Discretionary access control and mandatory access control, Risk Management

Assignment Help:

Question:

(a)

(i) Explain what is meant by Discretionary Access Control and Mandatory Access Control.

(ii) What is the difference between the two types of access control?

(iii) Which method would be the most effective to ensure that users do not share files with other users not approved for access?

(b) Outline the three differences between the Liberty Alliance specification and the Microsoft .NET Passport System.

(c) Which of the following options below would be the MOST effective solution for preventing individuals outside the organization from modifying sensitive information on a corporate database. Explain the reasons for choosing one option and for rejecting the other two options.

Option 1: Screened Subnets
Option 2 : System access logs
Option 3: Role based access controls

(d) (i) Where should the Intrusion Detection System be placed on a network?

(ii) Identify one main weakness of signature based Intrusion Detection Systems.

(iii) Explain what is the main objective of network mapping when conducting a penetration test?

(iv) When is the best time to perform a penetration test?


Related Discussions:- Discretionary access control and mandatory access control

Currency hedging for exporting and importing company, I want an assignment ...

I want an assignment on a exporting and importing company and how does it do currency hedging and reduce the risk of currency fluctuation

What is the maximum amount of money the company, The marketing department o...

The marketing department of a vitamin water company wishes to determine the maximum expected payoff from introducing a new strawberry drink. What decision, in terms of choosing the

Safety and health policy, Question: Under Section 6 of the Occupational...

Question: Under Section 6 of the Occupational Safety and Health Act 2005, employers have a statutory duty to prepare and keep revised a written statement of their safety and he

What is industry risk, What is Industry Risk An industry may be view...

What is Industry Risk An industry may be viewed as group of companies which compete with each other to market a homogeneous product. Industry risk is that portion of an  inv

Explain extension and contraction risk, Question 1 (a)  Prepayment r...

Question 1 (a)  Prepayment refers to paying principal on a security before the due date. Prepayment risk is the risk associated with the early unscheduled return of principal

Implementation of risk management strategy, Evaluate risk management criter...

Evaluate risk management criteria against which risk can be assessed • Key factors to take into account in risk identification Critique techniques to identify and quantify ri

Underwriting Principles, Which of the following statements about group insu...

Which of the following statements about group insurance underwriting principles is (are) true? I. If a plan is contributory, 100 percent of the eligible employees must be covered.

Fixed income risk management, Fixed Income Risk Management You are a...

Fixed Income Risk Management You are asked in this assignment to insure the value of a bond portfolio during the (in hindsight) turbulent 8-month (or 245-day) period from 1

firms risk management strategies-tactics , 1. You are to analyze:  [1] in...

1. You are to analyze:  [1] internal financial options offered to employees as a benefit, [2] the external financial options that are offered by markets to outside investors who ma

describe a risk-free strategy and delta-hedging position, Explain how you ...

Explain how you would hedge a short position in a European (plain vanilla) call with six  weeks to maturity if the spot price is 60, the strike is 65 and σ = 0.3, r=0.1. You rehedg

Write Your Message!

Captcha
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd