Part B: Final coursework

Part B: Final coursework
This is worth 80% of the module marks. You are allowed to adapt, use or amend the material from
Part A to help you complete Part B.
You are a newly appointed Chief Information Security Officer (CISO) in an organisation. In the light
of the recent high profile of poorly-handled information security incidents, you have been asked to
write a 3000-word report to senior management in your organisation (which could be company or in
the public or third sectors) which (a) research, proposes and evaluates a model for security incident
handling, and (b) applies it to the organisation you have chosen.
You should develop an incident handling model from academic or credible professional sources.
Illustrate and analyse the model using examples from current news stories (from 2017 onwards).
Assess its strengths and weaknesses, and the implications in the light of the increasing need to
respect the privacy of the individuals whose data are stored in the systems.
In more detail, the report should follow the following structure:
 Cover sheet (as described below)
 Executive summary 250-300 words1
(This does not count towards the 3000-word limit)
 Introduction: An overview of the aim and scope of the report and its intended purpose, and the
context (ie relevant details of company sector and location2
).
 Proposed model – Model selection: Identification, selection3 and adaption of standard(s) for
information security incident handling that are appropriate for the organisation you have chosen,
justifying your choice. A diagram or table to illustrate the model would be useful.
 Proposed model – Explanation. This section should be structured around each of the stages in
the model that you have developed, illustrated using examples from relevant and current news
stories. It should identify the issues involved (for instance data breach, ransomware) and explain
how they relate to the model of incident handling that you have developed.
 Discussion and evaluation: This section should cover
o the relationship of the information security incident response with other information security
processes such as risk management
o the privacy and ethical implications of the available options and actual steps taken in the
examples you are using.
o the role of audit in providing assurance that the incident handling process is effective
o governance and compliance issues raised and the professional roles involved in managing
them.
 The Conclusion should include recommendations to management, and evaluation of the strengths
and weaknesses of the model you have evaluated, and consideration of the impact of any likely
developments in next few years.
 References: All sources, formatted as described in the next section
 Optionally: Appendices.
Information Security events are now regularly in the news and well reported and you should have no
problems finding examples to illustrate your report.

1 An executive summary should be around 10% of the length of the main work. It should be placed straight
after the cover sheet, be written in the present tense, and outline the purpose/objectives, findings and key
recommendations of the main report. Citations are not normally expected.
2 You need to supply (minimal) details of your company to contextualise the report.
3
Including how you decided the sources used can be considered credible
INF11809 | Security Audit & Compliance Assessment Brief
4 of 7
General submission rules
The aim of these individual assignments is to assess your knowledge, understanding, application, etc.
of the module material. Copying from any source or collusion between two or more students prevents
this aim from being achieved. So, the content of sources used must be EXPLAINED, not copied; you may
help each other by DISCUSSION only, not by sharing material you have written. Copying and collusion
are serious matters and will be dealt with through the University’s Academic Conduct Regulations.
This assignment is due to be submitted electronically via Moodle on or before the due date above.
You should use the originality report you obtain after submission to ensure that your report contains
no significant copying from any source.
If you have any problems with this assignment, please contact the module leader, preferably well
before the submission date. Grades and feedback will be available to students as indicated on the
Module Plan in the Module Handbook. Work submitted after the due date will be marked and receive
a maximum mark of P1 (the lowest pass). Prior warning of problems will help avoid penalties.
Style and format notes
The report will be marked online. Please take this into account when preparing your document.
You should use a formal style. Your work should be properly referenced throughout and include a
reference list. (You are not required to supply a separate bibliography. A reference list will be
sufficient.)
Front page should include: your matric number, the module id, word count, the coursework title.
Word length: It is suggested that your work should be near the upper limit; report of much less is
unlikely to contain adequate content, which will reduce the marks available. The mark for work over
the maximum wordcount will be reduced.
You may include appendices, tables and diagrams, the content of which should not be included in
the main word count. They can be used to justify and support the arguments in the main text; they
cannot earn you marks in their own right.
Page layout: Submissions should be single column, in a clear black font (eg Arial) 10-12pt in size,
justified and 1.5 line spaced. Captions for tables and figures should use an alternative font style to
the main text (eg italic or bold).
References: All sources used must be formally acknowledged. The author-date system of source
citation should be used in the text, e.g. (Smith, 2017) – use the published guidelines if necessary.
The APA formats used by Word and Mendeley are acceptable. Please do NOT use footnotes for
references (even for websites – they should also be properly cited)4

