INFS1701 Networking Security Group Project

Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 2

INFS1701 Sandbox Project

Topic: Social Engineering: Confidentiality, Integrity, Availability

Important dates:

Project released: Week 5 Lecture, Tuesday 10th October 2023, Project


will be introduced and explained by EY
Follow-up lecture/Q&A by EY: Week 8 Lecture, Tuesday 31st October
2023
Project due: Week 10 9.00am, Monday 13th November 2023
Followup lecture and Q&A by EY: Week 8 Lecture, Tuesday 31 st October
2023

Project Background

Company ABC holds personal identifiable information of millions of its


Australian customers and are facing nation-wide backlash after it was
revealed that a disgruntled employee successfully performed a social
engineering attack, which led to the release of more than 1 million
records/data with confidential customer information (including bank
details, home addresses and medical records).
In this project, you will be playing the role of cyber security consultants
and you have been employed by WeCare to research on social
engineering and its role in compromising the core principles of information
security (CIA). You will be reporting to the CISO of WeCare. To complete
this project, you will be required to:

 Divide into groups of 4. Groups must be from within your tutorials.


Your tutors can help with group formation.
 You might like divide the tasks where each member of the groups
focusses on one of the following: confidentiality, integrity,
availability and project management
 Choose a social engineering attack (e.g., phishing, pretexting,
tailgating) and investigate how it can impact the chosen aspect of
information security from different aspects i.e. confidentiality,
integrity and availability
 Prepare a 4-5 minute video presentation to share your findings,
including attack techniques, consequences, and potential
countermeasures. This video must feature all the members of the
group in some aspect.

(In the guest lecture, EY will discuss effective countermeasures and


prevention strategies against social engineering attacks. Engaging
students in a discussion about the importance of user education,
security policies, and technology solutions in mitigating social
engineering risks)
 As individuals, write a 200 word reflective report summarising what
you have learned about the impact of social engineering on
confidentiality, integrity, and availability.

Students will be assessed based on their group video presentations,


individual reflective reports, active participation in discussions, and their
ability to apply the principles of confidentiality, integrity, and availability
to real-world social engineering scenarios.

The project will not only enhance students' understanding of social


engineering but also highlight the critical role these attacks play in
compromising the core principles of information security. It will promote
critical thinking, teamwork, and practical knowledge relevant to their
future careers in cybersecurity or related fields.

The top 5 video presentations will be shared with the EY Team for internal
review. (Reviewed by Senior staff and/or a selected Partner/s).

Submission Details:

 Video recording presentation, uploaded as a private video on


UNSW learning management system. More information will be
provided via Moodle.

 Reflective individual report summarising what you've learnt


about the impact of social engineering on confidentiality, integrity,
and availability. This will also need to be uploaded to Moodle.
Marking:
The video and the individual self reflection will be marked separately
using the rubrics provided. The weightings of the marks are as follows:
- Group video: 80%
- Individual self-reflection: 20%

You might also like