Aircraft Solutions

1195 Words5 Pages
Security Assessment, Recommendations, and Solutions Amber Fuente DeVry University December 15, 2013 Abstract Aircraft Solutions located in California makes products and services for electronic, defense, commercial, and aerospace companies. After reviewing the scenario presented in case one I have identified to security weaknesses. Phase one will identify and explore the security weaknesses found. The first is a policy weakness regarding the use of firewalls and routers. The second is a hardware weakness also related to the use of servers. Phase One Firewall and Router Weakness The current policy regarding the frequency of firewall and router updates states that they should both be updated every two years. The vulnerability is that…show more content…
There is one server each for Accounting, Shipping, Direct Computer Numerical Control and Human Resources and Compliance. These servers are located at Aircraft Solutions headquarters in San Diego. Having the servers in only one location is a vulnerability of Aircraft Solutions. Servers in one location could go down for a few reasons including natural disaster, power failure, and hacking (Microsoft, 2002). Any state in the country can be susceptible to power failure. California has a history of earthquakes and mudslides. Hackers could attack the server and search for other vulnerabilities as well as cause denial of service errors, obtain financial information from databases and obtain credentials (AppliCure, 2012). If the server site is unavailable for any of these reasons Aircraft Solutions will not be able to provide the continuous customer support that is their competitive advantage. If the servers are attacked by hackers customer information may be stolen including product designs and financial data. If Aircraft Solutions customers lose the confidence they have for Aircraft Solutions then they will not do repeat business with Aircraft Solutions an even worse possibility is that customers may start publicly expressing their displeasure in the service they received from Aircraft Solutions. These customers may also have rights to obtain satisfaction for any losses through the legal…show more content…
The current policy states that all firewalls and routers are evaluated every two years and that all local servers are backed up to storage devices that are attached to the network and are maintained at the server location. This security policy is ineffective as it is not complete. Strong security policies should state acceptable and unacceptable user behavior, restrictions to resources, and conform to the company’s business plan (Firewall Design, 2012). The policy should include the specific IP addresses users are allowed to access as well as their specific destination ports. The components that make up the security policy as well as the security policy itself should be simple enough for administrators to change and troubleshoot errors but strong enough to keep unwanted access out (Firewall Design,
Open Document