Question

In: Computer Science

Information security policies are the core internal guidance for an organization and must be enacted prior...

Information security policies are the core internal guidance for an organization and must be enacted prior to the purchase of information security controls. There is a bit of a "chicken and egg" dispute in the information security community as to whether it is appropriate to first engage in risk assessment with policies created to address those findings or whether it is appropriate to first create policies against which a risk assessment can be performed. On a more granular level, security policy is meant to document what is important to a particular organization related to information technology assets, including data. This sequential order is critical to the success of an information security program because a successful program ensures that organizations do not spend too little or too much money when purchasing controls to enforce these policy decisions. For example, it is possible to purchase a certificate that uses DNA as the key to enforce an access control policy, but there are very few situations where that would be an appropriate or balanced choice. You are a new information security officer for Metro City Community College. Metro City has a small urban campus in downtown Detroit and also offers their catalog of courses online. One of the first tasks you are assigned is to create the information security policies that will guide all subsequent security projects that you propose. Use the study materials and engage in any additional research needed to fill in knowledge gaps. Write a 2–3 page paper that covers the following: •Describe the overall objectives of creating information security policy for this institution. •Analyze the benefits and challenges of enforcing information security policies within government agencies and organizations. •Evaluate how creation and enforcement of information security policies can impact customers and business partners that have a relationship with a government agency or organization.

Solutions

Expert Solution

  1. Describe the overall objectives of creating information security policy for this institution.

As the Security Officer of Metro City Community, I’ll establish the Information security policy for my organization with the following objectives:

  • The policies will comprise of well-defined, comprehensive, rules and practices that will regulate the access to the organization’s system and information.
  • Since our organization works online and is a provider of catalogue of online courses, hence the policies will lay the foundation of access control since it’ll have many levels of users restricted access.
  • Also, the laid policies should be organization oriented and should not be an imitation or a replica of already established security policies/rules.
  • The Information Security policies needs to ensure that it fulfils all parameters for user friendliness.
  • The policies will act as regulating body for vulnerable internet security threats and possibility of any incoming hack.

Scope of the Policies:

The scope of the policies will be limited to Metro City Community only.

Responsibilities –

Me as a Information Security Officer will be responsible for:
-Daily overall security check
-Weekly Internal audits within all modules of the System.
-Risk Assessment on every new release and planning for further improvements.

  1. Analyze the benefits and challenges of enforcing information security policies within government agencies and organizations.

Lets talk of Benefits first:

Protects Data-Integrity

This is one key benefits of Information security policies that, it helps to secure and Confidentiality and Data integrity.

Data and Information Security:

Since Metro City is an online based course offering organization, hence its maximum data comprises of Intellectual property i.e. Information which has been developed by its creators and are their own efforts for providing knowledge and information to users.

Ability to sustain vulnerable cyber attacks

Since it’s an online course offering organization hence it mostly deals with Internet. As mentioned in the last point of the Objectives, the policies act as a regulating body for vulnerable internet security threats and possibility of any incoming hack

Overall Governing policies for the organization

Lays down an effective foundation for overall organization’s working policies.

Provides Cost effective solutions to avoid third party security outsourcing

An efficient in-house development of Information security policies can thus reduce costs which would have employed to avail external defense services to combat potential security threats.

Challenges faced to enforce Information Security Policies:

Some of the practical challenges which may be faced while implementing Information security policies in my organization are:

  1. Continuous developments and change in work culture – With an increase of exponential customer demand and in an effort to provide enhanced models, the security policies are often left un-touched. Hence, they fall back with the current times and start generating loopholes. It is therefore very important to update Information security policies with time.
  2. Active Hackers – There are always in-ethical hackers present to decode every website and portal to gain administrative access over the system. There are dedicated underground teams running for this purpose and they always keep an eye to just wait for a small security glitch to get into the system and steal intellectual property.
  3. Discipline with team – As we know ‘Charity begins at home’, hence above all the policies, it is the primary responsibility of the employees within the organization to be disciplined, well-cultured and follow the offline Information security policies dedicatedly without any enforcement. If this fails, it’ll ultimately weaken the roots of the security in every level.
  1. Evaluate how creation and enforcement of information security policies can impact customers and business partners that have a relationship with a government agency or organization.

Impact over Customers and Business partners:

Customers and Business merchants taking services of the organization can be impacted in following ways:

Negative Impacts:

  1. Restricted Access – A customer needs to pay to avail respective services and the services depend on the specific type chosen either Demo, Full or Partial. The only impact on the customer will be that, he will not be eligible to avail full services in demo or trial offer. Also, on the other hand, suppose particular service is available in Full version but he doesn’t need rest of the services, then he’ll have to pay an unnecessary extra amount.
  1. Link breakage/Loophole – An overly sensitive and complicated security design may sometimes work negatively in cases where the customer may face inaccessibility. For Example, suppose Metro City integrates Payment gateway for customers to purchase a particular service. The customer selects the service and gets redirected to payment gateway, but the transaction gets cancelled midway and amount is deducted. This is a very common issue faced by most of the customers where in the loophole within the security structure may be either in the parent company or the merchant bank. Whatever may be the case, it surely has a negative impact on the customer.
  1. Inclination of Business partners towards organizations – Most common business partners associated with organizations are mostly either Banks, Courier services, third party vendors. Suppose an organization reaches a financial bank to tie up with it for all its customer transactions. The bank will deploy an audit on the past records of the organization. An organization with an effective laid down information security structure may have a poor record in terms of customer deliverables and satisfaction. Such an audit score by the third part merchant (govt. on non-govt) will definitely have a negative impact may not turn into a successful affiliation.

Positive Impacts:

  1. Gaining Customer’s confidence – Laying down effective Information Security policies may also have a positive impact like to help gain potential customer’s confidence in a way that a new customer will be more willing to take the organization’s service seeing an impressive Security structure.
  1. Possible tie-ups or Mergers with Business partners- With an effective Information Security and the smooth continuity between two successful organization and partner, may in the long run result in merger of the two thereby gaining an even large audience and raise up in the market competition.

Related Solutions

Core Competencies and Strategic Outcomes Every organization has core competencies it must consider during its strategizing...
Core Competencies and Strategic Outcomes Every organization has core competencies it must consider during its strategizing process. These competencies can include its knowledge or domain expertise on specific business activities, specialized technologies or infrastructure, and the unique skills of its employees. Accordingly, an organization must align strategies with its core competencies to achieve its growth and expansion goals. What are the various core competencies that a firm must recognize and strategize business based on these competencies? List as many core...
How often should IT security policies be reviewed within an organization? What is the impact if...
How often should IT security policies be reviewed within an organization? What is the impact if these policies are not reviewed on a regular basis?
Q1. Define information security Q2. Describe the information security roles of professionals within an organization
Q1. Define information securityQ2. Describe the information security roles of professionals within an organizationQ3. Explain these Necessary tools: policy, awareness, training, education, technologyQ4. Explain why a successful information security program is the responsibility of both an organization’s general management and IT managementQ5. Identify the threats posed to information security and differentiate threats to the information within systems from attacks against the information within systemsQ6. Differentiate between laws and ethicsQ7. Explain the role of culture as it applies to ethics in...
What are the different networks and areas where security policies must be adapted? Explain in your...
What are the different networks and areas where security policies must be adapted? Explain in your own word? Personnel safety Equipment safety Environmental impact Please dont just copy it from the internet Production loss Data loss
An organization has the following password policies: - password must be at least 16 characters long...
An organization has the following password policies: - password must be at least 16 characters long - three failed login attempts will lock the account for 5 minutes - password must have one uppercase letter, one lowercase letter, and one non alphanumeric symbol a database server was recently breached, and the incident Response Team suspect the passwords were compromised. Users with permission on the database server were forced to change their passwords for that server. Unauthorised and suspicious logins are...
Discuss the reasons for information security policies. One reason is to enable the creation of other...
Discuss the reasons for information security policies. One reason is to enable the creation of other more specific planning documents. What would happen in the absence of a policy document?
It is very important about how you craft your organization's security policies with your organization. Your...
It is very important about how you craft your organization's security policies with your organization. Your policy should comprehensively address all the main security vulnerabilities and risks within your organization. Remember your overall security policy, not all covers computers, internet, applications, servers, user access, etc.. but many other areas which we will delve into. Attached is a sample acceptable use policy from the SANS Institute. What sections really stand out to you and why?
So should information security team first assess the corporate culture prior to attempting to implement an...
So should information security team first assess the corporate culture prior to attempting to implement an insider threat program
Imagine that you are the Information Security Officer (ISO) of your organization. Develop a plan to...
Imagine that you are the Information Security Officer (ISO) of your organization. Develop a plan to conduct a Web application penetration test on your network. Identify and explain all steps necessary to successfully complete the test.
Personal information about customers is collected, used, disclosed, and maintained only in compliance with internal policies...
Personal information about customers is collected, used, disclosed, and maintained only in compliance with internal policies and external regulatory requirements and is protected from unauthorized disclosure. With reference to Privacy Concern how would you deal with SPAM and Identify Theft problem of your business organization?
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT