List two types of ICT networks.
It is an assignment which has some questions and we need to write the answers with the help of learning guide which is given in my school and we can also use other resources to answer the questions but mainly using learning guide.
Requirements:
Assessment Task 1 – Coversheet
Students: Please fill out this cover sheet clearly and accurately. Make sure you have kept a copy of your work.
Task 1 – Knowledge Test
Assessment Task 1 – Knowledge Questions
Please answer the following questions. A word limit of 150 words applies to each response, unless otherwise specified.
You must read thoroughly the “Student Workbook/Learner Guide” before attempting this Task.
List two types of ICT networks. Include a description of their configuration in your answer.
Complete the following table about network attacks, vulnerabilities and security technologies.
With the expansion of cloud services and new technologies, the use of mobile devices and the Internet of Things (IoT), there have also emerged a number of security issues. List two examples of emerging security issues.
Outline the terms auditing and penetration testing that can be used to measure a network’s security.
The student must outline the terms auditing and penetration testing that can be used to measure a network’s security. Their response may include but is not limited to:
A security audit is a systematic evaluation of the IT infrastructure defences and measures how well security protocols comply with a list of established criteria to ensure network security.
Penetration testing is used to try to breach an ICT system just like a hacker would. This will therefore determine if the IT infrastructure could withstand a range of attacks.
Outline two logging analysis techniques that can be used to measure the security of a network.
Outline two types of security measures that can be put in place in a network.
List a type of software that can be used for network security and summarise its capabilities.
List a type of hardware that can be used for network security and summarise its capabilities.
Given the importance of network security, describe the key features that a network security policy should include, as well as procedures that should be included.
Outline two network management and security process controls that can be put in place to ensure network security.
Explain the importance of a risk management plan and procedures in network security implementation.
Outline the process of developing risk management plans and procedures as part of network security planning.
Explain how risk management should be built into cost analysis and budgeting of network security. Give an example to illustrate your answer.
Learner Guide ICTNWK546 Manage network security
ICTNWK546 Manage network security | 2 CONTENTS Overview 3 Topic 1: Plan security design process 4 Topic 2: Identify threats to network security 11 Topic 3: Analyse security risks 17 Topic 4: Create a security design 21 Topic 5: Design security incidents response 27
ICTNWK546 Manage network security | 3 Overview Application of the unit This unit describes the skills and knowledge required to implement and manage security functions throughout a network. It applies to individuals with Information and Communications Technology (ICT) expertise and lead the development of strategic reviews of security and provide technical advice, guidance and leadership in resolution of specified problems. No licensing, legislative or certification requirements apply to this unit at the time of publication. Learning goals Learning goals include: • plan security design process • identify threats to security network • analyse security risks • create a security design • design security incidents response.
ICTNWK546 Manage network security | 4 Topic 1: Plan security design process Planning phase for network security design Taking on a project for managing network security can be a complex task. Project management can be key to a successful ICT project. The methodologies used in project management are a series of different processes designed to assist project managers and those overseeing or involved with projects. The goal of using these methodologies is to complete the tasks required for the project faster and with strategies in place to handle problems should they arise. There are a number of methodologies and frameworks that can be used to undertake a project. They can be in phases, stages and have differing terminology. The broad phases are: An example of a methodology would be Project Management Body of Knowledge (PMBOK) which is the entire collection of processes, best practices, terminologies, and guidelines that are accepted as standards within the project management industry. Project management requires a lot of documentation which is also used to manage a project throughout its lifecycle. Different stages of the project lifecycle will require varying documents that will need to be completed, reviewed and signed off. For ICT projects the technical documentation includes mapping networks, network diagrams, survey or site maps and this can be completed using specific software or organisational templates. For example, Microsoft Visio can be used to help map network diagrams. ICT networks When defining the planning phase for a security design, it is important to understand different ICT networks and their configuration as their differences can affect the way in which the design can be implemented. ICT networks include: Project initiationProject planningProject executionProject monitoring and controlProject closureLocal area networks (LANs)Large and small LANsVirtual private networks (VPNs)Wide area networks (WANs)Wireless LANs (WLANs).
ICTNWK546 Manage network security | 5 Network topology is the layout of how a network is connected and how the different nodes within the network communicate. How a network is connected can determine security as well as costs, maintenance, functionality, fault detection, performance, hardware and software being used and the utilisation of resources within the network. Each topology is configured differently and has its advantages and disadvantages. Which one is used will be dependent on factors such as location, area, cost and organisational requirements. A typical network topology for LANs are: Bus, Star, Mesh, Ring and Hybrid The star and extend star (tree topology) are the most popular topologies for Ethernet networks. Each network will also consist of various nodes, components, devices, connections and will be physically and logically arranged according to the configuration used. Physical topologies: Physical connections between nodes and the network, cables, and other devices such as switches and routers. Logical topologies: This is how and why the network is arranged, as well as the way in which data moves around it. Network diagrams and maps are used to visually represent the design and structure of a network. These diagrams and maps show both the physical and logical layouts. It is a good way to start the planning phase. Activity: Research and discuss Using the following links, describe three networks and their configurations. Common network topologies http://www.firewall.cx/networking-topics/general-networking/103-network-topologies.html https://en.m.wikibooks.org/wiki/Communication_Networks/Network_Topologies The trainer/assessor will facilitate a class discussion about the outcomes from the research. Type up your findings and include network diagrams of the topology configurations to illustrate your responses. Keep for future reference.
ICTNWK546 Manage network security | 6 Activity: Read The following articles provide an overview of wireless topologies: Wireless topologies: http://www.ciscopress.com/articles/article.asp?p=1876001 Wireless topology: https://www.brainbell.com/tutorials/Networking/Infrastructure_Wireless_Topology.html The type of WLAN topology can affect the performance of the network: https://www.controleng.com/articles/wlan-topologies/ WLAN topology: http://www.cs.uccs.edu/~gsc/pub/master/pjfong/UCCS%20Project/Articles/IE %20802_11%20Network%20Topology.htm Wireless LAN Architecture: https://en.wikipedia.org/wiki/Wireless_LAN Take any notes to summarise what you have read and keep for future reference. Planning for network security design The planning phase is the most important aspect of any project. It will define the way in which the project will be undertaken and be used as a framework for the other stages of the project. Formal methodologies such as the SDLC are often used to guide network administrators through the stages of planning, design and development, testing and maintenance of a project. If the planning phase has been done effectively, then the project will have a good chance of success. The planning phase should include both the physical and logical connections. Defining the planning phase will include the stages needed in order to start the project. • Assessing the current network or legacy o A network diagram of the current system, or a proposed network diagram o Current network security policies o Requirements for the network security o A list of ICT assets (information, software and physical resources that the organisation currently has) o Technical specifications for all components required for the network o Details of the network architecture and processes o Data to be protected
ICTNWK546 Manage network security | 7 • Analysis of threats and risks o Impacts of risks o Network segmentation o Monitoring and prevention o Security event logging o Development of a risk management plan o Development of a network security policy • Defining the network security plan o Documenting how the network security will be designed and implemented A network security plan will be dependent upon the requirements but generally, it can include: Activity: Practical Using the RTO network, or one that you have access to, review the network infrastructure. List down as much information as you can about the network. Draw a network diagram of the current system. You could use Microsoft Visio which is a vector graphics application used to create diagrams. The following is a tutorial which can be used to learn Visio: https://support.office.com/en-us/article/a-beginner-s-guide-to-visio-bc1605de-d9f3-4c3a-970c-19876386047c The purpose of the network security designA network diagram of the current system, or a proposed network diagramCurrent network security policies Requirements for the network securityA list of ICT assets (resources that the organisation currently has in place)Technical specifications for all components required for the networkAn analysis of threats and risksDevelopment of a network security policyRisk management plan
ICTNWK546 Manage network security | 8 The following website, Creately is an editable online program that can be used to draw a diagram and then export into Viso or Word for example: https://creately.com/diagram/example/gvmhx2ae4/ICT%20Diagram Take any notes to summarise what you have read and keep for future reference. Building phase for network security design In the building phase, network administrators and security specialists use the available hardware and software to create the security system as set out in the security design. At this stage, the network security design plan can be used to support the process of the build. It can include defining how the security design will be implemented: • Physical security and how you will: o Limit physical access to key network resources o Restrict access from unauthorised personnel o Protect from disasters (both human and natural) o Protecting from misuse of network equipment o Use protection strategies for external threats such as hacking, malware or unauthorised use of data The building phase for physical security will include how you will protect demarcation points, servers, hosts, backup storage routers, modems and cabling. • Authentication o Including authentication of users and devices. This identifies who is requesting the network services. Examples are routing protocols and user authentication. • Authorisation o Controls who can access network resources and what can be done after resources have been accessed. o Includes protecting and controlling directories and files on servers. o Providing permissions to users (using principle of least privilege (POLP) where users are only given rights for certain tasks). • Auditing o How data will be collected. o The response to security incidents. o Analysing log data. • Data Encryption o Encryption for data confidentiality.
ICTNWK546 Manage network security | 9 • Public or private key encryption o Document data encryption. • Packet filters o Protects network resources from unauthorised use, DoS attacks and theft. o Set up on routers, firewalls and servers. o Based on policies to either deny or accept specific types of packets. o An example is Access Control Lists (ACL). • Firewalls o Rules defined to protect the network. o Settings for static stateless and stateful packet-filter and proxy firewalls. • Intrusion detection and prevention o Intrusion detection systems (IDS) detects malicious events, collects and analysis real time security. o Intrusion prevention systems (IPS) can block traffic using rules added to a firewall or using configurations to deny or allow traffic. o Both can detect and prevent attacks on a network. Managing phase for network security design After the security design has been implemented, the administrator is responsible for managing the design to ensure it provides the security envisioned by the security design. Since most networks grow and change, administrators must carefully consider each change as to how it impacts on the security design. Managing the network security design can include: • using network maps for diagnostics, analysis and troubleshooting • accessing information on rules, access policies, and configuration compliance. • attack scenarios and simulations • how threats and attacks will be identified and analysed • security measures • security policies • designing audits and incident response procedures • documentation • ensuring compliance is maintained • change management procedures • continuous internal checks or audits • asset and inventory tracking • implementing a risk management plan.
ICTNWK546 Manage network security | 10 Organisational requirements You always need to ensure your activities align with organisational requirements relating to the planning, building and managing phases. These can be identified by talking with senior management and co-workers, reading internal policies and procedures and observing what others do ion the workplace. Common inclusions in these requirements relate to: • persons from within the business to involve in the process • external stakeholders who may or must be involved • requirements for site inspections and meetings with client and other stakeholders • template documentation to use for plans, reports and communications • timelines that apply and/or time allocations that are permitted for the process • relative importance of the project, budget and profit potential from the job • internal reporting on progress made.
ICTNWK546 Manage network security | 11 Topic 2: Identify threats to network security Determining why attacks occur To identify threats to the network security you have to determine why the attacks are occurring. Network attacks can be: Passive Active Where an attacker will just gain access to a network. Where an attacker will gain access to a network and modify, delete, steel, harm or encrypt data. This can be due to vulnerabilities in the security design and can occur because of: • poor or weak security design • weak passwords • poor social engineering protection • previously compromised accounts • internal mistakes • lack of internal controls or training • hardware and software are not properly installed or regularly updated • operating systems are not regularly updated • the misuse of hardware and software • lack of physical security • insecure passwords • unknown risks or vulnerabilities. Implementation of security polices along with training staff in security procedures and processes can support minimising attacks. Determining who the attack may come from To determine who the attack may come from, you need to ensure that the network uses different mechanisms to successfully identify and classify the threats or attacks. You can use specific techniques to identify and classify these, for example: • network visibility • the use of anomaly detection tools • network analysis • the use of intrusion detection and intrusion prevention systems • analysing network component logs • using network event logs and analytics • user logs • network performance monitoring logs • monitoring the network. You will not be able to protect or mitigate the network if you cannot view or detect what is going on.
ICTNWK546 Manage network security | 12 Common types of network vulnerabilities Common network vulnerabilities include: • poor configurations • inaccurate authorisations • interception • privilege escalation (expanding the penetration of the network to other systems or levels) • internal threats • external threats and viruses • social engineering. Determining how attacks occur Attacks can occur from: • Distributed Denial of Service (DDoS) attacks • Man in the Middle attacks • Malware/Injecting malicious code • phishing • weak infrastructure • unauthorised access • brute force • dictionary attacks • denial of service and by-pass • eavesdropping • hackers • user error • manipulation of data • penetration of the system • impersonation • IP address spoofing • viruses using logging • SQL injection • drive-by attack • cross-site scripting. Image by Saksham Choudhary on Pexels
ICTNWK546 Manage network security | 13 Some common attacks are: Dos (Denial of Service) Attack: These types of attacks don’t allow authorised users to use the computer. Once the attacker gets access to the network, they can block traffic so that valid users won’t be able to access the network. Attackers can alter the behaviour of applications by sending incorrect information to it. Modification of Data: This involves altering the information of other data and computer. IP address spoofing: In order to identify a valid user of a computer in network IP address is used. Sometimes IP address can be misread. In a same way attack have their special programs and ways to build IP packets which will look like they originate from valid addresses. After gaining access to network with valid IP dress they will do whatever they desire with it for e.g. modifying and rerouting router. They can also delete our data and execute network attacks. Man in the middle attack: An attacker hijacks a session between a client and network server. The attacking computer substitutes its IP address for the trusted client while the server continues the session, believing it is communicating with the client. Vulnerabilities or weaknesses of an ICT system that cause is a lack of authentication from the log in. Phishing: Trying to get personal information by pretending to be a legitimate person or organisation. This is often used to blackmail users. Some basic ways to detect security incidents include: • unusual behaviour • unauthorised access to servers and data. • anomalies in outbound network traffic • traffic sent to or from unknown locations • excessive use or consumption • unauthorised or accidental changes in configuration • locating hidden files • noting unexpected changes • abnormal browsing behaviour • suspect registry entries.
ICTNWK546 Manage network security | 14 Security technologies Using security technologies can support dealing with the threat of attacks and network vulnerabilities. Network security technologies cover both hardware and software threats. For example: With a Denial-of-Service (DoS) attack vulnerabilities or weaknesses of an ICT system that cause this are misconfigured network devices. There are many modern security technologies that have been developed to defend against most forms of DoS attacks. An example is the DDOS Attack Protection System offered by Cloudflare. In a Man in the middle attack, vulnerabilities or weaknesses of an ICT system that cause is a lack of authentication from the log in. There are many modern security technologies that have been developed to defend against Man in the middle attacks. An example is the inclusion of strong WEP/WAP encryption on access points. Emerging security issues With the expansion of cloud services and new technologies, the use of mobile devices and the Internet of Things (IoT), there have also emerged a number of security issues. For example: • The use of quantum physics to produce high performance processing power that could crack encryption • Using cloud technology to breach companies’ systems • Malware for mobiles • Device threats with multiple and growing mobile connectivity to networks • The use of cross-site scripting (XSS) attacks • Cryptojacking, exploiting vulnerabilities in networks to mine for cryptocurrency. Threat models used to categorise threats Threat modelling is used as a systematic and structured approach used to understand an environment and identify vulnerabilities and potential attacks and identify how to mitigate them. There are different methodologies used for threat modelling, consisting of different steps and processes. There are some general broad steps that are followed: Decompose the application or infrastructureDetermine the threatsDetermine countermeasures and mitigationsRank the threats
ICTNWK546 Manage network security | 15 Methodologies include: • STRIDE • VAST • Trike. For example, STRIDE breaks down categories of threat: The methodologies follow specific processes and come with their own tools and techniques. Activity: Read Threat models explained: https://www.csoonline.com/article/3537370/threat-modeling-explained-a-process-for-anticipating-cyber-attacks.html Take any notes to summarise what you have read and keep for future reference. Activity: Research and report Divide into small groups. You are to research one network system. This could be at the RTO where you are studying, approved by the trainer/assessor or your place of work. You are to write a report that addresses: An overview of the network system infrastructure, including topology, connections, hardware and software. Spoofing (or impersonating another person or computer): violatesauthenticityTamperingwith data: violatesintegrityRepudiation (or making it impossible to link an action you performed to you): violatesnon-reputabilityInformation disclosure: violating confidentialityDenial of service: violatesavailabilityElevation of privilege: violatesauthorisation
ICTNWK546 Manage network security | 16 Who uses the network and what they use it for (this can be a general overview, for example in a school situation it could be teachers and students to access the network shared resources and internet). Determine where attacks may come from on the network, how they might occur and any known vulnerabilities. Identify at least two network vulnerabilities and using a threat model design a way to categorise the threats. Your report should be between 1–2 pages long and be written in clear and concise English. Submit your report to your assessor trainer/assessor for feedback. Network security design specifications You may obtain network design specifications from the Request for Tender, Contract, Project Brief or similar. There is always a need to discuss and confirm these with the client to make sure there is a full and proper understanding of what is required. These specifications may address matters relating to: • access control • patching and testing • redundancy requirements • redundancy • segmentation • protective monitoring • physical security of the location and infrastructure.
