Assignment title: Network


Explain how a security awareness program will enhance the security of Epworth. 2. Epworth systems use the Bell-LaPadula model to enforce confidentiality with security levels TOP SECRET, SECRET, CONFIDENTIAL and UNCLASSIFIED ordered from highest to lowest. There are two documents (document A with SECRET security level and document B with CONFIDENTIAL security level) and four subjects: Alice has a TOP SECRET clearance, Bob has SECRET clearance, Charlie has CONFIDENTIAL clearance, and Diana has UNCLASSIFIED clearance. a) Explain who can read and write and who cannot read and write document A. b) Explain who can read and write and who cannot read and write document B. You must justify why a subject can read/write the document. 3. The Epworth risk analyst is 95% certain that the personnel server is vulnerable to a sync flood attack with a likelihood of 0.1. The analyst is also 80% certain that the financial database server is vulnerable to SQL injection attack with a likelihood of 0.2. Based on the risk analyst findings, the Epworth management agreed to fund an additional security control purchase for the financial database server or the personnel database server. a) Briefly explain the risk management strategy used by the Epworth management b) Assuming that the value of the personnel database server and the financial database server is 3000 each, which server should be provided with an additional security safeguards first? You must justify your answer. Be sure to use the correct formula and show step by step calculations