Thursday, January 14, 2016

Issue Specific Security Policy (ISSP)

For my CIS-608 class, i need to draft a generic, sample Issue Specific Security Policy (ISSP)  that would be useful to any home computer user. So I have prepared a sample Issue Specific Security Policy (ISSP) for my house hold : "Security Policy Document for use of personal devices in Khadka household". Please review and provide the feed back on my work:

Statement of Policy


This document establishes a policy for use of personal devices (cell phones, tablets, home computers, etc.) within the Khadka household premises to protect the sensitive information of the family members, relatives, visitors, and security of the Khadka house.
This document was developed because the use of personal devices within the Khadka household from the visitors, guest and neighbors increased during the last year which created the threat over the security of household assets. The use of the personal devices in the household network for personal communication, work related connections, gaming, television networks and use of the software created more thereat on the firewalls and injected malware in the network that created lots of downtime for the network repair during the peak hours and slowness in the browsing capacity.
This policy applies to all members of the Khadka family, guests, visitors and others using personal devices (Cell phones, tablets, laptops etc.) within the premise.
Failure to comply with the security requirements and policies will result in disciplinary action, legal issues and also restriction over the access of the network at any time inside the premise. Non- compliance includes willful or negligent violation of the personal devices, use of personal devices for the personal communication at family gathering, use of home network in personal devices at the dining table, use of computer software for gaming and video streaming over 2 hours continuously, negligence of the security policies that endanger the interest of Khadka family members.

All the users agree to comply by the household code of conduct to protect the household data. The use of the personal devices and connection to the household network should be authorized and authenticated. Access to the Khadka housed network must be:
  • Authenticated and verified for visitors and guests
  • Use of computer, laptops, and other devices within the household should be authorized
  • Gaming station and use of TV network should be authorized and monitored
  • Children under age of 16 should follow the guidelines of time limit (2 hours) for use of gaming devices, use of TV networks, mobile devices, computer usage
  • Restricted use of the personal devices and connecting to the network during family gathering and after waking hours.
  • Revoked when visitors, guests, outside family members tries to change the password and perform any infringement to the network.
  • Visitors, guest and outside members should require use of guest access to connect the network.
All the users and devices are required to comply all the existing security policies developed by Khadka hose hold and the current security policy. Some of the existing policies include:
  • Information security policy for Khadka household
  • Use of mobile and laptop policy
  • Wireless use policy
  • Remote access and device use policy
  • Network/Malware/Virus policy
  • Khadka family Privacy policy
  • Copyright Information policy
Personal devices including mobile devices, laptops, tablets, person computers, USB etc. are authorized to bring in the household premise but connection to the network should be authorized and monitored. These devices are prohibited to access the Khadka household’s communication, any personal information, sharing family member’s personal information to public. All guests/visitors should use guest password protected network to complete the use of the devices. Any guests/visitors required to use the personal devices for any emergency should be approved by the authorized house member.

Khadka house member is solely responsible for monitoring the use of external devices in the home network. Khadka household member should safeguard the software, networks and any household devices provided to the guests/visitors in any use. Khadka household is responsible for creating the guidelines of the device use in the Intranet and also publish all the lists of the approved devices, hardware, and password encrypted user accounts.

Guests/visitors/neighbors are prohibited from adding any software, personal passwords, network password and household data in the personal devices. Data includes email communication, house member’s information, financial information, household personal files, any persona bookmarks, passwords, user accounts. Capturing images and videos of the personal data are not authorized within the household premise. Paring the household devices with the personal using the Bluetooth is strictly prohibited and only permitted with authorization. Any form of personal USBs are not allowed to use in the family network, hardware and software to store Khadka family information and data.  

Failure to comply with the security requirements and policies will result in disciplinary action, legal issues and also restriction over the access of the network at any time inside the premise.

This policy will be reviewed and modified based on the family member’s agreement at the end of every year.

Khadka household is not responsible for any lost or stolen devices during the unauthorized use within the Khadka home premise. Any devices borrowed from the house has to be reported to the Khadka household if they are stolen or lost.





Thursday, December 17, 2015

Behavior Blocking: The Next Step in Anti-Virus Protection

Since we are learning Management of Information security in this week and after reading different articles regarding Data breach Investigation, I felt an importance of discussing the protection against computer virus. With the increasing threat to the computer application, vulnerability has increased to the internet world. There are different types of attack to the system which can damage the network and creates the threat tot eh infrastructure and security. Hoax, URL Spoofing and Phishing, Referer spoofing, Caller ID spoofing, DoS attack, spam, sniffer etc. are some of the common type of attack that happens in the computer, system network and security. To overcome this attack, organizations are using various IT security approaches including blacklisting, whitelisting, and behavioral based technologies, and software t o secure the system. Behavior blocking is a tool implemented for defense tactics in antivirus approach that monitors the file activities, software and operating system modification. This process guards the operating system and stops any unauthorized behavior within the operating system. Files and programs that are likely to present the threat to the operating system are blocked based on the analysis of the behavior pattern and this can be done by analyzing the content and code.

In signature- based approach also known as antivirus, actions (code/file transfer) are compared with the database activities called as signatures and if any suspicions are found, they are blocked whereas in behavior blocking the user behaviors are monitored and repetitive behaviors are blocked. So if any new behaviors are detected then the comparison fails and the approach will not work where as the behavior approach will block any unusual behaviors. These unusual behaviors create alert to the administrator and notify regarding exploitation of the vulnerability. For Example: If there are any W32/Viking virus variants files the users are not allowed to open this as it will infect the executable virus by copying itself to network and removable share drives. Behaviors blocking is also known as sandboxing as it observes the behavior of the running program and if any threats are detected then they are blocked.

After detecting malicious activity, Behavior Blocking performs one of the following actions:

Block: Prevents programs exhibiting malicious behavior from making changes to the computer.
Terminate: Closes programs that exhibit malicious behavior.
Clean: Closes programs that exhibit malicious behavior. If a program is verified to be a threat, deletes files and other objects associated with the malicious program.

Works Cited

Pachghare, V. K. (2015). CRYPTOGRAPHY AND INFORMATION SECURITY. New Delhi: PHI Learning Private Limited.
Stackpole, B., & Oksendahl, E. (2011). Security Strategy - From Requirements to Reality. Boca Raton: Taylor and Francis Group, LLC.
Webroot Software, Inc. (2013, January). User Guide for the Identity Shield. Retrieved November 14, 2015, from http://download.webroot.com/IdentityShieldUserGuide.pdf


Sunday, December 13, 2015

Week 2 Post - Benefits of integrating the IT/Security strategic plan with the Enterprise Strategic Plan

Enterprise strategic planning is about encouraging long-term thinking of the organization by establishing the directions and constraints that will guide the tactical achievement. While making the decisions of the future planning there are uncertainties and the future prediction is very difficult. “The best-laid plans of mice and men often go awry” (Funston & Ruprecht, 2007), so risk is involved with any strategic planning. Security Strategy is the plan that will moderate risk while complying with legal, statutory, contractual, and internally developed requirements to achieve the business goal. In-order to achieve the business goal organization must align both enterprise strategic plan and security strategic plan because enterprise’s strategic drivers are derived from scanning environmental factor which is a key essential within security strategic plan.
Since business strategy is all about proving that the company’s success and achieving stable long term earning growth over it’s competitor security strategic plan will help organization to adopt to its environment. Environment in macro level includes industry, competitor analysis, market research, product innovation. Security Strategic plan includes the environmental scan and performs SWOT (Strength, Weakness, Opportunities, and Threats) analysis that will leverage the strengths and minimize the weakness of the enterprise. The information will help in decision making for the business unit’s strategic plans. Security plans involves regulatory and legal requirements that enterprise has to determine before making decisions. Enterprise’s data security, privacy and informational management are handled by the security team and business has to make the decision whether these matters needs to be maintained in-house or outsourced. These insights will identify lots of question to strategic planners and minimize the future risk by addressing them in the strategy plan. Consumer always demands the standard of the product and it will make the company rise a step ahead of it’s competitor. Security plan will determine how to identify the higher standards for the performance, bandwidth, power, performance, flexibility, reliability, connectivity, integration, real-time solutions, and security. For example, HIPPA regulates each individual in health care profession and enforce them for the standards. Organizations benchmarking these standards and driving the strategic security initiatives always achieve the competitive advantage than others. Security strategy plan also determines the international standardized requirements for the organization. In order to perform the business in international arena business organization has to follow international security protocols and standards. For example, an airlines company has to follow the guidelines of International Civil Aviation organization (ICAO).To minimize the risk of the legal aspect and cost associated with it, enterprise has to incorporate all the policies and plans during the strategic planning and security strategic planning will provide all the analysis of the security beforehand so that the decision making is easier.
Integrating the security drivers within the enterprise strategic planning will effectively achieve the long-term business goals holistically. It will maximize the ability to manage the information risk by assessing and validating the compliance with ever-changing legal, regulatory, contractual or other applicable standards (Evans, 2015). Treating the security plans as different entity and alienating them will impact the decision making of the strategic planners and also gets into the legal and regulatory trouble. Market research will be weak and products might not address the need of the gap analysis. Lack of competitive intelligence and business intelligence will create vulnerability in decision making about everything from marketing, R&D, and investing tactics, to long term business strategies.

Works Cited
Evans, B. (2015, July 08). The Importance of Building an Information Security Strategic Plan. Retrieved September 20, 2015, from security Intelligence by IBM: https://securityintelligence.com/the-importance-of-building-an-information-security-strategic-plan/

Funston, R., & Ruprecht, B. (2007, May 01). Risk in the Strategic Planning Process. Retrieved September 20, 2015, from Business Finance : http://businessfinancemag.com/business-performance-management/risk-strategic-planning-process

Saturday, December 5, 2015

Week 1 Post - The roles and responsibilities of people involved in security policy framework creation

