2 Assignments

The final step in developing the network security plan is to define how the plan that you have developed will be implemented within the organization. Implementing security controls and adding security devices can be a complex process that will affect every aspect of the organization. A detailed plan that phases in controls and new devices—and has a backup plan for any problems—will greatly increase the success rate of implementing a network security plan.

  • For this assignment, you will add a detailed implementation plan of 4–5 pages, which will describe your proposed solution for the implementation of a network security plan in your organization.

  • Finally, you will refine the Network Security Plan document to produce the final draft version. Updates may be based upon peer and instructor feedback.

The project deliverables are the following:

  • Update the Network Security Plan with a new date.

  • Update the previously completed sections based upon your peers' and instructor's feedback.

  • Implementation Plan

    • Develop a plan to implement the security controls and policies that you identified in previous sections.

    • Develop a plan to implement new security devices and modify existing security devices that are required to monitor the network and the polices that were created or updated.

    • Describe how these controls, policies, and security devices have addressed the key security areas of confidentiality, integrity, authentication, authorization, and nonrepudiation cryptographic services.

  • Network Security Plan

    • Revise the entire document, and make any necessary changes and improvements.

    • Ensure that the final version is sufficiently detailed to allow the organization to confidently move forward with the implementation of the security controls and devices based upon your recommendations.

    • Previous instructor feedback should be addressed with appropriate changes.

  • Update your table of contents before submission.


Network Security Plan

This course has been composed of a series of Individual Project assignments that have contributed to a Key Assignment submission at the end of the course. Each week, you have completed a part of a network security plan. The full Key Assignment should include the following tasks:

  • Overview of Network and Existing Security (Week 1)

    • Select an organization as the target for the analysis.

    • Provide an overview of the organization's existing network architecture.

      • The overview will include description of the network, the topology, protocols allowed, connectivity methods and network equipment, number of routers, switches, and any other network equipment, such as VPN concentrators, proxies, etc.

    • Provide a summary of the current security devices currently in use on the network.

      • List the type of device, the vendor, and give a brief description of how the device is used.

  • Risk Assessment (Week 2)

    • Conduct an inventory of the devices within your network. Provide a summary of the number of desktops, laptops, network printers, and servers.

      • Identify key assets

        • Assets also include records and sensitive information that requires special protection.

      • Prioritize each asset or group of assets, and assign a value to each.

    • Identify and describe the risks within your environment.

    • Do not forget natural disasters.

    • Determine the likelihood that the risk could occur.

    • Identify the tools and methodology that you would use to conduct the risk assessment.

  • Security Architecture Plan (Week 3)

    • Based upon the risk assessment and your analysis, create an action plan to mitigate the risks that you have identified.

    • Identify and select appropriate technologies to protect the network and the organization’s information, and explain why you chose each technology.

      • Describe where you plan to place these technologies in the network, and explain why.

      • The plan should cover all layers of the OSI model.

    • Identify additional software that will be required to monitor the network and protect key assets.

      • Identify security controls that need to be implemented to assist in mitigating risks.

  • Security Policies (Week 4)

    • Create the Key Assignment first draft for peer review.

    • Continue the development of the plan.

      • Create a fourth section in the plan to list all of the policies you would have for your organization and a brief description of what each policy will contain.

      • Each policy will address how you plan to monitor the policy and what the appropriate punishments should be for violators.

      • Provide a timetable for when these policies should be reviewed and updated.

    • Continue development of the Network Security Plan with an Incident Response Plan of 2–3 pages.

      • Include the actions that need to occur when an incident is in progress.

      • Include how your organization will identify and classify incidents, what the response will be, and the plan to recover.

  • Implementation and Incident Response (Week 5)

    • Analyze previous submissions, and make changes as necessary to the final paper.

      • Submit a detailed implementation plan of 4–5 pages that will describe your proposed solution for the implementation of the Network Security Plan for the organization.

      • This is the last and final section of the Key Assignment and should bring together all aspects of the implementation in one cohesive paper.

      • Revise the previous sections so that the entire plan flows and has a strong introduction and conclusion.

    • Submit the final Key Assignment.