Operating Systems and Application Security Hardening - Engineering Assignment Help

Download Solution Order New Solution
Assignment Task :

Operating Systems and Application Security Hardening 

In this assessment, students will be required to design and implement a corporate identity and access management solution. This is a practical assessment, you will need to conduct research to determine the requirements and controls and fully implement your findings using virtual machines. It is an individual assessment which will be submitted in the form of a report. 

The first task will commence with determining the security requirements for this environment. Consideration should be given to both the security requirements of the environment itself (e.g. ensuring confidentiality, integrity and availability of the identity/access data itself) and the security implications that the identity and access management system will have on other corporate systems (e.g. ensuring it has the flexibility to support a variety of security best practices for other systems which use it as an identity / access control source). Students should refer to one or more cybersecurity frameworks (e.g. the Australian Signals Directorate Strategies to Mitigate Cybersecurity Incidents, or the NIST Cybersecurity Framework) when making recommendations in their report. 

Once the security requirements have been considered, students must detail the specific security hardening controls that they will implement in a virtual machine environment to address these requirements. It would be expected that the noted security hardening requirements will have associated controls implemented in the virtual machine environment. N.B. This assessment should be considered from the perspective of a real-world organisation. As such, the fact that this is a case study environment is not grounds for non-implementation of security controls. Additional specification of the target environment is outlined in the Assessment Scenario section of this document. 

The second major task will be to comprehensively document the security control implementation in a virtual machine environment which consists of at least one management server, one internal (managed) Windows client, one internal (managed) Linux client and one BYOD (unmanaged) device. A minimum of two case study services must be implemented and integrated with the identity and access management solution, a file server (demonstrated on all client devices) and user logon (demonstrated on the managed client devices). Additional case study services may also be implemented. 

Additional virtual machines may be required to fully explore and demonstrate the implemented security functionality. The documentation of this process should start from the installation of the guest operating systems and conclude with a fully operational and secure corporate environment. Although all stages of the implementation should be documented, the focus of the implementation documentation should be on security controls. 

In summary, this report consists of two major sections (in addition to an executive summary, introduction, conclusion and reference list): 

1. Investigation (in concert with one or more suitable cybersecurity frameworks) and design of a secure corporate identity and access management solution. This should be followed by an indication and discussion of the specific controls that will be implemented in Section 2, including justifying why they are important, and if any controls will not be implemented, justifying their exclusion. 

 

2. Practical implementation of the environment using virtual machines. This section is to be documented via the use of annotated screenshots. Please ensure that the screenshots are comprehensive as the virtual machines will not be submitted as part of this assessment. While all sections of the implementation need to be documented, additional focus (screenshots) should be made on sections of the implementation that relate to Operating System and Application security (in contrast to general setup). 

The word limit for this assessment is 2,500 words, however the implementation screenshots and their associated (brief) annotations do not count towards the word limit. 

You must also ensure that your design and implementation meet the client requirements (outlined below). 

 

Assessment Scenario 

Your identity and access management (IAM) solution should be built and secured for the fictional organisation LargeCorp. LargeCorp have three physical sites across a variety of geographical locations. Their internal organisational divisions include: Research and Development, Manufacturing, Human Resources, Finance, Information Technology Services and Marketing. R&D and Manufacturing staff are present at all LargeCorp sites whereas HR, Finance, IT and Marketing are all based at the LargeCorp head office. 

Client Requirements: LargeCorp supports both Windows and Linux clients and servers. They are a complex organisation with a variety of departments and subsections. They would like to delegate appropriate rights to managers within their organisation to allow for a level of self-service within the IAM system. While they have asked you to follow justified best practice, they have two specific requests based on their readings: support for multi-factor authentication and automated lifecycle management for user accounts (and other objects where possible). 

LargeCorp have requested that all best practices for maintaining confidentiality and integrity of their data and systems be employed. Industry standards require that a justifiably appropriate amount of audit data be collected from identity and access management transactions. 

 

This Engineering Assignment has been solved by our Engineering  Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.

Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.