Our Services

Get 15% Discount on your First Order

[rank_math_breadcrumb]

Discussion and Replies

Please see attachment for instructions.

 

 

 

In 250 words total, answer the questions below with 4 evidence base scholarly articles. APA format.

Based on the readings for chapter 3 Information Security Fundamentals and chapter 3&4 Information Security: Design, Implementation, Measurement, and Compliance, Discuss the following.

1. What are some of the cryptology methods used in my work organizations?

2. What do you find to be an advantage and disadvantage?

3. What are some things you think that may be lacking and or should be improved in the future?

400 words total, replying to the two posts below. Each reply must be 200 words for post 1 and post 2. 


S.B POST 1

In my organization, which operates within the public sector, cryptology plays a central role in protecting sensitive data, particularly within our records management systems and inter-agency communications. One of the most widely used cryptographic methods is AES-256 encryption, especially for database storage and file transfer protocols. This symmetric key encryption standard provides a strong balance of speed and security, and its adoption has helped ensure compliance with CJIS and other government data protection requirements (Peltier, 2013).

 

For secure external communication, we also rely heavily on TLS (Transport Layer Security), particularly for web-based applications and email systems. TLS ensures data confidentiality and integrity during transmission and is integrated into many of our public-facing platforms, such as citizen complaint portals and department-wide internal communications. Additionally, SHA-2 hashing is used for data integrity checks on documents submitted through our digital evidence systems.

 

A clear advantage of these methods is their maturity and wide adoption, which allows for relatively seamless integration into commercial off-the-shelf software and platforms. The downside, however, is that key management—especially for encrypted backup archives—can become cumbersome. We’ve experienced issues in the past where decryption keys weren’t properly maintained or rotated, leading to accessibility problems during audits or recovery efforts. As Peltier (2013) notes, poor key management can be a critical failure point, even when robust cryptographic tools are in place.

 

One area I believe needs improvement is end-user awareness and handling of encrypted data. While the backend systems are fairly secure, human error remains a vulnerability. For example, employees sometimes download sensitive encrypted files to personal devices or cloud drives, defeating the purpose of organizational encryption policies. Improving this would require stronger endpoint controls and mandatory encryption for local storage (Whitman & Mattord, 2021).

 

Going forward, I believe we need to evaluate quantum-resistant cryptography for long-term data protection, especially as federal agencies begin laying the groundwork for post-quantum encryption standards (NIST, 2023). While this might seem premature, critical data archived for 10+ years could be at risk once quantum computing becomes mainstream.

 

References

 

National Institute of Standards and Technology. (2023). Post-quantum cryptography: NIST’s approach and latest updates. 

Peltier, T. R. (2013). Information security fundamentals (2nd ed.). CRC Press.

Whitman, M. E., & Mattord, H. J. (2021). Principles of information security (7th ed.). Cengage Learning.


J.N POST 2

Currently, I am engaged in Communications Security (COMSEC) operations for the wing’s cybersecurity division, which plays a foundational role in safeguarding classified and sensitive information.  This vital role requires vigilance and expertise in implementing cryptologic methods designed to secure voice, data, and network communication.  These methods adherer strictly to standards approved by the National Security Agency (NSA), ensuring robust encryption and protection against potential breaches.  We operate on Key Management Infrastructure (KMI), a system that centralize control over key distribution, auding, and accountability.  The KMI’s integrated framework bring numerous advantages, including the enhanced security and automation of key lifecycle management processes such as distribution, revocation, and destruction.  Some challenges we face in COMSEC include the complexity of KMI, which can slow down operation when agility is needed in dynamic operational environments, particularly during emergencies.   KMI training is highly specialized and provided at only one location for the entire Air Force.  Training takes one month to complete, creating gaps in staffing.  Mastery of KMI operations takes years to fully grasp both operational and administrative to run the account effectively.  This steep learning curve places additional pressure on personnel to perform flawlessly in high-stakes scenarios. 

 

For future improvement in the administrative processes of COMSEC, unifying all documents to include digital signature would be highly beneficial.  Currently, handle numerous documents, with some requiring wet signatures and others relying solely on digital ones.  Standardizing this process would streamline operations and reduce complexity.  Interestingly, COMSEC falls under the IT domain, yet it often feels more like an administrative role.  Many of my co-workers who have spent the majority of their careers in COMSEC enjoy job security within this field but struggle to qualify for other positions in IT.

