Skip to main content
Case Study Undergraduate 1,224 words

Enterprise Security Management at Cincom Systems

~7 min read
Abstract

This paper examines the enterprise security management practices of Cincom Systems, a global enterprise software provider serving defense contractors in the United States, United Kingdom, France, and Australia. Drawing on firsthand internship experience, the paper explains how Cincom implements the Confidentiality, Integrity, and Availability (CIA) triad alongside a Role-Based Access Control (RBAC) model to meet stringent Department of Defense audit requirements. It also describes formal and informal security policies, the primary threats faced by the company — including sophisticated phishing and network impersonation attacks — and how Cincom uses HP's Mercury Interactive suite and Network Management Center to monitor and respond to security incidents in real time.

Key Takeaways
  • Introduction: Cincom Systems and Its Security Obligations: Overview of Cincom's defense clients and security scope
  • Adoption of the CIA Triad and RBAC Model: CIA triad and RBAC implementation for DoD compliance
  • Formal and Informal Security Policies: Varying security policies across divisions and projects
  • Analysis of Threats to Cincom's Systems: Phishing, VPN impersonation, and sophisticated hacking incidents
  • Information Security Management and Network Monitoring: HP Mercury Interactive and network management tools in use
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • The paper grounds abstract security frameworks — the CIA triad and RBAC model — in a specific organizational context, making theoretical concepts tangible and easier to evaluate.
  • The real-world case study of the shadow-Cintranet attack provides a compelling, detailed narrative that illustrates how security tools performed under genuine threat conditions.
  • The paper connects technical security decisions (server isolation, VPN restrictions, hardware firewalls) directly to compliance requirements from multiple national defense agencies, demonstrating an understanding of regulatory context.

Key academic technique demonstrated

The paper uses a case study methodology supported by primary observation (internship experience) and secondary academic citations. This combination allows the author to validate claims with peer-reviewed sources (Bertino & Sandhu, 2005; Knapp et al., 2006) while providing insider organizational detail that would be inaccessible through published literature alone.

Structure breakdown

The paper opens with a contextual introduction establishing Cincom's defense-sector relationships and the scope of the analysis. The second and third sections address the theoretical framework (CIA triad and RBAC) and accompanying formal policies. The fourth section shifts to threat analysis with a detailed incident narrative. The final section covers ongoing monitoring infrastructure and tools. The structure moves logically from framework to policy to threat to response, mirroring a standard security management lifecycle.

Introduction: Cincom Systems and Its Security Obligations

Cincom Systems is a global leader in the development, implementation, and service of enterprise software specifically designed for the needs of complex manufacturers. Its security and ethics policies reflect the company's long-standing customer relationships with defense contractors in the United States, the United Kingdom, France, and Australia. Each of these nations uses Cincom's software to manage their complex defense systems. As a result of these trust-based relationships, Cincom must adhere to very stringent requirements for data and information security.

The intent of this analysis is to explain how Cincom Systems used the Confidentiality, Integrity, and Availability (CIA) triad to better manage security requirements, and to define the formal and informal security policies the company has in place. Having served as an intern for the company for two years — specifically during summer and winter breaks — much of the information shared in this paper was drawn from those experiences. The main information security threats, how information security is managed, and how Cincom monitors computer and online usage are also discussed. Restrictions on access to company data are also addressed.

Adoption of the CIA Triad and RBAC Model

The Cincom security platform is predicated on the CIA triad of Confidentiality, Integrity, and Availability, and formal, audit-based procedures are in place for gaining access to specific information assets based on this model. As a former intern in the company's IT and marketing services organization over two years, many aspects of their security strategy became clear. The CIA triad model is supported through a series of user and data taxonomies — each role-based — that define specific data sets, fields, and, in the case of transaction systems, specific records and customer data (Bertino & Sandhu, 2005).

The CIA model is also used to manage the reporting analytics and metrics that drive overall security strategies. These metrics are provided to the U.S. Department of Defense as part of annual audits, as well as to defense agencies in the UK, France, and Australia. The audits conducted to ensure Department of Defense (DoD) compliance require that servers for government projects be physically located in a completely separate section of the computer room, with distinct security processes and procedures governing access.

Consistent with the CIA model, Cincom has aligned its CIA framework to the strategic IT plan and the overall strategic plan of the entire enterprise. One of the most challenging aspects of using the CIA triad is ensuring sufficient agility in the business model to achieve strategic goals while maintaining the security infrastructure and frameworks needed to protect information assets (Knapp, Marshall, Rainer, & Ford, 2006).

Cincom has adopted the CIA triad in conjunction with the Role-Based Access Control (RBAC) model (Bertino & Sandhu, 2005), as the audit and security requirements of the U.S. Department of Defense and foreign ministries of defense require a high level of auditability, visibility, and verifiability of activity within each database and across the entire IT system landscape. The RBAC model was adopted specifically to allow greater agility in global software development, testing, and sales efforts while ensuring a hardened and secure IT infrastructure. The CIA triad is specifically designed to provide enterprises with the flexibility needed to achieve these strategic objectives (Knapp, Marshall, Rainer, & Ford, 2006). Cincom has built compliance into its IT strategic plan with specific focus on attaining the shared objectives of confidentiality, integrity, and availability of data, while also ensuring its authenticity — verified every six months or more by the government agencies whose projects Cincom supports.

Formal and Informal Security Policies

The formal and informal security policies in place at Cincom vary significantly across divisions. For those divisions actively involved in projects and programs with the U.S. Department of Defense and related foreign ministries, requirements are very stringent down to the server level. There is a substantially greater level of auditing and monitoring with regard to network connections, which cannot be used in VPN configurations and have no available Web access. Web server software is prohibited on servers running any type of government project.

2 locked sections · 350 words
Sign up to read the full analysis
Analysis of Threats to Cincom's Systems210 words
The main threats the company faces include competitors attempting to bypass the firewall and access the contract management system, the use of phishing attacks on executives to gain access to corporate bank accounts, and the persistent impersonation of Virtual Private Network (VPN) sessions. The majority of these threats are relatively straightforward to stop. However,…
Information Security Management and Network Monitoring140 words
Information security is managed at Cincom through a variety of techniques, including hardware- and software-based firewalls. Network monitoring is based on an aggregated measure of overall load…
Read the full paper →
Plus 130,000+ examples & all writing tools

References

Bertino, E., & Sandhu, R. (2005). Database security — concepts, approaches, and challenges. IEEE Transactions on Dependable and Secure Computing, 2(1), 2–19.

Fulkerson, C. L., Gonsoulin, M. A., & Walz, D. B. (2002). Database security. Strategic Finance, 84(6), 48–53.

Knapp, K. J., Marshall, T. E., Rainer, R. K., & Ford, F. N. (2006). Information security: Management's effect on culture and policy. Information Management & Computer Security, 14(1), 24–36.

Spafford, E. H. (2008). Inspiration and trust. Communications of the ACM, 51(1), 61–62.

Tang, J. (2008). The implementation of Deming's system model to improve security management: A case study. International Journal of Management, 25(1), 54–68.

Tu, M., Li, P., Yen, I., Thuraisingham, B., & Khan, L. (2010). Secure data objects replication in data grid. IEEE Transactions on Dependable and Secure Computing, 7(1), 50–64.

Key Concepts in This Paper
CIA Triad RBAC Model DoD Compliance Network Monitoring Data Confidentiality Phishing Attacks VPN Security Security Audits Enterprise Software Threat Detection
Cite This Paper
PaperDue. (2026). Enterprise Security Management at Cincom Systems. PaperDue. https://www.paperdue.com/study-guide/enterprise-security-management-cincom-systems-80452

Always verify citation format against your institution’s current style guide requirements.