IT/CYSE 200T

Cybersecurity, Technology, and Society

Students in IT/CYSE 200T will explore how technology is related to cybersecurity from an interdisciplinary orientation.  Attention is given to the way that technologically-driven cybersecurity issues are connected to cultural, political, legal, ethical, and business domains. The learning outcomes for this course are as follows:

  1. Describe how cyber technology creates opportunities for criminal behavior,
  2. Identify how cultural beliefs interact with technology to impact cybersecurity strategies,
  3. Understand and describe how the components, mechanisms, and functions of cyber systems produce security concerns,
  4. Discuss the impact that cyber technology has on individuals’ experiences with crime and victimization,
  5. Understand and describe ethical dilemmas, both intended and unintended, that cybersecurity efforts, produce for individuals, nations, societies, and the environment,
  6. Describe the costs and benefits of producing secure cyber technologies,
  7. Understand and describe the global nature of cybersecurity and the way that cybersecurity efforts have produced and inhibited global changes,
  8. Describe the role of cybersecurity in defining definitions of appropriate an inappropriate behavior,
  9. Describe how cybersecurity produces ideas of progress and modernism.

My Work

Write up 1- Managing Chief Information Security Budget
Balancing the budget between training and additional cybersecurity technology can be quite achallenge. As a Chief Information Security Officer (CISO) to allocate limited funds I would firstassess the capabilities and risk of the organization and from that assessment prioritize thecritical needs of the organization. From there, I would distribute my resources to focus oninvesting in training programs to reduce human error, and continue to adjust and improve theorganization as needed.
Assess Risk and CapabilitiesAs CISO my first step to allocate limited funds between training and additional tech would be tofirst access the risk and capabilities of the organization. By obtaining an assessment on thecompany’s cyber structure, risk, infrastructure, tech, and employee skill level, I will be able togain a better understanding at what the strengths and weaknesses of the organization are.
Prioritize Critical NeedsAfter developing an assessment of the organization, I would then focus on what critical needsneed to be addressed within the organization. Factors such as chances software, hardware, access
control, education training, threat detection, etc are all things that need to be taken under
consideration when addressing these critical needs.After identifying the critical need of the organization it will help to narrow down how todistribute the budget and whether or not to focus more on investing in traditional cyber tech tobenefit the company or focus on training programs to help develop the skill of employees.
Human ErrorCybercriminals often target human vulnerabilities for cyber attacks, data breaches, etc. When wemake errors it directly contributes to risk that makes these cyber attacks easier. To prevent this Iwould focus on managing my budget so that more money is spent towards mitigating human erosin turn leading to less cyber attacks. By investing in training programs for employees it can allowfor them to become more educated on cyber security in turn leading to a safer and more securecompany.
Adjust and ImproveAfter figuring out the strengths and weaknesses of the company, seeing the critical needs of thecompany, and prioritizing reducing human error, I would then look to continue to adjust andimprove the organization with the remaining budget.Although most of the funds went toward human errors, finding cost effective cyber tech can helpto provide a strong security without needing the extra money. Also seeing that cybersecurity in a

long term process and not a one time investment is crucial. Using funds to continue the
development of staff and tech is a necessity to fight against the ever changing cyber attacks.CISO is a hard task and not knowing the basic cybersecurity practices and functions could leadto the downfall of a company. When managing a budget between training and tech it is importantto know what the company does well in and what it needs to improve on. After finding that outyou are able to make decisions on how to spend your budget and know which is more beneficialto the company.

Write up 2- How SCADA Systems Protect from Vulnerabilities

There are many vulnerabilities that can have a negative effect on critical infrastructure systemssuch as failure to identify and protect a security perimeter, cyber attacks, unauthorized access,etc. Because of this, there are systems put in place to help mitigate these threats such as theSupervisory Control and Data Acquisition, also known as SCADA. SCADA systems are effectivein mitigating these vulnerabilities because they provide access control and authentication,firewalls, endpoint protection, etc.
Critical Infrastructure
Critical Infrastructure are the systems, facilities, and assets that are necessary for the economyand society. These systems are so important because they help to manage public safety, health,and the economy. Because critical infrastructure is so vital for society and the economy, countries must follow strict rules and regulations when managing it. It’s important for those who manage critical infrastructure to be up to date and the pest practices and regulations to keep thenecessary security for these systems.
VulnerabilitiesSince critical infrastructure systems play a crucial role in our society, they are also a primarytarget for attacking. Some vulnerabilities related to the system include cyber attacks, outdatedtech, and security.

Because of our human advancements and us relying on tech, infrastructure systems are more
vulnerable to cyber-attacks. Attackers can find problems within the network, software orhardware to disrupt these systems and steal sensitive information causing even more damage.Cyber-attacks on infrastructure systems can also lead to huge financial losses. Because of theattacks the systems have to pay repair costs and any other factors that contributed to loss ofrevenue.Systems with outdated tech may be more likely to suffer from hardware glitches, software.failures and performance issues. Because of this service downtime or interruptions within thesystems can arise causing problems for the system. Another problem that arises with outdatedtech is that those systems may not be compatible with modern systems making it more difficultto integrate with newer infrastructure systems. Outdated technology can interfere with advancement and the adoption of emerging technologies that could strengthen critical infrastructure systems. Because of this organizations may struggle to adapt to evolving threats and operational challenges.Security plays a crucial role in ensuring the protection of infrastructure systems. If aninfrastructure system has poor security then it is more likely to cyber attacks and stoleninformation. Another problem that arises with poor security is that it can lead to a loss in publictrust. If a system is constantly getting hit with cyber threats or attacks then the public will losetrust in that service. By implementing a good security system it will help to negate theseproblems and allow for an improved system.

SCADA Systems
Supervisory Control and Data Acquisition or SCADA refers to the systems that look over andcontrol the entirety of a site. “Nearly all the control actions are automatically performed by theremote terminal units (RTUs) or by the programmable logic controllers (PLCs).” (SCADASystems pg1). The host has control over functions for usage of intervention or overriding. Data isaccumulated at PLC/RTU level and from there the operator in the control room can then makechanges to the PLC/RTU controls via HMI. “The HMI, or Human Machine Interface, is an apparatus that gives the processed data to the human operator. A human operator uses HMI to control processes.” (SCADA Systems pg 2) , meaning that once the processed data is in the hands of the operator they can then use the HMI to make changes as they see fit. The HMI helps to provide diagnostics of data, management information, trending information, detailed schematics, etc.SCADA systems can be very beneficial systems as they are helpful in protecting critical infrastructure systems which are essential for society.
Mitigating VulnerabilitiesSCADA does well to mitigate threats related to critical infrastructure systems because theydemonstrate good control, management and monitoring capabilities. For example SCADAsystems use master stations. “Master stations can have multiple servers, disaster recovery sites,and distributed software applications in larger SCADA systems. For increasing the systemintegrity, multiple servers are occasionally configured in hot-standby or dual-redundantformation, providing monitoring and continuous control during server failures.”(SCADASystems pg 4), thus showing how the system can be in constant watch of cyber attacks and even if the attack is to work the system has recovery sites to minimize the damage. No matter what
threat is thrown their way the SCADA can be in control of everything. Scada systems alsoimplement advanced security systems such as encryption protocols, authentication mechanisms,intrusion detection systems, etc. SCADA systems help to mitigate the threats of cyber attackbecause of how secure it is. Scada systems are also not outdated, “SCADA systems are now inline with the standard networking technologies. The old proprietary standards are being replacedby the TCP/IP and Ethernet protocols.”(SCADA Systems pg 4), with SCADA systems being upto date it has better system performance and is less prone to downtime or server interruptions.Scada systems are used by organizations to allow them to be as efficient as possible. Theft is avery useful tool for protecting against vulnerabilities to infrastructure systems. Because of all thetime and effort that was put into the development of these systems they are effective in havingreliable security, protecting against cyber attacks, managing data, communication, etc. All thefactors are contributors to the Scada system’s success.
Discussion Board Post- In this discussion board, you are the CISO for a publicly traded company. What protections would you implement to ensure availability of your systems?
Some protections I would implement to ensure availability of my systems is ddos protection and also backup systems. Since ddos attacks lead to service outages implementing this protection system will lead to our services still being available even under an attack. Having backup systems in a secure location will lead to restoring systems quickly in the event that there is a system failure.