Presentation on Report to Chris Taylor

profileDivad
317676-1418197-DjenabouDiallo-Sep192022401PM-Report_To_Your_Supervisor_Djenabou_Diallo.docx

Report to Your Supervisor

Djenabou Diallo

UMGC

WRTG 393

Memo

Date: September 16, 2022

To: Chris Taylor (Company Supervisor)

From: Manager; Customer Care Desk

Subject: Company Data Management Crisis

The purpose of this memo is to bring to your notice a data management problem identified by the customer management desk. The business has done a great job developing its IT department to suit consumer expectations and other business requirements, including staff growth. However, it has come to my knowledge that only a small number of responsible directors from each ICT department are legally permitted to use personal credentials to access information on the corporate website. Such is particularly dangerous if any staff member must take a required leave. Additionally, the business can violate a confidentiality agreement involving client information and a cyber-security concern, which would make it liable for any harm or losses. Furthermore, this must be corrected immediately to prevent further harm to the IT division. Comment by Author: Why the big indent here?

Thank you. Comment by Author: A comma, then under this your name would work well.

Executive Summary

The Lawn and Order Service Company has been conducting business for a while and has recently experienced noticeable growth. The company is experiencing a crisis in managing data, which has to be resolved as soon as possible to prevent additional consequences. The key problems are the stringent secrecy and the fact that individual directors control the company's IT departments' security credentials. Access to the business's blog, WordPress website, customer database, and payroll Information technology departments are some of these. (Dvorsky et al., 2021). The fact that each director owns the security information for each department shows that, if any must go, the remaining employees will not have access to the affected department. An absent employee may maintain the company's database improperly. As a result, the business must review its security information management rules at the manager's request so that, in the event of a person's absence, the business would still have access to and control over the relevant database. Comment by Author: The indents are massive--just use traditional spacing/tabbing here? When you format the EC, it’ll “stand alone” in the document. See this UMGC link for some great advice on this; also, we’ll be working on the ES layout in the week 8 discussions. http://polaris.umuc.edu/ewc/web/exec_summary.html?_ga=2.16137974.1558961064.1606924676-1244463797.1594332107 Usually the sections of an ES are: Purpose Methods Findings/Conclusions But we can modify this for the White Paper to better reflect (Problem/Solution/Conclusion). Comment by Author: Is this the actual title? Comment by Author: Is this a crisis? Or a potential one? Comment by Author: Watch some random capitalization...

The organization must support job sharing, mandate vacations, evaluate job rotation rules, amend IT confidentiality policies, and negotiate password and other login information agreements with suppliers to handle this. The outcomes guarantee that personally identifiable information about IT security is not used (Wengler, 2021). The firm will have someone else in charge of managing the relevant website and the company's database if one or more directors are required to miss work due to a mental health issue or other personal reasons. The business will be protected from unforeseen future database control concerns, breaches of private customer information, and cyber-security issues thanks to these modifications being correctly implemented in the IT department. Comment by Author: Remember, you're writing to the boss. You cannot tell him what he must do. You can make recommendations, though!

Table of Cont ents Comment by Author: You won't need the memo or ES in the TOC. Just the data that comes after it… (a small note). Good formatting here!

Contents Memo 2 Executive Summary 3 The Problem 5 Suggested Solutions 6 Conclusion 9 Graphic 10 References 11

The Problem

Due to a sharp rise in consumers and the company's growth in size, Lawn and Order Services has made significant IT advancements. In response, the business created a database for current and former clients for management, a website for the business powered by Word Press for updating information, and a Word Press blog for the business to use as a marketing tool for weekly updates on specials, services, and other important company. Additionally, the business maintains payroll information in a company payroll database. The directors of these divisions are the proprietors of the company's access credentials, including usernames and passwords. As a result, these individuals are the only ones working for the organization with access to relevant information (Bartosova et al., 2021). This is not the best decision for the business because it directly endangers its database. Comment by Author: Good overview Comment by Author: Remember audience--think "this could be risky" and provide limitations on assertions?

Due to unfavorable vendor restrictions and a lack of login security credentials, the firm will not have the legal power to connect to the website and run them. Moreover, the firm may suffer immensely if one or several of the Information Technology heads were sacked by the business, quit their roles for personal reasons, or was compelled to leave due to medical reasons. The issues will arise if the corresponding IT director abuses the data under their control and reneges on customers' agreements on the confidentiality of their personal information, such as identifying information and email addresses. Furthermore, since the corporation lacks access to the data that would have gone with the websites, it will be unable to access and use them. Comment by Author: Show with some specifics from the assignment overview?

Suggested Solutions

The business should be eager to adopt appropriate IT staff policies as soon as possible to solve these issues and prevent unforeseen future threats and damages. As solutions, the customer management desk suggests the following: division of roles, contracts with suppliers that include passwords and other login information, IT confidentiality agreements, employment rotation plans, and mandatory vacation regulations.

a) Separation of duties

This is one of the most significant fundamental building blocks for internal company controls and long-term IT database risk management. The critical tasks of a department or process are divided across several people or departments as part of the separation of roles (Wengler, 2021). For Lawn and Order Services, this will be crucial since it will guarantee that the business has backup staff available to take over for any departments or key IT directors who are unable to work (Figure 1). Additionally, sharing login information will make it less likely for a corporation to lose data due to a single person's absence. It will also lessen the possibility of fraud, misinformation, human-made blunders, and extortion.

b) Mandatory Vacations

This is also a critical decision since it enables an organization to require employees to take a specific amount of time off work every year. The company's feeling of purpose may be revived, and workers' love for their job may be reignited by this policy (Bartosova et al., 2021). Additionally, it will enable the business to use additional staff to manage the location where the director has accepted a mandatory assignment so that, in the event of a complete absence, the business will have someone available to manage the location or department and carry out similar responsibilities as the absent worker. Comment by Author: Makes sense!

c) Job rotation policies

Policies governing job rotation might be crucial in resolving this situation and averting more harm. It will function by temporarily delegating a worker from a similar IT department to carry out the specific responsibilities of a different worker in the same department. It will assist the business in developing a staff of reserves to fill in for any absent directors now or in the future, whether for temporary absences or permanent termination (Bartosova et al., 2021). It ensures the business will function successfully with or without a particular employee. Additionally, it will enable the business to recognize employee potential and spend money on departmental training when new skills are required.

d) Agreements with vendors, including password and other login information

The corporation should thus review the contracts stating the supplies of services and goods, such as date, time, and place, in the vendors' agreements with the various department heads and directors. Doing this will make it impossible for anybody to steal the business' credentials or other crucial information (Dvorsky et al., 2021). Additionally, it will enable certain vendors to give login credentials to the business to prevent misuse by any level of terminated personnel. The organization will also need to agree with the suppliers to provide the management with direct control over how the site is used and run so that any non-current employee of the company cannot access the websites. Comment by Author: Good data/discussion on this page and clear tone.

e) IT confidentiality agreements

Keeping passwords and another website information private between employees, employers, service providers, and the firm management is equally crucial for the business. Such will prevent the incorrect people from using these people's personal information at any moment and misusing the company's IT database (Wengler, 2021). Keeping the company's ideas and some sensitive information private will be required. Additionally, this will protect the clients from information misuse.

Conclusio n Comment by Author: Format-wise, I think you can bump this up to the prior page.

The need for prompt action is exceptionally strong to prevent the organization from suffering adverse effects. IT database management issues either now or in the distant future. The management should move quickly to implement procedures like job rotation, separation of tasks, and vendor agreements that include IT confidentiality agreements, passwords, and other login information. The database for this firm will be incredibly safe.

Graphic Comment by Author: Label the graphic? I imagine this graphic is borrowed from the web. Add a citation for it on this page.

The design of the office will permit unlimited office access anytime the accountable employee is away, preventing the absence of personnel from impeding business operations. Comment by Author: This doesn’t seem to directly reflect any of the problem or solution content, though. For example, an open office layout doesn't mean direct access to computers.

References

Bartosova, T., Taraba, P., & Peterek, K. (2021). Approach to the risk management process in logistics companies. Chemical Engineering Transactions, 86, 403-408.

Dvorsky, J., Belas, J., Gavurova, B., & Brabenec, T. (2021). Business risk management in the context of small and medium-sized enterprises. Economic Research-Ekonomska Istraživanja, 34(1), 1690-1708.

Wengler, D. D. (2021). A Segregation of Duties Teaching Case Regarding Employee Fraud in a University Athletics Department. Journal of Forensic and Investigative Accounting, 13(2). Comment by Author: Italicize journal names and add page numbers.

image1.jpeg