Question

In: Computer Science

Case Study: Regional Gardens Case study Regional Gardens Ltd is a company that runs a few...

Case Study:

Regional Gardens Case study Regional Gardens Ltd is a company that runs a few related gardening enterprises. It has a large display garden that it opens for public inspection several times a year. These enterprises include the Regional Gardens Nursery which sells plants and garden supplies to the public, and Regional Garden Planners which provides garden advice, design and consultancy services. Regional Gardens Ltd has a small data centre at its main site in Bathurst where the company’s servers and data storage is located. The company has the following server infrastructure: • 2 x Active Directory domain controllers on Windows Server 2008 R2, (2 x Xeon 3.6GHZ, 8GB RAM, 140GB HDD); • 3 x SQL Server 2003 database servers on Windows Server 2003 (2 x Xeon 2.8GHZ, 4GB RAM, 250GB RAID-5 array); • 1 x Exchange 2007 email server on Windows Server 2008 R2 (2 x Xeon 3.6GHZ, 8GB RAM, 250GB RAID-1 array); • 4 x Windows Server 2003 File and Print servers (2 x Xeon 2.8GHZ, 4GB RAM, 250GB RAID-1 array); • 2 x Windows Server 2008 R2 running Microsoft SharePoint 2013 (2 x Xeon 2.8GHZ, 4GB RAM, 250GB RAID-5 array); • 2 x Red Hat Enterprise 5 Linux servers running Apache and TomCat (2 x Xeon 2.8GHZ, 16GB RAM, 140GB HDD). This infrastructure has not been updated for some time and the Regional Gardens Board is concerned that a full upgrade may now cost them more than it is worth. The Board is now considering moving some, or all, of their current infrastructure into the Cloud. The Board sees this as a strategic move to future-proof the company and is looking to a move to the cloud to ensure that its services are: • Readily available and always accessible, • Capable of handling heavy loads in times of peak demand, • Capable of serving downloads to users as required, • Secure from attacks, • Capable of providing detailed reports on usage. Regional Gardens is considering the following strategic proposal: • They plan to retain their data centre solely for archival and long-term data storage. This would entail updating their data storage infrastructure in the Bathurst Data Centre and moving all other infrastructure into the Cloud. • They plan to initially move all their Web Services into the Cloud in order to provide an increased level of HA (High Availability) as well as a better degree of flexibility in supplying data to their customers and employees. Their web services are running on the current Red Hat Enterprise Linux servers using Apache Tomcat • They plan to change their current web software architecture to take advantage of the flexibility and scalability that can be gained by moving to a Microservices model (this would entail the use of such services as AWS Lambda or Azure Functions, Containers, Data Services, and Cloud Edge capability and monitoring). All Microservices are to be designed so that they can be easily moved from one cloud to another to suit requirements or to take advantage of price differentials. • They also plan to migrate their Garden Design LoB (Line of Business) applications to the cloud in order to increase the application's flexibility and availability. The Garden Design LoB application suite will require: o several IaaS instances running Windows Server 2019 o several PaaS instances for Microsoft SharePoint 2019 Enterprise • Regional Gardens would like to keep their gardening data sets in Australia. The Regional Gardens Board is contemplating this strategy to increase the company’s flexibility and responsiveness. The Board also expects to achieve significant savings by migrating to a Cloud based ICT infrastructure. They appreciate that this would entail retraining for: • Their existing ICT staff so that they can manage the new Cloud based infrastructure, • Their development staff so that they can start to develop using a Microservices model. Regional Gardens have some 70 garden design, horticultural and support staff that work on different projects for clients in New South Wales. The Board has been looking at the steady increase in workload in garden design and consulting and want to expand this business unit into an Australiawide enterprise. They have been advised that a move to using a Cloud based infrastructure would be an advantage to them. Currently the designers use a locally installed Dynascape software suite on each of their PCs (the Dynascape system requirements are an i7 processor, a minimum of 4GB RAM and a minimum 2GB HDDR6 video card) on each PC. But Dynascape now offers it’s software on an SaaS basis (see https://www.dynascape.com/ and https://www.capterra.com.au/software/5930/dynascape#about). The Board is particularly concerned about the security of their garden design process and their intellectual property for garden design. They are also concerned to keep their client data secure. Accordingly, they are looking for a solution that keeps their design and client data on the company’s own servers in its Bathurst data centre.

You must read the Regional Gardens Case Study in Interact before attempting this assignment

The Regional Gardens Board is considering the following strategic proposal:

  • They plan to retain their data centre solely for archival and long-term data storage. This would entail updating their data storage infrastructure, and moving all other infrastructure into the Cloud.
  • They plan to implement a multi-cloud strategy to prevent vendor lock-in and provide the ability to take advantage of price differentials.
  • They have now moved all their existing Web Services to a IaaS instance in the Cloud that has been designed to provide HA (High Availability) and a better degree of flexibility in supplying data to their customers and employees. This IaaS instance uses a number of Red Hat Enterprise Linux servers using Apache Tomcat.
  • They plan to change their current web software architecture to take advantage of the flexibility and scalability that can be gained by moving to a Microservices model (this would entail the use of such services as AWS Lambda or Azure Functions, Containers, Data Services, and Cloud Edge capability and monitoring). All Microservices are to be designed so that they can be easily moved from one cloud to another to suit their changing requirements.
  • They also plan to migrate their Garden Design LoB (Line of Business) applications to the cloud in order to increase the application's flexibility and availability. The Garden Design LoB application suite will require:
    • A number of IaaS instances running Windows Server 2019
    • A number of PaaS instances for Microsoft SharePoint 2019 Enterprise
  • Regional Gardens would like to keep their gardening data sets in Australia.

The Regional Gardens Board is contemplating this strategy as a way to increase the company’s flexibility and responsiveness. The Board also expects to achieve significant savings by migrating to a Cloud-based ICT infrastructure. They appreciate that this would entail retraining for:

  • Their existing ICT staff so that they can manage the new Cloud-based infrastructure,
  • Their development staff so that they can start to develop using a Microservices model.

Regional Gardens has again approached you to advise them on this strategy. The Board is also concerned about how this strategy will affect their BCP (Business Continuity Plan) and their backup and disaster recovery strategies.

2. Describe the major Information Security risks that you see associated with the move to this Microservices strategy for Web Services. You should name and describe each risk that you identify, estimate its likelihood and consequence and then describe a possible control for the risk. This should be presented in a tabular form.

Solutions

Expert Solution

Answer2)

Risks and control associated with the new Hybrid Cloud and Microservices strategy

Risk name

Risk description

Control

Lack of encryption

Data transmission over the network can be vulnerable to eavesdropping and MitM (Man in the middle) attacks if data is not encrypted before transmitting.

Cryptographic protocols are necessary, endpoint authentication and use of a reliable proxy server is useful to prevent this threat. VPN (virtual private network) must be implemented. Transmission encryption using SSL/ TLS and secure shell (SSH)

Unprotected APIs

Unprotected APIs can exposure confidential data to outsiders by authentication exploitation or personal data manipulation

API keys must be handled securely, verification of third parties before releasing API key is must

DoS (Denial of Service) attacks

The cloud network is rendered inaccessible by attacker through disruption of services in shared resources such as RAM, CPU, network bandwidth and disk space.

Flow analytics, firewall intrusion detection and prevention systems

Poorly defined SLA

Loss of control over data, unsure of cloud security measures taken by the cloud service provider

Cloud vendor should clearly define SLA with access protections and permissions, reasonable expectation of service, well-defined security controls

Data leakage

Cloud provider’s failure to provide adequate security controls can result in comprise of confidential information, data loss or corruption, unauthorized access

Data loss prevention mechanism must be implemented, software errors and infrastructure malfunctions must be eliminated

Note: Plzzz don' t give dislike.....Plzzz comment if u have any problem i will try to resolve it.......


