ITEC326 Information Systems Security
Task:
Analyse common security threats and security requirements for an IT system
• Evaluate security risks using standard models and propose mitigation techniques
• Recommend appropriate security measures to protect IT systems from security threats
• The feedback from this assessment will help students to be ready to correct any conceptual misunderstanding and apply in real-world scenarios
Context
The context of this assignment is that you have been employed as a security specialist and you are required to assess security threats and identify effective security measures to mitigate risks. To perform your jobs, you need to investigate an IS/IT system, identify five common security threats, analyse security requirements, rating the risks for each threat, calculate the severity of security threats on the whole system and recommend appropriate security solutions.
In this assignment, you have to choose an Information System or IT system to write a report on security analysis and planning. You can choose a system from the following list or your own. However, you must choose an IS or IT system. The report would be based on two security models: TRIDE and DREAD. First, you need to identify 5 common security threats to your selected system. Then, you should list the security requirements to deal with those threats using STRIDE model. In the second part of your report, you have to analyse the risk of each threat on your system using DREAD model. You also need to measure the overall risk of the system and propose appropriate security measures to overcome the threats.
List of IS or IT Systems:
1. Enterprise Resource Planning
2. Data Warehousing
3. Office Automation
4. Global Information Systems
5. Library Management Systems
6. Online Ticket Reservation Systems
7. Hotel Management System
8. Banking System
9. Healthcare System
10. Supply Chain Management System