MSc Global Financial IS Security, Continuity & Ethics Project

Verified

Added on  2019/09/23

|5
|909
|205
Project
AI Summary
This project is a comprehensive Information Security Audit for National Bank, a financial services company. As the Chief Security Officer, the student is tasked with conducting an audit comprising two parts. Part 1 involves creating an enterprise-size information systems network diagram, explaining the OS and applications, and discussing potential vulnerabilities in hardware, software, and people, supported by real-world examples. Part 2 requires the development of a Security Policy Framework Document to protect National Bank's information systems, covering aspects like acceptable usage, business continuity, disaster recovery, ethics, security architecture, management practices, and network security. The project emphasizes research, professional presentation, and adherence to academic integrity, with specific deadlines for submission. The student needs to submit this project in two parts, first an IS architecture with vulnerabilities and second a security policy framework document.
Document Page
MSc. Global Financial IS Global Financial IS Security, Continuity & Ethics
Global Financial Information Systems
YEAR1
SEMESTER 2
Global Financial Information Systems Security,
Continuity & Ethics
CONTINUOUS ASSESSMENT
EXAMINERS: INTERNAL:
EXTERNAL:
INSTRUCTIONS /INFORMATION:
1.
WATERFORD INSTITUTE OF TECHNOLOGY
1
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
MSc. Global Financial IS Global Financial IS Security, Continuity & Ethics
Global Financial Information Systems
Security, Continuity & Ethics
CA Project Semester 2 2017
Table of Contents
Overview...........................................................................................................................................3
Part 1 Systems Architecture and potential vulnerabilities (40%).......................................................3
Part 2 Security Policy Framework Document (60%)..........................................................................3
Submission Details.............................................................................................................................4
2
Document Page
MSc. Global Financial IS Global Financial IS Security, Continuity & Ethics
Global Financial Information Systems Security, Continuity & Ethics
Continuous Assessment Project (100%)
Overview
Scenario: You have been appointed as Chief Security Officer (CSO) of National Bank. National
Bank operates in the Financial Services sector and is headquartered in Dublin with
approx 200 employees. There are 20 branches nationwide with approx 7-10
employees per branch and 2 international offices of 20 employees each. National
Bank has been tasked with undertaking a security audit of its Information Systems.
As CSO, it is your job to carry out this audit.
The CA project will form an overall Information Security Audit, broken into two parts. Part 1 will ask
you to assess the current Information Systems architecture and discuss potential vulnerabilities,
while Part 2 will ask you to define a Security Policy Framework document to protect National Bank's
Information Systems from the vulnerabilities as discussed in Part 1.
Both parts of the CA Project should be professionally presented in report format, with a cover page,
table of contents, body of report, references and appendices were appropriate.
Part 1 Systems Architecture and potential vulnerabilities (40%)
Create an enterprise size information systems network diagram showing all hardware entities, while
also explaining the typical Operating Systems (OS) and Applications set up. This will require some
initial research as to what forms a typical enterprise network in order to develop a diagram for an
enterprise size network in the financial services sector. In terms of branch offices, the inclusion of 1
in the diagram will suffice, with a note stating "x 20"
Discuss potential vulnerabilities in terms of hardware, software and people, citing examples of real-
world attacks, where applicable.
Part 2 Security Policy Framework Document (60%)
With regard to the enterprise information system described in Part 1, outline a Security Policy
Framework Document which will help to protect National Bank's Information System. This part of
the project will require significant research on your part and should be a substantial document (20-
30 pages). Questions such as "What exactly is a Security Policy Framework Document?", or "Who is
such a document written for?" etc. need to be answered before beginning the document.
3
Document Page
MSc. Global Financial IS Global Financial IS Security, Continuity & Ethics
The structure of the Security Policy Framework Document should roughly follow:
Cover page
Table of Contents
Introduction - briefly explaining the purpose of the SPFD and why it is required (summarise
Project Part 1)
Acceptable Usage Policy - explaining which users can use specific parts of the network, and
documenting what these users can and cannot do.
Business Continuity Planning - exposure of internal and external threats (can be
summarised from Project Part 1) and plan to allow the business to continue under adverse
conditions.
Disaster Recovery Planning - plan to allow the business IS infrastructure to recover from
adverse conditions.
Ethics - guidance on ethical issues surrounding the use of an Information System
Security Architecture and Models - schemes for specifying and enforcing security policies
Security Management Practices - to ensure confidentiality, integrity, and availability of the
organization's assets and information.
Applications, Telecommunications and Network Security - plan to protect at technology
level
References
Appendices (where appropriate)
Class notes should be used as guidance to expand on these section headings, but online, book,
journal etc research should be carried out in order to get more detail and real-world
implementations.
Plagiarism
Plagiarism is a serious issue. Students must avoid plagiarism in the completion of this project.
Remember to always reference material that you have sourced from the Internet, books, journals,
newspapers, etc. Also, please note that taking material from another student and passing it off as
your own work also constitutes plagiarism. Any student who is found to have submitted plagiarised
work will receive zero marks for their assignment.
Submission Details
Continuous Assessment Part % Submission Date
Part 1 - IS Architecture & Vulnerabilities 40 Sunday 3th March 17:15 via TurnItIn
Part 2 - Security Policy Framework Document 60 Sunday 30th March 17:15 via TurnItIn
Table 1 - CA Project Part Submission Dates
4
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
MSc. Global Financial IS Global Financial IS Security, Continuity & Ethics
Please not that all submissions are to be made electronically ONLY via TurnItIn on the dates declared
in Table 1 - CA Project Part Submission Dates. Late submissions will not be accepted, as TurnItIn will
automatically close the project submission upload option at 17:15 on each submission date. If there
is a problem with submission please contact me at jdgriffin@wit.ie before the submission closure in
order to register your issue.
5
chevron_up_icon
1 out of 5
circle_padding
hide_on_mobile
zoom_out_icon
[object Object]