CST 630 CALUMS Cyber Exploitation & Mitigation Methodologies Presentation

Publish By: Admin,
Last Updated: 16-Jul-23
Price: $120

You have been appointed the deputy chief information security officer at one of the subsidiaries of the media company you work for. 

As the company continues to expand geographically, the CEO wants to manage travel costs by using real-time low cost commercial video conferencing systems for meetings and collaboration. However, such systems come with security issues.

There have been disturbing reports of malicious actors stealing emails, videos, and sensitive data from other media companies. 

The company’s chief information officer, or CIO, and chief technology officer, or CTO, say that video conferencing systems will integrate with the current enterprise networks. But they did not assess system options.

They, along with the chief information security officer, or CISO, have asked you to recommend a modernization strategy for the company’s video conferencing while maintaining the security of the sensitive information discussed by the users. 

Business communications between subject matter experts, engineers, and executive leaders must be protected.

 Your task is to provide a proposal for a secure video conferencing system.

You need to analyze the features of three videoconferencing systems and provide an overview of each system. 

After you complete the overview of the systems, you’ll recommend a system which best meets the business functionality and security requirements. 

You will also prepare a set of high-level executive briefing slides to give the CEO and CIO an overview of your study. 

Your study and recommendation will be critical to the company’s success.

Cybersecurity professionals are frequently required to assess the security, risk applications, and systems for business communications before they can be added to an organization’s network. 

CISOs need to assess risks posed to the organization and develop new security measures or adjust current measures to address these risks appropriately.

 These evaluations involve comparing competing applications or systems against the organization’s baseline to determine the best balance between business needs and the security and risk appetite of the organization.

Videoconferencing and collaboration systems vary in cost, configuration, functionality, use, and collaboration capability. 

These systems are trusted to facilitate sensitive and proprietary discussions through their use of encrypted communication channels. 

Yet these systems have vulnerabilities and are prone to threats and attacks ranging from phishing, credential compromise, and even malware insertion. 

Therefore, analysis of possible threats, attacks, and vulnerabilities inherent in these systems is critical in developing defense and protection strategies for voice and video data at all endpoints and during transit.

In this project, you will present your proposal in the form of a narrated slide deck. Be sure to refer to Guidelines for Presentation on Secure Videoconferencing. Also, you will complete a lab report on secure videoconferencing. There are six steps to the project, and the project as a whole should take about two weeks to complete. Begin with the workplace scenario above and then continue to Step 1.

Step 1: Develop Functional Requirements for Videoconferencing

The first step in your proposal for a secure videoconferencing system is to develop a set of functional requirements for videoconferencing that you believe the media company will need based on its geographic dispersion and business needs.

In developing those requirements, research three videoconferencing solutions such as Zoom, Skype, GotoMeeting, Polycom, and Cisco WebEx and explain their capabilities, advantages, and disadvantages. Identify costs as well as implementation and support requirements.

The functional requirements and the three possible solutions will be a section of your proposal. In the next step, you will review the challenges of implementing those solutions.

Step 2: Discuss Implementation Challenges

In the previous step, you outlined the requirements for secure videoconferencing for the company and outlined three potential solutions. Part of your final proposal should also include the advantages and disadvantages of the implementation options for the three systems you selected. This section of the proposal also must include the changes the media company will need to make to implement the systems.

Additionally, explain how system administration or privileged identity management will operate with these systems. You will also need to examine how data exfiltration will occur with each of the new systems.

The changes to the systems and challenges for the implementation of these potential solutions will be an important section of your proposal. In the next step, you will take a closer look at each of the potential videoconferencing vendors.

Step 3: Identify Vendor Risks

You’ve finished outlining the pros and cons of three videoconferencing systems. Now, it’s time to take a close look at how they serve their clients. This will take some research. Look at the systems’ known vulnerabilities and exploits. Examine and explain the past history of each vendor with normal notification timelines, release of patches, or work-arounds (solutions within the system without using a patch). Your goal is to know the timeliness of response with each company in helping customers stay secure.

This step will be a section of your proposal.

In the next step, you will outline best practices for secure videoconferencing that will be part of your overall proposal.

Step 4: Develop Best Practices for Secure Videoconferencing

The last few steps have been devoted to analyzing potential videoconferencing solutions. But obtaining a trusted vendor is just part of the security efforts. Another important step is to ensure that users and system administrators conduct the company’s videoconferencing in a secure manner. In this step, outline security best practices for videoconferencing that you would like users and systems administrators to follow. Discuss how these best practices will improve security and minimize risks of data exfiltration as well as snooping.

Goal: You will create a proposal for a secure videoconferencing system for management. Your task is to recommend a system that best meets the business functionality and security requirements of the company. The system must be trusted to facilitate sensitive and proprietary discussions through the use of encrypted communication channels. You need to analyze the features of three videoconferencing systems and provide an overview of each system. The material must include your analysis of possible threats, attacks, and vulnerabilities inherent in these systems. After you complete the overview of the systems, you’ll recommend a system which best meets the business functionality and security requirements. Also include your recommended defense and protection strategies for voice and video data at all endpoints and during transit.

Deliverables: Proposal for Secure Videoconferencing with Executive Summary, Slides to support Executive Briefing, Lab report: Generated from Workspace.

Step 1: Develop Functional Requirements for Videoconferencing

“Functional Requirements” section

  • Research three videoconferencing solutions
    • explain their capabilities,
    • advantages, and
    • disadvantages.
    • Identify costs as well as implementation and support requirements.
  • Develop a set of functional requirements for videoconferencing that you believe the media company will need based on its geographic dispersion and business needs.

Step 2: Discuss Implementation Challenges

“Implementation Challenges” section

  • Include the advantages and disadvantages of the implementation options for the three systems you selected.
  • Include the changes the media company will need to make to implement the systems.
  • Explain how system administration or privileged identity management will operate with these systems.
  • Examine how data exfiltration will occur with each of the new systems.
  • Based on the systems’ known vulnerabilities and exploits, examine and explain the past history of each vendor with
    • normal notification timelines,
    • release of patches, or work-arounds.
    • timeliness of response with each company in helping customers stay secure.
  • Outline security best practices for videoconferencing that you would like
    • users and
    • systems administrators to follow.
  • Discuss how these best practices will improve security and minimize risks of data exfiltration as well as snooping.
  • Follow the lab instructions to develop system integrity checks for files shared between users of the videoconferencing systems. Include those in your lab report.
  • Executive Briefing: This is a three- to five-slide visual presentation for business executives and board members.
  • Executive Summary: This is a one-page summary at the beginning of your proposal.
  • Proposal for Secure Videoconferencing: Your report should be a minimum 6-page double-spaced Word document with citations in APA format. The page count does not include figures, diagrams, tables or citations.
  • Lab report: Generated from Workspace.

Step 3: Identify Vendor Risks

“Vendor Risks” section

Step 4: Develop Best Practices for Secure Videoconferencing

“Best Practices” section

Step 5: Develop System Integrity Checks

Lab report