Don't use plagiarized sources. Get Your Custom Essay on
Part B: Final coursework
Get an essay WRITTEN FOR YOU, Plagiarism free, and by an EXPERT!
Order Essay

 

 

 

 

 

 

 

The NIST SP 800-53 Framework in UK’s MoD

Matric Number

Module Identification

Coursework Title

Word count

 

 

 

Executive Summary 

This report aims to show how a security incident-handling model such as NIST can be adopted and effectively used in a governmental or public institution such as the Ministry of Defense. The report is guided by four main objectives, namely the security overview and status in the Ministry of Defense of the UK and the implications of adopting NIST SP 800-53 in the MoD. It also describes the importance of the framework in the management of information security in the ministry. Finally, outlining the strengths and weaknesses exhibited during the assessment for both the MoD and the NIST framework. The MoD works to ensure that the UK is prosperous and secure through the protection of its people, territories, and its national as well as global interests.

NIST cybersecurity framework is one of the most implemented security incident handling models, especially among governmental agencies. The NIST SP 800-53 standard, however, is the most appropriate standard in addressing security incidents in the UK’s MoD as it has specific controls and standards designed for federal information systems. The NIST SP 800-53 contains operational, technical, and management controls that safeguard, support, and ensure system resilience. These controls and standards ensure that the information systems are secure to increase integrity, confidentiality and information security. The primary purpose of this framework is to help organizations understand, improve, and manage any cybersecurity risks effectively. NIST consists of three main components, namely the Core, the Implementation Tiers, and Profiles. NIST incident handling model is achieved through four main steps, namely preparation, detection and analysis, containment, eradication, and recovery, and finally, post-incident activities.

 

The NIST SP 800-53 Framework in UK’s MoD

Report Overview

Security incidence response and handling have become imperative components of IT among businesses and public institutions. This is in response to the existing and emerging security threats such as information breaches, hacking, failure of systems, and fraud activities taking place. A security incident handing model contains the processes and standards that govern the incident response before, during and after a security issue occurs. There has been no single system described as perfect and without any faults such as malware. Data loss, or breaches from external and internal forces (Broad, 2013). Thus, this report aims to show how a security incident-handling model such as NIST can be adopted and effectively used in a governmental or public institution such as the Ministry of Defense. In achieving this aim, the report is guided by four main objectives. They include the security overview and status in the Ministry of Defense of the UK, the implications of adopting NIST SP 800-53 in the MoD, the importance of the framework in the management of information security in the ministry. Finally, outlining the strengths and weaknesses exhibited during the assessment for both the MoD and the NIST framework.

Since the report focuses on the Ministry of Defense in the UK, it is imperative to give an overview of the governmental agency. The MoD is a central administrative agency of the UK government. It is mandated to implement any defence policies developed ad set by HMG (Her Majesty Government) and was formed in 1964 (Gov.UK, 2019). The MoD works to ensure that the UK is prosperous and secure through the protection of its people, territories, and its national as well as global interests. This is achieved through the robust and reliable armed forces and other stakeholders such as IT management allies. The MoD is described as the ministerial department that houses or is supported by 27 different agencies such as the Cabinet Office, the Attorney General’s Office, and departments of Justice, among others. The primary purpose of this overview is to show how imperative and sensitive the MoD is to the security protocol of the company. It deals with many departments, hence, houses much information and data of both the citizens and the country at large (Gov.UK, 2019). Moreover, the department contains eight primary defence responsibilities, has priorities of protecting the people, global influence, and prosperity. Nevertheless, it includes the regular armed forces (Royal Navy, British Army, and Royal Air Force), civilian personnel, and trading funds.

The security of any country is achieved from secure defence data handling, privacy, and confidentiality. Defence matters, information, and data are treated as confidential and sensitive affairs for the maintenance of peace and security. Once that top-secret and sensitive data is exposed or acquired by the ‘wrong’ people, the country suffers much data loss and overall compromise of the country’s security protocol. It is therefore essential that an effective incident handing mode be implemented as it prepares the institutions, manages the situation, and minimizes the damages and risks. Thus, the report shows various instances the UK’s MoD has been subject to breaches, loss of sensitive defence data and the devastating implications of these instances.

Overview of the NIST: NIST SP 800-53 Model

NIST cybersecurity framework is one of the most implemented security incident handling models, especially among governmental agencies. The primary purpose of this framework is to help organizations understand, improve, and manage any cybersecurity risks effectively. NIST stands for National Institute of Standards and Technology, which was developed through a collaboration of industries and governmental agencies. NIST contains unique standards, practices, and guidelines that facilitate its mandate of protecting any critical infrastructure and the cybersecurity issue of an organization. The framework operates effectively not only in helping organizations manage and reduce cybersecurity risks but also fosters communication systems between internal and external stakeholders (Keller, 2013). This communication channel designed is imperative in the management of risk and cybersecurity elements. The most appropriate NIST standard, in this case, is the NIST SP 800-53 standard.

NIST consists of three main components, namely the Core, the Implementation Tiers, and Profiles. Each component has unique and specific roles and responsibilities in managing and reducing cybersecurity risks.

(Broad, 2013)

For instance, the core plays two significant roles, namely agendas setting and aligning the framework with an organization’s cybersecurity and risk management processes. It is in the core component that all activities, controls, and expected outcomes are provided. Moreover, it provides the users with guidelines on how to implement the controls and activities in an understandable language and that which aligns with each organization’s risk management and cybersecurity processes (Girken, 2019). Secondly, the implementation tiers provide the users or organizations with the context in which they can view cybersecurity risk-management process. These tiers are instrumental as they are used as communication tools that help in discussing the budget required, mission priority, and risk appetites. Finally, the profiles are used to help organizations align their processes and organizational requirements with the standards of the framework. Moreover, through these profiles, an organization can easily prioritize its opportunities in the quest to improve its cybersecurity.

NIST incident handling model is achieved through four main steps, namely preparation, detection and analysis, containment, eradication, and recovery, and finally, post-incident activities. According to the NIST version 1.1 framework on cybersecurity, the main steps required in handling cybersecurity issues include identification, protection, detection, response, and recovery (Girken, 2019). These steps form the basis upon which the four main stages of the NIST incident-handling model is based upon.

(Broad, 2013)

The first step involves preparing for the response or incident handling in a security incident. While preparing for the incident handling, four main aspects are determined, namely asset compiling, development of a communication plan, incident ranking, and finally creating an effective response plan. When compiling the assets, an organization must include all tangible and intangible assets such as servers, laptops, networks, and application, among others (Kelley Dempsey, 2014). Once they are compiled, an organization must rank them in importance and ensure they are monitored effectively in cases of any risks. Once they are ranked with the order of importance, a communication plan is then created outlining essential stakeholders, their roles, media to contact them, and the role of each stakeholder in each incident type. These aspects enable the development of an effective incident-handling plan.

In the second step, detection and analysis of a security incident are conducted. At this point, an organization must have identified the security incident at hand; it could be a data breach, hacking, system failure, among others. During this step, adequate research is required on the magnitude and impact of the incident. The situation is analyzed outlining the entry point, weaknesses, and the breadth of the breach, reoccurrence levels, and severity of the incident. This enables organizations to identify the most effective security tools and mitigation strategies (Maclean, 2017). The third step requires containment, eradication, and recovery elements. Containment involves stopping the ‘bleeding’ and patching the incident entry point. Eradication, on the other hand, involves removing the threat entirely through security tolls, and finally, recovery involves getting the systems operational once again.

In the final step, post-incident activities include monitoring, follow up plans, and learning from the lessons and incident experience. It is in this step that areas of weakness and improvement are defined and recommended.

(Keller, 2013)

The NIST SP 800-53 is the most appropriate standard in addressing security incidents in the UK’s MoD as it has specific controls and standards designed for federal information systems. These standards help governmental agencies meet the FISMA requirements and heighten the security of IT systems. The NIST SP 800-53 contains operational, technical, and management controls that safeguard, support, and ensure system resilience. These controls and standards ensure that the information systems are secure to increase integrity, confidentiality and information security. The security of any country is achieved from secure defence data handling, privacy, and confidentiality (Lord, 2018). Defence matters, information, and data are treated as top-secret and sensitive affairs for the maintenance of peace and security. Hence, the NIST SP 800-53 provides the most appropriate standards to achieve this aspect.

The controls are classified into three main classes based on the impact they have. These classes include high, moderate, and low impact classes with other 18 families. Complete compliance with the NIST SP 800-53 is characterized by practices such as NIST analysis and understanding, employee education and post-assessment (Lord, 2018). These security control families include

  • Access Control
  • Audit and Accountability
  • Awareness and Training
  • Configuration Management
  • Contingency Planning
  • Identification and Authentication
  • Incident Response
  • Maintenance
  • Media Protection
  • Personnel Security
  • Physical and Environmental Protection
  • Planning
  • Program Management
  • Risk Assessment
  • Security Assessment and Authorization
  • System and Communications Protection
  • System and Information Integrity
  • System and Services Acquisition

Adoption of NIST: NIST SP 800-53 in UK’s MoD 668

Over the years, the MoD has been faced with numerous security incidents ranging from data breaches, loss, ransomware, and hacking of the systems. For instance, in a report conducted in 2018, 37 security breaches were exposed, whereby sensitive military information was sent via the internet in an unprotected manner. In these 37 cases, it was reported that authorized third parties could access information as documents and rooms were left unsecured. In the report, Jake Moore stated that the security incidents numbers were rising and the number was concerning.

Moreover, he attributed the risks and incidents of human errors, and staff training was essential in minimizing these incidents (Muncaster, 2018). At this point, the NIST SP 800-53 is imperative as through the three compliance practices, employee-training controls are provided. Among the controls and families of this framework, awareness and training controls are present. It offers operational controls necessary for training and software solutions that can help MoD train its staff (Gallagher, 2010). Training aspects include real-time and trending security issues and the best practices and solutions to incorporate. This will help eliminate human errors and careless actions that threaten the ministry’s information security.

The British military has also been an easy target of security incidents and information breaches that have resulted in the theft of military secrets hence becoming a national security threat. The MoD confirmed that the ministry experienced manor cyber warfare mostly from China, Russia, Iran, and North Korea. There were Chinese hackers identified as APT10 who hacked the British military system to obtain military and intelligence information. For this breach and hacking to occur, the main reasons were unprotected data, spies’ unauthorized access to restricted offices and cabinets, and the computer hardware was unprotected as well (Jowitt, 2018). In such an instance, NIST SP 800-53 controls that could address such issues include configuration management, system and communication protection, identification and authentication, and system services acquisition controls (Lord, 2018).

The audit and accountability controls would have been effective in addressing the issue of espionage malware. In one incident, the ministry’s computer peripherals had not been checked for espionage malware, and rooms were left exposed, which resulted in the theft of mobile phones and laptops. These devices were connected to classified systems, documents, and devices in the ministry that led to the loss of sensitive military information. In addition, conducting a risk assessment on the handling and storage of documents, devices, and access would have been effective in this case (Jowitt, 2018). The UK’s MoD is faced with an ongoing cyberwar with other nations that has resulted in system braches and ransomware incidents. One aspect that the MoD should recognize is that once these data breaches, hacking, and ransomware are conducted, the information is re-laid and left to the exposure of the media. The information can be exposed through printed, social, or traditional media, which can be used to compromise the national security of the country. Thus, the NIST SP 800-53 provides the media protection controls that the ministry can adopt to manage, control, and protect the disclosed information and data.

These instances can easily be classified in the three control baselines, namely high-impact, moderate-impact, and low-impact baselines, through the NIST SP 800-53. Classifying the impact caused by these security incidents would help the MoD rank the 37 issues from those with the highest impact to the lowest impact. This classification and ranking help the ministry to identify the main entry point and significant weakness of the information system. Identifying this weakness allows the department to adopt the most effective controls in containing, eradicating, and recovering the information and systems.