When we talk about the organization and business process, each roles and responsibilities are accountable in order to achieve the goal. Similarly for selecting the perfect security policy framework, changing the existing framework or building the secure framework different individuals are required and each individual are equally responsible for their roles and responsibilities. Each individual performs the separate task and manages the task that they are responsible for the work. This includes managing the team (managers), developing secure framework (security architects), ensuring the data quality (data engineers) , office/Vendor management etc .which are building blocks of the whole security framework. Each security policy framework creation is risk based approach so different person working to minimize or solve the risk has individual task assigned to them. Risk governance provides the overview of the risk evaluation and defines the key personnel that are working to ensure the technology risk, manage/articulate the risk. Each step of this process has different hierarchical order of the organization who are adding values to produce the high quality products and services. Organizational structure depicts the roles and responsibilities of people involved in security policy framework creation and implement framework that establish the standards for identifying and managing risk. For example people working on the executive governance (board of directors) are responsible for the decision making, managerial task, dealing with the audit issues, CISO are responsible for any technology related security issues. Security administration manages the access management referring to user access to the different systems, physical facilities and manages the application security management. These different layers of the organizational structure has to work together to achieve the secure business component. Security management works together with operational management to ensure application security requirements are met. When we talk about the separation of duties for the creation of the security policy framework we are associating each business function with risk. Each individuals working on the organization structure has their skill set defined and they are hired for their individual roles. For example, developers can code as per the requirement and tester can verify the application are functioning as per the requirement but when these individuals are assigned to design the security architecture of the organization then they are not qualified for the task. To summarize, each individuals has their own skills set and they mastered in them to produce the quality works. If one has to work outside the comfort zone then there are risks associated with the work and transnational responsibility and accountability are in jeopardy. These roles and responsibilities are also associated with the organizational security governance and compliance to the standards. Creating the strong security policy framework helps in minimizing the risk and the only way to measure the level of security is framework. Framework defines the essentiality of the regulatory compliance the set the standards and controls. When these roles and responsibilities are not properly defined or managed then security risk can be increased, compliance and standards can be in danger and business can have legal issues.

Thursday, June 3, 2010

Information Media -260

Technology has developed so fast that the software that i used last year has been changed to new one and the whole university is updating to windows7.So it was really important to learn how to be updated, so i took this class and it was really informative abd useful for me in the future educational purposes.Everything i learned from IM-260 was helpful though it was summer class and have 11 days class period but Jennifer covered a lot and helped a lot in building the technology updated.There were serious matters of security in the face book and i was abl to resolve it through this class and i came to learn various web 2.0 sites that are really useful.The most important part of this class was web developing and creating teh web page. I really learned a lot about web pages and using the dream weaver software.Even though i had some ideas on photoshop but i was unfamilar to dreamweaver.During the course i was able to use both CS4 and CS3 webs and find some differences that they donot support each other.Still i have some problems in fixing the size of the web page i will find it how to make them constant in everyformat. The other thing i liked about this class is the active participation from all and the teacher. I used to thought four hours classes will be boring and sleepy but i was really exciting about this class and tell my friends to take this class. In addition i learned how to make social resume and do social networking which is one of the great achievement of this class.To sum up IM 260 was really helpful and technology updated.

Wednesday, June 2, 2010

Response to the peer teaching 2...

Today, second last day of the class was fun as we learned about google sites, voki and slide rocket. Talking about the google sites, google has broad search engine that is really helpful in case of further use.Google sites helps in developing some web2.0 pages like dream weaver but not professional.This is helpful in developing small webpages. Voki was the fun dealing with different sound effects and the different faces that anyone can make in the webpage. It might be useful in making the sound effects and post them in the personal webpages.I think everyone in the class found voki interesting than the yahoo pipes that me and my friend shaurav presented. Though the topic sounds interesting but we have to dig a lot to collect information and operate them to make the proper yahoo pipes.About sliderocket, i found it useful in my summer classes that i am going to take in the july.It was the option for powerpoint and i found different stuffs that powerpoint doesot support such as group meeting and 3-D Animation.I hope this web will be really helpful for me in future use to present in my class. I found every group members prepared and helpful during the lab classes.Taking this class is really helpful for me in future classes for using the technology.

Tuesday, June 1, 2010

Response to the peer teaching

Peer teaching was really exciting and i learned some important tools that might be useful in future use such as google doc. and zoho.I found google Docs really useful as i could make important group presentation and share with members of my group so they will be able to read and edit the presentation.In this way if one member could not appear in the meeting then they will be able to learn what we worked on and what were our plannings for the projects.Moreover google Docs was helpful in sharing important documents to the family members by inviting them to google Docs.Similarly Zoho was helpful is making spreadsheets for the maths classes and the management classes. I found Zoho more advanced than google Docs. as they have more features and really easy to operate. For my future use i am going to use the Zoho.About EfolioMinnesota i found some confusion and hard to operate. I think this web will be also useful for the professional life in making the data base regarding the education and the experiences that might be useful in finding jobs. As we know social networking is important, Efolio will really helps in making networks and findings jobs.In Addition i found all the group members were really prepared and well managed and i had thought each group will teach for an hour but it was short and sweet.During the lab time each groups helps around the class which was really impressive and cooperative. From today's class i got more confidence and learned how to present to the class for my peer teaching tomorrow.