Related Solutions

Case Study: Regional Gardens Case study Regional Gardens Ltd is a company that runs a few...
Case Study: Regional Gardens Case study Regional Gardens Ltd is a company that runs a few related gardening enterprises. It has a large display garden that it opens for public inspection several times a year. These enterprises include the Regional Gardens Nursery which sells plants and garden supplies to the public, and Regional Garden Planners which provides garden advice, design and consultancy services. Regional Gardens Ltd has a small data centre at its main site in Bathurst where the company’s...
Case Study: Regional Gardens Case study Regional Gardens Ltd is a company that runs a few...
Case Study: Regional Gardens Case study Regional Gardens Ltd is a company that runs a few related gardening enterprises. It has a large display garden that it opens for public inspection several times a year. These enterprises include the Regional Gardens Nursery which sells plants and garden supplies to the public, and Regional Garden Planners which provides garden advice, design and consultancy services. Regional Gardens Ltd has a small data centre at its main site in Bathurst where the company’s...
Case study This case study is about Zama Brooks Ltd, a company that has been known...
Case study This case study is about Zama Brooks Ltd, a company that has been known to have bad results for the past three years. Our company has been trying to carry out an analysis to undermine whether acquisition of controlling shares in Zama Brooks Ltd will yield fruits. You are the financial director in the company interested in obtaining controlling shares in Zama Brooks Ltd and management at the company are so eager to produce good results. Management has...
Discuss what you would recommend should be included in Regional Gardens' BCP as a result of...
Discuss what you would recommend should be included in Regional Gardens' BCP as a result of their adoption of a Cloud and Microservices approach. You will need to consider, as a minimum, the issues of application resilience, backup and disaster recovery in a hybrid cloud environment
Case study 6.1 Accounting for brands West Ltd is a leading company in the sale of...
Case study 6.1 Accounting for brands West Ltd is a leading company in the sale of frozen and canned fish produce. These products are sold under two brand names. Fish caught in southern Australian waters are sold under the brand ‘Artic Fresh’, which is the brand the company developed when it commenced operations and which is still used today. Fish caught in the northern oceans are sold under the brand name ‘Tropical Taste’, the brand developed by Fishy Tales Ltd....
Case study 6.2: Converting to LPG – is it worth it. Green fuel runs out of...
Case study 6.2: Converting to LPG – is it worth it. Green fuel runs out of gas5 The cost of converting a car to run on liquefied petroleum gas (LPG) is about £1,500 in the UK, towards which a government grant would contribute about £700. From September 1 2004, LPG will on average cost 40.7p per litre, compared with 79.1p for ordinary unleaded petrol. However, LPG cars usually have slightly worse fuel consumption, losing about 13% in terms of miles...
Case Study 5 Waleed Company Ltd. is a wholesaler of building and hardware materials in Muscat....
Case Study 5 Waleed Company Ltd. is a wholesaler of building and hardware materials in Muscat. Company furnished the following information to measure its performance by using different ratios for the year 2019: - Company started its business with share capital and debts of RO 1,789,000 consisting of 558,000 shares of RO 2.500 each and bonds payable RO 394,000. Company’s assets including building worth RO 125,000, machinery worth RO 135,000, cash available in the office RO 62,500 and at bank...
Case Study: Trump De Tomato Ltd (TDT) is a company in aquacultural industry specialised in farming...
Case Study: Trump De Tomato Ltd (TDT) is a company in aquacultural industry specialised in farming of aquatic organisms. TDT is considering opening a new farm in Sandy Bay. This project would involve the purchase of 13 hectares land at a price of $1,000,000 (Note that: The land is not subject to depreciation for accounting and tax purposes). In addition to that, the company will need to purchase eight special equiments which cost $125,000 each. The equipments are expected to...
Case study 1 Janine works as palliative care nurse at a regional health facility and relates...
Case study 1 Janine works as palliative care nurse at a regional health facility and relates the following conundrum. Janine describes looking after Jack who recently returned to the palliative care service after a further unexpected exacerbation of his respiratory lung cancer. Jack is rapidly deteriorating with little tolerance for any activity and cannot undertake any activities of daily living. Shirley, his wife is constantly at his side offering as much support as possible. Jack is highly dependent and has...
Do a case study of Northeastern Airlines. Northeastern Airlines is a regional airline serving nine cities...
Do a case study of Northeastern Airlines. Northeastern Airlines is a regional airline serving nine cities in the New England states as well as cities in New York, New Jersey, and Pennsylvania. While nonstop flights are available for some of the routes, connecting flights are often necessary. Northeastern Airlines Service Area The network shows the cities served and profit in U.S. dollars per passenger along each of these routes. The routes from ?Boston-to-Providence and from Providence-to-Boston make only $ 9...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT