Module: Cyber Security TM256-23B
Assignment: TMA03
,Question One
a.
Three steps that could have been taken by the IT manager to prevent the network
infrastructure from being compromised are:
1. Endpoint security/antivirus software: a line of defense that could have been taken
to bolster the college's network security would have been the installation of a
comprehensive endpoint security solution and antivirus software. These security
measures would contain essential features such as real-time scanning, virus
detection and proactive procedures. With regular updates, the anti-virus software
would have lowered the possibility of a virus on a student’s laptop from spreading
onto the network. Endpoint security and antivirus software is a defense barrier
against unauthorised access, with regular scans, alerts and blocking of malicious
websites and downloads, automatic updates to shield endpoints from the latest
threats and the ability to identify various types of malware (Trellix, 2023).
2. Network Access Control (NAC): by introducing network access control to the
network, the IT manager could have prevented unauthorized or unsafe devices from
connecting to the network. NAC enforce stringent access controls that include device
registration, security checks and endpoint validation. A network access control
ensures that only authorised devices can access the network by implementing
switches, firewalls and wireless access points (Cyborg security, 2023).
3. VLANs and Network Segmentation: Through the implementation of network
segmentation and VLANs (Virtual Local Area Networks), specific sections of the
network can be isolated, creating separate zones or subnets for users such as
students, teachers and guests. This strategic approach, overseen by the IT manager
will effectively minimize the potential impact of a security breach as the network is
divided. The use of access controls and firewall rule restricts communication between
the various segments thereby preventing the spread of a virus or malware from
infecting the entire network (Cisco, 2023).
, b.
When implementing a Bring Your Own Device (BYOD) throughout the college, the first thing
to establish is clear acceptable use policy (Brook, 2022). By outlining the rules for personal
device usage on the college network, the policy will either permit or prohibit activities, apps
and content whilst providing guidance on responsible and ethical conduct such as respecting
intellectual property, maintaining a secure digital environment for all with guidance and
accountability for behaviour. Acceptable use policy must also specify how data is handled
and stored in keeping with regulations such as GDPR (IBM, 2023).
Secondly, it would be advisable to determine the specific goals of the policy, as a college, the
goal maybe to enhance the learning experience, increase productivity or improve
accessibility to resources. By setting the goal, it will help to shape the policy and set
expectations for the college and students. Ultimately, the BYOD policy should aim to
safeguard the network IT infrastructure whilst meeting the needs of both the college staff
and students.
Next, it is important to enhance the overall security standards for the connectivity of
personal devices to the college IT infrastructure. By setting minimum security requirements
for personal devices, TechTarget (2022) has outlined some essential elements of a BYOD
security policy which include specifying which applications users can access, setting
minimum security controls that every device should have, device authentication with SSL
certificates and possibly the right to wipe devices should they be lost or stolen.
Once policies are agreed and set, educating users on security practices is another significant
consideration. Conducting regular cyber security awareness programs for staff and students
on best practice security measure on their personal devices. Coving such topics as cyber and
password hygiene, safe browsing and how to avoid suspicious emails and unsecure websites
(Kaspersky, 2023).
Assignment: TMA03
,Question One
a.
Three steps that could have been taken by the IT manager to prevent the network
infrastructure from being compromised are:
1. Endpoint security/antivirus software: a line of defense that could have been taken
to bolster the college's network security would have been the installation of a
comprehensive endpoint security solution and antivirus software. These security
measures would contain essential features such as real-time scanning, virus
detection and proactive procedures. With regular updates, the anti-virus software
would have lowered the possibility of a virus on a student’s laptop from spreading
onto the network. Endpoint security and antivirus software is a defense barrier
against unauthorised access, with regular scans, alerts and blocking of malicious
websites and downloads, automatic updates to shield endpoints from the latest
threats and the ability to identify various types of malware (Trellix, 2023).
2. Network Access Control (NAC): by introducing network access control to the
network, the IT manager could have prevented unauthorized or unsafe devices from
connecting to the network. NAC enforce stringent access controls that include device
registration, security checks and endpoint validation. A network access control
ensures that only authorised devices can access the network by implementing
switches, firewalls and wireless access points (Cyborg security, 2023).
3. VLANs and Network Segmentation: Through the implementation of network
segmentation and VLANs (Virtual Local Area Networks), specific sections of the
network can be isolated, creating separate zones or subnets for users such as
students, teachers and guests. This strategic approach, overseen by the IT manager
will effectively minimize the potential impact of a security breach as the network is
divided. The use of access controls and firewall rule restricts communication between
the various segments thereby preventing the spread of a virus or malware from
infecting the entire network (Cisco, 2023).
, b.
When implementing a Bring Your Own Device (BYOD) throughout the college, the first thing
to establish is clear acceptable use policy (Brook, 2022). By outlining the rules for personal
device usage on the college network, the policy will either permit or prohibit activities, apps
and content whilst providing guidance on responsible and ethical conduct such as respecting
intellectual property, maintaining a secure digital environment for all with guidance and
accountability for behaviour. Acceptable use policy must also specify how data is handled
and stored in keeping with regulations such as GDPR (IBM, 2023).
Secondly, it would be advisable to determine the specific goals of the policy, as a college, the
goal maybe to enhance the learning experience, increase productivity or improve
accessibility to resources. By setting the goal, it will help to shape the policy and set
expectations for the college and students. Ultimately, the BYOD policy should aim to
safeguard the network IT infrastructure whilst meeting the needs of both the college staff
and students.
Next, it is important to enhance the overall security standards for the connectivity of
personal devices to the college IT infrastructure. By setting minimum security requirements
for personal devices, TechTarget (2022) has outlined some essential elements of a BYOD
security policy which include specifying which applications users can access, setting
minimum security controls that every device should have, device authentication with SSL
certificates and possibly the right to wipe devices should they be lost or stolen.
Once policies are agreed and set, educating users on security practices is another significant
consideration. Conducting regular cyber security awareness programs for staff and students
on best practice security measure on their personal devices. Coving such topics as cyber and
password hygiene, safe browsing and how to avoid suspicious emails and unsecure websites
(Kaspersky, 2023).