cybersec polic and planning
· READINGS:
· CHAPTER 4 AND 5
NIST Standards And Guidelines
· SP-800-100, Chapters 2, 4, 8, 9, 10, 13, and 14 - PDF (7.8 MB)
Additional Standards And Guidelines
· PCI-DSS v.3.2, pages 5-19, 20, 36, 50, 66, 88, & 105 - PDF (1.7 MB)
Additional Required Reading
· A Definition of the GDPR, by Nate Lord (Digital Guardian / Data Insider Blog, June 19, 2018)
· Explaining the GDPR to an American, by Rita Heimes (IAPP.org / DPO Confessional Blog, Jan. 30, 2018)
· California Consumer Privacy Act of 2018 (CA Privacy Act website)
·
· Review the three web pages on Ownership, Control, and Security
Briefly Review the following samples of public sector InfoSec policies:
· Australian DoD InfoSec Manual - Executive Companion, 2014 - PDF (2 MB)
· Australian DoD InfoSec Manual - Principles, 2014 - PDF (2.3 MB)
· King County, WA - Enterprise InfoSec Policy - PDF (237 KB)
· Los Angeles County, CA - IT & Security Policy - PDF (506 KB)
· Los Angeles County, CA - IT Physical Security Policy - PDF (323 KB)
· Los Angeles County, CA - InfoSec Awareness Training Policy - PDF (336 KB)
· Nashville, TN - HR Security Policy - PDF (479 KB)
· Nashville, TN - Physical Environment Security Policy - PDF (516 KB)
· Nashville, TN - Governance Statement - PDF (398 KB)
· Orange County, CA - IT Security Policy - PDF (405 KB)
· Orlando, FL - Computer Systems Security Policy - PDF (101 KB)
· Sacramento County, CA - IT Security Policy - PDF (60 KB)
· Sacramento County, CA - Perimeter Security Policy - PDF (20 KB)
· San Diego, CA - InfoSec Policy - PDF (150 KB)
· San Diego, CA - InfoSec Standards and Guidelines - PDF (228 KB)
· San Diego, CA - Acceptable Use Policy - PDF (625 KB)
· San Diego, CA - Protection of Sensitive Data Policy - PDF (696 KB)
· State of California - Chapter 5300 InfoSec Policy - PDF (453 KB)
· State of California - Updated InfoSec Policy (SAM-5300) - PDF (37 KB)
|
Hide Assignment Information |
|
|
Instructions |
|
|
Based on the reading materials and textbook, decide what are going to be your Top 10 InfoSec policies that you are going to recommend to the company you have selected from the three options of Week 1 Homework Assignment. The list needs to be prioritized, so that the most important policy is priority #1, the second most important policy is priority #2, and continuing to the tenth most important policy is priority #10 (this does not make it the "least important" policy - they should all be important). Each policy on the list should have a policy title/subject and include 2-4 sentences to describe/highlight the purpose of the policy. Then, in addition, you need to explain your justification for the priority order of the top 5 policies by providing 3-4 paragraphs to explain why you prioritized them in their particular sequence – as if you are justifying the list to the Owner/CEO.] Assignment outcomes: (1) Prioritized list of top 10 InfoSec policies (with descriptions) and (2) justification for the sequence of the top 5 policies. |
Below is the option chosen from week one
Option #1:
Company Overview: Financial Services company, privately owned (LLP), providing brokerage services for investments and loans, with a primary office in San Diego (Kearny Mesa) and three field offices (in Vista, Poway, and El Cajon) • Company Size: Small Business – 40 employees in total; 1 Branch Manager and 6 staff at each field office, and the Management Team, an Office Manager, and 15 staff at the main office • Management Team: The Owner/CEO, CFO, and COO • IT/Security Services: They contract with third parties for all IT services, which are managed by the COO; they have no internal IT staff and no cybersecurity staff • Company’s Mission: To provide the best brokerage services for our customers, with high rates of return and lowest fees • Technical Environment: They use PCs running Windows 10; an office application suite runs locally on each PC; shared financial applications run from cloud-based services; email is provided through cloud-based services with the capability to send digitally signed, encrypted messages; shared file storage is provided through cloud-based services, with the ability to encrypt files or entire folders/directories; they have a secure Fax machine in each office