1 of 69

COMPUTER SECURITY�����INDIVIDUAL FINAL ASSESSMENT����BY,�80002365 – AROSHA SILVA���

1

This Photo by Unknown Author is licensed under CC BY-SA-NC

2 of 69

2

3 of 69

INTRODUCTION

Safe Drive Automobiles (SDA), 

  1. A rapidly growing market leader,
  2.  Relies heavily on its digital systems to drive business, resulting in a substantial digital footprint. 
  3. Recently faced a Triple Extortion attack,
  4. Seeks immediate and strategic overhaul to protect valuable customer data

3

4 of 69

OVERVIEW

4

Detailed examination of high-risk deficiencies, including outdated Operating Systems, weak authentication protocols (MD4), and poor data handling practices.

Review on how to reduce risks and benefits that can be gained.

5 of 69

CRITICAL SECURITY FLAWS

  1. Default and outdated OS.
  2. Poor Password Policies.
  3. Weak Authentication Standards.
  4. Unsecure Cryptographic Hashing.
  5. Deficient Data Disposal
  6. Environmental deficiencies and physical security.

5

6 of 69

DEFAULT AND OUTDATED OS.

“Support for Windows 10 ended on 14 October 2025. Microsoft no longer provides software updates, security fixes, or technical assistance to Windows 10” - (Microsoft, 2025).

6

1.

7 of 69

1. DEFAULT AND OUTDATED OPERATING SYSTEMS.

Software updates involve much more than merely enhancing functionality or fixing minor glitches” (Bist and Vinay, 2025)

  • According to a survey conducted by TechTarget (2025), “32% of cyberattacks exploit unpatched software vulnerabilities”

7

Outdated systems: According to Microsoft (2022), the main reason that an outdated system pose security issues is that they will no longer receive security updates.

Default system configurations: "Leaving factory default configurations enabled can create exploitable vulnerabilities for attackers (CISA, 2022)."

8 of 69

This table illustrates the rising number of CVEs and the persistent exploitation of known vulnerabilities,

reinforcing the critical need for timely updates as a foundational element of cyber security.

8

9 of 69

CIA TRIAD IMPACTS

9

Confidentiality: Allows attackers to easily steal sensitive data (Microsoft, CISA).

Integrity: Unprotected from business records and customer data alterations (NIST, SANS).

Availability: Risk of unavailability/unreadability of data due to data encryption

(CISA, CIS).

"According to Microsoft (2024), an unsupported OS means that 'every device running on that unsupported platform becomes an open door to attackers.”

According to cvedetails (2025), there are over 20 known vulnerabilities in Windows 10.

10 of 69

SOLUTIONS – OUTDATED OPERATING SYSTEM

  1. Backup all the data (ADAPT IT, 2025).
    1. Recommended strategy: Incremental Backup.
  2. Upgrade Windows to the latest version.

2.1. Current release: Windows 11 Enterprise, version 25H2 (Microsoft, 2025).

  • Use Anti-virus protections that provide multilayered protection designed to prevent and neutralize malware, ransomware, unauthorized access, and hijacking (Kaspersky, n.d.,).
  • Enable or increase logging and monitoring of legacy IT

10

- Software that is no longer supported by the vendor or in-house -

11 of 69

SOLUTIONS – CONFIG. DEFAULT SETTINGS

  1. Control: ISM-0383; Revision: 11; Updated: Jun-25; Applicable: NC, OS, P, S, TS; Essential 8: N/ADefault user accounts or credentials for operating systems, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
  2. Control: ISM-0341; Revision: 4; Updated: Dec-21; Applicable: NC, OS, P, S, TS; Essential 8: N/AAutomatic execution features for removable media are disabled.
  3. Control: ISM-1250; Revision: 3; Updated: Dec-24; Applicable: NC, OS, P, S, TS; Essential 8: N/AThe user accounts under which server applications run have limited access to their underlying server’s file system.
  4. Control: ISM-1584; Revision: 1; Updated: Sep-21; Applicable: NC, OS, P, S, TS; Essential 8: N/AUnprivileged users are prevented from bypassing, disabling or modifying security functionality of operating systems.
  5. Control: ISM-1592; Revision: 2; Updated: Jun-25; Applicable: NC, OS, P, S, TS; Essential 8: N/AUnprivileged users do not have the ability to install unapproved applications, rom bypassing, disabling or modifying security functionality of operating systems.

11

12 of 69

BENEFITS

12

Customer and Business data protection: Help make sure deployment of updates and patches is timely, safe, and efficient with Windows Autopatch (Microsoft, 2025).

Comprehensive device and app management (Microsoft, n.d.)

- Microsoft Intune: cloud-based UEM Service to protect data on BYOD policy.

Access to modern productivity tools: Voice typing, snap layout and groups, Copilot integration (Microsoft, 2025).

Accelerate business success with AI: Copilot (Microsoft, 2025).

Increased brand reputation and customer trust.

13 of 69

WEAK PASSWORD POLICIES

"Security is always a chain, and it is only as strong as its weakest link. A weak password policy is a broken link."

Bruce Schneier,

Security Expert and Cryptographer

13

2.

14 of 69

IDENTIFIED WEAK PASSWORD POLICIES

14

Current password policy :

Minimum of 5 characters.

Mandatory requirement of having one special character.

No additional rules such as case characters.

15 of 69

15

  1. According to the Office of the Australian Information Commissioner’s (OAIC) Notifiable Data Breaches Report: January to June 2024, cyber security incidents involving compromised credentials made up 63% of all breaches during this period.
  • Week combinations for the password.

16 of 69

CIA TRIAD IMPACTS

16

Confidentiality: allows unauthorized individuals to easily access data

(Microsoft, 2019; NIST SP 800-63B).

Integrity: Easy and direct access to alter and delete data (CISA, OWASP).

Availability: makes data less authentic or unavailable or lock the account

(CISA & MS-ISAC, CIS).

17 of 69

SOLUTIONS

17

18 of 69

WHAT MAKES PASSWORD STRONG?

18

Specific password requirements for user accounts and privileged accounts:

    • Minimum length requirement:
      1. 12+ for standard users.
      2. 14+ for privileged users.
    • Setting the user account to be locked after a maximum of five unsuccessful password attempts
    • Ensuring all successful and unsuccessful password log in events are centrally logged.
    • Avoid reusing same and common passwords.

19 of 69

19

(BitWarden.com - Orenstein, 2025)

“Password length is a primary factor in characterizing password strength” (Orenstein, 2025).

The four-character sets are:

  1. Numerical characters such as 12345.
  2. Lowercase letters such as abcde.
  3. Uppercase letters such as ABCDE.
  4. Special characters such as !$%&?.

20 of 69

BENEFITS

20

  1. Dramatic Reduction in Account Compromise thus prevents data leakage (Techbrain.com.au - Alex, 2025) .
  2. Availability of data and systems as needed (ACSC, 2024).
  3. Enhanced Compliance and Legal Protection such as,
    1. AUS GOVT Information Security Manual (ISM)
    2. Security of Critical Infrastructure Act requirements
    3. Privacy Act 1988 (APP 11) : “Organizations must take "reasonable steps" to protect personal information”.

21 of 69

WEAK AUTHENTICATION STANDARDS

“Amateurs hack systems; professionals hack people.”

Bruce Schneier,

Security Expert and Cryptographer

21

3.

 "You can have the strongest castle walls in the world, but it doesn't matter if you leave the key under the doormat.”- Common Cybersecurity Aphorism / Folk Wisdom

22 of 69

IDENTIFIED AUTHENTICATION ISSUES

22

Current Authentication practices :

Use of Single factor Authentication method.

Use of a password for Authentication.

23 of 69

CIA TRIAD IMPACTS

23

Confidentiality: stolen credential grants attacker unrestricted access (NIST SP 800-53).

Integrity: no barriers to protect data manipulation(PCI DSS),(NIST SP 800-53).

Availability: prone to ransomware and service disruption(ACSC,2022), (NIST SP 800-53).

“They might manage to steal one proof of identity such as your PIN, but they still need to obtain and use the other proofs of identity to access your account”

(ASD, n.d.).

24 of 69

HOW TO MITIGATE THE ISSUE?

24

Key recommendations for Australian businesses in 2025:

    • Mandate MFA methods:
      1. Something a user knows (such as a password or PIN).
      2. Something a user has (such as a specific hardened device).
      3. Something a user is (such as biometric trait, for example a fingerprint).

    • User training and awareness.

- Educates staff to recognize phishing and the importance of the second factor.

25 of 69

25

(Microsoft, asd.gov.au, NIST)

26 of 69

2. Single Factor Authentication.

26

- BATOI

27 of 69

SFA - VS - MFA

27

28 of 69

BENIFITS

28

  1. Makes it harder for cybercriminals to take over your account, by adding extra layers of protection thus highly phishing resistance (Australian Signals Directorate, n.d).
  2. Strengthens Data Protection and Regulatory Compliance.
    1. Notifiable Data Breaches (NDB) scheme: Requires organizations to notify individuals and the OAIC if a data breach is "likely to result in serious harm”.
    2. Privacy Act 1988 (APP 11) : “Organizations must take "reasonable steps" to protect personal information”.
  3. Reduces Employee Password Management Burden (ACSC, 2022).
  4. Protection Against Credential Stuffing Attacks (Cloudflare, Inc., n.d.).

29 of 69

UNSECURE CRYPTOGRAPHIC HASHING

ISSUE:

The application stores user passwords in a database using the Message Digest 4 (MD4) cryptographic hash function”.

29

4.

30 of 69

UNSECURE PROTOCOL

30

  • "If you collect it, you must protect it. If you cannot protect it, do not collect it."�
  • Common Privacy & Security Mantra

31 of 69

UNSECURE PROTOCOL

31

Why use of MD4 is not recommended?

  • MD4 is practically broken in 1995.

- Hans Dobbertin discovered the first full-round MD4 collision attack in 1995 (Sadeghi-Nasab & Rafe, n.d.).

  • Use of MD4 considered as a Digital negligence.

- susceptibility to collision attacks, where two different inputs produce the same hash output. (mojoauth, n.d.).

32 of 69

CIA TRIAD IMPACTS

32

Confidentiality: reverse engineering hashed passwords grants access to password protected data (NIST SP 800-63B, Sec 5.1.1.2).

Integrity: can no longer trust who is making changes

(Stickney, 2025).

Availability: creates a pathway for complete system takeover through credential harvesting, leading to service disruption. (OWASP, n.d.).

33 of 69

SOLUTIONS

33

1. Argon2id: designed to be both CPU and GPU hard, making it extremely resistance to specialized hardware attacks (Biryukov, A., Dinu, D., & Khovratovich, D, 2017).

2. BCRYPT: Best alternative to argon2id. Thanks to its adaptability and flexibility we can increase its iteration count to counter fast hardware (Provos, N., & Mazières, D. (1999).

3. SCRYPT: Designed to be memory hard.

-Requiring large amounts of RAM for computation, making parallelization with Asics/GPUs economically infeasible (Percival, C., 2009).

NIST SP 800-63B, Sec 5.1.1.2 explicitly warns against using fast, general-purpose hashes for passwords.

34 of 69

34

35 of 69

BENIFITS

35

Automatic salting: increased account protection.

Regulatory compliance: Security of Critical Infrastructure Act requirements : Data storage or processing

Reduced liability and cost.

Customer trust and confidence.

36 of 69

DEFICIENT DATA DISPOSAL

ISSUE:

“The company disposes storage devices with data being deleted using software with a single pass”.

36

5.

37 of 69

37

THE RISKS OF LEFTOVER DATA:

A RECOVERY STUDY

“We purchased six computers over the e-commerce platform eBay in the U.K. We bought a mix of personal and what appeared to be previous work devices. Focusing on those where there was no statement about them being securely wiped”

“It is also worth noting that the data was captured using software that is available to anyone with the right knowledge highlighting its vulnerability to fraudsters and other malicious actors with moderate forensics skills”

(Alvarez & Marsal holdings, 2022)

Keywords: invoice, court, bailiff, applicant.

  • Images of building identification cards, salaries of employees, invoices and other internal business correspondence.

38 of 69

CIA TRIAD IMPACTS

38

Confidentiality: recoverability of data deleted in single pass makesdata accessible to unauthorized persons (ACSC, 2023),

(IEEE Security & Privacy, 1(1), 17-27).

Integrity: Recovered data cannot be trusted as authentic, as it may have been altered (NIST Special Publication 800-88 Rev. 1).

Availability: Data is unavailable for legitimate use but remains available to threats, causing operational disruption

(Verizon, 2023).

According to Verizon's 2023 Data Breach Investigations Report (DBIR), which analyzed 16,312 security incidents, 15% of all breaches involved physical assets.

39 of 69

“Take reasonable steps to destroy or permanently de-identify personal information that is no longer needed”.

Privacy Act 1988 & APP 11’

39

40 of 69

SOLUTIONS

40

  1. Adapt secure destruction methods: (Wesupply labs, n.D.)
  2. - Digital: overwriting, cryptographic erasure, or wiping with dod-grade software.
  3. - Physical: degaussing, shredding, or pulverizing hard drives and storage media..
  4. Partner with accredited destruction services (Commonwealth procurement rules ,2023).

- Providers with National Association for Info. Destruction AAA or RS certifications.

- Always ask for a certificate of destruction (cod).

  1. Train employees. (Wesupply labs, n.D.)

- Conduct regular workshops on proper data handling and device disposal.

- Emphasize that improper data destruction can expose organizations to internal security threats.

3)

2)

41 of 69

BENIFITS

41

1. Controlled data leakages.

-”Ensures that sensitive data does not fall into the wrong hands” (Recycle IT, 2024).

2. Financial and legal benefits (ACCC, 2022).

  1. Reputational & Trust Benefits.

- According to a PwC survey, 87% of consumers will take their business elsewhere if they don’t trust a company with their data.

42 of 69

Environmental deficiencies and physical security.

“A breach alone is not a disaster, but mishandling it is.” 

– Serene Davis

Global Head of Cyber for QBE Insurance

42

6.

43 of 69

ISSUE

  1. No physical security mechanism exists to safeguard the SDA's IT systems (end devices and servers).
  2. Employees can enter the SDA's server room and access the servers, switches, routers, etc.
  3. Regular power surges.

