Instruction
Assignment 1 (4 short paragraphs double spaced):
• Paragraph #1: Summary of findings: risks, threats, and vulnerabilities found throughout the seven domains of a typical IT infrastructure
• Paragraph #2: Approach and prioritization of critical, major, minor risk assessment elements
• Paragraph #3: Risk assessment and risk impact summary to the seven domains of a typical IT infrastructure
• Paragraph #4: Recommendations and next steps for executive management
Assignment 2: 1 short paragraph (double spaced):
Risk Mitigation
Company M designs, manufactures, and sells electronic door locks for commercial buildings. The company has approximately 1,500 employees in three locations around the United States and generates $50 million in annual revenues. Over 5,000 wholesalers and distributors access the Company M business-to-business (B2B) Web site to place orders and track fulfillment.
In the past year, Company M experienced 22 information security incidents, most of which involved lost or stolen laptops, tablet PCs, and smartphones. In addition, the company dealt with four serious malware events that originated from an unpatched server, an insecure wireless network used in the manufacturing plant, an insecure remote connection used by a sales person, and a headquarters employee who downloaded a game from the Internet to her workstation. Three of the malware incidents resulted in files that were erased from the company’s sales database, which had to be restored, and one incident forced the B2B Web site to shut down for 24 hours. Submit your responses to the following questions:
1. Identify and discuss technological and financial risks that Company M faces.
2. Which domains of the IT infrastructure were involved during the four malware events?
3. What types of security policies should Company M institute to mitigate those risks?
Business Considerations
When creating a security policy framework, it’s important to align business objectives with the correct framework. Discuss what can happen if the framework you choose as a foundation does not fit your organization’s business objectives. Why is it important to pay attention to business objectives?
Assignment 3 - 1 page double spaced:
Learning Objectives and Outcomes
♣ Understand the importance of information security policies and the role they play in business activities to ensure sound, secure information.
♣ Identify four IT security controls for a given scenario.
Scenario
♣ The organization is a regional XYZ Credit Union/Bank that has multiple branches and locations throughout the region.
♣ Online banking and use of the Internet are the bank’s strengths, given limited its human resources.
♣ The customer service department is the organization’s most critical business function.
♣ The organization wants to be in compliance with Gramm-Leach-Bliley Act (GLBA) and IT security best practices regarding its employees.
♣ The organization wants to monitor and control use of the Internet by implementing content filtering.
♣ The organization wants to eliminate personal use of organization-owned IT assets and systems.
♣ The organization wants to monitor and control use of the e-mail system by implementing e-mail security controls.
♣ The organization wants to implement this policy for all the IT assets it owns and to incorporate this policy review into an annual security awareness training program.
Assignment Requirements
Using the scenario, identify four possible information technology (IT) security controls for the bank and provide rationale for your choices.
Required Resources
♣ Access to the Internet
Submission Requirements
♣ Format: Microsoft Word
♣ Font: Times New Roman, 12-Point, Double-Space
♣ Citation Style: APA
♣ Length: 1–2 pages
Assignment 4 - 1 page double spaced:
Assignment 5B
Assignment: Policy Implementation Steps
Learning Objectives and Outcomes
♣ Explain proper policy implementation steps and describe factors relating to its success.
Scenario
Two health care organizations have recently merged. The parent organization is a large medical clinic that is HIPAA compliant. The clinic recently acquired a remote medical clinic that provides a specialty service. The remote clinic is organized in a flat structure, but the parent organization is organized in a hierarchical structure with many departments and medical clinics. These organizations are in the process of aligning their operations. You are asked to make major refinements to the organization’s cell phone use policy immediately.
Assignment Requirements
Read the scenario carefully and then research examples of cell phone policies and implementation. Write a report citing examples of at least three successful cell phone policy implementations found in your research. Indicate how you would analyze your organization, and then how you would identify and finalize a cell phone use policy for the organization. In addition, provide a rationale as to what types of business challenges would be overcome or enhanced.
Required Resources
♣ Access to the Internet
Submission Requirements
♣ Format: Microsoft Word
♣ Font: Arial, 12-Point, Double-Space
♣ Citation Style: Your school’s preferred style guide
♣ Length: 1–2 pages