Sunday, January 24, 2016

Week 6- Security Risk of Using Personal Devices while travelling in public transportation

Research conducted by PublicTransportation.org concluded, "In the year 2013 Americans took 10.7 billion trips in the public transportation" proving the record high ridership. In the world, of all trips made to and from work  35% use public transportation and underdeveloped countries are at high end of using public transportation, Whether the intent is to commute to work or non work related, most of commuters use mobile devices for communication, browsing, listening music, taking photographs, playing games etc. While using these devices some way or other these devices use the public networks which are unsecured and posses high risk of security. Public transportation commuters are even accessing the company data on the unsecured and unknown networks. Unsecured data can easily be exploited by the elite hackers using the public Wi-Fi networks and use them against the company security data networks. Some travelers even use the public network for the company task while travelling and or talking to the colleague regarding important work related data posses threats in company privacy policy. 
It is equally important to protect the personal information while using these mobile devices because you never know who you are travelling with and using the cellular phones or laptops or tablets openly gives opportunity to the criminals. Openly texting, entering personally identifiable information, entering banking information, displaying work related information while  travelling in the public transportation should strictly be  considered as vulnerable. On the other hand, if  any suspicion is occurred that someone is watching your messages, works then you should confront the individual asking the intent and report the issue to concerned authority if unusual behavior is noticed. If you feel company data is shared then the action should be notified to the security team as soon as possible. 
With increasing Security risk, companies are moving towards "Bring Your Own Device (BOYD)" policies  which will force security team to conquer mobile device management in order to maintain the company data and network security. 
To conclude, using mobile device in public transportation should be strictly be monitored and using company data in public networks should strictly prohibited. If any suspicious activities are noticed, confront them to ask the privacy of the usage and if in any case company data is compromised then notify  to the IT security team as soon as possible. 

References:
http://www.worldmapper.org/posters/worldmapper_map142_ver5.pdf
http://www.publictransportation.org/news/facts/Pages/default.aspx

Thursday, January 14, 2016

Week 5 :Business Internet/email use policies- Legal and ethical issues of an employer being able to monitor the computer use/emails of employees-

Since we are deep diving the security policies this week, I would like to discuss the business internet/email policies. Some organizations keep an eye on it's employee, what they are doing during and off work.Monitoring has both benefits and impact to the organization and employee. I am discussing some legan and ethical issues of an employer being able to monitor the computer use or email use of an employee.

As we all know, the Company owns the rights to all data and files in any computer, network, or other information system used in the Company. It also reserves the power of retrieving the data sent or received by the employee using the company internet access or company’s property. The company has always closed monitored in its employees and to all data and files sent or received either personal or professional. Employees must be fully aware of the discipline of the company. They must know that the electronic mail, messages which are sent or received though the company’s internet or web base application can be traced and view by the company officials at any time without any notice. There is no expectation of privacy in any information or activity conducted, sent, performed, or viewed on or with Company equipment or Internet access (www.twc.state.tx.us). It is completely clear that using of the internet at office by the employees during the working hour is totally unacceptable, however I believe that there is always a pros and cons for such kind of cases.
Employers has started to put close monitoring on their employee due to excess increase in cyber loafing and lawsuits through the new inventive technologies. At the same time both parties are clear regarding the ethical implications of constant monitoring. The company does monitoring on its employee’s action to closely monitor the work productivity and the efficacy. At the same time monitoring also helps to track the actual amount of time they spend on the work and or sitting idle.
Computer monitoring also allows the employer to keep records of the employees’ performance, and provides the information required to set the company’s performance standard and helps in the appraisal review process. Not only this it also allows the employer to keep closer look on the employees’ access to information about their own level of performance and also give an access to employees to judge their own level of performance. It also helps to create the flexibility in work location by allowing the employee to telecommute or" flex time".

On the contrary, Employer feels the pressure of working under the hostile environment and feeling of invasion in their territory. Because of the unfriendly environment the productivity of the company might not meet the company’s standard. Monitoring is intrusive and has a high potential risk for abuse in the companies’ employer (Mishra & Crampton, 1998). Since the employees can have direct access to track of each and everything they can use it against the employee. The monitored employees are also likely to have less control over their jobs, monitor work load pressures, more arguable interaction with the customers and less fairness of their work. With the major increase in stress it has also been found employee reporting the psychological and physical health issues.