ICTNWK546 Manage network security | 17 Topic 3: Analyse security risks Elements of risk management A security strategy outlines major security concerns and the way in which an organisation will deal with them. Risk management is a process used to identify, assess and control threats. The ISO 31000 standard for risk management identifies the key elements of the risk management: Activity: Read Read more on the elements of the risk management process: https://www.corporatecomplianceinsights.com/key-elements-of-the-risk-management-process/ Take any notes to summarise what you have read and keep for future reference. Risk management can help to protect an organisation’s assets, prevent data loss, theft or corruption, manage system or application failure or downtime, meet compliance requirements and from internal and external security threats. The benefits of risk management: • reduces the likelihood of risks occurring • provides an organisation with peace of mind • protection of data and resources • meeting compliance requirements • meets quality standards to improve reputation • improves business operations • prevents financial loss. Assets requiring protection The next step to analysing security risks is to determine the assets that require the most protection. Assets can include: • data and information • hardware and software. Risk identificationRisk analysisRisk evaluationRisk treatmentMonitor and review
ICTNWK546 Manage network security | 18 This is a major and quite complex task, requiring collaboration and consultation with users of the system, management and any other stakeholders. An asset register can be used to gather, record and store information relating to each asset. This could be documented in a spreadsheet. For example, assets recorded could include a complete list of every device connected on the LAN: • computers/workstations/peripheral devices • components and devices • hardware and software. You would need to also record relevant information for each asset, for example: • internet/WAN information • active directory information • procedural documentation for set up and configuration • any supporting documentation relating to the LAN set up • reference documentation including IP mapping, switch configuration files, routing summaries, design summaries, meeting notes, any further diagrams. Activity: Group work Divide into small groups. Ensure you divide the work equally. Create a spreadsheet to record assets for hardware in the room allocated by the trainer/assessor. List each asset with a brief description of each. What further assets would require protection and why? Your trainer/assessor will provide your group with feedback. Submit all work as professionally written documents within the timeframe allocated. Categorising assets and calculating their value It is then necessary to define standards for determining the importance of each asset. A list of criteria can be used so that you can prioritise each one through classification. Categorisation may fall into both tangible and non-tangible items, current and fixed assets. When you classify assets, you need to assign each item into a group, based on common characteristics. The classification used will depend upon the asset. For example, an information asset may be categorised as HIGHLY CONFIDENTIAL, RESTRICTED ACCESS, INTERNAL USERS ONLY; or a physical asset may be categorised as CRITICAL, MAJOR, MINOR.
ICTNWK546 Manage network security | 19 Calculating the value of each asset can be used to then prioritise each asset into order of importance. Some assets will be harder to value than others; it is much easier to calculate the value of a server and its physical components compared to data or information loss. Activity: Read How to conduct an IT asset evaluation: https://www.exittechnologies.com/blog/it-tips/the-it-asset-valuation-guide/ Take any notes to summarise what you have read and keep for future reference. Activity: Group work Divide into your previous groups. Ensure you divide the work equally. Refer back to the spreadsheet you created to record assets for hardware. For each asset listed, work out a way in which you can categorise these. Work out a value for each asset. Using a relevant function on the spreadsheet, sort the data so that you can clearly see the assets that hold the most priority and biggest risk if they were to be lost, stolen, damaged or corrupted. Submit all work as a professionally written document within the timeframe allocated. Risk management plans A risk management plan can be used to minimise any impacts of potential risk by using a strategy to deal with them. Having a risk management plan and procedures is vital for network security. A risk management plan and procedures will ensure that possible threats and the risks are identified. It will also include treatment measures that need to be put in place to protect against and manage attacks. Risk management plans and procedures are developed as part of the network security design. They are to be designed specific to the network security design and should involve a range of stakeholders to identify a range of risks and how to handle them. The risk management plan can be used to support an organisation to: • understand the risks and how they can be prevented or managed • outline a process to follow • provide employees with a clear framework to use • minimise the likelihood of an incident negatively impacting on the business.
ICTNWK546 Manage network security | 20 It can also include: • business impact analysis • a security plan • disaster recovery • business continuity plans • contingency plans. Risk management is important for cost analysis and budgeting of network security because the costing and budgeting needs to take into account potential risks that may affect costs. For example, the network may need to build in additional software to guard against identified threats. Activity: Read An example of a risk management plan: https://www.northam.wa.gov.au/documents/708/sample-risk-management-plan Source a risk management plan that relates to ICT. Develop a risk management plan that could be used for the network allocated to you by the trainer/assessor. You must include the risk of data loss, corruption, theft, and privacy and confidentiality of student information. Address both internal and external threats. Take any notes to summarise what you have read and keep for future reference. Organisational requirements Standard practice is that all risk management activities when implementing and managing security functions throughout a network must align and comply with organisational risk management requirements. The standard model of risk management applies in relation to: • risk identification • risk evaluation and assessment • development of risk controls. In addition, there may be organisational risk management requirements for you to adhere to in relation to: • designation of roles within the business who must be involved in the process • use of a nominated external consultant to assist in the process • leverage of previous risk management reports as prepared for projects already undertaken by the business • use of nominated risk identification, risk analysis and risk control templates • need to present draft risk controls to a panel/team for their review and consideration prior to approval for implementation.
