Ask Operation Management Expert

Module 7 Team Module Summary Discussion Case: What are you going to do about the company’s security problems?

You are the new IT manager at InvestCo, a small securities firm, and three days after you started your new job the secretary to the CEO was tricked into giving the CEO’s password over the phone to someone she thought was in the IT department. Luckily she quickly discovered that she had been tricked and had the CEO immediately change his password. When asked, the secretary said she knew the CEO’s password because it was the same one that he used for his Facebook account. You’ve been told that as far the IT staff can determine, the hacker probably did not use the stolen password before the CEO’s password was changed. However, if the thief had gotten in, he would potentially have had access to the extensive data that the company keeps on its clients. The CEO is very concerned about the potential liability and loss of customers if the client data had been stolen. Now it is your task to reexamine the firm’s policy on employee and customer account passwords, craft a new security and data retention policy, and to make a recommendation to the CEO.

InvestCo holds, trades and manages stock and bond portfolios for clients. There is an existing security and password policy that has been in place for 3 years. Some longer-term employees remember the security training that occurred back then, but there has been no training since the old policy was put in place. The password policy was strengthened two years ago so that passwords had to be longer, couldn’t be reused and had to be changed monthly. Following that change, an intern was hired to help reset passwords when employees and clients couldn’t remember their password.

Due to the financial nature of the company’s business, your recommendation must make the security of financial data paramount. But your recommendations must take usability and accessibility by employees and customers into account. A very secure but inaccessible system would be bad for business, but so would a very accessible but insecure system. So your task is to identify the problems with the existing security at InvestCo. Then craft a security policy and implementation and maintenance plan that addresses those problems while striking a balance between security and accessibility.

Begin by reading an article named Kill the Password, by Mat Honan

Learn about the technology of passwords by reading the following websites:

Hashing Wikipedia page(Links to an external site.) (Links to an external site.)

Salting Wikipedia page(Links to an external site.) (Links to an external site.)

Multi-factor Authentication Wikipedia page(Links to an external site.) (Links to an external site.)

Password Managers Wikipedia page(Links to an external site.) (Links to an external site.)

Learn about many of the ways passwords are compromised on the following websites or online articles:

Phishing Wikipedia page(Links to an external site.) (Links to an external site.)

Key Loggers Wikipedia page(Links to an external site.) (Links to an external site.)

Dictionary Attach Wikipedia page(Links to an external site.) (Links to an external site.)

Brute Force Attack Wikipedia page(Links to an external site.) (Links to an external site.)

Social Engineering Wikipedia page(Links to an external site.) (Links to an external site.)

How Passwords are Cracked(Links to an external site.) (Links to an external site.)

Aggressive Password Policies(Links to an external site.) (Links to an external site.)

People Using Common Passwords(Links to an external site.) (Links to an external site.)

Million Recently Compromised Passwords For Sale Online(Links to an external site.) (Links to an external site.)

Passwords From Hacked Game Site Dumped Online(Links to an external site.) (Links to an external site.)

Learn about alternative policies to consider by reading the following online articles:

Google Looks to Kill the Password Using the Ring on Your Finger(Links to an external site.) (Links to an external site.)

Stanfords Password Policy Shuns One Size Fits All Security

(Links to an external site.) (Links to an external site.)

Question 1: Chose a password policy to present to your boss the CEO. In your recommendation be sure to address how it improves security and or accessibility. How would your recommended policy have helped the recent security breach? Identify at least one negative factor related to your recommended

Stay with the current policy but have everyone change his or her password. Send the CEO’s secretary to training on recognizing social engineering. Teach everyone how to craft better passwords

Move to an aggressive password policy where strong passwords are required, weak passwords are prohibited, and users are required to change their password frequently. Provide everyone with a password manager so that people stop hoarding passwords, passwords are compliant with the new aggressive rules, and strong passwords become disposable.

Keep the current password policy but add in multi-factor authentication for every login. The additional factors may include an RSA token or a smartphone app, as well as the potential for biometrics, and location based limitations (logins only at known locations)

Craft your own password policy. Provide details.

Question 2: In the security breach described in the first paragraph there are several types of security problems. Using the list below, identify how each item in the list shows up in the case.

Employee training problems

Employee/company operating process and procedure problems

Need for client security procedures

Need for a password policy for clients

Need for a better password policy for employees

Need for a data retention policy

Need for a data access policy

Need for Intrusion detection/prevention measures

Operation Management, Management Studies

  • Category:- Operation Management
  • Reference No.:- M92024422

Have any Question?


Related Questions in Operation Management

Conflictdefine functional versus dysfunctional conflict in

Conflict Define functional versus dysfunctional conflict in a work group and explain how you can increase functional conflict and decrease dysfunctional conflict. Develop a response that includes examples and evidence to ...

For this assignment you will need to find 2 articles in

For this assignment, you will need to find 2 articles in business that can help describe what are IT strategic initiative being undertaken by an organization are like. Choose a different organization for each of the arti ...

Coping with problems joe is a little nervous he has just

Coping With Problems Joe is a little nervous. He has just been transferred from another plant to take over a production line. Production is down and there is a serious problem with absenteeism. To make matters worse, the ...

Over 30 years ago michael porter identified a holistic

Over 30 years ago Michael Porter identified a holistic approach to understanding how competitive forces shape strategy. He posited that the only way to truly insulate an organization from underlying economic volatility i ...

You are the contracting officer for an air-to-ground

You are the contracting officer for an air-to-ground missile development program. A contract for pre-production models of the missile was awarded by your predecessor and the contractor is behind schedule. In a program me ...

The ikea case provides an excellent opportunity to apply

The IKEA case provides an excellent opportunity to apply strategic management concepts to a large privately-held company that is expanding into India. IKEA is a Netherlands-based Swedish company with a presence in 44 cou ...

Can you answer for me the following questions about social

Can you answer for me the following questions about social loafing and the three main causes of free-riding. 1. Give a description of the phenomenon of social loafing. 2. Give a description of the phenomenon of free-ridi ...

1 analyzing the bridgestonefirestone and ford motor company

1. Analyzing the Bridgestone/Firestone and Ford motor company, is it sufficient to use the ISO/QS 9000 standards as the main basis of vendor/product selection? 2. What position to these cars company ( 1. Volkswagen, 2. F ...

Research the effect of primary and secondary seat belt laws

Research the effect of primary and secondary seat belt laws on the occurrence of motor-vehicle injuries and fatalities. Explain how epidemiologic studies influenced the development of current seat belt laws. Describe how ...

Please provide a brief paragrap of the key takaways from

Please provide a brief paragrap of the key takaways from each of the following topics: Designing Clear Visuals in business reports Designing Successful Documents and Websites Writing Winning Proposals

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As