Part 2: As your final assignment of the term you should imagine that you are the manager of information security for a mid-sized company and have been asked to deliver a 10 slide presentation to the company’s leadership team related to the information security risks related to WIFI, mobile, Bluetooth and IoT devices.
Discuss the unique risks to each of these technologies and your recommendations for the countermeasure to their common and well-known risks. Your leadership team has also asked for you to include a slide which will update the vulnerability assessment created in unit 1 to reflect new categories for evaluation that would include the addition of Bluetooth and IoT devices (this slide will summarize the changes you would make to the vulnerability assessment completed in unit 1). Please provide a 10 slide PowerPoint presentation that includes a cover slide with your name and unit number, content slides to support the part 2 assignment, slides containing your LabSimscreen shots, and a slide with your citations to support any research.
Vulnerability Assessment Template
How
One of the first items to consider is the type of test to be performed, internal or external. An internal test focuses on systems that reside behind the firewall. This would probably be a white box test. An external test focuses on systems that exist outside the firewall, such as a web server. This would, more than likely, be a black box test.
Who
Determine if the penetration tester is allowed to use social engineering attacks that target users. It’s common knowledge that users are generally the weakest link in any security system. Often, a penetration test can target users to gain access. You should also pre-determine who will know when the test is taking place.
What
The organization and the penetration tester need to agree on which systems will be targeted. The penetration tester needs to know exactly which systems are being tested, and as they cannot target any area that isn’t specified by documentation. For example, the organization may have a website they do not want to be targeted or tested. Some other systems that need to look at include wireless networks and applications.
When
Scheduling the test is very important. Should the test be run during business hours? If so, this may result in an interruption of normal business procedures. Running the tests when the business is closed (during weekends, holidays, or after-hours) may be better, but might limit the test.
Where
Finally, will the test be run on-site, or remotely? An on-site test allows better testing results but may be more expensive than a remote test.
Last Completed Projects
| topic title | academic level | Writer | delivered |
|---|
