IT/CYSE 200T

Cybersecurity, Technology, and Society

A big benefit of the NIST Cybersecurity Framework is being able to understand the cybersecurity risks that any organization might have. The CSF Core allows those who are not experts in cybersecurity to understand the risks that are involved. The CSF Tiers provides context on how the organization views risks and what is in place to manage those risks. The Quick-Start Guides are also very helpful. They help organizations get a brief description of what they might need to get started on their cybersecurity improvement path. The guides can also be revised on their own timeline, depending on what the company needs. New guides can also be added as needed. 

At my future workplace, using the CSF Core, I could be the one to explain the risks and detail the outcomes to someone who might not be in the cybersecurity field. I would need to make sure I use a common language to explain to them so they understand the impact it could have. Using the CSF Tiers, I could put the different risks at different levels to provide a context on what is most important and what is least important. Lastly using the Quick-Start Guides, I would use that to get a brief description on what I would use first to get a company started on their path on improving what cybersecurity risk they might have. I can also use that to revise for the future and use more guides, if needed.

Discussion Board: Malicious Code –

The researchers in the article found key DNA sequencing and analysis software weaknesses that could lead to cyberattacks. As proof, they inserted malicious code into a synthetic DNA sample and showed that they could turn that biological information into electronic data, which could be used to exploit the buffer overflow vulnerability in the software. Since DNA technologies are increasingly being used in conjunction with digital technologies, organizations should realize that DNA data is a possible vector for attack.

Isolation strategies are crucial for mitigating the effects of B2D cyber-attacks. To isolate the software used for DNA analysis, the researchers advocated certain “sandboxed” environments such as virtual machines (VMs) and containers, from the critical systems. These technologies provide controlled environments, which limit access of unauthorized companies to sensitive data and networks since all software processes are isolated in systems.

The ethical and security concerns of inputting biological data, such as fingerprints, as untrusted information are important. The researchers said DNA should be treated like files from strangers, as it may be used to create executable digital data. This perspective challenges the vicious thinking that biological samples are intrinsically safe. The attitude fosters more robust validation processes, secure software engineering, and spurs awareness of new and evolving bio-cybersecurity risks.

The fusion of innovative genomics technology and a prepared cybersecurity approach is crucial for organizations to maintain. DNA sequencing can introduce unforeseen security risks in the interaction between biotic and technological worlds. Hence, addressing these concerns by incorporating risk assessment, secure coding, and system monitoring components into genomic research can make an impact. A balanced approach will promote the required scientific discovery while safeguarding research infrastructure from changing threats.  

Discussion Board: Cybersecurity and Criminal Justice –

In the first reading, Oesteraas says that because different professions have different understandings of the concept of cybercrime, they are uncertain which jurisdiction the crime should fall under and how severe it should be. Another issue with jurisdiction is if the offenders are all across the world. Cyberattacks can be launched from anywhere, targeting people outside of their country. Investigations by both countries would be needed to identify the people and prosecute them. Each country has its own ways of solving crimes, which can hinder traditional enforcement strategies. One traditional crime that has become more difficult to prosecute is stalking (cyberstalking). People can hide their identities and location using VPNs. They would also need evidence of the crime, and the perpetrator could easily erase it before the police could secure it. With a lack of evidence, the stalker can easily return to stalking the same person or choose to stalk someone else.

Based on the second reading, conducting research takes much more time than committing a technology-related crime. Researchers want to understand how an individual commits a crime and why they commit crimes. They also need to conduct testing on their research, which takes a lot of time. Technology-connected crimes can be committed with the touch of a button, creating a lag in technology-related crime and criminal justice research. 

One of the specialized courses could be “Cybercrime and Forensics,” which bridges the gap between social science and STEM disciplines. It studies both human behavior (social science) and technical systems (STEM). 

In my opinion, if the money allows it, there should be a “cyber unit”. Having people who specialize in dealing with cybercrimes will help make a more unified decision about what judgment to pass on to criminals and will ensure they know how to handle digital evidence.