Question

1. Explain the cuckoo’s egg exploit using the 4 security tenets of confidentiality, integrity, availability, and...

1. Explain the cuckoo’s egg exploit using the 4 security tenets of confidentiality, integrity, availability, and accountability.

2. Questions - answer, and remember to cite chapters:

  • Name 5 default passwords that Cliff saw that every system administrator should have changed immediately upon installing new software that came with default, known passwords.
  • Name 3 passwords Cliff and other system users use (NOT the hacker) and discuss why they are poor;
0 0
Add a comment Improve this question Transcribed image text
Answer #1

ANSWER

The basic tenets of information system security are confidentiality, integrity, and availability, sometimes known as the CIA triad.

  • Confidentiality ensures that the information is not disclosed to unauthorized persons or processes.
  • Integrity is achieved by accomplishing the following three goals:

1. Preventing the modification of information by unauthorized users.

2. Preventing the unauthorized or unintentional modification of information by authorized users

3. Preserving internal and external consistency:

  a). Internal consistency refers to a logical connection among data in the system. For example, assume that an internal database holds the number of units of a particular item in each department of an organization. The sum of the number of units in each department should equal the total number of units that the database has recorded internally for the whole organization.

b). External consistency refers to a logical connection among objects in the real world and their representations in the system. Using the example previously discussed in (a), external consistency means that the number of items recorded in the database for each department is equal to the number of items that physically exist in that department.

Availability ensures that a system’s authorized users have timely and uninterrupted access to the information in the system. Additional factors that support information system security are:

  • Authenticity: The confirmation of the origin and identity of an information source.
  • Identification: A user claiming an identity to an information system
  • Authentication: The confirmation and reconciliation of evidence of a user’s identity .
  • Accountability: Assigning responsibility for a user’s actions
  • Privacy: Protection of individually identifiable information
  • Organizational Security Policy: A high-level statement of management intent regarding the control of access to information and the personnel authorized to receive that information.

Availability:

  • Availability is best ensured by rigorously maintaining all hardware, performing hardware repairs immediately when needed and maintaining a correctly functioning operating system environment that is free of software conflicts. It’s also important to keep current with all necessary system upgrades. Providing adequate communication bandwidth and preventing the occurrence of bottlenecks are equally important. Redundancy, failover, RAID even high-availability clusters can mitigate serious consequences when hardware issues do occur. Fast and adaptive disaster recovery is essential for the worst case scenarios; that capacity is reliant on the existence of a comprehensive disaster recovery plan (DRP). Safeguards against data loss or interruptions in connections must include unpredictable events such as natural disasters and fire. To prevent data loss from such occurrences, a backup copy may be stored in a geographically-isolated location, perhaps even in a fireproof, waterproof safe. Extra security equipment or software such as firewalls and proxy servers can guard against downtime and unreachable data due to malicious actions such as denial-of-service (DoS) attacks and network intrusions.
  • ACCOUNTABILITY – holds user accountable. Can be Audited.
Add a comment
Know the answer?
Add Answer to:
1. Explain the cuckoo’s egg exploit using the 4 security tenets of confidentiality, integrity, availability, and...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Cuckoo's Egg: Tracking a Spy Through the Maze of Computer Espionage Explain the cuckoo’s egg exploit...

    Cuckoo's Egg: Tracking a Spy Through the Maze of Computer Espionage Explain the cuckoo’s egg exploit using the 4 security tenets of confidentiality, integrity, availability, and accountability.

  • The discussion: 150 -200 words. Auditing We know that computer security audits are important in business....

    The discussion: 150 -200 words. Auditing We know that computer security audits are important in business. However, let’s think about the types of audits that need to be performed and the frequency of these audits. Create a timeline that occurs during the fiscal year of audits that should occur and “who” should conduct the audits? Are they internal individuals, system administrators, internal accountants, external accountants, or others? Let me start you: (my timeline is wrong but you should use some...

  • A new version of the operating system is being planned for installation into your department’s production...

    A new version of the operating system is being planned for installation into your department’s production environment. What sort of testing would you recommend is done before your department goes live with the new version? Identify each type of testing and describe what is tested. Explain the rationale for performing each type of testing. [ your answer goes here ] Would the amount of testing and types of testing to be done be different if you were installing a security...

  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

  • Write down your analysis of this case on factors like 1. the negotiation process, strategy and...

    Write down your analysis of this case on factors like 1. the negotiation process, strategy and tactics PACIFIC OIL COMPANY (A)* "Look, you asked for my advice, and I gave it to you," Frank Kelsey said. "If I were you, I wouldn't make any more concessions! I really don't think you ought to agree to their last demand! But you're the one who has to live with the contract, not me!" Static on the transatlantic telephone connection obscured Jean Fontaine's...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT