Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask HR Management Expert

Project : Manager's Deskbook

Company Background & Operating Environment

Use the assigned case study for information about "the company."

Policy Issue & Plan of Action

The Manager's Deskbook contains issue specific policies and implementation procedures which are required to mitigate risks to the company and to otherwise ensure good governance of the company's operations. The Chief Information Security Officer (CISO) and key CISO staff members held a kick-off meeting last week to identify issue specific policies which should be added to the company's policy system in the IT Governance category. The policies will be disseminated throughout the company by incorporating them into the Manager's Deskbook. The required issue specific policies are:

1. Data Breach Response Policy

2. Preventing / Controlling Shadow IT Policy

3. Management and Use of Corporate Social Media Accounts Policy

For the purposes of this assignment, you will create a policy recommendations briefing package (containing an Executive Summary and draft policies) and submit that to your instructor for grading.

Note: In a "real world" environment, the policy recommendations briefing package would be submitted to the IT Governance board for discussion and vetting. After revisions and voting, a package containing the accepted policies would be sent to all department heads and executives for comment and additional vetting. These comments would be combined and integrated into the policies and sent out for review again.

It usually takes several rounds of review and comments before the policies can be sent to the Chief of Staff's office for forwarding to the Corporate Governance Board. During the review & comments period, the policies will also be subjected to a thorough legal review by the company's attorneys. Upon final approval by the Corporate Governance Board, the policies will be adopted and placed into the Manager's Deskbook. This entire process can take 9 to 12 months, if not longer.

Your Task Assignment

As a staff member supporting the CISO, you have been asked to research and then draft an issue specificpolicy for each of the identified issues. These policies are to be written for MANAGERS and must identify the issue, explain what actions must be taken to address the issue (the company's "policy"), state the required actions to implement the policy, and name the responsible / coordinating parties (by level, e.g. department heads, or by title on the organization chart). After completing your research and reviewing sample policies from other organizations, you will then prepare an "approval draft" for each issue specific policy.

• The purpose of each issue specific policy is to address a specific IT governance issue that requires cooperation and collaboration between multiple departments within an organization.

• Each issue specific policy should be no more than two typed pages in length (single space paragraphs with a blank line between).

• You will need to be concise in your writing and only include the most important elements for each policy.

• You may refer to an associated "procedure" if necessary, e.g. a Procedure for Requesting Issuance of a Third Level Domain Name (under the company's Second Level Domain name) or a Procedure for Requesting Authorization to Establish a Social Media Account.
Your "approval drafts" will be combined with a one page Executive Summary (explaining why these issue specific policies are being brought before the IT Governance Board).

Research:

1. Review NIST's definition of an "Issue Specific Policy" and contents thereof (NIST SP 800-14 p. 14)

2. Review the weekly readings and resource documents posted in the classroom. Pay special attention to the resources which contain "issues" and "best practices" information for:

• Data Breach Response

• Preventing / Controlling Shadow IT

• Social Media

3. Review NIST guidance for required / recommended security controls

• NIST SP 800-53 Access Control (AC) control family (for Social Media policy)

• NIST SP 800-53 Incident Response (IR) control family (for Data Breach policy)

• NIST SP 800-53 System and Services Acquisition (SA) control family (Domain Name, Shadow IT, Website Governance)

4. If required, find additional sources which provide information about the IT security issues which require policy solutions.
Write:

1. Prepare briefing package with approval drafts of the two IT related policies for the Manager's Deskbook. Your briefing package must contain the following:

• Executive Summary

• "Approval Drafts" for

o Data Breach Response Policy

o Preventing / Controlling Shadow IT Policy

o Management and Use of Corporate Social Media Accounts Policy

HR Management, Management Studies

  • Category:- HR Management
  • Reference No.:- M92199340
  • Price:- $40

Priced at Now at $40, Verified Solution

Have any Question?


Related Questions in HR Management

1 describe how the performance management process is linked

1) Describe how the performance management process is linked to employee selection, training, and development. 2) What sources could be used to evaluate the performance of people working in the following jobs? a) sales r ...

Work motivation assignment -details of assignment

Work Motivation Assignment - Details of Assignment - Introduction - Call-centres are a ubiquitous part of modern life. Whenever we have problems with our mobile and computer devices, travel plans, credit payments or onli ...

Question training needs assessment exerciseinstructionsread

Question: Training Needs Assessment Exercise Instructions:Read the Grand View Grocers Corporation case. Grand View Grocers Corporation, headquartered in Clewiston, Florida, is among the nation's top grocery chain compani ...

Question chi-square worksheetpart 1 interpret chi-square

Question: Chi-Square Worksheet Part 1: Interpret Chi-Square Results Review the following output from a chi-square test, and answer the questions below. Chi-Square Test Frequencies: a 0 cells (0.0%) have expected frequenc ...

Question to move or not to movecomplete the to move or not

Question: To Move or Not to Move Complete the To Move or Not to Move simulation within the LearnScape platform. You will need to create a single Microsoft Word file and save it to your computer. As you complete each week ...

1 in 250 words or more answer the questions why is

1. In 250 words or more, answer the questions, Why is multicultural relativism insufficient as an acceptable ethical model for the global community and universal, moral absolutes imperative? 2. What does "building your o ...

Assignment 3 evaluating disparate impact and employee

Assignment 3: Evaluating Disparate Impact and Employee Selection You are employed as an HR consultant for a mid-sized bank. The bank employs 200 tellers across its branches. You need to recommend to the bank what to cons ...

Question need references1what are the components of

Question: Need References 1. What are the components of competitive strategy? Within competitive strategy what is the relevance of a value change framework? What are the implications for customers and the competition? 2. ...

Assignment goal-setting frameworkthe first of six steps of

Assignment: Goal-Setting Framework The first of six steps of performance management consists of goal setting, as detailed in Chapter Three. Assume that you work for the Los Angeles Tribune, a large but struggling newspap ...

The exercise develop implement and assess an employee

THE EXERCISE: DEVELOP, IMPLEMENT AND ASSESS AN EMPLOYEE SELECTION SYSTEM FOR A BANK TELLER POSITION Part 1: Employee Selection and Assessment For this exercise, assume you are employed as an HR consultant for a mid-sized ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As