Is the OS the primary piece of software responsible for the security of the overall system? Explain your answer and give examples to support your conclusion. How does this affect confidentiality, integrity, and availability for the system? Which of these factors is most influenced by the OS?
The OS acts as a primary piece of software responsible for security of the overall system since so that OS ensures that unauthorized person do not access the system and software parts of the OS need to protect themselves which is very important for an operating system to work accordingly.
It do affects the Confidentiality,integrity and availability of the system.
Confidentiality:Confidentiality allows the authorized users to access protected and sensitive data in the computer systems.The best example for this is biometrics ,the system or software allows the user access only when the required user id and passsword requirements satisfy or ensured.
Integrity:Integrity is the accuracy of either the data or system integrity.The OS consists of some protection mechanism to ensure the data integrity such as matching of the domain and which does not match with any others.example for integrity is to declare defined domains in the database such that no columns are consistent such that if the column consists of numerical data the it should accept only numeric values other than alphabetical or any other values.
Availability:Availability is the amount of time the system actually operating and the amount of time it is alllowed to accept the processess.If a system is highly available then it disables the malfunctioning and continue operating at reduced capacity which is a loss to the system.even if the system is less available then the system may crash and become unavailable totally.so it need to be in a balanced state always
All these factors influence the OS in their respective ways Confidentiality by protecting the system,integrity by providing consistent and accurate data and availabilty by malfunctioning and functioning the system capacity accordingly
Is the OS the primary piece of software responsible for the security of the overall system?...
Which role has the PRIMARY responsibility for the documentation of control implementation? Systems security engineer Control assessor Information System Owner (ISO) Information Owner/Steward When making determinations regarding the adequacy of common controls for their respective systems, Information System Owner (ISO) refer to the Common Control Providers’ (CCP) Privacy Impact Assessment (PIA) Business Impact Analysis (BIA) Authorization Packages Vulnerability Scans An organization-wide approach to identifying common controls early in the Risk Management Framework (RMF) process does which of the following? Considers...
Network Security Consider an automated teller machine (atm) in which users provide a personal identification number (pin) and a card for account access. Give examples of confidentiality, integrity, and availability requirements associated with the system and, in each case, indicate the degree of importance of the requirement.
1. Explain the cuckoo’s egg exploit using the 4 security tenets of confidentiality, integrity, availability, and accountability. 2. Questions - answer, and remember to cite chapters: Name 5 default passwords that Cliff saw that every system administrator should have changed immediately upon installing new software that came with default, known passwords. Name 3 passwords Cliff and other system users use (NOT the hacker) and discuss why they are poor;
"Software and System Standards" Please respond to the following: Describe system and software standards that could be used for the description of control constructs in C, C#, or Java. Explain how software standards are used to improve the quality of software in an organization. Provide examples to support your answer.
Consider Windows, Linux and Mac OS X. If the security of your operating system were your primary consideration, which OS would you choose as your primary? Don't make assumptions based on what you may have heard. Do a little reading. The links below may be useful to get you started. Why did you select the OS you did? How can you further protect yourself, considering that all operating systems have their own challenges?
Attacks:
Passive – attempt to learn or make use of information from the
system that does not affect
system resources
• Active – attempt to alter system resources or affect their
operation • Insider – initiated by an entity inside the security
parameter
• Outsider – initiated from outside the perimeter
Threat Consequences
Unauthorized disclosure is a threat to confidentiality
•Exposure: This can be deliberate or be the result of a human,
hardware, or software error
•Interception: unauthorized access to...
IT Subject - System Security. Question 3 Most of the current organizations are relying on IT services to process their daily operational and business processes. However, on the other hand, some of these organizations do not fully enjoy the benefit of these IT services as intended. To a great extent, this is dependent on the availability of the services uninterrupted. The degree of availability defers from company to company. The degree of availability is normally higher and commonly found among...
1. What are the important considerations in choosing a Red Team (or attack team) for your software system? Give examples to justify your position. 2. How should you utilize the results of a static analysis of the system? What criteria should determine the level of action taken on any item? 3. Why is it important to probe and attack a system both at rest and in action? Give examples of information that is provided by each that the other could not provide. 4. What...
HOMEWORK 1: CS 386 (Cryptography) Due Date: January 25, 2018 1. Write short answers for each one of them a) Method of concealing data including messages, files, keys and passwords is known as: b) Method to protect blocks of data from being altered is known as c) What are three parts of CIA triad? d) What is the main difference between accountability and availability e) What is the ITU-T recommended security architecture for OSI called? 2. Explain the differences between...
Give three examples of a business decision for which you would not use a decision support system or any other software. Give three non-business examples. Explain your choices.