Security Plan: Green Products
The following security plan was put together by Green Products. Because of the
increasing fraud in online transaction, Green Products has decided to make a new security
plan to improve the security of our online business.
This plan was developed by group 2 members: Xin Ma, Robert Mccullough, Jenny
Bymoen, Preet Sidhu and Wendy Mcfawn.
About Green Products
We are running a 3-person company specializing in selling environment friendly
products. Our staff includes office administrative, sales and marketing personnel.
Objectives
To make a reliable security plan, improve the security level for our online business
activities, educate our employees. Our main priority is continuing grow our business.
Project Team
Section 2: Assessment Results
Our assessment has produced the following results.
Skills and Knowledge
We need to internalize as much of this knowledge as possible by doing as much of the
work as we can. Doing so will also help us save money.
Our Network and Systems
Desktops: Three (one per member of staff plus one old machines acting as print
servers)
Laptop computers: Three (one each for each staff)
Printers: Two (one high-end plotter and one printer-fax combo unit for general
use)
Servers: One (running Small Business Server 2003 and looking after files, the
Internet connection, e-mail, and our customer database)
Internet connection: 1.5 Mbps cable modem connection
The server and several of the computers are linked by 100 Mbps Cat5 Ethernet cables.
The remainder is linked by an 802.11g wireless network with an access port. All
computers run Windows 7 Professional except for the two print servers and two
administrative computers, which run Windows XP.
Security
We decide to use the following
Virus protection: Mcaffee will be installed on all the computers and laptops in
the office, and the update will be required weekly.
Spam-filtering software: Green products will use Spam Fighter Pro to prevent
spam mails from trying to affect our computers.
Firewall: The router our ISP provided to us has the setup up function already, so
there is no extra firewall needed to be installed.
Updates: All the computers and laptops in the office are required to be updated to
date.
Passwords: All of our computers, servers and laptops are required to setup a
password for technician maintaining and repairing, users are required to setup
their own password for using computers.
Physical security: Servers will be setup in a locked room; one employee will be
responsible for taking care of that room.
Wireless networking: A strong password is needed for accessing our internal
wireless network.
Backups: We back up data on the server to a Digital Audio Tape (DAT) drive on a
weekly basis, The server contains our primary customer database, so well-tested
backups are essential, as is keeping a copy of backups offsite.
Assets
Besides the physical property, our main assets are:
Our product designs and marketing collateral
Records of our contracts with vendors
Our e-mail database and archive of past e-mail messages
Sales orders and the customer database
Financial information
Line-of-Business (LOB) software for online booking and reservations
Paper legal records stored in various filing cabinets
All these assets are considered secret and should be accessible only on a need-to-know
basis. In addition, they need to be protected and backed up as safely as we can manage.
Risks
We believe the risks break down into four main categories:
Intruders (viruses, worms, hijacking of our computer resources or Internet
connection, and random malicious use). These are the risks that anyone using
computers connected to the Internet faces. High risk, high priority.
Internal threats. Whether accidental or deliberate, a member of staff may misuse
his or her privileges to disclose confidential information. Low risk, low priority.
Accidents and disasters. Fires, floods, accidental deletions, hardware failures, and
computer crashes. Low risk, medium priority.
Priorities
1. Intruder deterrence:
Firewall
Virus protection
Strengthening the wireless network
Ensuring that all computers are configured to be updated automatically
Ongoing user education and policies
2. Disaster prevention:
More frequent backups with offsite storage
Ensure backup of users’ local data
Offsite backup of critical paper documents
Regularly testing the backups by performing a restore
3. Internal security and confidentiality:
Strong password policy and user education
Review security for filing cabinets and confidential documents
Section 3: Security Plan
After performing our assessment, we have devised the following security plan.
Action Items
1. Select, purchase, and install a hardware firewall (or ask our ISP or technology
consultant to provide one).
2. Enable Windows Firewall on the server and on all desktop computers.
3. Make sure that antivirus software is installed on all computers and that it is set to
automatically update virus definitions.
4. Configure computers running Office Outlook 2013 to use Junk E-mail filtering.
Select, purchase, and install spam-filtering software on the mail server, if
necessary.
5. On the wireless network, disable service set identifier (SSID) broadcasting,
choose and configure a sensible SSID, enable WPA encryption, enable MAC
filtering, and configure the access point to allow traffic only from the desktop and