You have just been hired as an Information Security Engineer for a videogame development company. The organization network structure is identified in the below network diagram and specifically contains:
|1) 2 – Firewalls||5) 2 – Windows Server 2012 Active Directory Domain Controllers (DC)|
|2) 1 – Web / FTP server||6) 3 – File servers|
|3) 1 – Microsoft Exchange Email server||7) 1 – Wireless access point (WAP)|
|4) 1 – Network Intrusion Detection System (NIDS)||8) 100 – Desktop / Laptop computers|
|9) VoIP telephone system|
The CIO has seen reports of malicious activity being on the rise and has become extremely concerned with the protection of the intellectual property and highly sensitive data maintained by your organization. As one of your first tasks with the organization, the CIO requested you identify and draft a report identifying potential malicious attacks, threats, and vulnerabilities specific to your organization. Further, the CIO would like you to briefly explain each item and the potential impact it could have on the organization.
Write a four to five (4-5) page paper in which you:
- Analyze three (3) specific potential malicious attacks and / or threats that could be carried out against the network and organization.
- Explain in detail the potential impact of the three (3) selected malicious attacks.
- Propose the security controls that you would consider implementing in order to protect against the selected potential malicious attacks.
- Analyze three (3) potential concerns for data loss and data theft that may exist in the documented network.
- Explicate the potential impact of the three (3) selected concerns for data loss and data theft.
- Propose the security controls that you would consider implementing in order to protect against the selected concerns for data loss and data theft.
- Use at least three (3) quality resources in this assignment (no more than 2-3 years old) from material outside the textbook. Note: Wikipedia and similar Websites do not qualify as quality resources.