MIS607 : Cybersecurity Assessment Threat Model Report - IT Assignment Help

Download Solution Order New Solution
Assignment Task:

 

The Subject Learning Outcomes demonstrated by successful completion of  the task below include:  

a) Explore and articulate cyber trends, threats, and staying safe in cyberspace, plus protecting personal and company data. 

b) Analyse issues associated with organizational data networks and security to recommend practical solutions towards their resolution.

c) Evaluate and communicate relevant technical and ethical considerations related to the design, deployment, and/or the uses of secure technologies within various organizational contexts.

 

Task Summary 

You are required to write a 1500 words Threat modeling report in response to a case scenario by identifying the  threat types and key factors involved. This assessment is intended to build your fundamental understanding of  these key threats so that you will be able to respond/mitigate those factors in Assessment 3. In doing so, this assessment will informatively develop the knowledge required for you to complete Assessment 3 successfully.  

Context 

Security threat modeling or threat modeling is a process of assessing and documenting a system's security risks. Threat modeling is a repeatable process that helps you find and mitigate all of the threats to your products/services. It contributes to the risk management process because threats to software and infrastructure are risks to the user and environment deploying the software. As a professional, your role will require you to understand the most at-risk components and create awareness among the staff of such high-risk components and how to manage them. Having a working understanding of these concepts will enable you to uncover threats to the system before the system is committed to code.  

Task Instructions 

1. Carefully read the attached case scenario to understand the concepts being discussed in the case.  

2. Review your subject notes to establish a relevant area of investigation that applies to the case. Re-read any relevant readings that have been recommended in the case area in modules. Plan how you  will structure your ideas for the threat model report.  

3. Draw a use of DFDs (Data Flow Diagrams):  

• Include processes, data stores, data flows  

• Include trust boundaries (Add trust boundaries that intersect data flows) 

• Iterate over processes, data stores, and see where they need to be broken down 

• Enumerate assumptions, dependencies  

• Number everything (if manual)

• Determine the threat types that might impact your system 

• STRIDE/Element: Identifying threats to the system. 

• Understanding the threats (threat, property, definition) 

4. The report should consist of the following structure:  

A title page with subject code and name, assignment title, student’s name, student number, and lecturer’s name. The introduction will also serve as your statement of purpose for the report. This means that you will tell the reader what you are going to cover in your report. You will need to inform the reader of a) Your area of research and its context  

b) The key concepts of cybersecurity you will be addressing and why you are drawing the threat  model 

c) What the reader can expect to find in the body of the report  

The body of the report) will need to respond to the specific requirements of the case study. It is advised that you use the case study to assist you in structuring the threat model report, drawing DFD, and presenting the diagram by means of subheadings in the body of the report.  

 

The Business &Communication Insurance Case Study 

The Business &Communication Insurance (B&C Insurance) began business as a private health insurer, established by Gary RT.L & family in 1965 through the Health Insurance Commission. This company was set up to compete with private "for-profit" funds. The company’s headquarters is located in New York and has offices in various other countries including Spain, Australia, and Hong Kong. The CEO of B&C Insurance recently received a  ransom email from an unknown company claiming that they have access to the company strategic plans and personal details of 200,000 clients. A sample of personal details of 200 clients was included in the email as a proof’.  

Ransom emails are normally sent through unreliable external networks that are outside the company’s security boundary. The CEO consulted the senior management and they acted promptly to investigate and contain the threat with the aid of forensic computer specialists. The first step was to validate the threat. The management team found a discussion on a hacker site in the darknet that had personal information of 200,000 clients of B&C  Insurance for sale. This also included the details of the 200 clients, provided in the ransom email as ‘proof’. The investigation also confirmed that the details of the 200 customers are genuine.  

The senior management considered the need to identify threats and give practical guidance on how to manage the risks of identity fraud to be of utmost importance. Therefore, a team of consultants was appointed to prepare a series of reports to identify various threats and to develop cybersecurity crisis management plans in order to respond to potential threats/ risks of sophisticated hackers penetrating into the internal systems of the company and accessing client information.  

As the cybersecurity specialist in the team, you have been asked to write a report to identify the threat types and key factors involved. In doing so, you are required to identify the most ‘at-risk’ components, create awareness among the staff of such high-risk components and how to manage them. In addition, this report is to help key stakeholders, including the executive managers, make decisions on what course of actions must be undertaken to mitigate potential threats.

 


This MIS607 - IT Assignment has been solved by our IT Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.

Be it a used or new solution, the quality of the work submitted by our assignment Experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.