proposal for an information security initiative
Network & Information Security, ITSS4360.5u1, Summer 2020 (Homework #2 – Due August 4, 2020 by 11:59pm)
Professor Teaching Assistant
Nate Howe, [email protected] Hong Zhang, [email protected]
Homework #2 is designed to help students combine various lessons from the semester into an organized, logical, and professional proposal for an information security initiative. Students will work individually and assume the identity of the Director of Information Security for a hypothetical organization they describe. Each student will develop a business proposal for an information security initiative for consideration by senior management of a hypothetical organization. Consider the Chief Executive Officer, Chief Financial Officer, and Chief Risk Officer to be the target audience. The proposal will be delivered in the form of a memo which must include all of the requirements listed below to be considered complete.
Each student will submit one Microsoft Word document to eLearning before the deadline of August 4, 2020 11:59pm to be considered for full credit.
a) Background on the organization, including size, core competencies, industry, challenges, and strategic direction. Help the reader imagine the context of the organization where you work as the Director of Information Security.
b) Describe key considerations you have as the Director of Information Security. How would you spend your time protecting the organization, in general?
c) Describe the problem to be solved by your proposal. Consider an unresolved security risk which you believe can be mitigated using the approach you are proposing. It could be a change to people, process, technology, or facilities. It might even involve more than one of those elements. What is the likely impact if the risk is NOT mitigated? Explain why you are confident that your proposed approach will be successful in solving the problem you identified.
d) Is there a regulatory / legal requirement for you to have the security control you are proposing? Consider your industry and refer to other players in that industry who have already suffered security incidents.
e) Are their independent organizations recommending the security initiative you are proposing? Explain what they recommend and why they can be trusted to provide reasonable guidance.
f) If your proposal is approved, what project management considerations have you already developed? What are the risks to the successful delivery of the project? What new processes will be created and necessary to sustain the security controls you have introduced with this project?
g) Will vendor services be needed for your initiative to be successful? Describe those services and give examples of providers that we are likely to engage.
h) What financial costs have you estimated will be associated with your proposal? Distinguish between one-time and recurring annual costs. Distinguish because hardware, software, services, and human labor, as appropriate. Remember to associate the cost of control with the potential cost of an incident, such that it only makes sense to approve your proposal if your project costs less than the incident itself.
i) What training should be developed in support of your proposed change? Will this impact our internal staff and their productivity? Do our external stakeholders, such as regulators, partners, and customers need to be informed?
Students must include citations of all sources of information considered and reviewed. If other students, faculty, professionals working in industry, books, videos, or sources were consulted, links or short descriptions must be included. Submissions including content copied from additional sources but not including references to such source information may be considered incomplete and may receive a reduced score.
From The Syllabus – Homework Assignments
Homework assignments must be submitted on time to receive full credit. Specific details of each homework assignment will be provided in separate documents. Homework is to be submitted electronically using approved UT Dallas systems and must be received by 11:59pm on the assigned date. Late homework will lose one letter grade per day and will be counted as a zero after four days.
Always cite sources and indicate with whom you collaborated. There is no room for dishonesty, plagiarism, or cheating. Properly citing sources and collaborations will help students avoid these pitfalls.