1) Define the vulnerability assessment requirement, propose a solution, and justify the solution.
2) Define the security policy requirement, propose a solution, and justify the solution.
Question 1: Define the vulnerability assessment requirement, propose a solution, and justify the solution.
Answer:
Definition - Vulnerability Assessment
Vulnerability Assessment is a testing process used to identify and set the severity levels to as many security defects as possible in a given time-period. This Vulnerability Assessment process may involve both automated or manual techniques to do / cover maximum security defects.
doing Vulnerability Assessment in an organization helps in finding the Vulnerabilities in their software so that proposed software solutions become bug-free and security related impacts are avoided too.
How - Vulnerability Assessment Work
Three Main Steps involved in Vulnerability Assessment
Step 1: Identify Vulnerabilities in the given software and group the Vulnerabilities ranging from Critical to Simple mis-configurations
Step 2: Prepare the Vulnerability Report and share the same Report with Developers
Step 3: Create a track issue for the Vulnerabilities Then guide Developer with re-producing the identified Vulnerabilities and fixing the same.
Proposed Solution With Justification for using Vulnerability Scanner Tool.:
Vulnerability Scanner Tool used in order to access Vulnerability requirements are satisfied and all are proper and fine.
Using Vulnerability Scanner Tool major Vulnerability can be identified and can be fixed
Justification:
[1] identify potential weakness in the network like missing proper network patches, weak passwords, mis-configured firewalls
[2] Vulnerability Assessment can be either Free Trail Version Vulnerability Scanner Tool or Paid Licensed Vulnerability Scanner Tool. Ideally we need to use Paid Licensed Vulnerability Scanner Tool to find reliable and maximum Vulnerabilities.
[3] Vulnerability Scanner Tool Configurations can be modified so that outcome of getting more and maximum Vulnerabilities in ease manner.
Question : 2 Define the security policy requirement, propose a solution, and justify the solution
Answer:
Definition - Security Policy
Every Organization has set of security policies , set of objectives that comprises rules of behavior need to be followed by users and administrators.and requirement for system and management that collectively ensure the security of network and computer systems in the organization. Security Policy will be never complete and keeps on updated by organization depends on time-to-time.
A Proper Security Policy describes these below and Security Policy Works on the below
[1] Security Policies to be informed to users, staffs, managers, reporters, human-resource people so that uniformity and unity within the organization
[2] Security Policy Specify Mechanisms how to implement security integration.
Proposed Solution
[3] Protects people and Information
[4] To Set Rules for expected behaviour
Justification
[5] Assign Authorized Staff People to investigate security constraint issues
[6] Declare and Define the consequences of voliations
1) Define the vulnerability assessment requirement, propose a solution, and justify the solution. 2) Define the...
Define the following vulnerabilities in simple words: Short answers only 1. Heartbleed vulnerability 2. Ticketbleed vulnerability 3. OpenSSL CCS vulnerability. (CVE-2014-0224) 4. OpenSSL Padding Oracle vulnerability (CVE-2016-2107) 5. Poodle 6. Logjam vulnerability 7. Freak vulnerability
Software Engineering
Part 2: Software security: (7 marks) Assume you are performing preliminary security risk assessment. 1. The first step in performing a preliminary risk assessment is asset identification. List down three assets you identify in an in-store automated supermarket shopping system when conducting the preliminary risk assessment. (3 marks) 2. Identify two possible security risks associated with an in-store supermarket shopping system and propose a system requirement that might reduce each of those risks. (4 marks)
Define hazard vulnerability in analysis and identify several, at least 2, situations one would conduct this analysis on.
Please write clear in the explanation thanks
1 2 0 -1 3 2 1 -1 2 1 oand RREF(A)- 1 3 -1 2 Suppose that A3 21 a. s there a unique solution to Ax-22 Justify your reasoning completely ?Justify your reasoning completely. b. Are the column vectors of A a basis for R? Justify your reasoning. c. Define geometrically the span of A.
1 2 0 -1 3 2 1 -1 2 1 oand RREF(A)- 1 3 -1 2...
5. Propose a mechanism to justify the formation of the following product. (4) Br 1. NaNH2, Liq NH3
Plz show the solution
2. Propose a solution to check which modeling approach between M/M/1 and M/D/1 would be more accurate to model queue size at a right turn bay.
2. Propose a solution to check which modeling approach between M/M/1 and M/D/1 would be more accurate to model queue size at a right turn bay.
1) What is IoT? 2) uses, needs, obstacles, requirement, and risk 3) What is iCloud? 4) uses, needs, obstacles, requirement, and risk 5) Intersection between IOT and Cloud 6) If two technologies meet together what will happen 7) Associated risk in IoT and Cloud methodology 8) Contribution, in theory, is to solve a problem is cybersecurity? 9) What model can be used and this will target a percentage in the methodology? 10) Vulnerability in IoT and Cloud model? I need...
Please explain: 1- How does Buffer Overflow Vulnerability Lab working? 2- What are the features of Buffer Overflow Vulnerability Lab? 3- What are the advantage of Buffer Overflow Vulnerability Lab?
1. What attributes predispose individuals to vulnerability? 2. What are three enabling characteristics? 3. What is the third determinant of vulnerability?
Which role has the PRIMARY responsibility for the documentation of control implementation? Systems security engineer Control assessor Information System Owner (ISO) Information Owner/Steward When making determinations regarding the adequacy of common controls for their respective systems, Information System Owner (ISO) refer to the Common Control Providers’ (CCP) Privacy Impact Assessment (PIA) Business Impact Analysis (BIA) Authorization Packages Vulnerability Scans An organization-wide approach to identifying common controls early in the Risk Management Framework (RMF) process does which of the following? Considers...