Distinguish between vulnerability threat and control

Assignment Help Management Information Sys
Reference no: EM131239602

1. Distinguish between vulnerability, threat, and control.

2. Theft usually results in some kind of harm. For example, if someone steals your car, you may suffer financial loss, inconvenience (by losing your mode of transportation), and emotional upset (because of invasion of your personal property and space). List three kinds of harm a company might experience from theft of computer equipment.

3. List at least three kinds of harm a company could experience from electronic espionage or unauthorized viewing of confidential company materials.

4. List at least three kinds of damage a company could suffer when the integrity of a program or company data is compromised.

5. List at least three kinds of harm a company could encounter from loss of service, that is, failure of availability. List the product or capability to which access is lost, and explain how this loss hurts the company.

6. Describe each of the following four kinds of access control mechanisms in terms of (a) ease of determining authorized access during execution, (b) ease of adding access for a new subject, (c) ease of deleting access by a subject, and (d) ease of creating a new object to which all subjects by default have access.

• per-subject access control list (that is, one list for each subject tells all the objects to which that subject has access)

• per-object access control list (that is, one list for each object tells all the subjects who have access to that object)

• access control matrix

• capability

7. Suppose a per-subject access control list is used. Deleting an object in such a system is inconvenient because all changes must be made to the control lists of all subjects who did have access to the object. Suggest an alternative, less costly means of handling deletion.

8. File access control relates largely to the secrecy dimension of security. What is the relationship between an access control matrix and the integrity of the objects to which access is being controlled?

9. One feature of a capability-based protection system is the ability of one process to transfer a copy of a capability to another process. Describe a situation in which one process should be able to transfer a capability to another.

10. Suggest an efficient scheme for maintaining a per-user protection scheme. That is, the system maintains one directory per user, and that directory lists all the objects to which the user is allowed access. Your design should address the needs of a system with 1000 users, of whom no more than 20 are active at any time. Each user has an average of 200 permitted objects; there are 50,000 total objects in the system.

11. Give an example of the use of physical separation for security in a computing environment.

12. Give an example of the use of temporal separation for security in a computing environment.

13. Give an example of an object whose sensitivity may change during execution.

14. Respond to the allegation "An operating system requires no protection for its executable code (in memory) because that code is a  duplicate of code maintained on disk."

15. Explain how a fence register is used for relocating a user's program.

16. Can any number of concurrent processes be protected from one another by just one pair of base/bounds registers?

17. The discussion of base/bounds registers implies that program code is execute only and that data areas are read-write-only. Is this ever not the case? Explain your answer.

18. A design using tag bits presupposes that adjacent memory locations hold dissimilar things: a line of code, a piece of data, a line of code, two pieces of data, and so forth. Most programs do not look like that. How can tag bits be appropriate in a situation in which programs have the more conventional arrangement of code and data?

19. What are some other modes of access that users might want to apply to code or data, in addition to the common read, write, and execute permission?

20. If two users share access to a segment, they must do so by the same name. Must their protection rights to it be the same? Why or why not?

Reference no: EM131239602

Questions Cloud

Prices are flexible in our economy : Explain why it is important that prices are flexible in our economy? What are the implications if the government started to control prices for products, how would this influence buying?
What does price elasticity of demand equal at this quantity : A firm’s demand function is as follows: Qx = 400 - 5Px + Py - 2Pz + 2I. Assume initial values of Px = 50, Py = 20, Pz = 20, I = 50. Determine the quantity of X that will be sold assuming the initial values. Develop the corresponding Total Revenue and..
Find a lower bound on the possible degrees of the vertices : The goal of this problem is to use Euler's formula to list all possible regular polyhedra. (In this case, regular means that every face has the same number of edges and every vertex has the same degree.)
Budget line consists of all points : True or False? Explain! (a) Monopoly outcome is always inefficient, even if the monopolist cannot price discriminate. (b) The budget line consists of all points that a consumer can afford by spending all her income and among which she is indifferen..
Distinguish between vulnerability threat and control : Suppose a per-subject access control list is used. Deleting an object in such a system is inconvenient because all changes must be made to the control lists of all subjects who did have access to the object. Suggest an alternative, less costly mea..
Describe the impact of making a small increase : The volatility of a certain market variable is 30% per annum. Calculate a 99% confidence interval for the size of the percentage daily change in the variable.
The law of diminishing marginal product holds : A decentralized organizational structure is more likely to further the cause of good strategy execution than is a centralized organization structure. Variable costs will initially increase and then decrease. The law of diminishing marginal product ho..
Participants interact to ensure that goods and services : Identify the three participants in a free business market. Write a brief memo explaining these participants interact to ensure that goods and services are distributed in a manner that satisfies consumers. Your memo should include answers to the f..
Compute the thickness of the petersen graph : Give an example of a 4-regular planar graph and an example of a 4-regular non planar graph.

Reviews

Write a Review

Management Information Sys Questions & Answers

  How to judge whether it is worth processing an order

How to judge whether it is worth processing an order of $ 1,000 at a gross margin of $ 200?

  Securing an organizationdana and michael are in the weekly

securing an organizationdana and michael are in the weekly staff meeting with donna and the rest of her staff. folks we

  Bead bar systems development life cycle phasesplan a system

bead bar systems development life cycle phasesplan a system development project for the bead bar using the seven

  What social functions does the content order and preparation

In infant feeding, how do socio-cultural or economic factors affect the choice of breast feeding, the length of breast feeding or artificial feeding, the techniques of weaning, types of foods used, and maternal beliefs about the optominal size sha..

  Define and explain the web technology and big data

A key challenge to Chief Information Officers (CIOs) and their staff is the ever-changing landscape in the Information Technology world. Each member of Group B should select one of the topics listed below and then do some research. In your posting,..

  Step-wise answer to change managementwhat would you

step-wise answer to change managementwhat would you recommend to the management of a firm going global on the issue of

  Calculate the expected savings the company may expect

Calculate the expected savings the company may expect for the first five (5) years, assuming cost per user remained the same and the number of users remained constant at 1,500 users

  Analysis of togaf to either dodaf or feaf

Conduct an in-depth analysis of TOGAF to either DoDAF or FEAF. Referring to assigned readings, and adding the results of your own additional scholarly literature search and analysis, write a 6 to 8 double spaced page paper that addresses the follo..

  Describe a supportive organizational culture

Describe a supportive organizational culture and business processes for collaboration. List and describe the various types of collaboration and social business tools.

  Stretegic alliance agreements

Are supply chain management and the establishment of strategic alliance agreements with select suppliers more conducive to private sector organizations

  Determine the goals in your completed diagram

Determine the goals, in your completed diagram, that require further refinement and explain why. Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources

  Supply chain questions for a beer wholesalerquestion 1

supply chain questions for a beer wholesalerquestion 1 focus on beer as an end item for the consumer. and you have to

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd