Network Security Management: Importance and Strategy
This paper examines the importance of network security management in an era of increasingly sophisticated cyber threats. It traces the evolution of network security from the 1986 Computer Fraud and Abuse Act through the emergence of CERT and the explosion of internet-based attacks. Using real-world examples — most notably the 2011 Sony PlayStation Network breach — the paper demonstrates the financial, legal, and reputational consequences organizations face when network security is inadequate. It also outlines a framework for implementing effective network security strategies, covering authentication, monitoring, vulnerability testing, encryption, firewalls, intrusion detection, and incident response.
- Introduction: Context for growing cyber threats and network vulnerability
- What Is Network Security?: Definition and scope of network security management
- Network Security Management and Its Relevance: Historical evolution from 1986 legislation to modern threats
- Financial, Legal, and Reputational Consequences of Breaches: Sony case study illustrating costs of inadequate security
- Implementation of an Effective Network Security Management Strategy: Prevention, detection, and response framework for businesses
- Conclusion: Network threats persist; organizations must minimize exposure
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- Grounds abstract concepts in concrete, high-profile case studies — particularly the Sony PlayStation Network attack — giving readers quantifiable evidence of financial and legal consequences.
- Moves logically from historical context to current relevance to practical recommendations, giving the argument a clear and persuasive progression.
- Acknowledges the limitations of network security (complete elimination of threats is impossible, security can impede operational flexibility) rather than overstating its benefits, lending the analysis credibility.
Key academic technique demonstrated
The paper effectively uses the case study as an evidential strategy. Rather than relying solely on general claims, the author anchors each major argument — financial loss, legal liability, reputational damage — in a documented real-world incident. This technique transforms broad assertions about network security risks into concrete, falsifiable claims supported by cited sources, which is characteristic of well-constructed undergraduate applied technology writing.
Structure breakdown
The paper opens with a brief framing section before dividing into four substantive areas: a definitional section establishing what network security is; a historical section tracing its evolution; an extended analysis of consequences (financial, legal, reputational, competitive); and a practical implementation section covering prevention, detection, and response. A short conclusion synthesizes the paper's central claim. The structure mirrors a standard problem–context–solution argumentative essay, appropriate for an undergraduate technology or information systems course.
Introduction
For data to flow from one computer to another, those computers must be interconnected in what is known as a network. With such interconnectedness comes the risk of data interception, and it is for this reason that network security is considered crucial.
In recent years, the number of corporations that have experienced attacks on their computing resources has been increasing. Outages have ranged from denial-of-service attacks to viruses to other more sophisticated forms of attack. Notably, these attacks — which are rarely publicly acknowledged by affected companies — are occurring at a time when organizations are becoming ever more dependent on information systems and networks to conduct business. Today, communications between an organization and its stakeholders, including employees and customers, are primarily carried out through networks. Any disruption to these networks could be potentially catastrophic for individual firms.
Organizations also stand to lose significantly should an unauthorized individual gain access to their networks and computer systems. Network security management is therefore of great relevance to companies that wish to safeguard their most critical resources.
During the past few years, the internet has evolved greatly, and computer networks have grown in size, complexity, and relevance. These changes have triggered the emergence of a new breed of cybercriminals and other malicious individuals who are constantly seeking ways to compromise vulnerable networks. This paper concerns itself with the importance of network security. In doing so, it defines network security, briefly discusses how network security management has evolved over time, and addresses the implementation of an effective network security management strategy.
What Is Network Security?
For purposes of this discussion, the definition offered by Richardson and Thies (2012) will be used. According to the authors, a network is essentially "an interconnection of two or more computers with some means of sending messages back and forth" (Richardson & Thies, 2012, p. 389). Given the role networks play in facilitating remote access, they tend to be particularly vulnerable to remote attacks and acts of sabotage.
Network security comprises all the initiatives and measures embraced by an organization in a bid to protect its network. Such initiatives and measures protect not only the integrity but also the reliability and usability of data. Network security management, therefore, seeks to offer protection to the network from both misuse and unauthorized access.
Network Security Management and Its Relevance
Before addressing the importance of network security management, it is worth highlighting how it has evolved over time. The move toward effective network security strategies has been fueled by increasing instances of theft and misuse of sensitive organizational data over networks. Many companies have in the past lost millions — mostly quietly — to hackers.
Although interest in network security has spiked within the last decade, specific incidents in the early 1990s may have been what first convinced businesses of the need for a comprehensive network security policy. The 1986 Computer Fraud and Abuse Act was created after it emerged that crimes involving the use of computers to commit fraud and related activities were on the rise (Senft, Gallegos, & Davis, 2012). However, as Senft, Gallegos, and Davis (2012, p. 11) further point out, despite being created to "protect against attacks in a network environment," the act had several weaknesses and faults. It was around this time that authorities were beginning to grapple with the theft of crucial information from military computers. Among those accused or convicted of computer-related crime during this period were Robert Morris and Ian Murphy.
Later, as the world was coming to terms with the costs of network security failures — primarily following the release of the Morris Worm — the U.S. government orchestrated the formation of a response team charged with addressing computer risk incidents. That team was named CERT, the Computer Emergency Response Team (Wang & Ledley, 2012). Regardless of the measures being put in place, however, network security concerns continued to grow in the 1990s after the internet became widely available to the public. It was during this decade that businesses began to adopt far-reaching measures aimed at protecting their computing infrastructure from network attacks.
In the words of Canavan (2001), "network and computer security is crucial to the financial health of every organisation." This is especially true given the increasing number of network security incidents reported daily not only across the nation but around the world. Within the past two decades, network security incidents have increased significantly, effectively validating the central claim of this paper: that the relevance of network security management cannot be overstated.
Network security management is particularly valuable in preventing losses arising from the misuse of data. In the absence of adequate network security management approaches, data manipulation, destruction, and breaches of confidentiality would likely become common occurrences.
A report from the year 2000 on network attacks noted that companies would lose close to $1.6 trillion to hacking and other network attack incidents. According to Canavan (2001), whichever way one looks at it, this "is a staggering amount of money with a direct effect on companies' return on investment or assets." That report was released over two decades ago. Today, companies continue to lose billions of dollars to credit card thieves, hackers, and other individuals or entities who exploit system and network vulnerabilities to steal customer information, stall operations, or spy on competitors.
Conclusion
The elimination of all network security problems is virtually impossible. As technology continues to advance, approaches to network security that are considered effective today may not be as effective tomorrow. Individuals with malicious intent continue to work harder, seeking — and sometimes finding — vulnerabilities and ways to circumvent existing security measures. Nevertheless, organizations can significantly minimize instances of network security breaches by making it expensive and difficult for intruders to penetrate the security mechanisms in place.
As this paper has demonstrated through historical context, real-world examples such as the 2011 Sony PlayStation Network attack, and a review of implementation strategies, network security management is not optional — it is a business imperative. The financial, legal, and reputational costs of neglecting network security far outweigh the investment required to protect critical organizational resources.
References
BBC. (2013). Sony fined over 'preventable' PlayStation data hack. BBC. Retrieved from http://www.bbc.co.uk/news/technology-21160818
Canavan, J. E. (2001). Fundamentals of network security. Artech House.
Cole, E., Krutz, R. L., & Conley, J. (2005). Network security bible. John Wiley & Sons.
Finkle, J., & Hosenball, M. (2014). Exclusive: More well-known U.S. retailers victims of cyber attacks — sources. Reuters. Retrieved from http://www.reuters.com/article/2014/01/12/us-target-databreach-retailers-idUSBREA0B01720140112
Malcom, J. (2012). Consumers in the information society: Access, fairness and representation. Consumers International.
Richardson, T., & Thies, C. N. (2012). Secure software design. Jones & Bartlett Publishers.
Senft, S., Gallegos, F., & Davis, N. (2012). Information technology control and audit (4th ed.). CRC Press.
Tassi, P. (2011). Sony pegs PSN attack costs at $170 million, $3.1B total loss for 2011. Forbes. Retrieved from http://www.forbes.com/sites/insertcoin/2011/05/23/sony-pegs-psn-attack-costs-at-170-million/
Wang, S. P., & Ledley, R. S. (2012). Computer architecture and security: Fundamentals of designing secure computer systems. John Wiley & Sons.
Create your account
Always verify citation format against your institution’s current style guide requirements.