ICTNWK546 Manage network security | 21 Topic 4: Create a security design Attacker scenarios and threats The use of attacker scenarios and threats can be used to simulate or predict the types of attack that may occur and thus put in measures to help prevent them. The attacker scenarios and threats can be: • ways in which a hacker may try to infiltrate a network • malicious cyber-attack scenarios • human incompetency • system failure • use of ransomware • data breaches. Prototypes or dummy systems and decoys can be used to test and conduct scenarios before systems are deployed. An organisation will look at common types of threats first such as unauthorised access or SQL injection attacks. You can evaluate the outcomes from attacker scenarios, along with further security information to plan suitable control methods and countermeasures. Control methods will include physical and logical measures such as connectivity of devices and components and firewalls. Countermeasures are used as a protection strategy. Some examples are: • Access control (to verify the identity) • Authentication (such as certificates) • Data confidentiality (for example VPNs, subnetting) • Data integrity (cryptography, encryption) • Availability (resource allocation) Activity: Read Read through the following attack scenario for virtual machine runtime hack: https://www.sciencedirect.com/topics/computer-science/attack-scenario Classifying network attack scenarios using an ontology approach: https://core.ac.uk/download/pdf/145042558.pdf Take any notes to summarise what you have read and keep for future reference.
ICTNWK546 Manage network security | 22 Security measures for network components There are specific measures that you can take for securing network components: • Auditing and penetration testing techniques can be used to measure a network’s security. o A security audit is a systematic evaluation of the IT infrastructure defences and measures how well security protocols comply with a list of established criteria to ensure network security. o Penetration testing is used to try to breach an ICT system just like a hacker would. This will therefore determine if the IT infrastructure could withstand a range of attacks. • Logging analysis and techniques can be used to measure the security of a network. Networks systems generate logs that document the system activities. Log analysis is a method of evaluating these records. Specific logging analysis techniques may include: o Pattern detection and recognition filters messages based on a pattern book. Patterns in data, and deviations from this can help detect anomalies. o Correlation analysis involves collating logs from different sources and systems and sorting meaningful messages that pertain to a particular event. Correlation analysis helps to find connections between data that is not visible in a single log. For example, if there has been a cyber-attack, correlation analysis would put together the logs generated by your servers, firewalls, network devices and other sources, and find the messages that are relevant to that particular attack. Security measures that can be put in place in a network include: • Firewalls are perimeter devices that permit or deny traffic based on a set of rules configured by the administrator. It can be as simple as a router with access lists or it can be complex, such as having a set of modules controlled from one central location but distributed through the network. • Antivirus software such as McAfee and Norton Antivirus are very popular security measures that recognises viruses in a system and isolates or eliminates it. it is very common for antivirus software to be installed on all a company’s machines These must be regularly updated to ensure that the latest virus and malware is recognised. • Intrusion-detection systems: Host-based IDS are installed on a server or an important target within an organisation and make sure that the system state matches a particular set baseline. Network-based IDS consist of a network sniffer picking up all traffic. The sniffer is attached to a database of known attack signatures. The Network-based IDS analyses each packet and checks it for known attacks. Software that can be used as a security measure includes: • Social engineering tactics are used by attackers to build phishing campaigns that deceive recipients into sending them to sites that install malware. Email security applications block incoming attacks as well as controlling outbound messages to prevent sensitive data being sent. • Virtual private networks encrypt connections between an endpoint and a network, usually over the Internet. Remote-access VPN most commonly use IPsec or Secure Sockets Layer to authenticate the communication between the network and a device.
ICTNWK546 Manage network security | 23 Hardware that can be used as a security measure includes: Devices and components such as firewalls and routers. Firewalls come as hardware and software. A physical firewall device can be purchased, and many routers have firewall software built into them. Most routers have Wireless Encryption (WEP) or Wi-Fi Protected Access (WPA) encryption options, and many have both. Network management and security process controls that can be put in place to ensure network security. At an overriding level, network management and security process controls include Security Policies. Security policies essentially limit access and makes the network secure and protects and manages network operations. Specific network management and security process controls, such as network monitoring including logs and reports, can also be deployed. Network controls Network controls use solutions to control access into and out of a network. These are usually outlined in the security policies and procedures; and risk management plan. It provides network visibility, compliance, access control and strengthens the network infrastructure. Network controls can include: • policies • profiling • guest networking access • incidence response • integration with other security solutions. Network access can be for internal access and also for: • Guest users • Bring Your Own Device (BYOD) • The Internet of Things (IoT). The controls used include: Network Access Control (NAC) This is a security measure, using a set of protocols to define and implement a policy, that describes how to secure access to network nodes by devices when they attempt access. NAC provides an endpoint assessment a computer trying to gain access to the network and then enables access and enforces a security policy based on the state of the computer and the identity of the user. authenticationaccess controlsaccountabilityphysical
ICTNWK546 Manage network security | 24 Developing security policies Security policies provide a set of guidelines and rules to follow for computer network access. It is a formal document communicated at management level, outlining the principles, procedure and guidelines to enforce, manage and protect a company’s network. A security policy should be applied throughout the organisation to provide consistency and as a reference for employees. The aim of the policy is to protect an organisation from any security threats, both internal and external. It will also include any compliance to legislation and regulations. Given the importance of network security, there are a number of key features that a network security policy should include, such as: • purpose • scope • definitions • legislative context • policy statement • governance • responsibilities • security procedures.
A good security policy should also include the following procedures: Access and control of proprietary data and personal data Physical security protocols for dealing with visitors, locking doors, etc. Password policy Acceptable use policy for email, internet browsing, social media, etc. Data classification, defining critical and private data Reporting lost or stolen devices Reporting data loss or a suspected security breach Third party cloud or file sync services such as Gmail, Dropbox etc., that are used. Submission of documentation When all the above documents (such as policies, plans, protocols) have been prepared you need to provide these to ‘relevant persons’ and request their comment by a set date. In some cases, you may elect to hold one, or more face-to-face meetings, with these persons to discuss what has been produced.