Works Cited

Department of Health and Human Services. (n.d.). Security Standards: Technical Safeguards. Retrieved October 06, 2015, from http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/techsafeguards.pdf

Mishra, ,. J., & Crampton, S. M. (1998). EMPLOYEE MONITORING: PRIVACY IN THE WORKPLACE? Retrieved from http://faculty.bus.olemiss.edu/breithel/final%20backup%20of%20bus620%20summer%202000%20from%20mba%20server/frankie_gulledge/employee_workplace_monitoring/employee_monitoring_privacy_in_the_workplace.htm

www.twc.state.tx.us. (n.d.). INTERNET, E-MAIL, AND COMPUTER USE POLICY. Retrieved from http://www.twc.state.tx.us/news/efte/internetpolicy.html

Potential health risks related to cellular phone technology on human health - Week 4


In the communication industry use of telephones are significant and warmly welcomed for the human use. World health Organization (WHO) reports an estimate of 6.9 Billion subscriptions of the mobile phone globally (World Health Organization , 2014). Both wired and wireless communication, the signals are transferred and received as the form of radio frequency (RF) (analog) and electromagnetic waves in the case of digital media. The electromagnetic waves are non-ionizing radiation meaning they can move the atoms in the molecule but not enough to ionize (replace or remove the electrons). High energy radiations such as X-ray or Gamma rays are seriously hazardous to the human body. The exposure level of the radio waves to the human body for the longer duration can cause heat leading to the tissue burn, skin diseases but there are no clear indications of damaging the blood cells due to the exposure. The frequencies that are used in the mobile phones ranges from 900 MHZ to 2.1 GHZ and power of 0.1 to 2 watts. These exposures to the human body vary with the wavelengths, distance, handheld vs. hands- free and length of the call (World Health Organization , 2014).

Health effects

As it is certain that the longer use of the cell phones can cause the heat to the body cells and most likely affect the soft cells in the brain as use is closer to the head. According to NIH only biological effect of radiofrequency energy is heating and there has been no factual evidence on the brain tumors or cancers. On the other hand the study from World Health Organization Regional Office for Europe’s Health Evidence Network (HEN) on the impact on developing head and brain tumors (benign and malignant) concluded the evidence did not support the hypothesis but an increase in the risk of acoustic neuroma after 10 years or more of mobile phone use (World Health Organization and Health Evidence Network (HEN), 2006). Exposure to the radiation can cause short-term and long-term effect to the human body.

Short term effect

Brain performs all the electrical activity of the human body and the nerves transfer these signals to different parts including the skin. The radiation generated by the cell phones can cause heat to the human body, most likely to the skin in the ear and head section. This can increase the temperature to the exposed part of the human body affecting the electrical activity of the human body. People tend to keep the cell phones near to the heart and this can cause the heating in the exposed part and affect the neural functions related to the heart. The studies from health organizations does not suggest any evidence of the health effects due to the exposure to the radio frequency but practically increase the temperature of the tissue exposed (World Health Organization , 2014).The other side of the cell phone use hazard is battery explosion which is causing the serious burnt to the human body and sometimes leads to the human death.

Long term effect

The longer exposure to the radio frequency can cause human health effects most possibly to the lowest level of effect of the high radiation waves. Again the length of exposure to the radiation will depict the effect to the human body. The Interphone study report from World Health organization in 2010 concluded a median lifetime cumulative call time was around half an hour each day and this trend is slowly decreasing due to the technology of hands free and texting in use that prevents from bringing the cell phones closer to the brain cells. Most discussion in the world at present day is brain tumors and damage in the blood cells. People using the cell phones closer to the brain for longer time might expose to the radiation and slowly these radiations can damage the blood cells and also cause some damage in the temporal organ of the human body. Effect on the brain cells, stem cells, skins leads to the rupture in the DNA that will stop the cells growth leading to the blood barrier to the human body. People keeping the cell phones close to the reproductive organs can cause the damage in count of sperm cells leading to the infertility. The exploratory study conducted by Weston A. Price Foundation (WAPF) on ten human bodies to cell phone radiation stressor illustrate substantial changes in the blood from short-term cell phone radiation exposure in nine out of ten human subjects (Weston A. Price Foundation , 2015). So several studies have been conducted by various health organizations to verify the possibility of brain cancer due to the exposure to the cell phone radiation for longer time but there has not been any definitive study that proves the theory. The research result depends on the various measuring factors such as duration of use, participant’s health condition, age, frequency of the radiation and many more which is always volatile and results cannot be replicated. In other hand the cell phone use in the children are increasing day by day and radiation might affect the brain cells but still researches conducted by US, Spain, Denmark, Sweden, Norway, and Switzerland does not prove any cases of brain cell damage or proved cancer.

