Instructions Your boss wants you to draft a two- to three-page vulnerability process and assessment memorandum addressing the main points of a VM process for Mercury USA. You will cover the main...

1 answer below »
instructions included in the files. use the template to do the assignment


Instructions Your boss wants you to draft a two- to three-page vulnerability process and assessment memorandum addressing the main points of a VM process for Mercury USA. You will cover the main elements of a vulnerability management process, tailored to Mercury USA's business in the transportation sector, evaluate the OpenVAS scanning tool, and provide recommendations for mitigating the vulnerabilities found within the OpenVAS report. The third-party pen tester used the free tool Open Vulnerability Assessment Scanner (OpenVAS) to scan Mercury USA’s network. Review the report from the OpenVAS Scan. As you review the scan, consider some important points from Lesson 5.6, Remediation: · Priority · Difficulty of implementation · Communication/change control · Inhibitors to remediation · MOUs · SLAs · Business process interruption · Degrading functionality Vulnerability Management Process Memo MEMO [date] [Your name and course number/section] [Opening Salutation]: Overview In this section, provide a brief overview to establish the purpose of your memorandum. You should introduce the topics in Parts 1, 2, and 3, below. Remember that you are writing to your immediate boss to help her address the CEO’s concerns over recent cybersecurity attacks against the transportation sector. Additionally, your boss has provided you with the results of a recent pen testing engagement performed by a third party on behalf of Mercury USA. Part 1: Vulnerability Management (VM) Process Recommendation In this section, present a recommended VM process for Mercury USA. Highlight the major VM process components as you learned in your studies. Explain how your recommendation meets the business needs of Mercury USA. Consider the transportation sector and the overall scenario in context. The text and questions below represent specifics to focus on while writing the memorandum. Do not include the specific text of the questions in your final submission. · What are the main elements of a VM process, tailored to Mercury USA and the transportation sector? · How will you plan for and define the scope of a VM process? · How will you identify the assets involved? · How will you scan and assess vulnerabilities? · What is/are the industry standard scanning tools? Support your findings. · What frequency of scanning do you recommend and why? · How will you report the results of scanning and recommended countermeasures? Part 2: Vulnerability Scanning Tool Evaluation and Recommendations After performing an analysis of the vulnerability report provided by the third-party penetration testers, present your evaluation of the tool and your recommendations here. The text and questions below represent the specifics to focus on while writing your memorandum. Do not include the specific text of the questions in your final submission. · Identify the scanner used to produce the report. Is the tool open source or commercial? Do you consider the tool to be industry standard? · What are some advantages to using the tool? Disadvantages? · What is your overall impression of the tool’s output? · Does the tool provide enough reporting detail for you as the analyst to focus on the correct vulnerabilities? Can you appropriately discern the most critical vulnerabilities? · Do you think mitigations for the vulnerabilities are adequately covered in the report? · Do you think the reports are suitable for management? Explain why or why not. · Would you distribute the report automatically? Explain why or why not. · Would you recommend that Mercury USA use the tool? Explain why or why not. Part 3: Business Case Example In this section, provide an example of what could happen if Mercury USA does not implement your recommendations for a VM process (e.g., data exfiltration, hacker intrusions, ransomware, etc.). The text and questions below represent the specifics to focus on while writing your memorandum. Do not include the specific text of the questions in your final submission. · What are some of the outcomes to the business if your example occurred? · How does your recommended VM process address the example you used? · For the tool you evaluated in Part 2 above, do you think the tool will be adequate? Why or why not? Closing In this section, summarize the main points of your argument for a VM process, tool evaluation, and use the case example to support your recommendations. Keep in mind that you are addressing the CEO’s concerns over recent cybersecurity attacks against the transportation sector and how you can help increase Mercury USA’s overall security posture to protect the organization against attacks, breaches, and data loss. Cybersecurity Threat Analyst Mercury USA References Use in-text citations in the body of your memorandum as appropriate. Add all sources you used here. This example citation uses IEEE style. Use a style of your choice or ask your instructor for clarification. When using the associated course content, ensure that you cite to the chapter level. [1] "Chapter 5: Implementing an Information Security Vulnerability Management Process", Pearson CompTIA Cybersecurity Analyst (CySA+), 2020. [Online]. Available: https://www.ucertify.com/. [Accessed: 28- Apr- 2020]. Vulnerability Management Process Memo | [Document subtitle]
Answered Same DayMar 09, 2021

Answer To: Instructions Your boss wants you to draft a two- to three-page vulnerability process and assessment...

Deepti answered on Mar 09 2021
148 Votes
Vulnerability Management Process Memo
    MEMO
    
[date]
[Your name and course number/section]
[Opening Salutation]:
Overview
This memorandum aims at recommending vulnerability management
process best suitable for Mercury, USA. It is divided into three parts. First, the process itself is summarized with its main elements. Second, the vulnerability scanning tool is recommended specifically for Mercury and transport sector. The third part discusses a problem which may occur in the company if the recommendation is not implemented and how the recommended tool serves as the best solution for to overcome the problem.
Part 1: Vulnerability Management (VM) Process Recommendation
Mercury USA offers extensive rail, truck, ocean and barge freight operations including freight contracts, etc. VM process recommended for the company shall include the main stages of scanning, prioritizing and remediating.
The main elements of VM process for Mercury shall include asset management, patch management, vulnerability scanning, penetration testing, vulnerability assessment, metrics, tracking and reporting. The scope of recommended VM process shall include security of all physical and virtual assets of all the business operations of Mercury. The assets shall be identified using vulnerability scanner. It will identify different systems running on Mercury’s network such as servers, databases, desktops, switches, firewalls, peripheral devices, etc. These assets will be probed for their operating systems, software, ports, user accounts, file system, etc. This information shall be used to relate known vulnerability to the scanned systems. For running this association, the scanner shall use vulnerability database in which vulnerabilities enlisted in it which are publicly known. Some of the tools are OpenVAS (Rahalkar, 2019), W3AF (Qianqian, 2014), Nikto2 (Agashe, 2008), Nmap (Orebaugh, 2008)....
SOLUTION.PDF

Answer To This Question Is Available To Download

Related Questions & Answers

More Questions »

Submit New Assignment

Copy and Paste Your Assignment Here