100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Essay

Security infrastructure design document

Rating
-
Sold
-
Pages
3
Grade
A+
Uploaded on
04-09-2023
Written in
2023/2024

Overview: Now that you’re super knowledgeable about security, let's put your newfound know-how to the test. You may find yourself in a tech role someday, where you need to design and influence a culture of security within an organization. This project is your opportunity to practice these important skillsets. Assignment: In this project, you’ll create a security infrastructure design document for a fictional organization. The security services and tools you describe in the document must be able to meet the needs of the organization. Your work will be evaluated according to how well you met the organization’s requirements. About the organization: This fictional organization has a small, but growing, employee base, with 50 employees in one small office. The company is an online retailer of the world's finest artisanal, hand-crafted widgets. They've hired you on as a security consultant to help bring their operations into better shape. Organization requirements: As the security consultant, the company needs you to add security measures to the following systems: An external website permitting users to browse and purchase widgets An internal intranet website for employees to use Secure remote access for engineering employees Reasonable, basic firewall rules Wireless coverage in the office Reasonably secure configurations for laptops Since this is a retail company that will be handling customer payment data, the organization would like to be extra cautious about privacy. They don't want customer information falling into the hands of an attacker due to malware infections or lost devices. Engineers will require access to internal websites, along with remote, command line access to their workstations. Grading: This is a required assignment for the module. What you'll do: You’ll create a security infrastructure design document for a fictional organization. Your plan needs to meet the organization's requirements and the following elements should be incorporated into your plan: Authentication system External website security Internal website security Remote access solution Firewall and basic rules recommendations Wireless security VLAN configuration recommendations Laptop security configuration Application policy recommendations Security and privacy policy recommendations Intrusion detection or prevention for systems containing customer data

Show more Read less
Institution
Course








Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Study
Course

Document information

Uploaded on
September 4, 2023
Number of pages
3
Written in
2023/2024
Type
Essay
Professor(s)
Unknown
Grade
A+

Subjects

Content preview

Introduction

This document explains the preliminary user-oriented functional design based on the design
specifications and the technical and non-technical needs listed in the requirements paper.

Additionally, it provides a high-level overview of the system architecture, explains the data design
related to the system, and specifies design goals that the chosen methods should reach. The high-
level system design is presented, and some low-level details are provided, covering hardware,
software details, techniques for storing and retrieving data, and external interfaces.

Overview

The client needs an IT infrastructure to carry out company operations that involve internal VPN
access for customers and staff and e-commerce apps. The main focus is on the appropriate
authentication system, security of the websites and wireless connections, essential firewall, VLAN
and user device configurations, and customer and client information privacy.

Authentication
One-Time Password generators will be used as a secondary authentication factor to be integrated
into an LDAP server's centrally managed authentication process.

External Website

The external website is mainly used for purchase activity by customers. Its essential goal is to provide
a secure e-commerce transaction complying with Payment Card Industry Data Security Standard. To
do this, it is necessary to:

 Protect the confidentiality of the data;
 Reliable authentication to the website;
 Reliable authorisation system, denying unauthorised access to the website and user
data;
 Ensure integrity of the data;
 Ensure availability and usability of the data and functionality;
 Secure and continuous logging and archiving of the transactions for later reference and
support activities.

Since the customer-facing website will be an e-commerce site allowing users to browse and buy
products and create and log into accounts, it will be delivered via HTTPS with an SSL certificate. This
website would be open to the general public.

Internal website

The internal employee website, which requires authentication for employee use, will also be
delivered through HTTPS. Only authenticated accounts in the company's internal network will be
permitted access. The internal website will be secured from malicious traffic and access using a
firewall restricting access to the company's intranet only. The multi-factor authentication system will
allow reliable and user-friendly authentication for employees. The administrators must manage user
accounts, their access permissions and activity supervision.

Secure remote access

A network-level VPN solution, such as OpenVPN, will be required since engineers need remote
command-line access to workstations and internal websites. In addition to a VPN, a reverse proxy is
$9.04
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
liucijavaitukaityt

Get to know the seller

Seller avatar
liucijavaitukaityt The Open University
Follow You need to be logged in order to follow users or courses
Sold
0
Member since
2 year
Number of followers
0
Documents
2
Last sold
-

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions