The common criteria address these four problems of tcse

Assignment Help Computer Networking
Reference no: EM13855656 , Length: 2000 words

Question 1: The Trusted Computer System Evaluation Criteria (TCSEC) had several drawbacks. They include: 


(1) It only addressed confidentiality aspects and not integrity and availability of security; 
(2) It focused on operating system products; 
(3) Its evaluation process was too slow; and 
(4) It suffered from Criteria Creep. 

Recall that criteria creep is the process of refining evaluation requirements as the industry gains experience with them, making the evaluation criteria something of a moving target. (See Section 21.2.4.2 of Bishop) 

How well did the Common Criteria (CC) address these four problems of TCSEC? 

Question 2: This question is on Vulnerability Analysis as discussed in INFA670 Session 4. The vulnerability analysis, in practical terms, is to find what software and services are running in your enterprise, whether various systems and applications in your enterprise are properly patched, and whether they are configured correctly and, as the name indicates, what vulnerabilities exist in various infrastructure components and applications and the significance of the vulnerabilities discovered. 

For this exercise, assume that you are a security officer for a large networked enterprise consisting of thousands of IP addresses (hosts, servers and devices) running thousands of services and applications on those machines. 

Discuss in detail one vulnerability analysis tool that is suitable for this (deployment) environment. Justify to your CTO or CIO why the tool you have selected is appropriate for this environment from the perspectives of: 

  • Mapping: Determining what is running where

• Ability to identify versions and patches (or lack of them) of software 
• Vulnerability Analysis (both false positive and false negative aspects should be considered) 

  • Usability

• Performance (Is it taking a whole day to run? Or is it bringing down a system?) 

  • Cost

You may consider one of the tools discussed in the Section 4 Discussion Forum such as SAINT (Security Administrator's Integrated Network Tool), beyondtrust Retina suite of products, and Tenable Network Security Nessus (and their derivatives). You have the liberty to consider open source or free products such as OpenVAS. You may also consider products not discussed in the class. (You may decide you need a suite of tools. That is fine too.) 

State your assumptions/restrictions about the tool clearly. For example, the tool could not be employed beyond the firewall. Another example is the type of privilege the tool needs to have in order to be successful. 

Question 3 :The CMMI® Model for Development has several process areas (PAs), 22 in Version 1.3 to be exact. For this exercise, we will consider the following 4 PAs: (1) Configuration Management, (2) Organizational Training, (3) Requirement Management, and (4) Risk Management. These 4 PAs are also applicable for CMMI for Services and CMMI for Acquisition. Let us suppose you are interested in achieving a higher "Capability Level" in these process areas in one project or several projects in your enterprise. (If your enterprise does not develop any software, consider improving the services you offer or acquisitions you make.) For each of these four PAs, 
1. Briefly describe what the process area is and why it is needed. Enumerate improvements you expect to see for these process areas in your enterprise. 
2. Describe specific goals for the process area. 
3. List resources/tools you may use to assist or automating the process area. 

Provide all above three answers in saparate document along with references. Write your response in 2000 words count total including all three answers

Verified Expert

Reference no: EM13855656

Questions Cloud

Principles of marketing : Principles of Marketing
Target marketing and swot analysis : Target Marketing and SWOT Analysis
Estimate survival in patients : A study is conducted to estimate survival in patients following kidney transplant. Key factors that adversely affect success of the transplant include advanced age and diabetes. This study involves 25 participants who are 65 years of age and older..
Product and competitive advantage : Product and Competitive Advantage
The common criteria address these four problems of tcse : Recall that criteria creep is the process of refining evaluation requirements as the industry gains experience with them, making the evaluation criteria something of a moving target. (See Section 21.2.4.2 of Bishop) How well did the Common Criteria (..
Identify a theory or idea from a non-business course : Identify a theory or idea from a non-business/non-MIS course that relates to concepts in IT. Explain where it came from, what it is, and how it relates to MIS/IT.
Steps in maintaining chain of custody for digital evidence : List the steps in maintaining chain of custody for digital evidence? Why is important to follow the chain of custody when gathering evidence
Wrote using ethical scholarship visual aesthetics proper : Wrote using ethical scholarship, visual aesthetics, proper grammar, and mechanics.
Discuss the differences between gaap and ifrs : Discuss the differences between GAAP and IFRS: What are implications of the differences in financial reporting? What are two advantages and two issues with each?

Reviews

Write a Review

Computer Networking Questions & Answers

  Write a paper on security architecture and design

Write a paper on Security Architecture and Design, Operations Security, Cryptography and Business Continuity and Disaster Recovery Planning.

  Network security

A firewall is generally set up to protect a particular network or network component from attack, or unauthorized penetration, by outside invaders. However, a firewall also may be set up to protect vital corporate or institutional data or resource..

  Decision-making process to help the company grow

How would you utilize this information in the decision-making process to help the company grow?

  Communication on global, national, and local levels

The Internet empowers enhanced communication on global, national, and local levels. With all of the positive aspects, by its very design the Internet is very difficult to control and over time various societal and legal issues have arisen.

  Compare and contrast the design process of a cell phone

Compare and contrast the design process of a cell phone interface using paper prototyping versus a tool such as Microsoft Visio, open source wireframing or mockup tools. Identify which method you would prefer to use, and why

  Give your opinion on whether or not the argument that

value please respond to the followingbullassess bcp as a process that adds business value. give your opinion on whether

  Security issues

Provide an example explaining the best use of Virus, Encryption, VPN, Firewall securities, when and why?Which security areas you are using and applying to your securities? Also explain why?

  Suppose a client computer with ip address 1271929230 in

suppose a client computer with ip address 127.192.92.30 in building zz requests a large web page from the server in

  Discuss the design approach that will control traffic flow

Discuss the design approach that will control traffic flow, hence improving performance. Use diagrams where possible support your discussion points.

  Web server with one cpu that serves web requests

Suppose a web server with one CPU that serves web requests; each web request requires three (time) units of CPU processing and 9 (time) units to read data from disk.

  About the research proposal paper

With this assignment, you will develop the first section of your Research Proposal paper for this course. Your paper will follow the standard outline of the proposal for the Directed Research Project (DRP).

  Count back from the secondary after last frame

If the poll bit is on in the sixth frame, what will be the N(R) count back from the secondary after the last frame? Assume error-free operation.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd