Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

You are the newly hired Network Security Administrator for UMESCo, a financial c

ID: 3839274 • Letter: Y

Question

You are the newly hired Network Security Administrator for UMESCo, a financial consulting company. This company has seven branch offices around the country, connecting to the primary office over L2TP/IPSEC VPN tunnels. There are one hundred employees at the main office, and an average of 25 at each remote office. All employees have access to FinanceWare, the antiquated and proprietary financial ERP system used by your company, via the SSH-based client installed locally on their Windows 8.1 desktops, running in a server/client environment. The system is maintained by the IT Department, and all IT personnel are located full-time at the main office where the FinanceWare system is housed. Recently, several of the senior staff have asked to access FinanceWare from their mobile devices or web browsers when on the road, or meeting with clients. The software is old, and does not have any sort of web or mobile interface whatsoever. The back-end product is a Microsoft SQL database, and the front end client application is unable to be modified. The Chief Information Officer (CIO) has stated that his Network and System Engineers will be making changes to the firewall to publish the FinanceWare system to an external public IP address, allowing any mobile or web-enabled devices with Internet access to log in from anywhere. Due to the age of FinanceWare, a custom interface will need to be created by a 3rd party vendor, as there are no on-staff software engineers at UMESCo and the software version owned does not support a user interface for mobile clients. The vendor has stated that they will need administrative access to the Application server in order to set up Microsoft IIS and configure the web server functionality to work with their newly-created web app that interfaces directly with the SQL database on the local server. The vendor has stated that their software will be Javascript based, heavy with SQL statements and use custom views for the security groups set up in SQL as the means of security. Note that the SQL based access will allow the users to have the same rights in the field that they have in the office based on their user login (read only or read/write). The CIO has asked you to prepare a report for him detailing what you consider to be potential security vulnerabilities with his new plan. You must: Identify what you consider to be potential security threats in the scenario above. Develop a plan that, by using the methods, tools and ideals covered in this course, integrates effective security and protection against the potential threats you have identified. Prepare a succinct report to the CIO of UMESCo, Mr. Smith, detailing your identification of the threats, your plan to address them, and the desired results of your plan. Make sure to include an executive summary instead of an abstract since it is a business document.

Explanation / Answer

±hen, I pronounced what sort o² information o² every variable I will utilize is. I pronounced all o² the fbs 1-3
also, the number o² fbs as "whole number" on the grounds that these numbers will dependably remain as entire numbers,
no decimals. I additionally announced "twofold" to client enter, the raTo (amongst fb2 and 3) and furthermore the
di³erence between the brilliant and fb raTos on the grounds that all these will contain a decimal place. ±o
demonstrate the aggregate I announced it as a "string" variable since it will then contain any set o²
characters I dole out it as well. ±o have the circle know when to stop and rehash I announced 'ag as a"
Boolean" expression.
Gather User InpuT
What I will be collecTng is whatever gets inpuµed into the textbox alongside "How near the
Brilliant RaTo should we get?" which then gets appointed as a "twofold" factor into the post box

Hire Me For All Your Tutoring Needs
Integrity-first tutoring: clear explanations, guidance, and feedback.
Drop an Email at
drjack9650@gmail.com
Chat Now And Get Quote