CMGT 430 Week 1 Individual Assignment  IT System Connection Table       
It is important to know the different interconnections each system has. IT systems do not operate alone in the modern enterprise, so securing them involves securing their interfaces with other systems as well.
Complete the University of Phoenix Material: IT System Connection Table for four different IT systems. The table is located on your student website.
Note two systems they connect with and their connection type.
Note two security vulnerabilities the system may have and 2 to 4 ways each vulnerability could be potentially exploited.
CMGT 430 Week 1 Supporting Activites
CMGT 430 Week 1 Supporting Activity Architecture of Enterprise Systems
Write a 200- to 300-word short-answer response for the following:
Discuss the general architecture of enterprise systems, including both hardware and software components. Provide at least two examples of each for a system with which you are familiar (from experience or research).
CMGT 430 Week 1 Supporting Activity   Most Important Security Issues
What are two important security issues that enterprise systems commonly face? How do these issues threaten information and what high-level steps can a company take to mitigate these threats?
CMGT 430 Week 2 Individual Assignment Applying Risk Management Consulting
You have been hired as a consultant by one of the Virtual Organizations.
Choose a different Virtual Organization than the one used in your team project.
Write a 1,100- to 1,400-word persuasion paper in which you do the following:
Describe how the organization can apply risk management principles in their efforts to secure their systems.
Describe how protection efforts will vary over time.
Include three different example sets, each with a vulnerability, related risk, and way to mitigate (control) that item.
Format your paper consistent with APA guidelines.
CMGT 430 Week 2 Learning Team Assignment Enterprise Security Plan: Vulnerabilities and Threat Pairs
A first step to developing an enterprise security plan is to identify the specific vulnerabilities and related risks facing an organization. This list should be fairly exhaustive. Many vulnerability and threat pairs will not make the final cut for remediation, but an organization can only properly prioritize these if it has fully covered all of the risks.

Select any Virtual Organization.
Create a list of 50 information security vulnerabilities with related threats relevant to the organization:
Most vulnerabilities will have more than one related threat.
Cover both physical and logical vulnerabilities.
Place your list in the first two columns of a table in a Microsoft® Word or Excel® document. The table will resemble the following:
Vulnerability Threat Probability Impact Suggested Mitigation Steps
Include approximately 25 pairs involving physical security and approximately 25 involving logical security.
The other three columns will be used next week. Each row in the table should be a specific vulnerability with a related threat, though it is most likely that some vulnerabilities will have more than one possible threat in the table.
Submit your table to your faculty member.
CMGT 430 Week 2 Supporting Activites
CMGT 430 Week 2 Supporting Activity  Information System Protection
Discuss three different stages of a specific effort (hypothetical or real) to protect an information system. What would be done at each stage of the effort? Is the systems development life cycle (SDLC) an appropriate process to implement information security solutions? Why or why not?
CMGT 430 Week 2 Supporting Activity   Mitigation Steps
Imagine you are a security consultant. What are four specific enterprise system threats? For each threat, what mitigation steps should acompany take?
CMGT 430 Week 3 Individual Assignment Using Roles Paper
Refer back to your Virtual Organization used in the Week Two Applying Risk Management Consulting assignment.
A better way to control user access to data is to tie data access to the role a user plays in an organization. Some organizations are still learning this. Your paper this week persuades the leader of your target organization of the importance of controlling user access.
Write a 1,100- to 1,400-word persuasion paper in which you discuss the following:
The value of separating duties in the organization
The value of using roles to segregate the data and system access needs of individuals in the organization
Why a role-based access control (RBAC) system would be the best way to accomplish this
How to handle distributed trust management issues for users going to or from business partner networks
Format your paper consistent with APA guidelines.
CMGT 430 Week 3 Supporting Activites
CMGT 430 Week 3 Supporting Activity  Policy and Update Management
Complete the "Policy and Update Management" lab. What did you learn? What did you think was most valuable?
CMGT 430 Week 3 Supporting Activity Distributed Trust Management
Do you feel distributed trust management is important to organizations? Why or why not? Could future technology change your stance?
CMGT 430 Week 3 Learning Team Assignment Enterprise Security Plan: Ranking the Pairs
Extend your table from Week Two to include Probability of Risk and Impact of Risk on the organization and include mitigation steps of the top 20 pairs.