ICTNWK540 Design, build and test network servers | 26 Relevant persons can include: • head of the technical department • external consultancy who has been part of the development work to this stage • manufacturers or suppliers of infrastructure • installers • the client. The input received from these persons must then form the basis for revision of the documents, re-presentation for a final check and approval, and ultimate implementation. Activity: Read Review the following network security policy for the Villanova University: https://www1.villanova.edu/villanova/unit/policies/AcceptableUse/security.html An example of a security policy – Network protection and information security policy: https://txwes.edu/media/twu/content-assets/documents/it/Network-Protection-and-Info-Security-Policy.pdf Take any notes to summarise what you have read and keep for future reference. Activity: Group work Divide into small groups. Ensure you divide the work equally. Research a network security policy that could be used in an educational context in Australia. Use the policy as a guidance to create an outline for a network security policy for the network allocated by the trainer/assessor for this task. Add suitable control methods that can be used as well any countermeasures. Submit all work as a professionally written document, within the timeframe allocated. Your trainer/assessor will provide your group with feedback.
ICTNWK540 Design, build and test network servers | 27 Topic 5: Design security incidents response Auditing and incident response procedures An incident response procedure is a method used for handling security breaches, threats and incidences. It can help to identify and effectively minimise damages or costs caused by the incident as well as finding and fixing the cause. An incident response plan can contain: • analysis of the environment including the likelihood and severity of potential incidents • identification of assets • a plan for each incident type • roles and responsibilities • procedures, resources, tools and guides • review and reporting. Furthermore, an organisation may need to address the effects of non-compliance due to an incident, the impacts that could occur across the organisation, any impacts to workers. A typical incident response procedure could include: Activity: Read Cyber Security Incident Response guide: https://www.crest-approved.org/wp-content/uploads/2014/11/CSIR-Procurement-Guide.pdf Take any notes to summarise what you have read and keep for future reference. Audits can be undertaken to identify any risks of a security breach, as well as determining the effectiveness of the preventative measures. An audit can include a review of both physical and logical measures such as policies, assets, network infrastructure, protocols, passwords, firewall definitions, modification of files, access to files, user login profiles, etc. identifyinvestigatetake actionrecoverreport.
ICTNWK540 Design, build and test network servers | 28 Network security audits can help determine any underlying security issues as well has the effectiveness of the measures implemented. It can be used to identify: • how well an organisation is protected • if threats are internal or external. The audit process should review the entire network, including the architecture, software and hardware, tools used to perform specific actions, connections made to external networks, access control and privileges for users, and organisational policies and procedures. It may also cover compliance issues during the process. Documenting security incidents All security incidents should be clearly and sufficiently documented. This ensures that there is an audit trail and also can be used as future reference for any further incidents. Best practices or guidelines for completing documentation may include using specific organisational templates or procedures. This could include an incident report log, adding incident reports to a file or a formal incident reporting mechanism. Documenting incidents can help to improve the incident response plan as well as using the information to respond to additional security measures needed. Implementing configurations from incident response procedures An incident response outcome can be used to analyse and plan solutions to any compromised networks. It could include implementation of new configurations to countermeasure an attack. The configurations could include: • changes to remote access • access privileges • network access • physical configuration of devices. Any information reported from the incident response procedure can be used to make these changes. Testing Perhaps the second most important part of managing network security (other than planning) would be testing phase. Testing should be carried out on a continual basis during the analysis, design and implementation of the network security design. However, vigorous tests should also be carried out before the network goes live and so that approval can be gained and the project signed off. To conduct testing you would need to develop a test plan, specifying each test activity, the expected result and the outcome. Testing is cyclic and should be carried out until there are no errors or bugs remaining and any scenarios prove to be secure.
ICTNWK540 Design, build and test network servers | 29 Testing should include devices, services, DNS, firewalls, VPNs, anti-virus, IDS and URL filtering. Before testing takes place, it is important to ensure that the security policies and processes are clearly understood and any tools and resources are available to support testing. There are a number of tests that can be carried out for a network and what is tested will be defined by the way in which the network has been configured and what security measures have been put in place. Testing can be carried out by security administration staff and also users of the system. The following are common network tests: • Network scanning for ports and network services • Authorised hacking to check vulnerability • Vulnerability scans using automated software • Password cracking • Penetration testing on the network to determine any security flaws. Activity: Read Network security testing: https://www.secureworks.com/centers/network-security Penetration testing: https://www.imperva.com/learn/application-security/penetration-testing/ Take any notes to summarise what you have read and keep for future reference. Submission for sign off You need to provide all completed documents to the client for their final approval as a distinct stage in the overall process. Obtaining sign-off for the network security design could be from a supervisor, client or any relevant stakeholders. Working on this type of project may include using project management software, tools, techniques and frameworks, which means you may need to complete specific paperwork, documentation and undertake close project procedures before sign off can be granted. Submission can involve: • provision to relevant personnel of hard copies of all documentation – there may be a requirement for nominated number of copies, instead of ‘just one’ • provision of an electronic version to nominated recipients on a closely controlled email distribution list • provision of the documents by a given date by a set time – such as by December 21st, 2020 by 4:00PM
ICTNWK540 Design, build and test network servers | 30 • holding a meeting on a given date with those to whom the documents have been submitted – so you can explain aspects of the job, judge the reaction of stakeholders, solicit questions, and listen first-hand to their input. At these meetings you are expected to explain or justify decisions taken, and/or take on board concerns and comment from those present so they can be accommodated in a subsequent revision to the plans, protocols and similar. Any requirements for change trigger the need to review the documents involved, and re-present them again for approval and sign-off. Signing off on a project can mean the release of funds, resources, budgets, payments and a product or service to a client.
