For this assignment, we are tasked with conducting an asset identification and analysis on Harry and Mae’s Inc.’s assets; this is a vital first step in the risk assessment process. By carefully extracting each identifiable piece of hardware, software, or other property, I created a chart that lists the asset’s name, description, quantity, cost (both per unit and total), and finally, the cost of all the assets combined. Armed with the data shown below, one can quickly ascertain which assets are more valuable, thus requiring enhanced risk assessments and mitigation procedures. It is important to note that some of the asset costs shown below are estimations due to the limited information we have available to us.
Asset | Description | Quantity | Cost (Each) | Cost (Total) |
Internet | Comcast Business Services: Fully redundant fiber (100Mbps down and 50Mbps up) | 1 | Unknown | Unknown |
Nexus Core 700 Switches | NX-OS 5.0 | 2 | $7500 | $15,000 |
Cisco ME 3600X Switches | 2nd layer, located in each building on campus | 2 | $8500 | $17,000 |
Aruba WAPs | Aruba Networks Grid | 125 | $450 | $56,250 |
Dell SonicWall NSA 4600 | Connect Comcast Internet to the core network | 2 | $3200 | $6,400 |
Aruba 6000 Mod Controllers | Serves Aruba WAPs | 2 | $1200 | $2,400 |
Barracuda Spam and Virus Firewall | Core network, forwards mail traffic | 2 | $450 | $900 |
Cisco 2960-S POE Switches | 3rd layer, connects Desktop PCs and POE phones with Gigabit copper LANs | Unknown | $650 | $650+ |
FTP Server | Enabled for both internal/external networks and remote situations. Also used as a staging server | 1 | $1700 | $1,700 |
HP StorageWorks Server (SAN) Email Server (Microsoft Exchange Server 2010 SP3 | 200TByte, provides storage for the HP ProLiant DL380 G7 Servers | 1 | $20,000 | $20,000 |
Web Server (IIS) | Internal and external (with public IP address) connections | 1 | $1700 | $1,700 |
HP ProLiant DL380 G7 Servers | Version 5.1 of VMWare vSphere | 10 | $3000+ | $30,000+ |
AD Domain Controller | One account for the entire campus | 1 AD Account, 2 Controllers | Unknown | Unknown |
First AD Organizational Unit | Campus | 1 | Unknown | Unknown |
Second AD Organizational Unit | Accounting and Finance Group | 1 | Unknown | Unknown |
Dell OptiPlex 3020 Workstations | Windows 7, joined to AD | 400+ | $450 | $180,000 |
POS System | Hosted as a virtual server on VMware vSphere Hypervisor (ESXi) version 5.1 | 2 | $1000 | $2,000 |
Off Campus-NAT Firewall | No further data | 1 | $500 | $500 |
Off Campus-WAP | Setup by franchise owner | 1 | $450 | $450 |
Employees | No further data | 400+ | Unknown | Unknown |
Symantec Endpoint Protection | All Campus Workstations | 400+ | Unknown | Unknown |
WSUS | Updates Microsoft applications | Unknown | Unknown | Unknown |
Microsoft Internet Explorer 10 | Company Standard Browser | Unknown | Unknown | Unknown |
Norton Antivirus Software | Off-Campus | Unknown | Unknown | Unknown |
Microsoft PPTP VPN Clients | (Off-Campus) POS Processing | Unknown | Unknown | Unknown |
Campus Building | Physical Location | 1 | Unknown | Unknown |
Off-Campus Buildings | Physical Location | 100+ | Unknown | Unknown |
Perimeter Fence | Campus | Unknown | Unknown | Unknown |
Surveillance Cameras | Campus | Unknown | Unknown | Unknown |
Smart Card Access Systems | Campus | Unknown | Unknown | Unknown |
Security Staff | Campus | Unknown | Unknown | Unknown |
Security Alarms | Campus | Unknown | Unknown | Unknown |
UPS | Campus, 36-hours | Unknown | ||
Security Fire, Water, etc. Sensors | Campus | Unknown | Unknown | Unknown |
Power Generator | Campus | Unknown | Unknown | Unknown |
(BYOD) Employee Mobile Devices | Campus | Unknown | Unknown | Unknown |
Website- http://www.harryandmae.com | Hosted on the single web server, public | 1 | Unknown | Unknown |
Website- http://www.haryandmae.local. | Hosted on the single web server, private (pay statements, work performance, vacation time, personal information) | 1 | Unknown | Unknown |
Website- http://www.HandMScranton.com | Owned by franchise owner in Scranton, PA | 1 | Unknown | Unknown |
Company Facebook Account | Owned by franchise owner in Scranton, PA | 1 | Unknown | Unknown |
Company Twitter Account | Owned by franchise owner in Scranton, PA | 1 | Unknown | Unknown |
Company Instagram Account | Owned by franchise owner in Scranton, PA | 1 | Unknown | Unknown |
Total: $320,150+ |
Reference
Wheeler, E. (2011). Security risk management: Building an information security risk management program from the ground up. Waltham, MA: Syngress.
Categories: Security