Monday, April 4

ITC568 - Cloud Privacy and Security - Assessment item - 4


 

Table of Contents

Introduction. 3

Benefits and Issues of Layered Defence and Zero Trust Approaches. 3

Implementation Strategy for the Protection of DR alarm Data. 6

References. 8

 


 

Introduction

One of the main purposes of this report is to describe about the security strategy of layered defence and zero trust to offer a protection for the data and prevents the data from the privacy loss across the organization and its various storage sites in the AWS and their data center of on-premises. Here, it discusses both strengthen and weakness of zero trust and layered defence security models. The objective of this research report is to review and research the probable privacy loss and data protection strategies to prevent the DR alarm data’s as securely. Based on the comparison of both security models, it suggests one of the suitable strategy for the DR alarm to secure the data’s from privacy loss and protection of data. Different kinds of research papers has been analyzed to recommend the better suitable approach in preventing the data’s from the loss of privacies and to meet the international privacy requirements for DR alarm. In this case, it finds some key differences between the zero trust and layered defence strategies as well as their corresponding benefits and issues.

Benefits and Issues of Layered Defence and Zero Trust Approaches

The strategy of layered defence has been utilized to determine the security system which is constructed using the multiple policies and tools to protect the multiple network areas. This can safeguarded against the multiple threats involving the insider attacks, theft, worms, un-authorized accesses and the other considerations of security.

Beneficiaries of Layered defense Strategy

1.      This desired strategy of layered defence could protects or safe-guard from the attacks through the attachment of e-mail, applications, files, links, adware and more.

2.      The security of DNS level has been utilized in this strategy to defend against the threats which originates at the level of net-work.

3.      The programs of end—user education is used to address the sources of 93 percentage of all breaches that is the user errors (Chellappan, 2015).

4.      In this process, it includes various kinds of layers. All these layers could work combined to tighten a security and it involves a better chance to halt the intruders from the network breaches than utilizing the solution of single security.

5.      This strategy primarily encompasses a multiple technical control. This multiple controls might involve encryption, sand-box or faux environment, fire-wall, authorization, intrusion prevention and the detection.

Issues involved in Layered defence Strategy

1.      By including a multiple security layers in the DR alarm which is crucial to secure the data at all levels across the multiple devices and apps.

2.      One of the essential part of any net-work securities i.e., UTM or fire-wall could stands as a major barrier between the cyber-space and a network. When some of the fire-walls are multi-functional and others could be highly sophisticated and difficult for the DR alarm.

3.      The organization of DR alarm communicated heavily by the cyber thieves and e-mail that are aware keenly. In the frequent time end user or end point protection were not enough to safeguard from opening an infected attachments and the e-mails.

4.      In this case, many risks were associated with utilizing an internet access to conduct the DR alarm’s business activities. With this strategy, security is more complex due to the multiple layers and the channels of communication among itself finds to be open to attack.

5.      Some of the layers offered in this strategy finds to be vulnerable for the certain kinds of attacks when compared with the other security strategies. Hence, it could finds critical to under-stand the risks which are imposed through every services that intends to offer or use (Cho, 2014).

 Beneficiaries present in Zero Trust Strategy

The beneficiary of implementing the zero trust model in DR alarm could go far beyond a security. Here, it lists some major beneficiaries like,

1.      The strategy of zero trust enables the team of security to work smartly. Because, this could uses the centralized monitoring and that generates easily the reliable DR alarm data stored on a single location.

2.      This could delivers a better protection for the data of DR alarm. The frame-work of zero standing privilege is combined with the just—in—time access and that secures the malware or rogue workers from gaining the accesses to a larger portion of DR alarm net-work.

3.      The strategy based on a zero trust could also provide the robust protections for the DR alarm employers and data’s in any of the locations.

4.      The framework of zero trust helps to ensure the continuous compliances with each request of access which is being logged and evaluated.

5.      From increasing the visibility to improving the productivity, it makes a better usage of IT sources and facilitates the compliances. This could guides to construct the resilience and strengthen through-out the companies of DR alarm.