 

Reference:

 

Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central,

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

project 3 of 485

Follow the attach instructions to complete the work. Make sure it aligns with the Rubric Project #3: Presentation for Board of Directors Your Task: Padgett-Beale’s Chief Information Security Officer (CISO) has tasked you to continue supporting the Merger & Acquisition team’s efforts to bring Island Banking Services’ security program into

project 2 of 485

Fellow the attach instructions to complete this work. Make sure it aligns with the Rubric Project #2: Cybersecurity Implementation Plan Your Task: The Acquisition of Island Banking Services has moved from the strategy development phase to the integration phase. In this phase, the M&A team will develop transition and implementation

PROJECT 1 of 485

Fellow the attach instructions to complete this work. Make sure it aligns with the rubric Project #1: Cybersecurity Strategy & Plan of Action Your Task: You have been assigned to support the Padgett-Beale Merger & Acquisition (M&A) team working under the direct supervision of Padgett-Beale’s Chief Information Security Officer (CISO).

proj3-Final

Project 3: Cloud Portfolio Report  Step 1: Review BallotOnline’s Cloud Services Offerings  You’ve now had a lot of experience working on many aspects of the cloud at BallotOnline, and you will take a look at what you’ve done in the past. In this step, you will write up how you

AWS Simple Monthly Calculator

Discussion: AWS Simple Monthly Calculator Contains unread posts Now that you have discussed BallotOnline’s cloud services offerings, you will discuss the AWS Simple Monthly Calculator. You should cover the following areas: · What are some of the general use cases that are covered? · What are the requirements to use

D 5 0F 485

Follow the attach instructions to complete this work. Assessing Maturity for Cybersecurity Program Before you begin read:  Our class focuses on integrating many different aspects of cybersecurity, information security, and information assurance.  Recent developments in the field of cybersecurity have resulted in a number of “maturity models” which can be

Discussion 4 of 413

Follow the attach instructions to complete the work Data Breach Reporting Policy Review the Red Clay Renovations company profile and the weekly readings. Provide specific information about “the company” in your response. Due to changes in state and federal laws, Red Clay leadership decided the CISO will be the sole

discussion 4 of 485

Follow the attach instructions to complete this work. Cultural Differences as Barriers to Success The Merger & Acquisition team hired a team of external consultants to assist with identification of cultural issues which could result in barriers to the successful acquisition of Island Banking Services by Padgett-Beale. The consultants conducted

project 3 of 413

Follow the attached instructions to complete this work Download the attached detailed assignment description for this project. You should also review the rubric shown below for additional information about the requirements for the project and how your work will be graded. Please make sure that you use both the assignment description file

Project 2 of 413

Follow the attach instructions to complete this work. Make sure it aligns with the rubric Project #2: Manager’s Deskbook Company Background & Operating Environment Red Clay Renovations is an internationally recognized, awarding winning firm that specializes in the renovation and rehabilitation of residential buildings and dwellings. The company specializes in

Project 1 of 413

Follow the attach instructions to complete this work. Make sure it aligns with rubric Project #1: Employee Handbook Company Background & Operating Environment Red Clay Renovations is an internationally recognized, awarding winning firm that specializes in the renovation and rehabilitation of residential buildings and dwellings. The company specializes in updating

Discussion and Replies

Please see attachment for instructions     Discussion   In 250 words total, answer the questions below with 4 evidence base scholarly articles. APA format. 1. Discuss some of the common issues with implementation of security policy. 2. What are some possible mitigations to ensure policy can be enforced. Replies

revision x 10

I need someone to follow all of the instructions that is provided for revision that can be done no later than tomorrow, do not request bid if this price is not enough or if you cannot fulfill the requirements this is a time sensitive manner I cannot wait 3-4 days

Python

 Throughout this course, you have been exposed to programming techniques in several scripting languages. In your opinion, which scripting language is most useful for performing system administration tasks. Why? 

Computer Science Assignment

Intro to Data Mining –  Intro to Data Mining (ITS-632-A03) Chapters covered till noe upto chapter 4 For the midterm, select one key concept that we’ve learned in the course to date and answer the following: 1. Define the concept. 2. Note its importance to data science. 3. Discuss corresponding

Bibliography References

Please see the attach instructions to create a bibliography from the references in the attachment. 10 Directions You must used the below outline and 10 references to complete the bibliography assignment. Use the 10 references from the outline paper below to review, and create a short abstract on how you

D 3 85

Follow the attach instructions to complete this work. You will start by writing a short paper as described in the discussion question. You will be using information from this week’s readings and from your own research to address the information needs expressed in the question.  1. Create an MS Word

D 3 413

Follow the attach instructions to complete this work. Policy Mandates: US vs European Approaches to Privacy Laws In addition to the week 3 course readings, read:  Key issues  and  ( General Data Protection Regulation (GDPR) ) Prepare a two-page briefing paper (5 to 7 paragraphs) that provides background information about