 

Security issue Baseline categorization NIST SP 800-53 controls
Cyber war High-impact Access control, contingency planning, risk assessment
Chinese hackers High-impact Configuration management, system and communication protection,
Human errors High/moderate impact Employee-training controls, awareness and training controls
Unprotected rooms, devices, cabinets, documents Moderate- impact Identification and authentication, system services acquisition controls,

Physical and environmental protection

Media exposure of data High/moderate impact Media protection
Information and document redactions High/moderate impact Media protection, access control

 

Discussion and Evaluation 

The NIST SP 800-53 has a close relationship with risk management processes, as it provides the risk assessment controls in the 18 families and controls. This shows that in addition to managing and securing the security of an organization’s information system, the NIST SP 800-53 identifies risk management as key in the operations of the systems. The framework argues that the management of an organization’s information system processes and programs requires the management of organizational and individual risks. Besides, the evaluation of the UK’s MoD shows that entry points of cyber-attacks include personal and corporate risks (Kelley Dempsey, 2014). Overly, the updated NIST SP 800-53 version, which is referred to as the NIST SP 800-53 Revision 4 provides a risk management framework. This risk management framework incorporates various controls of the framework in the 18 families and how risks can be managed in a security control structure. This is illustrated in the figure below.

(Gallagher, 2010)

The operations and conduct of NIST are in line with various controls and standards, namely the risk management frameworks as well as a privacy framework. The privacy framework of the NITS model operates in line with the GDPR of the EU, where privacy and confidentiality are essential aspects of any security incident-handling framework. Thus in response or compliance of the GDPR, the NIST framework developed the Privacy framework that guides organizations on the best strategies to manage privacy and any risk associated with it (Keller, 2013). The privacy framework is designed in a manner that it enables agencies and organizations to comply with domestic policies as well as international interests and policies. This ensures that adopting NIST does not compromise local policies and interests as well as complying with international cooperation.

NIST values privacy, transparency, collaboration, and integrity and supports all departments and functions in a government. More importantly, the NIST SP 800-53 Revision 4 provides for privacy controls that enable the satisfaction of government and compliance requirements. In addition, these privacy controls facilitate the tailoring of security control baselines that enhance security and privacy requirements.

System assurance is of high significance in handling any security incidence. The framework provides methods that measure the confidence and assurance of its effectiveness and efficiency. The criteria used to measure security- control assurance includes the ability to define processes, providing operational support, provision of security evidence, and improving personnel skills and expertise. Hence, auditing, in this case, will help identify whether the systems and framework are achieving the established assurance criteria (Maclean, 2017). Secondly, it ensures that effective operations are taking place and compliance to the set regulations and standards are maintained. This assures the organization or agency that the framework implemented does not compromise any legal or administrative regulations. Concisely, auditing is an assurance service that ensures that the MoD follows all the set guidelines, any weaknesses are identified, and areas that require improvement or addressing are addressed effectively

The NIST SP 800-53 compliance best practices include analyzing and understanding the standards and controls of the framework, educating employees on the best solutions, and conducting assessments that would determine improvement areas as well as possible weaknesses.

Conclusion 

The NIST framework, especially the NIST SP 800-53 is the most appropriate security incident-handling model for the MoD in the UK government. The model provides specific standards and controls that specifically address all security issues in the government. Implementing this framework in the Ministry of Defense will help combat any threat of the ministry’s infrastructures, as it provides risk-based approaches to manage risks and control the IT systems (Maclean, 2017). Moreover, the framework focuses on results and is reliant on effective standards in the series family. Implementing this framework will help the MoD assess its current cybersecurity status, determine the capabilities and limitations, and set mechanisms as well as goals to achieve. Most importantly, the three primary components of the framework provide significant benefits to the company. For instance, the core plays two vital roles, namely agendas setting and aligning the framework with an organization’s cybersecurity and risk management processes (Jowitt, 2018). The implementation tiers provide the users or organizations with the context in which they can view cybersecurity risk-management process. Finally, the profiles are used to help organizations align their operations and organizational requirements with the standards of the framework.