43

44 of 69

ISSUE

  1. PROTECT-14: Physical access to systems, supporting infrastructure and facilities is restricted to authorised personnel (ASD , 2024).
  2. Control: ISM-0225; Revision: 3; Updated: Sep-21; Applicable: S, TS; Essential 8: N/AUnauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas.
  3. Control: ISM-2070; Revision: 0; Updated: Sep-25; Applicable: S, TS; Essential 8: N/AUnauthorised photographic and video recording devices are not brought into SECRET and TOP SECRET areas.
  4. Control: ISM-0164; Revision: 3; Updated: Dec-21; Applicable: NC, OS, P, S, TS; Essential 8: N/AUnauthorised people are prevented from observing systems, in particular workstation displays and keyboards, within facilities.

44

45 of 69

CIA TRIAD IMPACTS

45

Confidentiality: Unauthorized access to Information via access to servers (NIST.SP.1800-28).

Integrity: Physical access allows for direct, undetectable tampering (ISBB, n.d.).

Availability: Operations are highly unreliable, leading to frequent operational disruption (NIST.SP.1800-28).

According to the 2023 Verizon Data Breach Investigations Report (DBIR)19% of all breaches involved internal actors

46 of 69

SOLUTIONS ForPOWER BLACKOUT

46

  • Use of hybrid Solar systems

- providing uninterrupted power during blackouts and protect devices + massive cost savings (SEO, 2025).

  • Emergency Backup Generators

- “Emergency backup generators continue to work even during power failures.” (Google, n.d.).

47 of 69

SOLUTIONS - PHYSICAL ACCESS

47

  1. Authorization is required to everyone who enters server and equipment rooms (Google, n.d.), (The Tool Belt, 2025).
  2. Keys or equivalent access mechanisms to server rooms, communications rooms and security containers are appropriately controlled. (Control: ISM-1074; Revision: 4; Updated: Dec-24; Applicable: NC, OS, P, S, TS; Essential 8: N/A).
  3. Security measures are used to detect and respond to unauthorized RF devices (Control: ISM-0829; Revision: 4; Updated: Mar-19; Applicable: S, TS; Essential 8: N/A).
  4. Ensuring systems, in particular workstation displays and keyboards, are not visible through windows, such as via the use of blinds, curtains, privacy films or workstation positioning (Control: ISM-0164; Revision: 3; Updated: Dec-21; Applicable: NC, OS, P, S, TS; Essential 8: N/A)

48 of 69

BENIFITS

48

Confidentiality, and Integrity is physically protected: decreased risk of losses from theft and vandalism.

Availability is guaranteed by a stable environment.

Prevents damage and additional costs to equipment and its data

Meets industry standards: aligned with Australian Work Health Safety (WHS) principles.

49 of 69

CONCLUSION

49

Modern Operating Systems deliver productivity gains through new tools and critical security through continuous updates.

Strong Passwords + MFA form an essential barrier, stopping unauthorized access even if credentials are stolen

Modern Cryptography ensures that breached data remains unreadable, protecting customer information at its core.

Secure Data Disposal & Physical Access Control prevent data leaks from discarded assets and unauthorized entry, securing the business's future.

50 of 69

REFERENCES - 1) USE OF OUTDATED OS / WINDOWS 21H1/21H2

50

  1. Cybersecurity and Infrastructure Security Agency. (n.d.). Weak configurationshttps://www.cisa.gov/secure-our-world/weak-configurations
  2. Cybersecurity and Infrastructure Security Agency. (2022). *Alert AA22-137A: Weak security configurations*. https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-137a
  3. Microsoft. (n.d.). Windows 10 21H1 end of servicing. Microsoft Learn. https://learn.microsoft.com/en-us/lifecycle/announcements/windows-10-21h1-end-of-servicing
  4. Microsoft. (n.d.). Windows 11 version 25H2 update history. Support. https://support.microsoft.com/en-us/topic/windows-11-version-25h2-update-history-99c7f493-df2a-4832-bd2d-6706baa0dec0
  5. Microsoft. (n.d.). Windows release health: Release information. Microsoft Learn. https://learn.microsoft.com/en-us/windows/release-health/release-information
  6. Australian Cyber Security Centre. (2021, October 6). Secure administration. https://www.cyber.gov.au/business-government/protecting-devices-systems/system-administration/secure-administration cyber.gov.au

51 of 69

51

  1. Center for Internet Security. (n.d.). CIS Benchmarkshttps://www.cisecurity.org/cis-benchmarks
  2. Cybersecurity and Infrastructure Security Agency. (n.d.). Stop Ransomware campaignhttps://www.cisa.gov/stopransomware
  3. FCN Austin. (2021). Version 21H1 Windows 10https://www.fcnaustin.com/version-21h1-windows-10/
  4. Microsoft. (n.d.). Why end-of-service is a business risk. Windows Business. https://www.microsoft.com/en-us/windows/business/knowledge-center/why-end-of-service-is-a-business-risk
  5. National Institute of Standards and Technology. (2013). *SI-2 Flaw remediation* (SP 800-53 Rev. 4). https://nvd.nist.gov/800-53/Rev4/control/SI-2
  6. SANS Institute. (2023). The importance of patchinghttps://www.sans.org/blog/the-importance-of-patching/
  7. Microsoft. (n.d.). End of support — Windows. https://www.microsoft.com/en-gb/windows/end-of-support?r=1#:~:text=Windows%2010%20end%20of%20support&text=What%20is%20Windows%2010%20end,Learn%20more. Microsoft

REFERENCES – 1.2) USE OF OUTDATED OS / WINDOWS 21H1/21H2

52 of 69

REFERENCES – 1.3) USE OF OUTDATED OS / WINDOWS 21H1/21H2

52

  1. CVE Details. (n.d.). CVE security databasehttps://www.cvedetails.com/
  2. Fernando, T. (2024). The hidden dangers of outdated software: A cyber security perspective. ResearchGate. https://www.researchgate.net/publication/391910669_The_Hidden_Dangers_of_Outdated_Software_A_Cyber_Security_Perspective
  3. Kaspersky. (n.d.). Anti-ransomware toolhttps://www.kaspersky.com/anti-ransomware-tool
  4. Microsoft. (2025, September 30). How to get the Windows 11 2025 update. Windows Experience Blog. https://blogs.windows.com/windowsexperience/2025/09/30/how-to-get-the-windows-11-2025-update/
  5. Microsoft. (n.d.). Back up and restore with Windows Backup. Support. https://support.microsoft.com/en-us/windows/back-up-and-restore-with-windows-backup-87a81f8a-78fa-456e-b521-ac0560e32338
  6. Microsoft. (2025). Windows 11 download. Microsoft. https://www.microsoft.com/en-us/software-download/windows11
  7. Adept IT Solutions. (2025, January 31). Why backup solutions are extremely important for businesses. https://www.adept-it.com.au/2025/01/31/importance-of-backup-solutions/

53 of 69

REFERENCES – 1.4) USE OF OUTDATED OS / WINDOWS 21H1/21H2

53

  1. Microsoft. (n.d.). Cloud endpoints. Microsoft 365. https://www.microsoft.com/en-us/microsoft-365/enterprise/cloud-endpoints
  2. Microsoft. (n.d.). Evaluate Windows 11 Enterprise. Microsoft Evaluation Center. https://www.microsoft.com/en-us/evalcenter/evaluate-windows-11-enterprise
  3. Microsoft. (n.d.). Microsoft Intunehttps://www.microsoft.com/en-us/security/business/microsoft-intune
  4. Microsoft. (n.d.). Windows 11 Pro FAQhttps://www.microsoft.com/en-us/windows/business/windows-11-pro#faqs

54 of 69

REFERENCES - 2–3) WEAK PASSWORDS & AUTHENTICATION STANDARDS�

54

  1. Batoi. (2022). Single factor vs multi-factor authenticationhttps://www.batoi.com/blogs/developers/single-factor-vs-multi-factor-authentication-impact-account-security-6331ac82f3dbc4
  2. Government of South Australia. (2022). SACSF Guideline 10 – Password managementhttps://www.security.sa.gov.au/documents/documents/SACSF-Guideline-10-Password-Management.pdf
  3. Hive Systems. (2023). Are your passwords in the green? https://www.hivesystems.com/blog/are-your-passwords-in-the-green
  4. StrongDM. (2023). Authentication vulnerabilitieshttps://www.strongdm.com/blog/authentication-vulnerabilities
  5. TechBrain. (2023). Enterprise password policyhttps://www.techbrain.com.au/enterprise-password-policy/
  6. Microsoft. (2019, August 20). One simple action you can take to prevent 99.9% of account attacks. Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/

55 of 69

REFERENCES - 2–3.2) WEAK PASSWORDS & AUTHENTICATION STANDARDS�

55

  1. Australian Cyber Security Centre. (n.d.). Essential eight explainedhttps://www.cyber.gov.au/acsc/view-all-content/essential-eight/essential-eight-explained
  2. Australian Signals Directorate. (n.d.). Australian Signals Directorate frameworkhttps://www.asd.gov.au/
  3. Cybersecurity and Infrastructure Security Agency. (n.d.). Stop ransomwarehttps://www.cisa.gov/stopransomware
  4. National Institute of Standards and Technology. (2017). Digital identity guidelines (SP 800-63B). https://pages.nist.gov/800-63-3/sp800-63b.html
  5. OWASP Foundation. (2023). Authentication cheat sheethttps://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html
  6. Cloudflare, Inc. (n.d.). What is credential stuffing? https://www.cloudflare.com/learning/bots/what-is-credential-stuffing/
  7. Cybersecurity and Infrastructure Security Agency. (2021). Ransomware guide S508Chttps://www.cisa.gov/sites/default/files/publications/CISA-Multi-State-Informational-Ransomware-Guide-S508C.pdf

56 of 69

REFERENCES - 2–3.3) WEAK PASSWORDS & AUTHENTICATION STANDARDS�

56

  1. Microsoft. (n.d.). Evaluate Windows 11 Enterprise. https://www.microsoft.com/en-us/evalcenter/evaluate-windows-11-enterprise
  2. Microsoft. (n.d.). Microsoft Intune. https://www.microsoft.com/en-us/security/business/microsoft-intune
  3. Microsoft. (n.d.). Windows 11 Pro for business. https://www.microsoft.com/en-us/windows/business/windows-11-pro
  4. Australian Prudential Regulation Authority. (2019). Prudential standard CPS 234: Information security. https://www.apra.gov.au/sites/default/files/cps_234_july_2019_for_public_release.pdf
  5. Australian Cyber Security Centre. (2024). Information security manual (December 2024). https://www.cyber.gov.au/sites/default/files/2024-12/Information%20Security%20Manual%20%28December%202024%29.pdf
  6. Cyber and Infrastructure Security Centre. (2018). Security of Critical Infrastructure Act 2018. https://www.cisc.gov.au/legislation-regulation-and-compliance/soci-act-2018

57 of 69

REFERENCES - 2–3.4) WEAK PASSWORDS & AUTHENTICATION STANDARDS�

57

  1. Australian Cyber Security Centre. (n.d.). Essential eight maturity model FAQhttps://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model-faq
  2. Center for Internet Security. (2021). CIS Controls v8https://www.cisecurity.org/controls/v8
  3. National Institute of Standards and Technology. (2020). Digital identity guidelines: Authentication and lifecycle management (NIST Special Publication 800-63B). https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-63b.pdf
  4. PBS. (2002). Interview with Bruce Schneier. Frontline. https://www.pbs.org/wgbh/pages/frontline/shows/hackers/interviews/schneier.html
  5. Australian Signals Directorate. (n.d.). Authentication. ASD's Blueprint for Secure Cloud. https://blueprint.asd.gov.au/design/platform/identity/authentication/
  6. Microsoft. (n.d.). Cloud endpoints. https://www.microsoft.com/en-us/microsoft-365/enterprise/cloud-endpoints

58 of 69

REFERENCES - 2–3.5) WEAK PASSWORDS & AUTHENTICATION STANDARDS�

58

  1. DemandSage. (2024). Password statisticshttps://www.demandsage.com/password-statistics/
  2. National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53 Revision 5). https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf
  3. Office of the Australian Information Commissioner. (2023). Security of personal information (APP 11)https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information
  4. PCIVault. (2024). PCI vault compliance resourceshttps://pcivault.io/
  5. Australian Cyber Security Centre. (n.d.). Practical cyber security tips for business leaders. https://www.cyber.gov.au/business-government/protecting-business-leaders/cyber-security-for-business-leaders/practical-cyber-security-tips-for-business-leaders

59 of 69

REFERENCES - 2–3.6) WEAK PASSWORDS & AUTHENTICATION STANDARDS�

59

  1. Office of the Australian Information Commissioner. (2024). Notifiable Data Breaches Report: January to June 2024https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-january-to-june-2024
  2. Ping Identity. (n.d.). Single-factor, two-factor, and multi-factor authenticationhttps://www.pingidentity.com/en/resources/identity-fundamentals/authentication/single-factor-two-factor-multi-factor-authentication.html
  3. National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53 Revision 5). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
  4. PCI Security Standards Council. (2022). Payment Card Industry Data Security Standard: Requirements and security assessment procedures (Version 4.0). https://listings.pcisecuritystandards.org/documents/PCIDSS_QRGv3_1.pdf
  5. Google. (n.d.). Passkeys overviewhttps://developers.google.com/identity/passkeys
  6. Microsoft. (n.d.-a). Register a passkey for passwordless authentication. Microsoft Learn. https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-register-passkey-authenticator?tabs=iOS

