ISYS1002 - Computer Cyber Security Fundamental Assignment

Download Solution Order New Solution

Assignment Task

1. Assume your selected organisation is currently using a password-based authentication system to control user access to the organisation’s information system. However, the Bring Your Own Device (BYOD) and work at home (due to COVID-19 impact) policy recently implemented by the organisation has raised some security concerns. As a security consultant, assess the risk from the BYOD policy and work at home to the organisation’s most critical/top five information assets you identified in Ass One.

  • Identify and discuss two (2) threats the BYOD and work at home policy may bring to each of the five (5) critical assets identified in Ass1.
  • Identify and discuss potential two (2) weaknesses (vulnerabilities) of each of the top five assets identified in Ass 1based on three information security components: confidentiality, integrity, and availability.
  • Assess and prioritise the risk to the organisation's information system using a qualitative risk assessment approach with the top five information assets against the threats identified above and document the risk assessment process in detail.
  • Do the cost-benefit analysis for two (2) years to recommend at least one (1) security measure against each asset to mitigate the risk (with the top threat) identified above. You are free to make any assumption about the asset values. Exposure factors (before and after control), and annualised rate of occurrence (before and after control) should be supported by your own and public domain knowledge and references. Cost of controls should be realistic and supported by vendor/provider references.

2. You have identified phishing as among the top cybersecurity threats faced by the organisation. Use the ACSC and available online resources to develop a guideline for organisation information system users to combat the threat. 

  • Define phishing attacks and discuss their distinctive characteristics with at least three (3) real-world examples.
  • Design three (3) examples for the organisation users to show how the attack could work.
  • Design instructions for the organisation users on how to prevent and/or safely handle these attacks. 

3. Investigate and document the ethical requirements that your selected organisation and its information system users will need to comply with.

  • What would be the consequence(s) for noncompliance with information privacy requirements in the context of information security for the organisation?
  • Discuss how non-ethical behaviour of the users and IT staff impacts security positions within the organisation.
  • Discuss methods or strategies your selected organisation should take to deter employees from unethical behaviour.

This ISYS1002 - Cyber Security has been solved by our PhD Experts at My Uni Paper.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.