CYSE 200T Coursework

  • Write-up: Components of a Business

One component of business is value-creation. This is discovering what people need, want, or could be encouraged to want, then creating it. This would fit in the product development component of an organization. Another component of business is market analysis and this would fit into the sales, marketing, and customer service. Market analysis is the gathering of information such as market trends, demographic info, and purchasing behavior, to better understand their customers which helps to meet consumer expectations.

I feel IT would fit into the cybersecurity part of a business; both are meant to protect an organization from threats as well as work with all different components of a business to ensure integrity and compliance. Key roles and responsibilities of IT within an organization include infrastructure and support, data security, innovation, and efficiency. IT should be organized in a way that makes sense for the particular organization. IT should be structured around clear functions such as infrastructure or security, as well as aligned with the goals of a business. Establishing standard operating procedures and helping foster communication between employees within an organization is important role of IT as well. Overall, how IT should be organized mainly depends on what your business is and what the businesses goals are. For example, Walmarts IT structure will be vastly different the IT structure of a small coffee shop because Walmart has locations globally, millions of consumers, and a major online retail presence. A small coffee shop has maybe hundreds of customers locally, and a much smaller online presence.

  • Write-up: SCADA Systems

Regarding critical infrastructure systems, there are multiple vulnerabilities that must be addressed. One vulnerability would be the use of legacy systems and old protocols: a lot of SCADA components rely on outdated operating systems as well as outdated protocols that do not have the needed encryption or authentication methods to ensure protection of these systems. Another vulnerability/threat, as stated in the article “SCADA Systems” is that there is “no security on actual packet control protocol”. This means anyone sending packets to a SCADA device could potentially gain control over that device, which therefore could compromise an entire system. Other vulnerabilities as stated in the article “Cybersecurity of Critical Infrastructure With ICS/SCADA Systems” include unpatched software, weak authentication methods, and lack of network segmentation. Misconfigurations are also a vulnerability. “Additionally, misconfigurations and Internet-exposed devices can create openings for cyber attackers to exploit, potentially compromising the safety and reliability of autonomous vehicles” (IEE).  

SCADA applications can help to mitigate these risks, one way being real-time monitoring and alerts. This allows operators to be able to immediately detect abnormal behavior within critical infrastructure systems and act. Another way to mitigate these risks is access control and authentication. SCADA systems implement RBAC as well as MFA to restrict access to critical systems. This allows only authorized personnel to have access, which is important for security and safety purposes. Encryption and secure protocols, as well as incident response and data logging, are other ways SCADA systems can help mitigate risk.  

SCADA systems are necessary to protect critical infrastructure which keeps our nation operational. If these systems are compromised, it could cause devastating real-world consequences on a large scale, ranging from industrial disruptions to environmental disasters to even the risk of human life. It is important that these systems and devices are protected to ensure continuity and safety. 

  • Write-up: The CIA Triad

The CIA Triad is a model that most organizations use to guide policies for information security. The three elements of the CIA Triad; confidentiality, integrity, and availability, are the foundation for protecting organizations and their systems. These three things work in unison to ensure data is “secure, accurate, and accessible” (What is The CIA Triad).   

Confidentiality is used to protect sensitive information from unauthorized access attempts, while integrity is the consistency and accuracy of data over its whole lifecycle. Integrity also ensures that “data remains accurate, authentic, and unaltered during storage or transmission” (What is The CIA Triad). Avialbilty is the assurance that systems, networks, and data, are all accessible to authorized users. Disruptions regarding availability can stop operations and cause major losses to an organization.  

Authentication is used to confirm a user’s identity, while authorization controls what resources the verified user can access once their identity is confirmed. An example of this would be when you log in to your bank account from your mobile device. Once you enter your username and password, that is authentication because it verifies your identity to access the app. Then, when you view your account balance, that is authorization. You can’t view other people’s accounts or information; you are only authorized and have access to your own information.