60 of 69

REFERENCES - 4) MD4 HASHING��

60

  1. EITCA. (2023). [Differences between MD4, MD5, SHA-1, and SHA-2]. https://eitca.org/
  2. Stevens, M., Bursztein, E., Karpman, P., Albertini, A., & Markov, Y. (2017). [The SHAttered attack: First practical SHA-1 collision]. https://shattered.io/
  3. OWASP Foundation. (n.d.). [Password storage cheat sheet]. https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
  4. GeeksforGeeks. (2023). *What is salted password hashing?* https://www.geeksforgeeks.org/ethical-hacking/what-is-salted-password-hashing/
  5. Wikipedia contributors. (n.d.). [MD4 hashing diagram] [image]. Retrieved November 2025, from https://upload.wikimedia.org/wikipedia/commons/thumb/1/1a/MD4.svg/330px-MD4.svg.png
  6. Massachusetts Institute of Technology, LCS. (2018). What is “Just My Code”? A study of debugging mental models (MIT-LCS-TM-434). https://dspace.mit.edu/bitstream/handle/1721.1/149165/MIT-LCS-TM-434.pdf?sequence=1
  7. SuperTokens. (2024, August 28). Password hashing & salting: A definitive guidehttps://supertokens.com/blog/password-hashing-salting

61 of 69

REFERENCES – 4.2) MD4 HASHING��

61

  1. Verizon. (2023). 2023 Data Breach Investigations Report. Retrieved November 2025, from https://www.verizon.com/business/resources/reports/2023-data-breach-investigations-report-dbir.pdf
  2. National Institute of Standards and Technology. (2019). Transitions: Recommendation for transitioning the use of cryptographic algorithms and key lengths (NIST Special Publication 800-131A Revision 2). U.S. Department of Commerce. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf
  3. Turner, S., & Chen, L. (2011). MD4 to historic status (RFC 6150). Internet Engineering Task Force. https://datatracker.ietf.org/doc/html/rfc6150
  4. Wang, X., Lai, X., Feng, D., Chen, H., & Yu, X. (2005). Cryptanalysis of the hash functions MD4 and RIPEMD. In R. Cramer (Ed.), Advances in cryptology – EUROCRYPT 2005 (pp. 1-18). Springer. https://doi.org/10.1007/11426639_1
  5. Bureau, F. T., & Microsoft. (2012). Analysis of the Flame Malware's MD5 collision attack. Microsoft Corporation. Retrieved November 2025, from https://www.microsoft.com/en-us/security/blog/2012/06/06/flame-malware-md5-collision-attack-analysis/

62 of 69

REFERENCES – 4.3) MD4 HASHING��

62

  1. Biryukov, A., Dinu, D., & Khovratovich, D. (2017). *Argon2: The memory-hard function for password hashing and other applications* (RFC 9106). Internet Engineering Task Force. https://datatracker.ietf.org/doc/html/rfc9106
  2. National Institute of Standards and Technology. (2019). Transitions: Recommendation for transitioning the use of cryptographic algorithms and key lengths (NIST Special Publication 800-131A Revision 2). U.S. Department of Commerce. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf
  3. OWASP. (2023). Password storage cheat sheethttps://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
  4. Percival, C. (2009). Stronger key derivation via sequential memory-hard functionshttps://www.tarsnap.com/scrypt/scrypt.pdf
  5. Provos, N., & Mazières, D. (1999). A future-adaptable password scheme. In Proceedings of the USENIX annual technical conference (pp. 1–12). USENIX Association. https://www.usenix.org/legacy/events/usenix99/provos/provos.pdf

63 of 69

REFERENCES – 4.3) MD4 HASHING��

63

  1. Sadeghi-nasab, A., & Rafe, V. (N.D.). [A comprehensive review on broken hashing algorithms]. Goldsmiths research online. Https://eprints-gro.Gold.Ac.Uk/id/eprint/33410/1/paper_en_v1.Pdf
  2. Mojoauth. (N.D.). Md4 in nim. Https://mojoauth.Com/hashing/md4-in-nim/
  3. Stickney, J. (2021, july 18). Hashing & integrity — the “I” in the CIA triad. Medium. Https://jacob-e-stickney.Medium.Com/hashing-integrity-the-i-in-the-cia-triad-98b722b6fe39

64 of 69

REFERENCES - 5) DEFICIENT DATA DISPOSAL���

64

  1. Cybersecurity Intelligence. (2023). The dangers of inadequate data disposalhttps://www.cybersecurityintelligence.com/blog/the-dangers-of-inadequate-data-disposal-6569.html
  2. Verizon. (2023). 2023 Data breach investigations reporthttps://www.verizon.com/business/resources/reports/2023-data-breach-investigations-report-dbir.pdf
  3. WeSupply Labs. (2024). What are the risks of incomplete data destruction? https://wesupplylabs.com/what-are-the-risks-of-incomplete-data-destruction/
  4. National Institute of Standards and Technology. (2014). NIST special publication 800-88 revision 1: Guidelines for media sanitization. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf
  5. Australian Cyber Security Centre. (n.d.). Secure destruction of ICT equipment. https://www.cyber.gov.au/acsc/view-all-content/publications/secure-destruction-ict-equipment
  6. Office of the Australian Information Commissioner. (n.d.). Data breach preparation and response. https://www.oaic.gov.au/privacy/guidance-and-advice/data-breach-preparation-and-response
  7. National Archives of Australia. (n.d.). Information disposal. https://www.naa.gov.au/information-management/disposing-information/information-disposal

65 of 69

REFERENCES – 5.2) DEFICIENT DATA DISPOSAL���

65

  1. Alvarez & Marsal. (2022, September). Forensically analysed PCs report: Data disposal risk analysishttps://www.alvarezandmarsal.com/sites/default/files/2022-09/Forensically%20analysed%20PCs%20Report.pdf
  2. Australian Cyber Security Centre. (2023). Secure destruction of ICT equipment and mediahttps://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/secure-destruction-ict-equipment-and-media
  3. Office of the Australian Information Commissioner. (2023). APP 11 — Security of personal informationhttps://www.oaic.gov.au/privacy/australian-privacy-principles/app-11-security-of-personal-information
  4. Australian Government Department of Defence. (2022). Information Security Manual (ISM)https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism
  5. Australian Cyber Security Centre. (2023). Secure destruction of ICT equipment and mediahttps://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/secure-destruction-ict-equipment-and-media

66 of 69

REFERENCES – 5.3) DEFICIENT DATA DISPOSAL���

66

  1. Garfinkel, S., & Shelat, A. (2003). Remembrance of data passed: A study of disk sanitization practices. IEEE Security & Privacy, 1(1), 17–27. https://doi.org/10.1109/MSECP.2003.1176992
  2. National Institute of Standards and Technology. (2014). Guidelines for media sanitization (NIST SP 800-88 Rev. 1). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf
  3. Office of the Australian Information Commissioner. (2023). APP 11 — Security of personal informationhttps://www.oaic.gov.au/privacy/australian-privacy-principles/app-11-security-of-personal-information
  4. Verizon. (2023). 2023 Data breach investigations reporthttps://www.verizon.com/business/resources/reports/dbir/
  5. Dell Technologies. (n.d.). Data removal processes for a solid-state hard drive. https://www.dell.com/support/kbdoc/en-lk/000150908/data-removal-processes-for-a-solid-state-hard-drive
  6. Recycle IT Australia. (n.d.). IT asset disposal. https://recycle-it.com.au/it-asset-disposal/

67 of 69

REFERENCES - 6) ENVIRONMENTAL DEFICIENCIES & PHYSICAL SECURITY����

67

  1. Ace Cloud Hosting. (2023). Cybersecurity quoteshttps://www.acecloudhosting.com/blog/cybersecurity-quotes/
  2. AstrodyneTDI. (2023). Applications for uninterruptible power supplieshttps://www.astrodynetdi.com/blog/5-applications-for-uninterruptible-power-supplies
  3. Generac. (n.d.). Healthcare power solutionshttps://www.generac.com/industrial/industry-expertise/healthcare/
  4. Google. (n.d.). Advancing security in data centershttps://datacenters.google/advancing-security/
  5. Google. (n.d.). Operating sustainably in data centershttps://datacenters.google/operating-sustainably/
  6. The Toolbelt. (n.d.). How an access control system can benefit your Australian business. https://thetoolbelt.com.au/how-an-access-control-system-can-benefit-your-australian-business/
  7. Safe Work Australia. (2023). WHS principles fact sheet: Principle 3 (May 2023). https://www.safeworkaustralia.gov.au/sites/default/files/2023-05/whs-principles-factsheets_principle3_may2023-0.pdf
  8. Australian Cyber Security Centre. (n.d.). Guidelines for physical security. https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-physical-security

68 of 69

REFERENCES – 6.2) ENVIRONMENTAL DEFICIENCIES & PHYSICAL SECURITY����

68

  1. Australian Cyber Security Centre. (n.d.). Secure your premises and equipment. https://www.cyber.gov.au/acsc/view-all-content/advice/secure-your-premises-and-equipment
  2. SGS. (2024, November). How ISO 31000:2018 can help reduce insurance costs. https://www.sgs.com/en-id/news/2024/11/how-iso-31000-2018-can-help-reduce-insurance-costs
  3. GeeksforGeeks. (n.d.). The CIA triad in cryptography. https://www.geeksforgeeks.org/the-cia-triad-in-cryptography/
  4. Information Systems for Business and Beyond. (n.d.). Chapter 6: Information systems security. https://ecampusontario.pressbooks.pub/businfosystems/chapter/chapter-6-information-systems-security/
  5. Freedom Energy Solutions. (n.d.). Hybrid solar systems explained: How they keep you powered 24/7. https://freedomenergysolutions.com.au/hybrid-solar-systems-explained-how-they-keep-you-powered-24-7/
  6. Australian Cyber Security Centre. (n.d.). Guidelines for physical security. https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-physical-security

69 of 69

MUCH OBLIGED!

To dear teacher:

Ms. Thanuja Irugalbandara

BY:

K.C AROSHA SILVA

8002365

80002365@learn.acbt.lk