Aircraft Solutions is a recognized leader in the design and fabrication of component products and services for companies in the electronics, commercial, defense, and aerospace industry. Based in Southern California, Aircraft Solutions has an excellent record of rendering services and employees that are dedicated to providing high quality customer service. The company’s workforce has a large skill base: design engineers, programmers, machinists, and assembly personnel to work in its enormous production plant and various segments of the industry. This assessment is to investigate weaknesses presented in the operations of the Aircraft Solutions business processes. Along with identifying vulnerabilities, an analysis of other related threats, concerns and risks will be presented.
Vulnerability Assessment
After further review to three relevant sections: hardware, software and policy, Aircraft Solutions needs special attention to hardware and policy relates processes. The Defense Division is routed through Headquarters, the Commercial Division is however directly connected to the Internet, but no firewall has been setup. This action is a concern for Aircraft Solutions. A policy vulnerability that has been noticed is the rule that states “routers and firewalls rule-sets would be evaluated once in every two years”. With today’s world and technology changing ever so often security threats happen by Internet hackers, on an everyday basis. This is a rather impractical and long time span for a company to ensure that their security measures are up-to-date. These weaknesses are detailed in the sections below:
Hardware Vulnerability
Aircraft Solution’s Commercial Division, connects to the rest of the world via the Internet causing hardware vulnerabilities due to the absence of security and safety that should be implemented, leaving great concern for major security threats. The Commercial Division is only able to access important data (budgets, shareholder information, contracts, etc…) from the world-wide web because there is no firewall in place to filter web traffic. This drawback maximizes environmental threats due to the lack of a firewall which exposes the network to external attacks and malicious content which can be sent easily over the Internet. According to the National Institute of Standards and Technology, to determine the likelihood of a future adverse event, threats to an IT system must be analyzed in conjunction with the potential vulnerabilities and the controls in place for the IT system. To measure risk, a risk scale and a risk-level matrix must be developed.
Table 1- Risk-Level Matrix
Threat Likelihood Low (10) Medium (50) High (100)
High (1.0) Low
10 X 1.0=10 Medium
50 X 1.0=50 High
100 X 1.0=100
Medium (0.5) Low
10 X 0.5=5 Medium
50 X 0.5=25 Medium
100 X 0.5=50
Low (0.1) Low
10 X 0.1=1 Low
50 X 0.1=5 Low
100 X 0.1=10
Risk Scale: High (>50 to 100); Medium (>10 to 50); Low (1 to 10)
Policy Vulnerability
Company has stated that the current security policy rules for routes and firewalls will be re analyzed every two years. This action will need to be revised due to security threats and hackers attempting to prevail every day. Vendors can provide regular monitoring and ensure patches are current and have been disseminated to protect from external threat and attacks. Aircraft Solution has not determined a definitive policy regarding how and when policy should upgrade equipment and modified business processes. As with any business, it is required that along with changes in company policies as a reaction to various business related factors such as sales fluctuations, changes in the economy, or other environmental factors that impact the company’s infrastructure it is natural and an intrinsic requirement for the security rule-sets related to firewall and router security have to be updated and modified. Using the same rules over again is risky and could lead to various levels of hacking and security breaches. Worst case scenario, if Aircraft Solutions decides to keep policy the way they are, it would just take a couple of disgruntled employees to t spread malicious content and see the company get destroyed through un-expired access permissions or provide that information to people with malicious intent. This could lead to legal problems, monetary loss, while impacting the company’s good will and public image in a very big way.
? Reference
Goguen, A., Feringa, A., Stoneburner, G., (2002). Risk Management Guide for Information Technology Systems. Recommendations of the National Institute of Standards and Technology.
