Question: Problem 1: Security Components and Goals (a). Explain how the three security services - confidentiality, integrity, and availability - are sufficient to deal with the
Problem 1: Security Components and Goals (a). Explain how the three security services - confidentiality, integrity, and availability - are sufficient to deal with the threats of disclosure, disruption, deception, and usurpation. (20 points) (b). Suppose you are the security manager of a company and one of your goals is to design security mechanisms based on three security goals (1) prevent the attack (2) detect the attack or (3) recover from the attack. Depending on the situation or application, you have to adopt one of these security goals. For each of the following statements, give an example of a application or situation in which the statement is true. (15 points) (i). Prevention is more important than detection and recovery (ii). Detection is more important than prevention and recovery (iii). Recovery is more important than prevention and detection (c). Users often bring in programs or download programs from the Internet. Give an ex- ample of a site for which the benefits of allowing users to do this outweigh the dangers. Then give an example of a site for which the dangers of allowing users to do this out- weigh the benefits. Explain your reasoning for choosing these websites. (15 points)
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