ICTNWK546Manage Network Security
Topic 1: Plan security design process © 2020 RTO Works2
Topic 1: Insert topic title PLANNING PHASE FOR NETWORK SECURITY DESIGN•Taking on a project for managing network security can be a complex task. Project management can be key to a successful ICT project. •The methodologies used in project management are a series of different processes designed to assist project managers and those overseeing or involved with projects. 3© 2020 RTO Works
Topic 1: Plan security design process ICT NETWORKSWhen defining the planning phase for a security design, it is important to understand different ICT networks and their configuration as their differences can affect the way in which the design can be implemented. 4© 2020 RTO Works
ACTIVITY: RESEARCH AND DISCUSS Using the following links, describe three networks and their configurations.Common network topologies:http://www.firewall.cx/networking-topics/general-networking/103-network-topologies.htmlhttps://en.m.wikibooks.org/wiki/Communication_Networks/Network_TopologiesThe trainer/assessor will facilitate a class discussion about the outcomes from the research. © 2020 RTO Works5
ACTIVITY: READThe listed articles provide an overview of wireless topologies.© 2020 RTO Works6
Topic 1: Plan security design process PLANNING FOR NETWORK SECURITY DESIGNThe planning phase is the most important aspect of any project. It will define the way in which the project will be undertaken and be used as a framework for the other stages of the project.7© 2020 RTO Works
ACTIVITY: PRACTICALUsing the RTO network, or one that you have access to, review the network infrastructure. List down as much information as you can about the network.Draw a network diagram of the current system.© 2020 RTO Works8
BUILDING PHASE FOR NETWORK SECURITY DESIGNIn the building phase, network administrators and security specialists use the available hardware and software to create the security system as set out in the security design. 9© 2020 RTO Works
MANAGING PHASE FOR NETWORK SECURITY DESIGNAfter the security design has been implemented, the administrator is responsible for managing the design to ensure it provides the security envisioned by the security design. 10© 2020 RTO Works
ORGANISATIONAL REQUIREMENTS•You always need to ensure your activities align with organizational requirements relating to the planning, building and managing phases.•These can be identified by talking with senior management and co-workers, reading internal policies and procedures and observing what others do ion the workplace.11© 2020 RTO Works
Topic 2: Identifying threats to network security© 2020 RTO Works12
DETERMINING WHY ATTACKS OCCURTo identify threats to the network security you have to determine why the attacks are occurring.Network attacks can be:13© 2020 RTO WorksPassiveActiveWhere an attacker will just gain access to a network.Where an attacker will gain access to a network and modify, delete, steel, harm or encrypt data.
DETERMINING WHO THE ATTACK MAY COME FROMTo determine who the attack may come from, you need to ensure that the network uses different mechanisms to successfully identify and classify the threats or attacks. You can use specific techniques to identify and classify these.14© 2020 RTO Works
COMMON TYPES OF NETWORK VULNERABILITIES•poor configurations•inaccurate authorizations•interception•privilege escalation•internal threats•external threats and viruses •social engineering.15© 2020 RTO Works
DETERMINING HOW ATTACKS OCCUR Some common attacks are:•Dos (Denial of Service) Attack•Modification of Data•IP address spoofing•Man in the middle attack•Phishing16© 2020 RTO Works
SECURITY TECHNOLOGIESUsing security technologies can support dealing with the threat of attacks and network vulnerabilities. Network security technologies cover both hardware and software threats.17© 2020 RTO Works
EMERGING SECURITY ISSUESWith the expansion of cloud services and new technologies, the use of mobile devices and the Internet of Things (IoT), there have also emerged a number of security issues.18© 2020 RTO Works
THREAT MODELS USED TO CATEGORISE THREATSThreat modelling is used as a systematic and structured approach used to understand an environment and identify vulnerabilities and potential attacks and identify how to mitigate them.19© 2020 RTO Works
ACTIVITY: READThreat models explained: https://www.csoonline.com/article/3537370/threat-modeling-explained-a-process-for-anticipating-cyber-attacks.htmlTake any notes to summarisewhat you have read and keep for future reference.© 2020 RTO Works20
ACTIVITY: RESEARCH AND REPORTDivide into small groups.You are to research one network system. This could be at the RTO where you are studying, approved by the trainer/assessor or your place of work.© 2020 RTO Works21
Topic 3: Analyzing security risks© 2020 RTO Works22
ELEMENTS OF RISK MANAGEMENT•A security strategy outlines major security concerns and the way in which an organisation will deal with them. •Risk management is a process used to identify, assess and control threats. 23© 2020 RTO Works
ACTIVITY: READRead more on the elements of the risk management process:https://www.corporatecomplianceinsights.com/key-elements-of-the-risk-management-process/Take any notes to summarisewhat you have read and keep for future reference.© 2020 RTO Works24
ELEMENTS OF RISK MANAGEMENTRisk management can help to protect an organisation’s assets, prevent data loss, theft or corruption, manage system or application failure or downtime, meet compliance requirements and from internal and external security threats.25© 2020 RTO Works
ASSETS REQUIRING PROTECTIONThe next step to analyzing security risks is to determine the assets that require the most protection.Assets can include:•data and information•hardware and software.26© 2020 RTO Works
ACTIVITY: GROUP WORKDivide into small groups. Ensure you divide the work equally.Create a spreadsheet to record assets for hardware in the room allocated by the trainer/assessor. List each asset with a brief description of each.What further assets would require protection and why?© 2020 RTO Works27
CATEGORISING ASSETS AND CALCULATING THEIR VALUE It is then necessary to define standards for determining the importance of each asset. A list of criteria can be used so that you can prioritize each one through classification. 28© 2020 RTO Works
ACTIVITY: READHow to conduct an IT asset evaluation: https://www.exittechnologies.com/blog/it-tips/the-it-asset-valuation-guide/Take any notes to summarisewhat you have read and keep for future reference.© 2020 RTO Works29
