Question

Southern New Hampshire University

ICYB 200 Module Three Case Study Template

After reviewing the scenario in the Module Three Case Study Activity Guidelines and Rubric document, fill in the table below by

completing the following steps:

7

1. Specify which Fundamental Security Design Principle applies to the control recommendations by marking the appropriate

cells with an X.

2. Indicate which security objective (confidentiality, availability, or integrity) applies best to the control recommendations.

3. Explain your choices in one to two sentences with relevant justifications.

Control Isolati Encapsula Comple

Recommendation on

tion

te

Media ti

on

Deploy an

automated tool on

network perimeters

that monitors for

unauthorized

transfer of

sensitive

information and

blocks such

transfers while

alerting information

security

professionals.

Monitor all traffic

leaving the

organization to

detect any

unauthorized use.

Control

Recommendation

Use an automated

tool, such as host

based data loss

prevention, to

enforce access

controls to data

even when data is

copied off a

system.

Physically or

logically

segregated

systems should be

used to isolate

higher risk

software that is

required for

business

operations.

Make sure that only

the resources

necessary to

perform daily

business tasks are

assigned to the end

users performing

such tasks.

Isolati

on

Encapsula Comple

tion

Minimize

Trust

Surface

(Reluctanc

e to Trust)

te

Media ti

on

Southern New Hampshire University

Trust

Relationsh

Securit

ips Object

ve

Minimize

Trust

Surface

(Reluctanc

e to Trust)

Trust

Relationsh

ips

Alignm

ent

(CIA)

Securit

y

Object

ve

Alignm

ent

(CIA)

Explain Your

Choices

(1-2 sentences)

Explain Your

Choices

(1-2 sentences)/nControl

Recommendation

Install application

firewalls on critical

servers to validate

all traffic going in

and out of the

server.

Require all remote

login access and

remote workers to

authenticate to the

network using

xutester

authentication.

Restrict cloud

storage access to

only the users

authorized to have

access, and include

authentication

verification through

the use of multi-

factor

authentication.

Make sure all data-

in-motion is

encrypted.

Control

Recommendation

S

Set alerts for the

security team when

users log into the

network after

normal business

hours, or when

users access areas

of the network that

are unauthorized to

them.

Isola ti

on

Southern New Hampshire University

Encapsula Comple

tion

te

Media ti

on

Minimize

Trust

Surface

(Reluctanc

e to Trust)

Isolati Encapsula

on

tion

Southern New Hampshire University

Comple

te

Media ti

on

Trust

Relationsh

ips

Minimize

Trust

Surface

(Reluctanc

e to Trust)

Trust

Relationsh

ips

Securit

y

Explain Your

Choices

Object (1-2 sentences)

ve

Alignm

ent

(CIA)

Securit

y

Object

ve

Alignm

ent

(CIA)

Explain Your

Choices

(1-2 sentences)/nSouthern New Hampshire University

After you have completed the table above, respond to the following short questions:

1. Is it possible to use DataStore and maintain an isolated environment? Explain your reasoning.

2. How could the organization have more effectively applied the principle of minimizing trust surface with Datastore to

protect its confidential data? Explain your reasoning.

3. How can the organization build a more security-aware culture from the top down to prevent mistakes before they

happen? Explain your reasoning.

Question image 1Question image 2Question image 3