• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Security Architecture

MIS 5214 - Section 001 - David Lanter

Security Architecture

MIS 5214.001 ■ Spring 2024 ■ David Lanter
  • Homepage
  • Instructor
  • Syllabus
  • Deliverables
    • Assignments
    • Case Studies
      • Case Study 1 – A High Performance Computing Cluster Under Attack: The Titan Incident
      • Case Study 2 – Data Breach at Equifax
    • Participation
    • Team Project
  • Harvard Coursepack

03 - Planning and Policy

Wrap Up

January 31, 2024 by David Lanter

Lecture presentation

 

Exercise 1:

How would you approach assessing the completeness (breadth and depth) of the Generic Information Security Policy example?

  • Generic Information Security Policy Example

 

Exercise 2:

Find a preliminary categorization for the following information system and adjust the categorization based on your analysis – present justifications for both preliminary and adjusted categorizations

Purpose: The system has two overarching purposes:

    1. For clients it is a system intended to help understand sewage and storm water collection and treatment systems (i.e. pipe networks, pump stations, and treatment plants) and their capacities, overflow characteristics and controls
    2. For the firm the system is intended to provide revenue through pay by clients for direct use of the service(s) of the system

Users:

  1. Municipal and regional water and sewer utilities will use the system to help plan capital improvement, operations, and maintenance of sewer systems (i.e. sewage treatment plants and sewage collection networks)
  2. External consultants helping water and sewer utilities plan capital improvement, operations, and maintenance of sewer systems
  3. The firm’s technical information system development staff working directly on the information system to provide, maintain, enhance and extend the services of the information system to (1) and (2)

 

Filed Under: 03 - Planning and Policy Tagged With:

Boyle and Panko: Chapter 2 Planning and Policy

January 24, 2024 by David Lanter 17 Comments

Filed Under: 03 - Planning and Policy Tagged With:

NIST 800 100 Information Security Handbook Chapter 8

January 24, 2024 by David Lanter 20 Comments

Filed Under: 03 - Planning and Policy Tagged With:

NIST 800 60 V1R1 Guide for Mapping Types of Information and Information Systems to Security Categories

January 24, 2024 by David Lanter 14 Comments

Filed Under: 03 - Planning and Policy Tagged With:

FIPS 200 Minimum Security Requirements for Federal Information and Information Systems

January 24, 2024 by David Lanter 16 Comments

Filed Under: 03 - Planning and Policy Tagged With:

My question to discuss with my classmates

January 24, 2024 by David Lanter 13 Comments

Filed Under: 03 - Planning and Policy Tagged With:

In The News

January 24, 2024 by David Lanter 5 Comments

Filed Under: 03 - Planning and Policy Tagged With:

Primary Sidebar

Weekly Discussions

  • 01 – Introduction (1)
  • 01 – Threat Environment (3)
  • 02 – System Security Plan (6)
  • 03 – Planning and Policy (7)
  • 04 – Cryptography (4)
  • 05 – Secure Networks (7)
  • 06 – Firewalls (5)
  • 08 – Access Control (7)
  • 09 – Host Hardening (5)
  • 10 – Application Security (6)
  • 11 – Data Protection (4)
  • 12 – Incident and Disaster Response (5)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in