Our Services

Get 15% Discount on your First Order

[rank_math_breadcrumb]

Discussion and Replies

Please see attachment for instructions.

 

 

 

In 250 words total, answer the questions below with 4 evidence base scholarly articles. APA format.

Based on the readings for chapter 3 Information Security Fundamentals and chapter 3&4 Information Security: Design, Implementation, Measurement, and Compliance, Discuss the following.

1. What are some of the cryptology methods used in my work organizations?

2. What do you find to be an advantage and disadvantage?

3. What are some things you think that may be lacking and or should be improved in the future?

400 words total, replying to the two posts below. Each reply must be 200 words for post 1 and post 2. 


S.B POST 1

In my organization, which operates within the public sector, cryptology plays a central role in protecting sensitive data, particularly within our records management systems and inter-agency communications. One of the most widely used cryptographic methods is AES-256 encryption, especially for database storage and file transfer protocols. This symmetric key encryption standard provides a strong balance of speed and security, and its adoption has helped ensure compliance with CJIS and other government data protection requirements (Peltier, 2013).

 

For secure external communication, we also rely heavily on TLS (Transport Layer Security), particularly for web-based applications and email systems. TLS ensures data confidentiality and integrity during transmission and is integrated into many of our public-facing platforms, such as citizen complaint portals and department-wide internal communications. Additionally, SHA-2 hashing is used for data integrity checks on documents submitted through our digital evidence systems.

 

A clear advantage of these methods is their maturity and wide adoption, which allows for relatively seamless integration into commercial off-the-shelf software and platforms. The downside, however, is that key management—especially for encrypted backup archives—can become cumbersome. We’ve experienced issues in the past where decryption keys weren’t properly maintained or rotated, leading to accessibility problems during audits or recovery efforts. As Peltier (2013) notes, poor key management can be a critical failure point, even when robust cryptographic tools are in place.

 

One area I believe needs improvement is end-user awareness and handling of encrypted data. While the backend systems are fairly secure, human error remains a vulnerability. For example, employees sometimes download sensitive encrypted files to personal devices or cloud drives, defeating the purpose of organizational encryption policies. Improving this would require stronger endpoint controls and mandatory encryption for local storage (Whitman & Mattord, 2021).

 

Going forward, I believe we need to evaluate quantum-resistant cryptography for long-term data protection, especially as federal agencies begin laying the groundwork for post-quantum encryption standards (NIST, 2023). While this might seem premature, critical data archived for 10+ years could be at risk once quantum computing becomes mainstream.

 

References

 

National Institute of Standards and Technology. (2023). Post-quantum cryptography: NIST’s approach and latest updates. 

Peltier, T. R. (2013). Information security fundamentals (2nd ed.). CRC Press.

Whitman, M. E., & Mattord, H. J. (2021). Principles of information security (7th ed.). Cengage Learning.


J.N POST 2

Currently, I am engaged in Communications Security (COMSEC) operations for the wing’s cybersecurity division, which plays a foundational role in safeguarding classified and sensitive information.  This vital role requires vigilance and expertise in implementing cryptologic methods designed to secure voice, data, and network communication.  These methods adherer strictly to standards approved by the National Security Agency (NSA), ensuring robust encryption and protection against potential breaches.  We operate on Key Management Infrastructure (KMI), a system that centralize control over key distribution, auding, and accountability.  The KMI’s integrated framework bring numerous advantages, including the enhanced security and automation of key lifecycle management processes such as distribution, revocation, and destruction.  Some challenges we face in COMSEC include the complexity of KMI, which can slow down operation when agility is needed in dynamic operational environments, particularly during emergencies.   KMI training is highly specialized and provided at only one location for the entire Air Force.  Training takes one month to complete, creating gaps in staffing.  Mastery of KMI operations takes years to fully grasp both operational and administrative to run the account effectively.  This steep learning curve places additional pressure on personnel to perform flawlessly in high-stakes scenarios. 

 

For future improvement in the administrative processes of COMSEC, unifying all documents to include digital signature would be highly beneficial.  Currently, handle numerous documents, with some requiring wet signatures and others relying solely on digital ones.  Standardizing this process would streamline operations and reduce complexity.  Interestingly, COMSEC falls under the IT domain, yet it often feels more like an administrative role.  Many of my co-workers who have spent the majority of their careers in COMSEC enjoy job security within this field but struggle to qualify for other positions in IT.

