Assignment Task
Case Study
Overview
Course Learning Outcomes Addressed
This assessment relates to the following course learning objectives (CLOs):
CLO 2. Explain the issues, information, problems, and concepts relating to the role that people play in cyber security, and how this relates to organisational process, technology and policy;
CLO 3. Identify and describe knowledge and skills required in managing human factors and behaviour to counter cyber threats;
CLO 4. Develop human behavioural knowledge relating to cyber security knowledge, and how these can be applied towards improved cyber security controls;
Task Description
This is a case study-based assessment. You are given a real-world scenario demonstrating how human behaviour can raise cyber security issues and how these issues can be controlled. This assessment aims at examining your knowledge in identifying and analysing risky human behaviour in large scale systems that cause cyber security attacks. You are to apply your knowledge gained during the modules to develop security control to reduce the occurrence of these risks.
Task Details
Scenario
The world’s largest online marketplace is Amazon (Amazon.com) who offer an extensive range of products from fashion and electronics to automotive supplies and food items. Customers can buy nearly anything from Amazon’s e-commerce platform which enables third-party sellers to promote and sell their products alongside Amazon’s own items. Amazon functions as a dynamic ecosystem, aligning various services to ensure a smooth interaction between consumers, retailers, delivery drivers, developers, and support teams.
In such a system, consumers, the primary users, access the app or through the website Amazon.com on their devices to browse and place orders. These orders are transmitted through the app or web interface to the retailers, detailing the items selected and the delivery location. Simultaneously, personal details and payment information are secured and encrypted for transactional purposes.
Amazon has a choice of shipping or fulfilment options for sellers, ‘Fulfilment by Amazon’ (FBA), ship it via Amazon Easy Ship or sellers can organise their own shipping. Many Amazon sellers use a mix of Amazon fulfilment and shipping their own orders. In the FBA option retailers store their products in Amazon’s fulfilment centre and Amazon will then pick, pack, ship, and provide customer service for these products. Whereas when retailers choose Amazon Easy Ship, the orders are picked up from an eligible location and delivered to the customer’s address. Regardless of the shipping method products would be input into Amazon’s database. This data is organised and displayed for customers to select their desired item.
The platform uses big data and AI to show customers preferential product and service recommendations to drive more sales and profit for Amazon and their retailers. Another group of users in Amazon platform are the delivery drivers who are essential for the physical delivery aspect and engaged through the platform. Once an order is placed, a driver is assigned to pick up the order within a certain time period from the fulfilment centre and deliver it to the specified location. This process is facilitated by location tracking and routing algorithms. Developers of Amazon platform maintain the functionality and user experience. They ensure seamless navigation, product interaction, order placement, and secure payment processing. In the background, databases store user profiles, order history, and retailer information. Support teams play a pivotal role in customer service. They manage customer inquiries, technical issues, and order discrepancies. This interaction is facilitated through customer service interfaces and ticketing systems, allowing for prompt issue resolution.
To keep the Amazon ecosystem functioning successfully, data flows through various layers of the Amazon platform, from the app or website browser’s user interface to the databases, ensuring orders are processed, communicated to retailers, and conveyed to drivers for delivery. Developers maintain the platform’s structure, and support teams troubleshoot any disruptions to the smooth operation of the process. This synchronization across services allows for a flawless experience for the customer while the digital ecosystem operates behind the scenes.
In the context of this scenario, answer the following Tasks:
Task 1. Explain with two (2) examples of how retailers can be attacked by a ransomware attack. Discuss how unaware retailers could disrupt the process of package delivery if they accidentally run into this attack
Task 2. Explain the required skills that developers of the Amazon platform would need to reduce the negative consequence of ransomware attack, as discussed in the previous question, regarding package delivery
Task 3. The customer using the Amazon platform can unexpectedly experience phishing emails. Explain with four (4) examples from the scenario of phishing emails that could be used in a cyberattack. For each example, provide (a) reasons why each example phishing email could be successful and (b) security controls to protect against these cyberattack
Task 4. Propose two (2) recommendations for developing the knowledge of Amazon delivery drivers in human behaviour that could reduce cyber security risks. You need to provide example(s) from the scenario to support your answer
Individual
This assignment must be all your own work. It is acceptable to discuss course content with others to improve your understanding and clarify requirements, but solutions to assignment questions must be done on your own.
