CMGT/430 v8
IT System Connection Table
CMGT/430 v8
Page 2 of 2
C:\Users\djshirey\OneDrive - University of Phoenix\F_Drive\Style Guides\UPX Logos\Horizontal format\UOPX_Sig_Hor_Black_Medium.png
IT System Connection Table
Student name:
When securing the modern enterprise, consider that IT systems do not operate alone. Securing them involves securing their interfaces with other systems as well. It is important to know the different interconnections each system may have.
Fill out the table below for four IT systems. Include the following:
· Note two enterprise systems they connect with and their connection type.
· Note two security vulnerabilities the connection may have and 2 to 4 ways each vulnerability could be potentially exploited.
Consider the following as you build your table:
· Two example rows have been entered into the table.
· Keep in mind that enterprise systems cover a certain task in the enterprise (HR, CRM, identity management, etc.). They are not the components of a system (such as servers).
· Connections can often be a direct connection/pipe, a file, a common database or something else.
· The vulnerability is what would make the connection vulnerable to an attack.
· The related risk is an attack that could target the weakness.
IT System
Target System
Connection Type
Possible Security Vulnerability
Related Risk
Example HR System
Identity Management System
Feeder File
File could be modified.
User rights might not be correctly updated.
Example
Customer Relationship
Management (CRM)
1. Sensitive Data
2. System Data
Web communications (https)
1. TCP/IP (denial-of-service attacks)
2. Cross-site scripting (XSS or CSS)
1. Mail bombs
2. Temporarily cease operation
3. Theft of data and information
4. Content spoofing
5. Not to be in compliance
6. Control of user browser
7. Deliver malware or warm
8. Execute arbitrary commands
9. Control of user account on vulnerable web application
Copyright© 2018 by University of Phoenix. All rights reserved.
Copyright© 2018 by University of Phoenix. All rights reserved.