(Solution) COIT20249 Assessment Details Assessment item 3—Report

Assessment Task

Students are required to write an academic report as per the format outlined in chapter 5 of the textbook. The report must follow the CQU APA referencing style. See the American Psychological Association (APA) abridged guide updated Term 2 2018 available from: https://www.cqu.edu.au/student-life/services-and-facilities/referencing/cquniversity-referencing-guides. Please note that the prescribed textbook uses APA referencing guidelines. See also the Referencing Style subsection below.
The report is to be based on the following cybersecurity use case for office and home systems.
With the recent progress of computer networks, growth of interconnected devices through Internet, cloud computing, big data and web services, the number of cyber threat/attack has grown exponentially. Malware attack, phishing, man-in-the middle attack, denial-of-service are some of the common types of cyberattacks that hits businesses every day. Therefore, cybersecurity is an essential practice for the digital age to protect systems, networks, applications, data/information and hardware from cyberattacks or unauthorised access, and to ensure the integrity, confidentiality, and availability of information. The goal is to prevent the risks to individuals and organisations such as, damage or loss of sensitive data, stolen money, theft of intellectual property, theft of personal and financial data, disruption to business.
The major challenges to cybersecurity efforts are mobile connectivity, online payment, the ever increasing use of cloud and Internet of Things (IoT) devices, remote access and third-party outsourcing. These days almost every business has a website and externally exposed systems that make it easier for the attackers to enter the internal networks. Moreover, most smart devices (both at home and at work) are connected to the Internet which makes the system prone to attack. Hence, ensuring cybersecurity is an absolute must for every business and also for individuals. Common types of cybersecurity are application security, hardware security, network security, cloud security, Data Loss Prevention (DLP), Cryptography, Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), Identity and Access Management (IAM), and Antivirus/anti-malware.
You are a Security Consultant of a famous security consulting company that provides security consulting services to a wide range of business, individual, education institutes and companies. Recently one of your clients, ABC Technologies (ABCT) has contacted your organisation to prepare a document on Cybersecurity as it was the recent victim of several cyberattacks.
Here are the details of your client company:
ABCT is an Australian technology company whose line of business ranges from different types high-tech products which include both software and hardware. ABCT has multiple offices nationwide, and two overseas offices. All computer services are provided by virtual private network (VPN), which is maintained in Canberra (the head office). ABCT allows their employees to work from home (using VPN connections) and also have a Bring Your Own Device (BYOD) policy for their employees who work onsite. Each location also provides free wireless LAN access to visitors/guests. ABCT currently have 10,000 regular customers. All their customer and product information are stored in the cloud. Because the company was the victim of several recent cyberattacks, they are concerned that company’s data might have been compromised and hackers might have gotten hold of customers’ information. They are also worried that they would lose the trust of their loyal customers, which could potentially result in a loss of revenue. So ABCT wants to improve their security system and security related policies. As a first step, they want your organisation to prepare a document on cybersecurity to train their staff on the basics of cybersecurity. As part of that, your team leader asked you to research and write a report that should cover the following tasks:
1. Explain what is cybersecurity and why it is important for ABCT?
2. Identify and explain at least 3 security vulnerabilities in ABCT’s system (you need to consider ABCT’s case as presented above). You need to justify your answer with evidence from research.
3. Do some research, and find and list 5 different types of emerging threats (that might affect ABCT) and describe each of them in detail. In your discussion include what damage the attack might cause, who is responsible for these attacks and their attack techniques.
4. Do some research, analyse the information and give your recommendations (at least 3) how to protect home and office from cyberattack.
Specifically your report should include the following (word count details are approximate guidelines):
1. Title page: unit code and name, assessment number, report title, assessment due date, word count (actual), student name, student number, CQU email address, campus lecturer/tutor, and unit coordinator. If applicable, add extension request ID and the new due date. Must be formatted to a standard required for a professional/business report. Check week 6 materials for example of a professionally formatted title page. Not included in the word count.
2. Executive summary: should include the purpose of the report, the problem including key issues considered and how they were investigated, your findings, and overview of your recommendations.
4
This part should be approximately three quarters of an A4 page but must not be longer than one (1) A4 page. Not included in the word count.
3. Table of Contents (ToC): should list the report topics using decimal notation. Need to include the main headings and subheadings with corresponding page numbers, using a format that makes the hierarchy of topics clear. Because you are including a ToC the report pages should be numbered in the footer as follows: title page has no page number; and main text to have Arabic numerals commencing at 1. Create the ToC using MS Word’s ToC auto-generator rather than manually typing out the ToC. Instructions can be found here https://support.office.com/en-gb/article/Create-a-table-of-contents-or-update-a-table-of-contents-eb275189-b93e-4559-8dd9-c279457bfd72#__create_a_table. Not included in the word count.
4. Introduction: provide a brief description of the organisation as given in the case scenario including any assumptions, a concise overview of the problem you have been asked to research, the main aims/purpose of the report, the objectives to be achieved by writing the report (include the tasks outlined in the case study) and how you investigated the problem. Provide an outline of the sections of the report. Should be approximately 250 words.
5. Body of the report (use appropriate headings in the body of the report.): Define key terms you will use in your report that are directly related to the problem and the technology considered. Then present your ideas on the topic and discuss the information you found in your research that was relevant to the report’s objectives. Provide an analysis of the information that you gathered. Ensure that you explore the tasks listed in the case study scenario.

 

Solution

Introduction
ABC Technologies (ABCT) is a software and hardware manufacturer. It is based in Australia and has multiple offices nationwide, and its head office is based in Canberra. Recently the company has been a victim of multiple cyber-attacks across its offices. The key assumptions to be taken into considerations include, the company has never implemented any cybersecurity measures since incorporation. ABCT has been a recent victim of numerous cyber-attacks in the form of a data breach, malicious infiltration, privacy violations, and phishing (Caravelli & Jones, 2019). The company is also a victim of malware attack, Denial of service, and Distributed Denial of service attack.
The major aim of this report is to give a detailed analysis of the attacks the client has undergone and suggested practical solutions of the same. The report also aims at suggesting the importance of cybersecurity to ABCT, various cybersecurity techniques, prevention measures, and how the client will combat the threats. Furthermore, the report will also outline several emerging threats that the client might face in the future and how to deal with them. At the end of my investigations, I came up with recommendations that I have also included in the report. This report contains eight sections including, executive summary, introduction, the definition of cybersecurity and its relevance to our client (ABCT),……….To access the rest of the solution for $10, please click on this purchase button.