II) Work-Flow of Credential Solution, How the transcript is ordered and sent
Step 1:
First, the student places order online at this link; https://www.credentials-inc.com/tplus/?ALUMTRO002690, which is administered by Credential Solution. They are expected …show more content…
If the student picks up the transcript, they must show photo ID to verify their identity and sign a document stating that the transcript has been picked up.
III) Threats & Solutions:
1) Confidential
1- RSA Encryption for Credit Card Information & Discuss “Pre-approval”
(SEAN/ANDY, either find the RSA information, or remind me how do I find the public key information for RSA!!)
As Credential Solutions accepts payments using Credit/Debit cards, the obvious security threat is credit/debit card fraud.
2- An employee wants to read student data in the Credential Solution database.
Another security concern is that an employee would try to read any student information on Credential Solutions database. Therefore, to address this concern all information is encrypted, even details such as student’s name. The reason why Credential Solution encrypts every piece of information is because they assume the unencrypted information may be useful to deduce the encrypted …show more content…
Therefore, it is plausible that someone would want to steal the official transcript when it is in transit. A good reason why I would think someone would like to steal a student’s official transcript is because it contains their home address, history of all the courses they completed, courses they are currently registered for, and any transfer credit and from which college they received it from. This information would be valuable if the perpetrator wants to be able stalk the victim.
The only solution to solve this risk would be Queens College to adopt and enforce an electronic transcript mailing policy only as this would avoid any risk incurred when sensitive documents are mailed.
2) Integrity
1- Official Transcript is tampered with on travel to