 

Reference:

 

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central,

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

Computer Science Wk 2 assignment

Please see attachment for instructions provide a one-page response to the following topic below utilizing supporting documentation obtained from your textbooks and the Internet.  Be sure to include an APA Reference Page Topic: Assess the various Access Control methods.

How can businesses benefit from incorporating AI Integration Services into their digital transformation strategies?

[url= Integration Services[/url] are transforming businesses by streamlining operations, enhancing customer experiences, and enabling data-driven decisions. By automating repetitive tasks, AI frees up resources for more strategic activities, improving productivity. AI tools like chatbots and recommendation engines offer personalized solutions, fostering customer loyalty. AI also helps businesses analyze large datasets

OSINT Project 2

 Download the attached detailed assignment description for this project. You should also review the rubric shown below for additional information about the requirements for the project and how your work will be graded. Please make sure that you use both the assignment description file AND the rubric when completing your work. 

OSINT Project

Instructions Download the attached detailed assignment description for this project. You should also review the rubric shown below for additional information about the requirements for the project and how your work will be graded. Please make sure that you use both the assignment description file AND the rubric when completing your

D 6 of 459

Follow the attach instructions to complete this work Questions: 1. How is technology increasingly used in healthcare beyond electronic health records (HER)?  Give some examples. 2. Would you personally participate in robot assisted/telesurgery as a patient or a medical professional?  Why or why not? Resources 20 Examples Of IoT Wearables

D 5 of 459

Follow the attach instructions to complete the work. Questions: 1. What are service robots and how are they used and categorized?  Give examples of each. 2. How would you leverage service robots to improve the availability, confidentiality, and integrity of a large (20MW+) data center? Resources Robots as a Platform

ITS 10 Help

Ethical Hacking help Login to your NDG Online account. Complete the following labs. Each lab is worth 40 points. NDG Online account Link- Log In | NDG Online Portal ([email protected] Password: Starballplayer23$ 1. NDG Ethical Hacking Lab 10: Web Pentesting 2. NDG Ethical Hacking Lab 11: Client Side Exploitations After

InfSec

 Blockchain technology will revolutionize cybersecurity

ITS 12 Help

Ethical HAcking Login to your NDG Online account. Complete the following labs. Each lab is worth 40 points. NDG Online account Link- Log In | NDG Online Portal ([email protected] Password: Starballplayer23$ 1. NDG Ethical Hacking Lab 08: Password Cracking with JTR and Hashcat 2. NDG Ethical Hacking Lab 17: Creating

ITS 13 Help

Ethical Hacking  Login to your NDG Online account. Complete the following labs. Each lab is worth 40 points. NDG Online account Link- Log In | NDG Online Portal ([email protected] Password: Starballplayer23$ 1. NDG Ethical Hacking Lab 06: Network Analysis 2. NDG Ethical Hacking Lab 07: Evading IDS Submit Your Lab

Replies

please see attachment for instructions   In 400 word total, replying to the 2 post below. Each reply must be 200 word.      N.B Post #1 Hello classmates,   I am active duty in the military and currently on Eastern Standard Time. I have 4 kids, I’ve been in

channing 4.25 r studio work

follow the insrtuction Group Project Mostafa Rezaei Big Data (Introduction to Data Science) General information The group project gives you the opportunity to practice many of the skills we learned in the class. It includes 5 steps: Step 1: Find and describe a data set Find a publicly available data

Computer Science English Homework

● Assignment to do For this assignment, research different tools that cloud storage service providers use to manage the vast arrays of drives in their environments. Also, research the current performance and trends of the types of hard drives in use: magnetic vs. SSD. Summarize your research in a 2-3

SQL Help13

Statements and query For the final project, you will be working with a Guitar Shop.  You will need the MySQL server and MySQL workbench installed, just as it has been throughout the class. You will also need the following file: Project Requirements: 1. Execute the attached create_my_guitar_shop.sql to create the

Computer Science WK1 Assignment

Please see attachment for instructions and PDF book     W1 Assignment Instructions:   In 2 pages, answer the questions below with 5 evidence base scholarly articles in APA format.  Recommend and expand upon Information Security & Risk Management. 1. What are some internal and external security threats when dealing

computering

SEE ATTACTED Module 4 Homework Here are the instructions for Module 4 Homework. You will use the Module 4 Homework Submit link to submit your work. If you do not see a link, this means you have missed completing a previous assignment or task.  Fix the emails! We have covered some email