Bonanza Offer FLAT 20% off & $20 sign up bonus Order Now
SEC301
US
University of San Francisco
This paper in focused on providing intensive discussion on qualitative risks assessment and quantitative risk assessment concerning the Ruskin Hospital system.
The system designed to withstand and recover from security attack is suitable to be developed for the hospital, Ruskin Hospital Content System is not just a system, it’s a sosphicated hybrid topology system whose different departments are interconnected. With initial set up of 21 desktop computers, 7 switches, 6 servers, 3 routers, connected to cloud technology, 1 laptop and 7 printer machines we can not turn the blind eye to security threats from unstructured, structured and internal this kind of system will be exposed to. Those risks are numerous which can only be assessed quantitatively and qualitatively.
Ruskin Hospital System is mostly exposed to three kind of security threats; unstructured security threats, structured security threats and internal security threats. Unstructured security threat comes from script kiddies who might be Information Technology who are always available in the facility, furthermore it could doctor and other who accidently can cause unfocused assault on network systems. The interruption of network will cause malfunction of the other since our network is independent on other sub networks.
Additionally, structured security threats are present. With facility having employed experts from different sort of backgrounds its difficulty to tell the motive of some. For this reason, I cannot assume the possibility of structured attack (Cherdantseva et al, 2016). From the intelligence gathered the facility is best among region therefore some employees can be comprised to sabotage its operation. Furthermore, this kind of system offers a powerful platform for some Information Communication to showcase their technical skills such curiosity mostly costs the company a lot of resources to recover in case malfunction.
On basis of internal security threat issues. This is most dangerous attack on this system with high chance of occurring since the staff have all the details that required to comprise the system.
The security system threats are numerous that can not be discussed in this paper only but the ones that are frequently reported by most company are discussed in this paper with following mitigation measures.
With unstructured security threats I recommend the company to ensure the system is only accessed with Information Technology experts. Furthermore, individuals under training can only be supervised to when accessing the system. The structured security threat must be prevented by issuing each IT expert with own computers, furthermore different employees should have varied privileges. Through these vulnerable employees cannot be access the system sensitive resources to cause harm. With internal security threats we have put major emphases in our inclusive quantitively risk assessment.
Ruskin Hospital System is used in different departments. This kind of system faces biggest threat nearly 90% from within. Employees who are greedy, disgruntled, unhappy with changes and opportunist pose a bigger challenge. With 21 desktop computers, 7 switches, 6 servers, 3 routers, connected to cloud technology, 1 laptop and 7 printer machines there many weak links to infiltrate the system (Teixeira et 2016). Breakdown of the system will a half cost of building to repair. These uncertain requires a standby contingency to protect the system.
The system will be under 24-hour observation. The information gathered during this time will form the basis of updating the system every two weeks. Each of 21 staff will have password with specific station.
This technology is most secure of all security protection mechanism in the market. Ruskin can implement this type cryptography in its database and files since the exchange of data between and the patient guarantee privacy. Through use same key data can be encrypted from sender then using the same key again the same data is decrypted. The plain text is converted into unreadable ciphertext in transmission, when the cipher text arrives to the recipient the same reconverts the information into readable text Its much simple for the Ruskin Hospital to employ this key since their no use multiple key to decrypt date.
Ruskin Hospital system cyber security will apply asymmetric cryptography security technology. Patients pass very sensitive that must be guarded with measures possible, imagine covid-19 patients details accidentally leaking to the public, the stigma the innocent will go through can cause further socio-health issues. The patients will have public security key. They will use this key to submit their details to enrollment. The registration officer will have private key. Through this the information in transition cannot be seen by any other person except the sender and recipient.
The asymmetric cryptography works uniquely, it encrypts data then decrypts the same data using two separates keys yet mathematically connected cryptographic key that is public key and private key.
In the world of technology their loopholes no matter how the system or technology applied might. Malioucus hackers motivated by selfish ambition such as extortion might come up with mechanisms to infiltrate into the system and carry out their motives. Although cryptography stands to be best to integrated with Ruskin it may pose the following risks.
Imagine keys being lost, corrupted deleted or even thrown away, the impact of such risk occurring is big since the cryptography lacks the undelete or recovery programs. Another risk is when the keys land in hand of attackers. They will use to cause an imaginable damage to the system. It is important to be conscious when using the system because mistakes can lead to unremovable damage.
With Ruskin System when Cryptography is exposed to above discussed risks, authentication attacks may occur. Attackers who got the keys usually infiltrate in the system and carry their attacks on the system such stealing information, causing system malfunction.
Public Key Infrastructure (PKI) is special key is baked into every website. This provides security to online based system by securing traffic. Many organizations use this mechanism even in their internal communication and access to connected devices.
Furthermore, another important mechanism the Ruskin System security is assured is through use of digital Certificates. This activity protects the system by verifying the identity of sender and receiver electronic message. Additionally, digital Certificates provides the means to encrypting or decrypting the information between the sender and receiver.
Achieving CIA and AAA framework
This paper focuses on cybersecurity of Ruskin Hospital System. A complete system must meet CIA model and AAA model framework as fa security is concern. CIA (Confidentiality, Integrity, and Availability) model is achieved since the Ruskin system through cryptography guarantees confidentiality, both symmetric and asymmetric cryptography only allows exchange of information between parties with common keys, furthermore the issue of integrity is accomplished because only the Hospital Registration Officer will be able personal information. Finally, availability is observed, with our components the system is guaranteed to deliver to the expectation, (Fekolkin, 2014).
AAA (Authentication, Authorization, Accounting) Model is implemented in Ruskin Hospital system. With cryptography Authentication occurs where before the sender and receiver can exchange information, they must common keys. Authorization is achieved since only the receiver with common key from sender can be able to decrypt information. Finally, Accounting is achieved since Ruskin system will keeps all transaction logs.
Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., & Staddart, K. (2016). A review of Cyber Security risk assessment methods for SCAPA systems. Computers & security,
Teixeira, A., Sou, K. C., Sandberg, N., & Johansson, K. H. (2015). “Secure control systems: A quantitative risk management approach. IEE control systems magazine.
Looking for academic assignment samples online? Need professional paper writers to back you up with advanced resources and other addons? Here we are! MyAssignmenthelp.co.uk takes up the responsibility to provide you with the following backups every time, on the move.
So, now that you are aware of our potential and the numerous perks that we have got in store for you, take a smart call. Our assignment help services in the UK shall make sure to help you secure a straight A+ every semester.
Upload your Assignment and improve Your Grade
Boost Grades