On the other hand, implementing the NIST framework possesses various weaknesses, mainly due to the conflict of interests presented in the governmental security programs. The MoD is a very sensitive department that has extensive and strained relationships. These strings attached and many departments attached result in a conflict of interest, which the framework does not address. Thus, when implementing the framework, the MoD should conduct security assessments of all related agencies to eradicate conflict of interests. The company should focus on risk categorization and baseline ranking to ensure they identify the most effective mitigation strategies as well as address the high-impacts entry threats (Broad, 2013). Finally, it is essential that once the MoD implements the NIST framework, continuous monitoring and post-assessment such as assurance audits and follow-up activities be conducted. This will increase the effectiveness and efficiency of the framework in the realization of maximized security of its information systems.

 

 

References

Broad, J. (2013). Risk Management Framework: A Lab-Based Approach to Securing Information Systems. New York: Elsevier.

Gallagher, G. L. (2010). Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach. NIST Special Publication 800-37.

Girken, E. (2019, January 22). Incident Response Steps Comparison Guide for SANS and NIST. Retrieved from https://cybersecurity.att.com/blogs/security-essentials/incident-response-steps-comparison-guide

Gov.UK. (2019). Ministry of Defence: About Ua. Retrieved from https://www.gov.uk/government/organisations/ministry-of-defence/about

Jowitt, T. (2018, October 15). MoD Secrets Exposed In Multiple Data Breaches – Report. Retrieved from https://www.silicon.co.uk/e-regulation/governance/mod-multiple-data-breaches-237915

Keller, N. (2013). Cybersecurity Framework | NIST. Retrieved from https://www.nist.gov › cyberframework

Kelley Dempsey, G. W. (2014). Summary of NIST SP 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations. NIST Computer Security Division, 1-10.

Lord, N. (2018, September 11). What is NIST SP 800-53? Definition and Tips for NIST SP 800-53 Compliance. Retrieved from https://digitalguardian.com/blog/what-nist-sp-800-53-definition-and-tips-nist-sp-800-53-compliance

Maclean, D. (2017, August 14). The NIST Risk Management Framework: Problems and recommendations. Cyber Security: A Peer-Reviewed Journal, Vol 1(3) pp: 207-217.

Muncaster, P. (2018, October 16). UK’s MoD Exposed in 37 Security Breaches: Report. Retrieved from https://www.infosecurity-magazine.com/news/uks-mod-exposed-in-37-security/

 

 

Homework Sharks
Order NOW For A 10% Discount!
Pages (550 words)
Approximate price: -

Our Advantages

Plagiarism Free Papers

All our papers are original and written from scratch. We will email you a plagiarism report alongside your completed paper once done.

Free Revisions

All papers are submitted ahead of time. We do this to allow you time to point out any area you would need revision on, and help you for free.

Title-page

A title page preceeds all your paper content. Here, you put all your personal information and this we give out for free.

Bibliography

Without a reference/bibliography page, any academic paper is incomplete and doesnt qualify for grading. We also offer this for free.

Originality & Security

At Homework Sharks, we take confidentiality seriously and all your personal information is stored safely and do not share it with third parties for any reasons whatsoever. Our work is original and we send plagiarism reports alongside every paper.

24/7 Customer Support

Our agents are online 24/7. Feel free to contact us through email or talk to our live agents.

Try it now!

Calculate the price of your order

We'll send you the first draft for approval by at
Total price:
$0.00

How it works?

Follow these simple steps to get your paper done

Place your order

Fill in the order form and provide all details of your assignment.

Proceed with the payment

Choose the payment system that suits you most.

Receive the final file

Once your paper is ready, we will email it to you.

Our Services

We work around the clock to see best customer experience.

Pricing

Flexible Pricing

Our prces are pocket friendly and you can do partial payments. When that is not enough, we have a free enquiry service.

Communication

Admission help & Client-Writer Contact

When you need to elaborate something further to your writer, we provide that button.

Deadlines

Paper Submission

We take deadlines seriously and our papers are submitted ahead of time. We are happy to assist you in case of any adjustments needed.

Reviews

Customer Feedback

Your feedback, good or bad is of great concern to us and we take it very seriously. We are, therefore, constantly adjusting our policies to ensure best customer/writer experience.