You May Also Find These Documents Helpful
-
The purpose of this paper is to explore and assess computer security as it relates to Aircraft Solutions. Aircraft Solutions provides products and services to a range of companies that require highly specialized skills. Information is accessed by internal and external users via their Business Process Management system.…
- 1345 Words
- 6 Pages
Better Essays -
Aircraft Solutions (AS) Security Overview Introduction Aircraft Solutions is a well respected equipment and component fabrication company who provides a full spectrum design and implementation solutions to several industries which includes; electronics, aerospace, commercial and the defense sectors. Aircraft Solutions employs a range of highly qualified professionals and houses an immense production plant, with an overall goal of providing high-quality solutions to accommodate specifications from a wide range of customer demands.…
- 1151 Words
- 5 Pages
Better Essays -
Weaknesses are a symptom that is prevalent in today’s information technology realm, indicating vulnerabilities and risks that come hand and hand with shared networks like Aircraft Solutions. With enterprises exchanging an unprecedented level of information over open networks, the vulnerabilities and possibility of compromised security by unwanted intruders is swelling up into a new type of beast.…
- 1105 Words
- 5 Pages
Better Essays -
The purpose of this paper is to evaluate the computer security for Aircraft Solutions. When discussing computer security, the three main areas aspects of any computer-related system are confidentiality, integrity, and availability. Confidentiality determines the security or privacy of the system. Integrity refers to only the authorized users making changes to parts of the computer system. Availability means if someone has a requirement to get onto the computer they are not impeded in that facet. The main challenge in constructing any secure system is determining…
- 870 Words
- 4 Pages
Better Essays -
Aircraft Solutions, headquarters located in San Diego, California develop and fabricate products and services for companies in the electronic, commercial, defense and aerospace industries. AS is made up of two (2) different divisions, the Commercial Division and the Defense Division. The Commercial Division is located in Chula Vista, CA and the Defense Division is located in Santa Ana, CA. AS company strategy is to offer low cost design and computer aided modeling packages to companies and assists them through the lifecycle of their product in an effort to save money for the consumer while profiting from their business.…
- 2440 Words
- 10 Pages
Best Essays -
Aircraft Solutions, with its headquarters in San Diego, California develop and fabricate products and services for different companies. It has two divisions, commercial and the defense. The commercial division is in Chula Vista, CA and the defense division is in Santa Ana, CA. They offer designs at low cost and computer aided modeling packages. They also provide lifecycle of the product being manufactured.…
- 2041 Words
- 9 Pages
Powerful Essays -
In 2008 Boeing had made all sorts of headlines in the media, due to some new technological developments in their newly designed 787 Dreamliner. These headlines that splashed across websites were initially brought about due to a FAA “special conditions” report. This topic of this report first appeared in Flight International, and then a few days later it gathered momentum in a critical follow up from Wired Magazine. According to Wired (2008), the FAA states “Boeing’s new 787 may be vulnerable to hacker attack”.…
- 1124 Words
- 4 Pages
Powerful Essays -
Aircraft Solutions (AS) is a recognized leader in the design and fabrication of component products and services for companies in the electronics, commercial, defense, and aerospace industry. The mission of AS is to provide customer success through machined products and related services, and to meet cost, quality, and schedule requirements.…
- 1868 Words
- 8 Pages
Powerful Essays -
Riordan Manufacturing performs an information systems security analysis over its physical and network security. Several elements of the IT system require revisions, such as restrictions to physical access to vital IT systems and upgrades to outdated systems within the network.…
- 2582 Words
- 11 Pages
Powerful Essays -
This paper is to outline Riordan Manufacturing’s existing Information Security Systems, determine their weaknesses, and develop solutions to those weaknesses by addressing security issues in the areas of physical, network, data, and the web.…
- 272 Words
- 2 Pages
Satisfactory Essays -
This security profile presents one control function from three primary policy and procedure controls. These controls are “System/New Technology Development Life Cycle” from Management Controls, “Security Training, Education, and Awareness” from Operational Controls, and “Remote Access” from Technical Controls. These controls are selected based on the lack of resolution based on information provided fiscal year 2006, 2010 (VA Office of Inspector General, 2011) and 2011 (VA Office of Inspector General, 2012) FISMA audits.…
- 1273 Words
- 6 Pages
Powerful Essays -
As Aircraft Solutions takes the next step in its growth, it is imperative that its IT infrastructure keep pace as to not counteract gains made by the company during this expansion. This is especially important given it designs and fabricates components for both commercial and defense related industry. Given the increase in staff as well as outside vendors accessing the network, a more centralized approach to antivirus protection has to be adopted. It is equally important that certain elements within the network that have been done manually, such as Access Control List policy, be automated to avoid consuming the IT department in an ever escalating bar of employee hours.…
- 2805 Words
- 12 Pages
Best Essays -
This article discusses Homeland Security's decision to renew Raytheon's contract as its cyber protector. In September Raytheon was picked as the main contractor for the Network Security Deployment division. This new contract is directly influenced by the companies new plans to prioritize cyber security as just last year the Office of Personnel Management was hacked, leaving data on 21.5 million people comprised. Moreover, in January of this year, a report on Homeland's cyber security admitted to limitations in ability to detect possible malware. Overall, cyber security is a controversial issue. An example of this is the debate surrounding the unlocking of a terrorist's iPhone in December, which Apple refused to do.…
- 111 Words
- 1 Page
Satisfactory Essays -
Since 9/11, security specialists are concentrated on wide security investments to defend and protect targets from terrorist attacks which is the main threat nowadays, theft, criminality and harm. Security experts entrusted with ensuring these facilities must conform to redesigned principles and controls while tending to the necessities of people and airlines. Physical security is by all account not the only concentration in today's assessed dangers. Network security is as critically essential as physical security. The way to deal with "solidify" airports requires security staff to interest in innovation that offers more prominent assurance, insight and IT…
- 97 Words
- 1 Page
Good Essays -
Aircraft Solutions (AS) is a recognized leader in the design and fabrication of component products and services for companies in the electronics, commercial, defense, and aerospace industry. Located in Southern California, AS has a dedicated, trained workforce and maintains a large capacity plant and extensive equipment to meet customer requirements. Much of the equipment is automated to increase production while reducing costs. The company's workforce has a large skill base: design engineers, programmers, machinists, and assembly personnel to work its highly-automated production systems.…
- 1368 Words
- 6 Pages
Powerful Essays