Issues in Zero Trust Approaches

With all the additional strengthen of security, the strategy of zero trust makes the security policies as complicated. Here, it involves some additional challenges which comes up with the strategy of comprehensive.

1.      Re-organizing the policies with-in the previous DR alarm network could be complex because, it still requires the function during the process of transition.

2.      The users of employee requires to be monitored closely with only the granted access that are essential. Clients, third parties and the consumers might also utilizes the DR alarm databases to access the data. This could refers that it requires a wide varieties of access points and the frame-work of zero trust needs the particular policies for every kind of a group.

3.      The security model of zero trust needs many authorization levels as it require all the DR alarm actors to be checked for the accesses (Sudakshina Mandal, 2021).

4.      Many of the legacy based system such as DR alarm systems does not includes enough capability to offer the access control in that respective manner.

5.      The issues arises with the unification problem across the cloud infra-structures and hybrid networks which hinder the verification and micro-segmentation, specifically while the certain plat-form of DR alarm could not run on the particular infra-structure of cloud provider.

Implementation Strategy for the Protection of DR alarm Data

Implementing the strategy of zero trust in the DR alarm environment is iterative. Breaking the strategies in to a series of smaller, repeatable procedures allows to improve upon the DR alarm process as the team gains the experiences with the zero trust technologies & principles.

Defines the protect surface

In the strategy of zero trust security, it focuses on defining the protect surfaces or every particular items which requires to protect or safe-guard from the attack. The protect surface must involve the assets, services, data and apps which is referred as the DAAS that are more crucial for DR alarm organization to secure against the attacks (Bobbert, 2020). Here, in this case, it utilizes the segmentation of network to control granularly and monitors the traffic to limit strictly in which the resources and users could request the accesses.

Mapping the inter-dependencies

One the protect surface has been defined, it requires to map its flow of traffic and the inter-dependencies. Essentially, mapping the inter-dependencies of DR alarm could allow to secure the protect surfaces with-out accidentally by breaking any relevant apps, work-flows or the services.

Build the architecture of Zero Trust Network

After defining the protect surface and reports the inter-dependencies & traffic flow, it constructs the architecture of zero trust net-work. For instance, it uses the next—generation fire-walls to segment the network oriented on the defined protect surface, monitors the traffic and enforces the control of access on all the layers of OSI model. The traditional fire-wall secures the layer by the four different layers of data link, transport, physical and the network). In contrast to that, next generation fire-wall protects the DR alarm data.

Establish the Policies of Zero Trust

To protect the DR alarm data, it requires to create the policies of zero trust security for the protect surfaces. In this case, one needs to remember that creating the policies of zero trust for every process, it secures the micro—perimeter and surfaces. Through this, it enquires to get the granular as probable to ensure to permit only the protected communication and traffic.

Monitor & Optimize

The final procedure is to monitor a protect surfaces and conducts the log reviews frequently to ensure that the operations of zero trust runs smoothly. According to this strategy, DR alarm company needs to monitor continuously all the device and user communication in to the newer micro perimeter. This could allow to remediate and detect the potential latencies, errors, performance problems as well as it creates the base-line for a normal behaviors (Mehraj, 2020). These kind of baselines could makes easier in a future to detect the teams of security and the detection of threat with the help of tools to spot the un-usual operation which could represent the breaches.

Assess the capabilities of Zero Trust Security

One of the most beneficiaries of zero trust security is in which it does not needs the disruptive or expensive technique over-haul to achieve it. Through utilizing this desired strategy, it could finds the existing gaps of DR alarm in the readiness of zero trust to overcome from spending of money on the solutions in which it do not requires to have.

Implementation of Layered Defense Approach

Encryption of e-mail

Once the e—mail leaves the server then it could be a fair game to any-one who were trying to intercept. While there is an sensitive details with in the e—mail then there could be a potential for the breaches of DR alarm data. With the encryption of e—mail, the e—mail & it’s relevant details were modified in to the format of non—readable.

