The common criteria address these four problems of tcse

Assignment Help Computer Networking
Reference no: EM13855656 , Length: 2000 words

Question 1: The Trusted Computer System Evaluation Criteria (TCSEC) had several drawbacks. They include: 


(1) It only addressed confidentiality aspects and not integrity and availability of security; 
(2) It focused on operating system products; 
(3) Its evaluation process was too slow; and 
(4) It suffered from Criteria Creep. 

Recall that criteria creep is the process of refining evaluation requirements as the industry gains experience with them, making the evaluation criteria something of a moving target. (See Section 21.2.4.2 of Bishop) 

How well did the Common Criteria (CC) address these four problems of TCSEC? 

Question 2: This question is on Vulnerability Analysis as discussed in INFA670 Session 4. The vulnerability analysis, in practical terms, is to find what software and services are running in your enterprise, whether various systems and applications in your enterprise are properly patched, and whether they are configured correctly and, as the name indicates, what vulnerabilities exist in various infrastructure components and applications and the significance of the vulnerabilities discovered. 

For this exercise, assume that you are a security officer for a large networked enterprise consisting of thousands of IP addresses (hosts, servers and devices) running thousands of services and applications on those machines. 

Discuss in detail one vulnerability analysis tool that is suitable for this (deployment) environment. Justify to your CTO or CIO why the tool you have selected is appropriate for this environment from the perspectives of: 

  • Mapping: Determining what is running where

• Ability to identify versions and patches (or lack of them) of software 
• Vulnerability Analysis (both false positive and false negative aspects should be considered) 

  • Usability

• Performance (Is it taking a whole day to run? Or is it bringing down a system?) 

  • Cost

You may consider one of the tools discussed in the Section 4 Discussion Forum such as SAINT (Security Administrator's Integrated Network Tool), beyondtrust Retina suite of products, and Tenable Network Security Nessus (and their derivatives). You have the liberty to consider open source or free products such as OpenVAS. You may also consider products not discussed in the class. (You may decide you need a suite of tools. That is fine too.) 

State your assumptions/restrictions about the tool clearly. For example, the tool could not be employed beyond the firewall. Another example is the type of privilege the tool needs to have in order to be successful. 

Question 3 :The CMMI® Model for Development has several process areas (PAs), 22 in Version 1.3 to be exact. For this exercise, we will consider the following 4 PAs: (1) Configuration Management, (2) Organizational Training, (3) Requirement Management, and (4) Risk Management. These 4 PAs are also applicable for CMMI for Services and CMMI for Acquisition. Let us suppose you are interested in achieving a higher "Capability Level" in these process areas in one project or several projects in your enterprise. (If your enterprise does not develop any software, consider improving the services you offer or acquisitions you make.) For each of these four PAs, 
1. Briefly describe what the process area is and why it is needed. Enumerate improvements you expect to see for these process areas in your enterprise. 
2. Describe specific goals for the process area. 
3. List resources/tools you may use to assist or automating the process area. 

Provide all above three answers in saparate document along with references. Write your response in 2000 words count total including all three answers

Verified Expert

Reference no: EM13855656

Questions Cloud

Principles of marketing : Principles of Marketing
Target marketing and swot analysis : Target Marketing and SWOT Analysis
Estimate survival in patients : A study is conducted to estimate survival in patients following kidney transplant. Key factors that adversely affect success of the transplant include advanced age and diabetes. This study involves 25 participants who are 65 years of age and older..
Product and competitive advantage : Product and Competitive Advantage
The common criteria address these four problems of tcse : Recall that criteria creep is the process of refining evaluation requirements as the industry gains experience with them, making the evaluation criteria something of a moving target. (See Section 21.2.4.2 of Bishop) How well did the Common Criteria (..
Identify a theory or idea from a non-business course : Identify a theory or idea from a non-business/non-MIS course that relates to concepts in IT. Explain where it came from, what it is, and how it relates to MIS/IT.
Steps in maintaining chain of custody for digital evidence : List the steps in maintaining chain of custody for digital evidence? Why is important to follow the chain of custody when gathering evidence
Wrote using ethical scholarship visual aesthetics proper : Wrote using ethical scholarship, visual aesthetics, proper grammar, and mechanics.
Discuss the differences between gaap and ifrs : Discuss the differences between GAAP and IFRS: What are implications of the differences in financial reporting? What are two advantages and two issues with each?

Reviews

Write a Review

Computer Networking Questions & Answers

  Operation of one-product vending machine using semaphores

Keep track of number of products keeping in machine and amount of money customer has inserted. Two processes are utilized, one which accepts money and keeps track of amount paid.

  Describe the various transmission mediums

Describe the various transmission mediums and explain the best use of each with various examples of business use. Identify communications capabilities of each medium and the types of signals that are used for each

  Define switched backbone networks

You are the network administrator for a small manufacturing firm that runs Ethernet. You are currently using hubs and repeaters for connectivity but have decided to upgrade to a Layer 2 (L2) switched infrastructure.

  Explain public-key cryptography standard

Explain in detail how PKCS (Public-Key Cryptography Standard), when combined with the RSA algorithm, can thwart Eve's attempt at discovering the encrypted figure.

  Components that make up a network management system

Write a two-and-a-half-page paper describing the components that make up a network management system

  Cost and quality create a work breakdown structure wbs and

create a work breakdown structure wbs and assign resources and cost by using a project management tool. as the it

  Your boss calls you into his office and he is extremely

your boss calls you into his office and he is extremely angry. he was embarrassed at a meeting because he put forward a

  A residential heat pump uses the ground as an energy source

a residential heat pump uses the ground as an energy source. at a particular operating condition the heat pump delivers

  What is cgi

What is the difference between a Web server and an application server? What functionality do typical application servers provide?

  He needs to describe the pros and cons of using stp and the

the it manager for a general discount company is considering the implementation of a fully meshed switched environment

  How the web user interfaces help donors to make decisions

Explain how the Web user interfaces help donors to make decisions and relate the emotional thread demonstrated in the case study to the emotional design model as discussed in Chapter 5 of the textbook.

  Prepare a 5-7 slide presentation on the network types you

create a 5-7 slide presentation on the network types. you may use various sources including your textbook. be sure to

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd