.

On basis of internal security threat issues.  This is most dangerous attack on this system with high chance of occurring since the staff have all the details that required to comprise the system.

The security system threats are numerous that can not be discussed in this paper only but  the ones that are frequently reported by most company are discussed in this paper with following mitigation measures.

Mitigation Plan

With unstructured security threats I recommend the company to ensure the system is only accessed with Information Technology experts. Furthermore, individuals under training can only be supervised to when accessing the system.            The structured security threat must be prevented by issuing each IT expert with own computers, furthermore different employees should have varied privileges. Through these vulnerable employees cannot be access the system sensitive resources to cause harm.       With internal security threats we have put major emphases in our inclusive quantitively risk assessment.

Quantitative Risk Assessment

Ruskin Hospital System is used in different departments. This kind of system faces biggest threat nearly 90% from within. Employees who are greedy, disgruntled, unhappy with changes and opportunist pose a bigger challenge. With 21 desktop computers, 7 switches, 6 servers, 3 routers, connected to cloud technology, 1 laptop and 7 printer machines there many weak links to infiltrate the system (Teixeira et 2016). Breakdown of the system will a half cost of building to repair. These uncertain requires a standby contingency to protect the system.

Mitigation Plan

The system will be under 24-hour observation. The information gathered during this time will form the basis of updating the system every two weeks. Each of 21 staff will have password with specific station.

Symmetric Cryptography

This technology is most secure of all security protection mechanism in the market. Ruskin can implement this type cryptography in its database and files since the exchange of data between and the patient guarantee privacy. Through use same key data can be encrypted from sender then using the same key again the same data is decrypted.  The plain text is converted into unreadable ciphertext in transmission, when the cipher text arrives to the recipient the same reconverts the information into readable text Its much simple for the Ruskin Hospital to employ this key since their no use multiple key to decrypt date.

Asymmetric Cryptography

Ruskin Hospital system cyber security will apply asymmetric cryptography security technology. Patients pass very sensitive that must be guarded with measures possible, imagine covid-19 patients details accidentally leaking to the public, the stigma the innocent will go through can cause further socio-health issues. The patients will have public security key.   They will use this key to submit their details to enrollment.  The registration officer will have private key. Through this the information in transition cannot be seen by any other person except the sender and recipient.

The asymmetric cryptography works uniquely, it encrypts data then decrypts the same data using two separates keys yet mathematically connected cryptographic key that is public key and private key. 

Risks involved in Cryptography

In the world of technology their loopholes no matter how the system or technology applied might.  Malioucus hackers motivated by selfish ambition such as extortion might come up with mechanisms to infiltrate into the system and carry out their motives. Although cryptography stands to be best to integrated with Ruskin it may pose the following risks.

Imagine keys being lost, corrupted deleted or even thrown away, the impact of such risk occurring is big since the cryptography lacks the undelete or recovery programs. Another risk is when the keys land in hand of attackers.  They will use to cause an imaginable damage to the system. It is important to be conscious when using the system because mistakes can lead to unremovable damage.

Attacks associated with the Cryptography

With Ruskin System when Cryptography is exposed to above discussed risks, authentication attacks may occur.  Attackers who got the keys usually infiltrate in the system and carry their attacks on the system such stealing information, causing system malfunction.

PKI and Digital Certification Security Mechanism

Public Key Infrastructure (PKI) is special key is baked into every website. This provides security to online based system by securing traffic. Many organizations use this mechanism even in their internal communication and access to connected devices.

Furthermore, another important mechanism the Ruskin System security is assured is through use of digital Certificates. This activity protects the system by verifying the identity of sender and receiver electronic message.  Additionally, digital Certificates provides the means to encrypting or decrypting the information between the sender and receiver.

Achieving CIA and AAA framework

This paper focuses on cybersecurity of Ruskin Hospital System.  A complete system must meet CIA model and AAA model framework as fa security is concern. CIA (Confidentiality, Integrity, and Availability) model is achieved since the Ruskin system through cryptography guarantees confidentiality, both symmetric and asymmetric cryptography only allows exchange of information between parties with common keys, furthermore the issue of integrity is accomplished because only the Hospital Registration Officer will be able personal information.  Finally, availability is observed, with our components the system is guaranteed to deliver to the expectation, (Fekolkin,  2014).

AAA (Authentication, Authorization, Accounting) Model is implemented in Ruskin Hospital system.  With cryptography Authentication occurs where before the sender and receiver can exchange information, they must common keys. Authorization is achieved since only the receiver with common key from sender can be able to decrypt information. Finally, Accounting is achieved since Ruskin system will keeps all transaction logs.

References

Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., & Staddart, K. (2016). A review of Cyber Security risk assessment methods for SCAPA systems. Computers & security,

Teixeira, A., Sou, K. C., Sandberg, N., & Johansson, K. H. (2015). “Secure control systems: A quantitative risk management approach. IEE control systems magazine.

Looking for academic assignment samples online? Need professional paper writers to back you up with advanced resources and other addons? Here we are! MyAssignmenthelp.co.uk takes up the responsibility to provide you with the following backups every time, on the move. 

  • Free samples 
  • Signup bonus 
  • Seasonal discounts 
  • Free access to blogs & more 

So, now that you are aware of our potential and the numerous perks that we have got in store for you, take a smart call. Our assignment help services in the UK shall make sure to help you secure a straight A+ every semester.

Why Student Prefer Us ?
Top quality papers

We do not compromise when it comes to maintaining high quality that our customers expect from us. Our quality assurance team keeps an eye on this matter.

100% affordable

We are the only company which offers qualitative and custom assignment writing services at low prices. Our charges will not burn your pocket.

Timely delivery

We never delay to deliver the assignments. We are very particular about this. We assure that you will receive your paper on the promised date.

Round the clock support

We assure 24/7 live support. Our customer care executives remain always online. You can call us anytime. We will resolve your issues as early as possible.

Privacy guaranteed

We assure 100% confidentiality of all your personal details. We will not share your information. You can visit our privacy policy page for more details.

Upload your Assignment and improve Your Grade

Boost Grades