 Data encryption

Similar to the encryption of e—mail, the data encryption secures the data from breaches even in a cyber-attack events. Through utilizing the effective plat-form of data encryption, it might not prevent the occurrence of a breaches, but it renders the data virtually with the un-readable data to any-one who were trying to access the DR alarm confidential related information.

Archiving of E—mail

Duplicate attachments, emails and the users saving every e—mail they could get it. It does not fetch a longer for the volumes of g-mail to geometrically expand because of various problems. The archiving of e—mail could resolve the problems while increasing the corporate searching of e—mail and decreases the needs of data storage and the costs for DR alarm (Coole, 2012).

Maintenance of Mobile Devices

Virtual offices and mobile work places were becoming norm. Maintaining the IT requirements of off—site workers and off—site components, it does not requires to be complex. While having the people in a field and requires to ensure a security and safety of the DR alarm components, proprietary details and the data in which it is being used, the management of mobile device is essential.

Web Filter

Internet has been considered as a great tool, but it also a secure place where the cyber criminals could prey on the un-secured web surfaces. Ensure the staff to utilize their corresponding time as effectively and were not going to a site that poses a security threat which is the necessary component for the business of DR alarm.

Application level based on Security

At this desired level, it includes some set of control measures on how the DR alarm customers could interacts with the specific apps. In this case, generally the DR alarm admins should requires to configure the security settings for every apps that could utilizes it. Hence, one should requires to have some special attentions to set up some security for those apps and services of DR alarm. The applications and the relevant services offered in the DR alarm by using the layered defense strategy finds to be secured among the un-authorized users who could seeks to gain the accesses.

Strategy on privacy loss

Strategies for privacy loss prevention

The privacy loss preventions are effectively held through the two different strategies for the DR alarms and two strategies are structured below with the functionality affects towards threats and risks;

Layered defence strategy

The layered defence is the basic security principle, whereas the DR alarms can use it to defend the data, users, and entire employee’s personal information. Basically, the single layer of security would not stop the whole attacks towards the organization and it does not give the full affect on the privacy loss protection, so the layered defence can be initiated through help of many layers for the effective data privacy loss prevention from the threats and risks.  However, if one layer fails to protect the data in organization, there are many layers induced which would delay and make the defence over the attackers in means of data access. Therefore, the defence layer affects the DR alarms to effectively mitigate the risks of a sensitive data breach and threats occurring.

Figure 1 - Layered defence strategy

The above figure shows the layered defence strategy design, which is designed with three types of elements physical, technical and people. It means, it would give the protection strategy to all these elements in the DR organization, the technical data and employees data will be grouped and protected with help of the layered defence strategy by without loss of privacy.

Trust zero strategy

The zero trust strategy affects the entire DR alarms data in means of data privacy loss prevention, it enhances the sensitive data to be more pervasive, interspersed overall the DR alarms, need of organization for considering the privacy measured which takes the data protection all around the DR alarms. The zero trust approach towards the data privacy and securing the data is much efficient, it does not let any unauthorized users to access the application, IOT device, alarm systems or any kind of process without proper trustworthy. In such cases, it keeps on evaluating the users, whether the attackers or intruders access to the privacy data as per the contextual information observed from the main system. It keeps the verification relies over the context, so that entire organization sources those needs to access the data from the system needs to prove the legitimate needs before accessing.

Benefits of layered defence strategy

Ø  The layered defence enables the mail protection effectively; some of the infected data that are sent between the employees and customers will be sorted out heavily. It keeps the email to be more secured and it makes the effective updates towards the email software. It regularly trains and updates the available software, the secure practices will be enabled through the layered defence, and it will highlight all the danger social way for the infiltration and password policies. The best practices and approaches are induced through the system of layered defence so it provides the strongest protection towards the privacy loss.

Ø  The patch management makes every employee in the organization to keep every system up to the date. Here, the departments of information system will be pushed to make the security updates for particular system and to patch up with the business devices and enhances the BYOD policy for the DR alarms. Accordingly, this initiation will affect the system in the organization in means of applying the antivirus software. Whereas, the patches can be made through the software providers for ensuring the offers are patched through latest files which requires to combat regularly and identifying the virus in the alarm systems.

Issues of layered defence strategy

Ø  This strategy supports only fewer components, whereas it could not give the protection to entire organization for the privacy loss.

Ø  Merging the layered defence towards the network layers are bit complication as it is processed with multiple layers.

Benefits of zero trust strategy 

Ø  This strategy will provide the public and private key for the personal data so that the unauthorized will not access the data from the data center. Some of the private key induced through the zero trust enables the more private progress this will be secured enough and will not unlock the data access unless the proper local gesture opens the system which enhances the effective privacy loss protection.

Ø  The zero trust helps to move behind the peripheral defence and will predict the person, devices and other entities for considering the threats toward the DR alarms. The DR alarms are processed with much sensitive data, proprietary information, and data confidential and personally-identifiable data. The data leakage protection is emerged through the user negligence which brings the responsibility by the leaders in organization, hence initiating the zero trust strategy will more suitable to mitigate the risks.

Issues of zero trust strategy

Ø  The zero trust lags to adopt for the larger types of network connectivity and it may lead to defects in the hardware system in the company tools.

Ø  The other challenges from the zero trust is an access will get locked if not brought to the regular workflows to the grinding halt.

The zero trust strategy behavioral is large in protecting the privacy data, it do features many types of the benefits as well functions for the data loss prevention. So, the zero trust could be adoptable method for the DR organization as it meets some of the international privacy requirements of the DR alarms with latest protocols and heavy security tools.

Strategy on data sovereignty

The data sovereignty remains to be the efforts from the government side for preventing the citizen’s data from non-falling into attack types through the measures which restricts the organization in transferring the data with proper procedure and protocols. So, towards DR alarms the data sovereignty has helped in many ways, the layered defence and zero trust is providing the effective strategy of data sovereignty for the DR alarms. Basically, the cyber threats or risks are emerged from the data, it remains to be the execution of cyber security strategies which will be effective for the business to protect the data of DR alarms.

 

References

 

Kalaivani Chellappan. (2015). Layered Defense Approach: Towards Total Network Security. International Journal of Computer Science and Business Informaticshttps://www.researchgate.net/publication/321622160_Layered_Defense_Approach_Towards_Total_Network_Security

Michael Coole. (2012). Defence in Depth, Protection in Depth and Security in Depth: A Comparative Analysis Towards a Common Usage Language. Proceedings of the 5th Australian Security and Intelligence Conference,https://doi.org/10.4225/75/57a034ccac5cd

Saima Mehraj. (2020). stablishing a Zero Trust Strategy in Cloud Computing Environment. 2020 International Conference on Computer Communication and Informatics (ICCCI)https://doi.org/10.1109/ICCCI48352.2020.9104214

Sudakshina Mandal,. (2021). Cloud-Based Zero Trust Access Control Policy: An Approach to Support Work-From-Home Driven by COVID-19 Pandemi. New Generation Computinghttps://link.springer.com/article/10.1007/s00354-021-00130-6

Young B. Cho. (2014). Survey of Layered Defense, Defense in Depth and Testing of Network Security. International Journal of Computer and Information Technologyhttps://www.ijcit.com/archives/volume3/issue5/Paper030518.pdf

Yuri Bobbert. (2020). Zero Trust Validation: From Practical Approaches to Theory. Scientific Journal of Research and Reviewshttps://doi.org/10.33552/SJRR.2020.02.000546

 

 

 

 

 

No comments:

Post a Comment

ITC506 - Topics in Information Technology Ethics - Assessment item 3

  Table of Contents Task 1: Argument Visualization . 3 Task 2 . 3 Introduction . 3 Utilitarianism Theory . 4 Deontology...