Works Cited

CTIA-THE WIRELESS ASSOCIATION. (2015). Background on CTIA’s Wireless Industry Survey . CTIA-The Wireless Association.

Weston A. Price Foundation . (2015, January 16). Does Short-term Exposure to Cell Phone Radiation Affect the Blood? Retrieved October 28, 2015, from http://www.westonaprice.org/modern-diseases/does-short-term-exposure-to-cell-phone-radiation-affect-the-blood/

World Health Organization . (2014, October). Electromagnetic fields and public health: mobile phones. Retrieved October 28, 2015, from http://www.who.int/mediacentre/factsheets/fs193/en/

World Health Organization and Health Evidence Network (HEN). (2006). What effects do mobile phones have on people’s health? Copenhagen: WHO Regional Office for Europe.

Issue Specific Security Policy (ISSP)

For my CIS-608 class, i need to draft a generic, sample Issue Specific Security Policy (ISSP)  that would be useful to any home computer user. So I have prepared a sample Issue Specific Security Policy (ISSP) for my house hold : "Security Policy Document for use of personal devices in Khadka household". Please review and provide the feed back on my work:

Statement of Policy


This document establishes a policy for use of personal devices (cell phones, tablets, home computers, etc.) within the Khadka household premises to protect the sensitive information of the family members, relatives, visitors, and security of the Khadka house.
This document was developed because the use of personal devices within the Khadka household from the visitors, guest and neighbors increased during the last year which created the threat over the security of household assets. The use of the personal devices in the household network for personal communication, work related connections, gaming, television networks and use of the software created more thereat on the firewalls and injected malware in the network that created lots of downtime for the network repair during the peak hours and slowness in the browsing capacity.
This policy applies to all members of the Khadka family, guests, visitors and others using personal devices (Cell phones, tablets, laptops etc.) within the premise.
Failure to comply with the security requirements and policies will result in disciplinary action, legal issues and also restriction over the access of the network at any time inside the premise. Non- compliance includes willful or negligent violation of the personal devices, use of personal devices for the personal communication at family gathering, use of home network in personal devices at the dining table, use of computer software for gaming and video streaming over 2 hours continuously, negligence of the security policies that endanger the interest of Khadka family members.

All the users agree to comply by the household code of conduct to protect the household data. The use of the personal devices and connection to the household network should be authorized and authenticated. Access to the Khadka housed network must be:
  • Authenticated and verified for visitors and guests
  • Use of computer, laptops, and other devices within the household should be authorized
  • Gaming station and use of TV network should be authorized and monitored
  • Children under age of 16 should follow the guidelines of time limit (2 hours) for use of gaming devices, use of TV networks, mobile devices, computer usage
  • Restricted use of the personal devices and connecting to the network during family gathering and after waking hours.
  • Revoked when visitors, guests, outside family members tries to change the password and perform any infringement to the network.
  • Visitors, guest and outside members should require use of guest access to connect the network.
All the users and devices are required to comply all the existing security policies developed by Khadka hose hold and the current security policy. Some of the existing policies include:
  • Information security policy for Khadka household
  • Use of mobile and laptop policy
  • Wireless use policy
  • Remote access and device use policy
  • Network/Malware/Virus policy
  • Khadka family Privacy policy
  • Copyright Information policy
Personal devices including mobile devices, laptops, tablets, person computers, USB etc. are authorized to bring in the household premise but connection to the network should be authorized and monitored. These devices are prohibited to access the Khadka household’s communication, any personal information, sharing family member’s personal information to public. All guests/visitors should use guest password protected network to complete the use of the devices. Any guests/visitors required to use the personal devices for any emergency should be approved by the authorized house member.

Khadka house member is solely responsible for monitoring the use of external devices in the home network. Khadka household member should safeguard the software, networks and any household devices provided to the guests/visitors in any use. Khadka household is responsible for creating the guidelines of the device use in the Intranet and also publish all the lists of the approved devices, hardware, and password encrypted user accounts.