ACTIVITY: GROUP WORKDivide into your previous groups. Ensure you divide the work equally.Refer back to the spreadsheet you created to record assets for hardware. For each asset listed, work out a way in which you can categorisethese.Work out a value for each asset.Using a relevant function on the spreadsheet, sort the data so that you can clearly see the assets that hold the most priority and biggest risk if they were to be lost, stolen, damaged or corrupted.© 2020 RTO Works30
RISK MANAGEMENT PLANS•A risk management plan can be used to minimize any impacts of potential risk by using a strategy to deal with them. •Having a risk management plan and procedures is vital for network security.31© 2020 RTO Works
ACTIVITY: READAn example of a risk management plan: https://www.northam.wa.gov.au/documents/708/sample-risk-management-planSource a risk management plan that relates to ICT.Develop a risk management plan that could be used for the network allocated to you by the trainer/assessor. You must include the risk of data loss, corruption, theft, and privacy and confidentiality of student information. Address both internal and external threats.© 2020 RTO Works32
ORGANISATIONAL REQUIREMENTSStandard practice is that all risk management activities when implementing and managing security functions throughout a network must align and comply with organisational risk management requirements.33© 2020 RTO Works
Topic 4: Create a security design© 2020 RTO Works34
ATTACKER SCENARIOS AND THREATSThe use of attacker scenarios and threats can be used to simulate or predict the types of attack that may occur and thus put in measures to help prevent them.35© 2020 RTO Works
ACTIVITY: READRead through the following attack scenario for virtual machine runtime hack: https://www.sciencedirect.com/topics/computer-science/attack-scenarioClassifying network attack scenarios using an ontology approach: https://core.ac.uk/download/pdf/145042558.pdfTake any notes to summarisewhat you have read and keep for future reference. © 2020 RTO Works36
SECURITY MEASURES FOR NETWORK COMPONENTSThere are specific measures that you can take for securing network components e.g. auditing and penetration testing techniques can be used to measure a network’s security. 37© 2020 RTO Works
NETWORK CONTROLSNetwork controls use solutions to control access into and out of a network. These are usually outlined in the security policies and procedures; and risk management plan. 38© 2020 RTO Works
NETWORK ACCESS CONTROL (NAC) This is a security measure, using a set of protocols to define and implement a policy, that describes how to secure access to network nodes by devices when they attempt access.39© 2020 RTO Works
DEVELOPING SECURITY POLICIES•Security policies provide a set of guidelines and rules to follow for computer network access. •It is a formal document communicated at management level, outlining the principles, procedure and guidelines to enforce, manage and protect a company’s network. 40© 2020 RTO Works
SUBMISSION OF DOCUMENTATIONWhen all the above documents (such as policies, plans, protocols) have been prepared you need to provide these to ‘relevant persons’ and request their comment by a set date.41© 2020 RTO Works
ACTIVITY: READReview the following network security policy for the Villanova University:https://www1.villanova.edu/villanova/unit/policies/AcceptableUse/security.htmlAn example of a security policy -Network protection and information security policy: https://txwes.edu/media/twu/content-assets/documents/it/Network-Protection-and-Info-Security-Policy.pdf© 2020 RTO Works42
ACTIVITY: GROUP WORKDivide into small groups. Ensure you divide the work equally.Research a network security policy that could be used in an educational context in Australia.Use the policy as a guidance to create an outline for a network security policy for the network allocated by the trainer/assessor for this task. Add suitable control methods that can be used as well any countermeasures.© 2020 RTO Works43
Topic 5: Design security incidents response© 2020 RTO Works44
AUDITING AND INCIDENT RESPONSE PROCEDURESAn incident response procedure is a method used for handling security breaches, threats and incidences. It can help to identify and effectively minimisedamages or costs caused by the incident as well as finding and fixing the cause.45© 2020 RTO Works
ACTIVITY: READCyber Security Incident Response guide: https://www.crest-approved.org/wp-content/uploads/2014/11/CSIR-Procurement-Guide.pdfTake any notes to summarisewhat you have read and keep for future reference. © 2020 RTO Works46
AUDITING AND INCIDENT RESPONSE PROCEDURES•Audits can be undertaken to identify any risks of a security breach, as well as determining the effectiveness of the preventative measures.•An audit can include a review of both physical and logical measures.47© 2020 RTO Works
DOCUMENTING SECURITY INCIDENTS•All security incidents should be clearly and sufficiently documented. •This ensures that there is an audit trail and also can be used as future reference for any further incidents48© 2020 RTO Works
IMPLEMENTING CONFIGURATIONS FROM INCIDENT RESPONSE PROCEDURESAn incident response outcome can be used to analyseand plan solutions to any compromised networks. It could include implementation of new configurations to countermeasure an attack.49© 2020 RTO Works
TESTINGPerhaps the second most important part of managing network security (other than planning) would be testing phase. Testing should be carried out on a continual basis during the analysis, design and implementation of the network security design. 50© 2020 RTO Works
ACTIVITY: READNetwork security testing: https://www.secureworks.com/centers/network-securityPenetration testing: https://www.imperva.com/learn/application-security/penetration-testing/Take any notes to summarisewhat you have read and keep for future reference.© 2020 RTO Works51
SUBMISSION FOR SIGN OFF •You need to provide all completed documents to the client for their final approval as a distinct stage in the overall process.•Obtaining sign-off for the network security design could be from a supervisor, client or any relevant stakeholders. 52© 2020 RTO Works
Collepals.com Plagiarism Free Papers
Are you looking for custom essay writing service or even dissertation writing services? Just request for our write my paper service, and we'll match you with the best essay writer in your subject! With an exceptional team of professional academic experts in a wide range of subjects, we can guarantee you an unrivaled quality of custom-written papers.
Get ZERO PLAGIARISM, HUMAN WRITTEN ESSAYS
Why Hire Collepals.com writers to do your paper?
Quality- We are experienced and have access to ample research materials.
We write plagiarism Free Content
Confidential- We never share or sell your personal information to third parties.
Support-Chat with us today! We are always waiting to answer all your questions.
