Reference no: EM134014679
INSIDE THE MIND OF A HACKER
Title - Offensive and Defensive Security Audit
LO 1: Critically analyse the various tactics that hackers use in breaching communication networks.
LO 2: Deconstruct and critically analyze the profit models, value chain, and standard business security practices from the viewpoint of a hacker.
LO 3: Recommend processes and practices to reduce the likelihood of data breaches.
Purpose
There are two tasks in this assessment and involves exploring the multiple ways in which a business or an organisation's security vulnerabilities can be exploited. You will be required to defend against such attempts to disrupt a hacking attack and secure the organisation's vulnerabilities (defensively) and by thinking like an offensive actor (or hacker).
Task details
For Task 1, analyse the security vulnerabilities of your selected organisation and outline a possible hacking execution plan (2500 words).
Choose one business or organisation from the three provided briefs below. Focus on the details within the brief. If essential information is missing, make reasonable assumptions and clearly state and explain them.
In task 2, you are required to record a two-minute video/voice message to your target organisation. This message should let the organisation know about your hack. Refer to the instructions for more topics of discussion to be included in your message.
Instructions
Task 1
Task 1 requires the detailed analysis of your chosen organisation's security vulnerabilities and the development of a possible hacking execution plan (total 2500 words). Below a suggested research and content divisions to help you kickstart your analysis:
Vulnerability analysis (identify three possible ways to breach the security of the organisation, and for each identified breach method):
identify the type of data you will attempt to obtain
discuss the potential target with respect to approach points
elaborate on your motivation behind the hack (i.e. from a hacker's perspective)
list the impacts of your chosen security breach on the organisation (i.e. financial costs, brand distortion, impact on employees)
identify a hacker or hacking group that could possibly be associated with this form of attack describe an example of where a similar approach has been used in a similar context.
Security plan (based on your chosen vulnerabilities, propose a security plan that can be implemented by your organisation to reduce exposure and your security plan should include the following):
focus on the social and organisation elements of ensuring good security, and the trade-offs between security and freedom.
suggest three approaches this organisation could take to enhance their cybersecurity, and for each approach discuss the:
resources required to implement this framework
evaluation of the effectiveness versus costs of your proposed security plan ability of the proposed framework to cover multiple vulnerabilities implications on the organisation and their core business
trade-offs between security, privacy and freedom.
Consider concepts related to Data Communication And Networking when evaluating how attackers may gain access to organisational systems and communication channels.
how does the global environment around hacking improve or complicate your defence plan?
discuss the role of the local and global hacking community and provide an example that could help you.
Security governance and risk management may also be examined through the lens of Information Technology And System practices within modern organisations.
Execution plan (select one of the possible options from the vulnerability analysis (above) and develop an execution plan. Your implementation plan should detail):
the resources required for this attack and how you will obtain them (e.g. tools, money, time, people) methodology for the attack, both technical and non-technical
the timeline for the planned attack and a step-by-step approach
a discussion of the impacts of your hacking attack on the organisation.
Where organisational data repositories are involved, reference to Database Management Dbms concepts may support the analysis of potential targets and data exposure risks.