🎁 Contribute Documents & Earn Free Downloads ✦ Upload your notes, past papers & textbooks ✦ Share knowledge · Unlock resources for free ✦ 🎁 Contribute Documents & Earn Free Downloads ✦ Upload your notes, past papers & textbooks ✦ Share knowledge · Unlock resources for free ✦ 🎁 Contribute Documents & Earn Free Downloads ✦ Upload your notes, past papers & textbooks ✦ Share knowledge · Unlock resources for free ✦ 🎁 Contribute Documents & Earn Free Downloads ✦ Upload your notes, past papers & textbooks ✦ Share knowledge · Unlock resources for free ✦ 🎁 Contribute Documents & Earn Free Downloads ✦ Upload your notes, past papers & textbooks ✦ Share knowledge · Unlock resources for free ✦ 🎁 Contribute Documents & Earn Free Downloads ✦ Upload your notes, past papers & textbooks ✦ Share knowledge · Unlock resources for free ✦

SEC 571 Week 7 Final Project; Netflix

DeVry University Information Technology SEC 571 Principles of Information Security and Privacy Della Reese 38 pages
View Full Course

Document Preview

Unlock Full 38 Page Document Instantly.

Document Overview

SEC571 Final Project: Netflix Student Name Date Introduction The maintenance of information security necessitates the use of robust and efficient measures. One potential approach to accomplish this objective is by employing a Skills, Education, Training, and Abilities (SETA) tool. In this presentation, an examination of several vulnerabilities will be undertaken, followed by the proposal of administrative and technical control measures to address those shortcomings. Additionally, I will present a comprehensive strategy outlining the implementation of the proposed control measure, along with a thorough cost-benefit analysis. Executive Summary Information security must be kept up by putting in place strong and effective means. One way to do this is through the use of a SETA tool. During this presentation, I will talk about a number of weaknesses and suggest administrative and technical control methods to deal with these weaknesses. I will also share a plan for how my suggested control will be put into place and a cost-benefit analysis of it. Organization Profile and Problem Statement Netflix Organization Netflix, created by Reed Hastings and Marc Randolph in Scotts Valley, California, is a subscription-based streaming service. Customers can watch TV and movies commercial-free on an internet-connected device. Founded August 29, 1997 renting and selling DVDs through mail from Netflix. After a year, they focused on rentals instead of sales. May 29, 2002, went public at $15 per share. The share price is $445 today. TV series and movies may now be downloaded to iOS, Android, and Windows 10 devices for offline viewing. Products & Services Movies Television shows Original series Documentaries Feature films Electronic games Hidden genre category list system Smart download feature DVD by mail service Next Games Products & Services Cont. Streaming Media Video on demand Film production Film distribution Television production SECURITY VULNERABILITIES CWE-89 SQL INJECTION Putting in bad SQL code to get unauthorized access to information like secret company data, user lists, or private customer information. Without proper removal or quoting of SQL syntax in user-controllable inputs, the changed query logic could escape security checks or add extra statements that change the back-end database, possibly by running system commands. CWE-79 CROSS-SITE SCRIPTING Failure or improper neutralization of user-controlled input before it is put into output that is used as a web page that is served to other users. In many cases, the attack can start before the target even knows what's happening. Even when users are careful, attackers often use methods like URL encoding or Unicode to hide the bad part of the attack so that the request doesn't look as strange (CWE Team, 2022). Once the attacker has inserted the malicious script, they can do a number of bad things, such as: Send confidential information Send fraudulent requests to a website on the victim's behalf Phishing tactics could be used to make sites look like ones that people trust. The script could take advantage of a weakness in an online browser and take over the victim's computer. This is called β€œdrive-by hacking.” THREAT ANALYSIS Phishing Attacks Cybercriminals try

Full content available after purchase or with an active subscription.

Related Products

SEC 571 Week 1 Discussion

SEC 571 Week 1 Discussion

SEC 571 Week 2 Course Project; Organization Profile and Problem Statement

SEC 571 Week 2 Course Project; Organization Profile and Problem Statement

SEC 571 Week 2 Discussion

SEC 571 Week 2 Discussion

SEC 571 Week 6 Course Project; Implementation Plan

SEC 571 Week 6 Course Project; Implementation Plan

Academic Use Notice: This resource is provided strictly as study support material to help students review concepts, understand topic structure, and prepare their own original academic work responsibly. It is not intended to be submitted directly as a student's own work.