Guests/visitors/neighbors are prohibited from adding any software, personal passwords, network password and household data in the personal devices. Data includes email communication, house member’s information, financial information, household personal files, any persona bookmarks, passwords, user accounts. Capturing images and videos of the personal data are not authorized within the household premise. Paring the household devices with the personal using the Bluetooth is strictly prohibited and only permitted with authorization. Any form of personal USBs are not allowed to use in the family network, hardware and software to store Khadka family information and data.  

Failure to comply with the security requirements and policies will result in disciplinary action, legal issues and also restriction over the access of the network at any time inside the premise.

This policy will be reviewed and modified based on the family member’s agreement at the end of every year.

Khadka household is not responsible for any lost or stolen devices during the unauthorized use within the Khadka home premise. Any devices borrowed from the house has to be reported to the Khadka household if they are stolen or lost.





Thursday, December 17, 2015

Behavior Blocking: The Next Step in Anti-Virus Protection

Since we are learning Management of Information security in this week and after reading different articles regarding Data breach Investigation, I felt an importance of discussing the protection against computer virus. With the increasing threat to the computer application, vulnerability has increased to the internet world. There are different types of attack to the system which can damage the network and creates the threat tot eh infrastructure and security. Hoax, URL Spoofing and Phishing, Referer spoofing, Caller ID spoofing, DoS attack, spam, sniffer etc. are some of the common type of attack that happens in the computer, system network and security. To overcome this attack, organizations are using various IT security approaches including blacklisting, whitelisting, and behavioral based technologies, and software t o secure the system. Behavior blocking is a tool implemented for defense tactics in antivirus approach that monitors the file activities, software and operating system modification. This process guards the operating system and stops any unauthorized behavior within the operating system. Files and programs that are likely to present the threat to the operating system are blocked based on the analysis of the behavior pattern and this can be done by analyzing the content and code.

In signature- based approach also known as antivirus, actions (code/file transfer) are compared with the database activities called as signatures and if any suspicions are found, they are blocked whereas in behavior blocking the user behaviors are monitored and repetitive behaviors are blocked. So if any new behaviors are detected then the comparison fails and the approach will not work where as the behavior approach will block any unusual behaviors. These unusual behaviors create alert to the administrator and notify regarding exploitation of the vulnerability. For Example: If there are any W32/Viking virus variants files the users are not allowed to open this as it will infect the executable virus by copying itself to network and removable share drives. Behaviors blocking is also known as sandboxing as it observes the behavior of the running program and if any threats are detected then they are blocked.

After detecting malicious activity, Behavior Blocking performs one of the following actions:

Block: Prevents programs exhibiting malicious behavior from making changes to the computer.
Terminate: Closes programs that exhibit malicious behavior.
Clean: Closes programs that exhibit malicious behavior. If a program is verified to be a threat, deletes files and other objects associated with the malicious program.

Works Cited

Pachghare, V. K. (2015). CRYPTOGRAPHY AND INFORMATION SECURITY. New Delhi: PHI Learning Private Limited.
Stackpole, B., & Oksendahl, E. (2011). Security Strategy - From Requirements to Reality. Boca Raton: Taylor and Francis Group, LLC.
Webroot Software, Inc. (2013, January). User Guide for the Identity Shield. Retrieved November 14, 2015, from http://download.webroot.com/IdentityShieldUserGuide.pdf


Sunday, December 13, 2015

Week 2 Post - Benefits of integrating the IT/Security strategic plan with the Enterprise Strategic Plan

Enterprise strategic planning is about encouraging long-term thinking of the organization by establishing the directions and constraints that will guide the tactical achievement. While making the decisions of the future planning there are uncertainties and the future prediction is very difficult. “The best-laid plans of mice and men often go awry” (Funston & Ruprecht, 2007), so risk is involved with any strategic planning. Security Strategy is the plan that will moderate risk while complying with legal, statutory, contractual, and internally developed requirements to achieve the business goal. In-order to achieve the business goal organization must align both enterprise strategic plan and security strategic plan because enterprise’s strategic drivers are derived from scanning environmental factor which is a key essential within security strategic plan.
Since business strategy is all about proving that the company’s success and achieving stable long term earning growth over it’s competitor security strategic plan will help organization to adopt to its environment. Environment in macro level includes industry, competitor analysis, market research, product innovation. Security Strategic plan includes the environmental scan and performs SWOT (Strength, Weakness, Opportunities, and Threats) analysis that will leverage the strengths and minimize the weakness of the enterprise. The information will help in decision making for the business unit’s strategic plans. Security plans involves regulatory and legal requirements that enterprise has to determine before making decisions. Enterprise’s data security, privacy and informational management are handled by the security team and business has to make the decision whether these matters needs to be maintained in-house or outsourced. These insights will identify lots of question to strategic planners and minimize the future risk by addressing them in the strategy plan. Consumer always demands the standard of the product and it will make the company rise a step ahead of it’s competitor. Security plan will determine how to identify the higher standards for the performance, bandwidth, power, performance, flexibility, reliability, connectivity, integration, real-time solutions, and security. For example, HIPPA regulates each individual in health care profession and enforce them for the standards. Organizations benchmarking these standards and driving the strategic security initiatives always achieve the competitive advantage than others. Security strategy plan also determines the international standardized requirements for the organization. In order to perform the business in international arena business organization has to follow international security protocols and standards. For example, an airlines company has to follow the guidelines of International Civil Aviation organization (ICAO).To minimize the risk of the legal aspect and cost associated with it, enterprise has to incorporate all the policies and plans during the strategic planning and security strategic planning will provide all the analysis of the security beforehand so that the decision making is easier.
Integrating the security drivers within the enterprise strategic planning will effectively achieve the long-term business goals holistically. It will maximize the ability to manage the information risk by assessing and validating the compliance with ever-changing legal, regulatory, contractual or other applicable standards (Evans, 2015). Treating the security plans as different entity and alienating them will impact the decision making of the strategic planners and also gets into the legal and regulatory trouble. Market research will be weak and products might not address the need of the gap analysis. Lack of competitive intelligence and business intelligence will create vulnerability in decision making about everything from marketing, R&D, and investing tactics, to long term business strategies.

Works Cited
Evans, B. (2015, July 08). The Importance of Building an Information Security Strategic Plan. Retrieved September 20, 2015, from security Intelligence by IBM: https://securityintelligence.com/the-importance-of-building-an-information-security-strategic-plan/

Funston, R., & Ruprecht, B. (2007, May 01). Risk in the Strategic Planning Process. Retrieved September 20, 2015, from Business Finance : http://businessfinancemag.com/business-performance-management/risk-strategic-planning-process

Saturday, December 5, 2015

Week 1 Post - The roles and responsibilities of people involved in security policy framework creation

When we talk about the organization and business process, each roles and responsibilities are accountable in order to achieve the goal. Similarly for selecting the perfect security policy framework, changing the existing framework or building the secure framework different individuals are required and each individual are equally responsible for their roles and responsibilities. Each individual performs the separate task and manages the task that they are responsible for the work. This includes managing the team (managers), developing secure framework (security architects), ensuring the data quality (data engineers) , office/Vendor management etc .which are building blocks of the whole security framework. Each security policy framework creation is risk based approach so different person working to minimize or solve the risk has individual task assigned to them. Risk governance provides the overview of the risk evaluation and defines the key personnel that are working to ensure the technology risk, manage/articulate the risk. Each step of this process has different hierarchical order of the organization who are adding values to produce the high quality products and services. Organizational structure depicts the roles and responsibilities of people involved in security policy framework creation and implement framework that establish the standards for identifying and managing risk. For example people working on the executive governance (board of directors) are responsible for the decision making, managerial task, dealing with the audit issues, CISO are responsible for any technology related security issues. Security administration manages the access management referring to user access to the different systems, physical facilities and manages the application security management. These different layers of the organizational structure has to work together to achieve the secure business component. Security management works together with operational management to ensure application security requirements are met. When we talk about the separation of duties for the creation of the security policy framework we are associating each business function with risk. Each individuals working on the organization structure has their skill set defined and they are hired for their individual roles. For example, developers can code as per the requirement and tester can verify the application are functioning as per the requirement but when these individuals are assigned to design the security architecture of the organization then they are not qualified for the task. To summarize, each individuals has their own skills set and they mastered in them to produce the quality works. If one has to work outside the comfort zone then there are risks associated with the work and transnational responsibility and accountability are in jeopardy. These roles and responsibilities are also associated with the organizational security governance and compliance to the standards. Creating the strong security policy framework helps in minimizing the risk and the only way to measure the level of security is framework. Framework defines the essentiality of the regulatory compliance the set the standards and controls. When these roles and responsibilities are not properly defined or managed then security risk can be increased, compliance and standards can be in danger and business can have legal issues.