Using your enterprise security plan proposal as a guide, write the enterprise technical infrastructure security plan for the organization. The framework should describe the technology infrastructure
|
Running head: ENTERPRISE SECURITY POLICY |
1 |
|
ENTERPRISE SECURITY PROPOSAL |
5 |
Enterprise Security Policy
Jamarious Jones
Bellevue University
09/25/2020
ASSURANT INSURANCE SECURITY POLICY
1. Overview
Contemporary companies rely on information as one of their primary organizational assets in the course of their operations. Consequently, data management is an integral part of corporate governance and running. Like all assets, information is valuable, and as such, a vulnerable asset that risks losing value in the event of loss, damage or distortion and misrepresentation.
Regarding Assurant Insurance’s primary objective of establishing practical and functional systems aimed at guaranteeing user convenience, the policy herein focuses on providing a roadmap to confidentiality and operational availability of data management and security protocols. The policy also seeks to protect company data from any form of compromise from any source whatsoever.
In line with the objectives mentioned earlier, the policy appeals for collective involvement in ensuring data security for the company. Holistic active participation in protection measures is geared towards preventing unauthorized access, use and modification of company data, and mitigating destruction and avoiding delay in service.
2. Purpose
This policy aims to guide Assurant Insurance employees on the best possible way of achieving the security threshold for data security; confidentiality, integrity, and availability.
It also seeks to encourage all employees to use all the facilities provided for by the company to effectively enhance data security within their respective organizational jurisdictions.
3. Scope
The Assurant Insurance Security Policy is a document addressed to all company employees whose job descriptions require the application of computers and computer-related devices. However, the particular emphasis is directed at individuals serving in the IT Department as they have supervisory discretion over all other staff members on matters of Information Communication Technology.
4. Risk Management and Security Principles.
4.1 Organizational Roles.
Dealing with the company’s security threats requires all company stakeholders' involvement, albeit in different ways. Each individual contributes to the safety of Assurant Insurance as per their qualifications and job description in the company organizational structure. The absence of an organization undermines order, which interferes with the ability to function correctly.
4..1.1. User Responsibilities.
All users, regardless of the job dispensation, are expected to follow specific guidelines recommended by I.T experts to enhance system security within the organization. Such recommendations for all users include;
1. Compliance with security procedures and protocols.
2. Protecting one’s user ID and password
3. Inform the I.T and Risk Management Department of any security issues, problems or concerns with your system as soon as they arise.
4. Back up all the systems that support I.T systems on your desk.
5. Value awareness of vulnerabilities and intrusions and report in case of an incident.
4.1.2. System Administrator.
The system administrator has access to hubs, firewalls, routers and host systems, which help their functional roles.
He/she is responsible for regular system checks of allocated work stations and even scheduled checks on the system.
Administrator passwords for individuals who’ve been terminated are cleared as soon as they exit the building. Due to their nature's sensitivity, admin passwords require more frequent updates than the recommended two weeks for other employees. Password updates for administrators are undertaken every 72 hours.
4.1.3. Manager’s Duty.
Managers serve as the ultimate link between employees and the I.T department. For security, they shall charge the I.T department with updating the security protocols of any compromised employee. Other than that, managers could only play a supervisory role over the employees to enforce clauses of the security policy.
4.2. Planning Processes.
Planning for security and management of organizational data is a cyclic process with no definitive ending. As information evolves, so does threats and various intrusions techniques that malicious individuals apply.
However, risk assessment provides an insight into certain aspects of system security and vulnerability. If the resultant insight is harnessed correctly, it could be the first line of defense.
4.2.1. Risk Assessment.
Standard risk management procedures call for problem identification and speculation of its impact on the organization based on size and intensity and its effect on the organization.
Risk assessment protocols include a survey on current security trends, identification of Assurant Insurance’s most valuable data asset and establishing ways through which an intruder may try to gain entry.
Each of those steps requires regular monitoring and reports, and establishing a proper chain of communication meant explicitly for the assessment process.
5. Policy
1.1. Information Classification
For the purposes of security, company employees only have access to information relevant to their work. In that way, a compromise on a single employee’s dataset only affects a section of Assurant Insurance. Also, office data for higher ranking receive more security attention based on the magnitude of such data as well as the sensitivity they bear.
1.2. Encryption.
Like classification, encryption works in a discriminatory manner and the choice of encryption level attained for a device depends on an employee’s position in the company. However, each employee’s device has some level of encryption within to at least provide security cover.
1.3. Non-Employee Personnel and Security.
For non-employee personnel with essential business to conduct with any of Assurant Insurance personnel, they are granted temporary clearance for access to the company’s system under the watchful eye of the employee they engage and an appointed I.T escort. Their clearances are as valid as their presence in the building and once they are gone, the system on which they worked undergoes a security update. As for security, they have access to employee logs matching a device/company resource to a particular employee but nothing more.
1.4. Application Communications.
When sharing information and applications have to interact, the employees responsible have to ensure that each device is in the standard security status. On that note, employees are discouraged from using personal communication devices to handle work issues since it opens the door for security compromises.
1.5. Viruses and Malicious Code.
For viruses and malicious codes, employees are required to activate ad blockers for certain sites under the direction of an employee from the I.T department. Also, anti-virus and anti-malware updates for each resident computer is available for each computer subject to request from an affected employee. In the case of a virus infraction into a computer though, the affected employee should quickly log out from any network in a bid to prevent further spread before consulting the I.T department.
1.6. Physical Security.
While it still remains a source of risk for data security, instances of physical infringements into an organization’s data space are on the decline today. However, there still lies need for precaution and the introduction of various protocols for physical security. For starters, having a fixed security presence in the form of guards could be helpful. Also, embracing the practice of multiple locks to secure a device protects it from physical harm.
1.7. Incident Reporting and Response.
The greatest asset in possession of an organization during times of crises is an efficient response protocol. In case of any issue that threatens the security of a system, Assurant Insurance employees are expected to act fast and decisively to quash the situation in its premature stages. The point of origin (employee affected) should sound an alarm by sending an alert and exiting the system altogether. For extreme cases, total system shutdown is acceptable since the company has a backup server. After exiting the system, the affected employee has to report to the ICT security manager the events of the incident in detail and with clarity.