Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask Computer Network & Security Expert

Cybersecurity Policy, Plans, and Programs Project: Manager's Deskbook

Company Background & Operating Environment - Use the assigned case study for information about "the company."

Policy Issue & Plan of Action - The Manager's Deskbook contains issue specific policies and implementation procedures which are required to mitigate risks to the company and to otherwise ensure good governance of the company's operations. The Chief Information Security Officer (CISO) and key CISO staff members held a kick-off meeting last week to identify issue specific policies which should be added to the company's policy system in the IT Governance category. The policies will be disseminated throughout the company by incorporating them into the Manager's Deskbook. The required issue specific policies are:

1. Data Breach Response Policy

2. Preventing / Controlling Shadow IT Policy

3. Management and Use of Corporate Social Media Accounts Policy

For the purposes of this assignment, you will create a policy recommendations briefing package (containing an Executive Summary and draft policies) and submit that to your instructor for grading.

Your Task Assignment

As a staff member supporting the CISO, you have been asked to research and then draft an issue specific policy for each of the identified issues. These policies are to be written for MANAGERS and must identify the issue, explain what actions must be taken to address the issue (the company's "policy"), state the required actions to implement the policy, and name the responsible / coordinating parties (by level, e.g. department heads, or by title on the organization chart). After completing your research and reviewing sample policies from other organizations, you will then prepare an "approval draft" for each issue specific policy.

  • The purpose of each issue specific policy is to address a specific IT governance issue that requires cooperation and collaboration between multiple departments within an organization.
  • Each issue specific policy should be no more than two typed pages in length (single space paragraphs with a blank line between).
  • You will need to be concise in your writing and only include the most important elements for each policy.
  • You may refer to an associated "procedure" if necessary, e.g. a Procedure for Requesting Issuance of a Third Level Domain Name (under the company's Second Level Domain name) or a Procedure for Requesting Authorization to Establish a Social Media Account.

Your "approval drafts" will be combined with a one page Executive Summary (explaining why these issue specific policies are being brought before the IT Governance Board).

Research:

1. Review NIST's definition of an "Issue Specific Policy" and contents thereof (NIST SP 800-14 p. 14)

2. Review the weekly readings and resource documents posted in the classroom. Pay special attention to the resources which contain "issues" and "best practices" information for:

  • Data Breach Response
  • Preventing / Controlling Shadow IT
  • Social Media

3. Review NIST guidance for required / recommended security controls

  • NIST SP 800-53 Access Control (AC) control family (for Social Media policy)
  • NIST SP 800-53 Incident Response (IR) control family (for Data Breach policy)
  • NIST SP 800-53 System and Services Acquisition (SA) control family (Domain Name, Shadow IT, Website Governance)

4. If required, find additional sources which provide information about the IT security issues which require policy solutions.

Write:

1. Prepare briefing package with approval drafts of the two IT related policies for the Manager's Deskbook. Your briefing package must contain the following:

Executive Summary

"Approval Drafts" for

  • Data Breach Response Policy
  • Preventing / Controlling Shadow IT Policy
  • Management and Use of Corporate Social Media Accounts Policy

As you write your policies, make sure that you address IT and cyber security concepts using standard terminology.

2. Use a professional format for your policy documents and briefing package. Your policy documents should be consistently formatted and easy to read.

3. Common phrases do not require citations. If there is doubt as to whether or not information requires attribution, provide a footnote with publication information or use APA format citations and references.

4. You are expected to write grammatically correct English in every assignment that you submit for grading. Do not turn in any work without (a) using spell check, (b) using grammar check, (c) verifying that your punctuation is correct and (d) reviewing your work for correct word usage and correctly structured sentences and paragraphs.

Attachment:- Assignment File.rar

Computer Network & Security, Computer Science

  • Category:- Computer Network & Security
  • Reference No.:- M92455557

Have any Question?


Related Questions in Computer Network & Security

Assignment wireless applications advances advantages and

Assignment : Wireless Applications, Advances, Advantages, and Disadvantages The adoption of wireless technologies varies from one industry to another, and is often based on the benefits provided versus the challenges, im ...

Security challenges in emerging networksassignment

Security Challenges in Emerging Networks Assignment Description The purpose of this assignment is to develop skills to independently think of innovation. In this assignment students will first learn how to develop knowle ...

Advanced wireless networks assignment -wlan design project

Advanced Wireless Networks Assignment - WLAN Design Project - Description: You need to form a group of at most four students, and select one of the case studies provided in Assessment module on VU Collaborate. In this pr ...

Security risk assessment executive summarya detailed

SECURITY RISK ASSESSMENT Executive Summary A detailed Information security risk assessment was carried out on Fiji Directories Limited (FDL) during October 15th 2018 to October 24th 2018. FDL, an ATH group company, is a ...

Question in regards to encryption does the public key and

Question : In regards to encryption, does the public key and private key come from the sender or does the receiver already have the private and is given the public key by the sender? The response must be typed, single sp ...

Content analysis assignmentoverviewthis assignment has

Content Analysis Assignment Overview This assignment has three major aims: - To help students gain good understanding of all ITECH1102 theoretical and practical material. - To encourage students to use content analysis s ...

Question a signal travels through an amplifier and its

Question : A signal travels through an amplifier, and its power increased and becomes doubled. Then calculate amplification for this condition 2 Discuss about the TCP/IP PROTOCOL SUITE and Principles of Protocol Layering ...

Final project incident response exercise amp reportyour

Final Project: Incident Response Exercise & Report Your Task You have been assigned to work incident clean-up as part of the Sifers-Grayson Blue Team. Your task is to assist in analyzing and documenting the incident desc ...

Part ian attacker seeks to view the contents of a specific

Part I An attacker seeks to view the contents of a specific Microsoft Word document file to which they do not have any kind of access. You may assume that: - no exploitable vulnerabilities of any kind exist; - the attack ...

You need to prepare packet tracer fileattached pdf contains

You need to prepare packet tracer file attached pdf contains topology and required configurations and assigned ip address. In packet tacer file you need to include banner, router and switches. 1. VLSM Design a) As first ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As