Question
ASSIGNMENT Dissect a new service proposed for the environment. Research and map out the protocol and information flow. Provide recommendations with associated risks to each recommendation. Multiple options should be presented to allow for business decisions to be made based on acceptable risk levels. Mitigation options should be provided where possible to improve security with each decision point. The new service is a human resources platform. The platform includes a web interface (HTTP) with a backend database. The information maintained includes not only personally identifiable information, but also HR sensitive discussions with employees. Access to this system is highly restricted as it is very important to protect the data appropriately. The specific HR representative for an employee and their management has access to specific records for that employee to assist them with any concerns. The network is segmented to enable system isolation. The architecture proposed may make use of physical segmentation as well as features provided through virtualization, micro-segmentation, access controls, and encryption. Include a detailed diagram and description of the security protection. As the interface description is simple, this should be completed on a single page. The following are the recommended material that was provided with the assignment: Frameworks NIST Cyber Security Framework. https://www.nist.gov/cyberframework NIST SP 800-53 (FISMA). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf ISO27001/2 (Limited access due to paywall). https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-2:v1:en The following are informative references to be used when determining control implementation options and understanding the architectural considerations and risks. NIST Platform Firmware Resiliency Guidelines. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-193.pdf BIOS Integrity Measurement Guidelines (Draft). https://csrc.nist.gov/files/pubs/sp/800/155/ipd/docs/draft-sp800-155_dec2011.pdf NIST 800-160: Systems Security Engineering Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v1.pdf NIST SP800-190 Application Container Security Guide. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-190.pdf