Part 1
Fill out the final three columns in the table from the previous week.
Rate the probability and impact of each vulnerability-threat pair as High, Medium, or Low. Note that these are independent of each other.
Rank the pairs in the order they should be addressed by the organization. Note that High/High rows will be at the top and Low/Low rows at the bottom. The team will have to decide where to rank rows not at these extremes.
Suggest specific mitigation steps to take for the top 20 rows. You will go into more detail for the final project due in Week Five. Leave the Suggested Mitigation Steps column empty for rows below the top 20.

Part 2
Prepare a brief explanation on the final rankings.
Describe how the team finally ranked the pairs and the reasoning behind the suggested mitigation steps.
Focus on the top 20 rows, but cover why the others were ranked lower and will not be addressed at this time.
Keep this explanation brief and clear but informative.
Submit your updated table and explanation to your faculty member.
CMGT 430 Week 4 Individual Assignment Controlling Access Paper
Continue the Applying Risk Management Consulting assignment for your chosen organization.
Refer to your Week Three individual assignment.
Write a 1,400- to 2,200-word paper in which you cover what concerns and potential actions the organization should take for each of the following areas:
Provision of organization data and access on an organizational website
How to allow mobile access to organizational system users (employees, contractors, and business partners)
Use of cloud resources such as processing and data storage outside the organization’s physical locations
Note. Brief the organization on the major issues involved but keep each section succinct.
Format your paper consistent with APA guidelines.
CMGT 430 Week 4 Supporting Activites
CMGT 430 Week 4 Supporting Activity Information Storage
Write a 200- to 300-word short-answer response for the following:
Under what factors would you recommend that an organization store information outside of its system? What dangers would you warn against? What recommendations could you provide to address the dangers?
CMGT 430 Week 4 Supporting Activity Mobile Access
Write a 200- to 300-word short-answer response for the following:
Consider an organization (nonprofit, employer, or personal use) that is familiar to you. If this organization was to open up mobile access to their systems, what three specific threats would be most important to consider and why? Are the risks greater as an internal user (employees, contractors, and so on) or an outside customer? Defend your claims.
CMGT 430 Week 4  Learning Team Assignment Draft of the Enterprise Security Plan and Presentation
An enterprise security plan is more than just a list of vulnerabilities and risks. It must present them in a meaningful way along with suggestions for specific steps to mitigate each of the most important vulnerabilities or risk pairs it finds. Your task this week is to produce the basics of that full presentation.
Part 1
Compile a full draft of the final Enterprise Security Plan document. This will not be complete, but will have at least a short paragraph about each major section of the paper, including the suggested controls.
Use the introduction and conclusion as an executive summary of the entire paper’s content.
Research at least eight sources that validate the choices made in the paper. This must go beyond basic definitions. The sources can be changed in the final week, if needed.
Format your paper consistent with APA guidelines.
Part 2
Create a Microsoft® PowerPoint® presentation on the findings in the Enterprise Security Plan to present to senior management at your chosen organization. Keep the slides uncluttered and concise.
Include well-formatted speaker notes for the presentation.
Submit a team progress report to your instructor including what your team accomplished during the week, challenges your team faced, and any questions you may have.
CMGT 430 Week 5 Learning Team Assignment   Enterprise Security Plan Paper
Finalize and update your Enterprise Security Plan paper. Incorporate any instructor feedback. Your introduction should preview the content in the paper at a high level and your conclusion should summarize the findings of the paper. The body should cover the required content clearly, concisely, and completely.
Format your final paper consistent with APA guidelines.
Submit the paper to the Plagiarism Checker in the Center for Writing Excellence. Include the results from Plagiarism Checker in a separate file submitted with your paper.
Submit your completed paper.
CMGT 430 Week 5 Learning Team Assignment   Enterprise Security Plan Presentation
Finalize your presentation for the Enterprise Security Plan. The presentation should target senior leadership at the organization and should effectively cover the material in the paper.
No specific number of slides is required. Your presentation should have a consistent look and feel, use text that works well with the background, and should present the material in an effective format. Your slides should not be overly crowded, pushing detailed information to the speaker notes area where possible.
The speaker notes should be sufficient enough to allow someone to read them and give the entire presentation. They should be well-formatted and easy to read, not just a single paragraph of text.
Submit the presentation to your faculty member.
CMGT 430 Week 5 Supporting Activites
CMGT 430 Week 5 Supporting Activity Valuable Resources for Information Security
What three specific resources (websites, journals, and so on) are valuable to stay current on information security? Why would each be effective?
CMGT 430 Week 5 Supporting Activity Enterprise Security Core Principles
Write a 200- to 300-word short-answer response for the following:
Discuss three of the core principles associated with enterprise security. Note why each is important and how an organization can integrate each one into its operations.

