Cyber Security

profileAneeb
Attachment_1602110906.rtf

Project 1: Policy Analyses

Start Here

It is important to understand a range of organizational policies and the impact of policy content from multiple perspectives in order to create fair, legal, equitable, and ethical policies that support organizational goals. Analysis of personal privacy issues related to various personal and business-related cybersecurity scenarios is pertinent in order to manage cybersecurity risks.

This is the first of six sequential projects. In this project, you will analyze three different types of policies—acceptable use policy, internet use policy, and a retail/commercial company privacy policy—using the ones that have been provided to you, or that you have retrieved from an organization such as Facebook (or another company with which you are affiliated).

You will identify the issues in the policies that you think employees, consumers, or individuals should be concerned about. You will rewrite two to three sections that may be in question, providing justification for your suggested modifications. Relate the questionable content to a recent issue in the news about cybersecurity.

By the end of the course, you will experience and learn the value of drafting and the importance of implementing policies in organizations not only from the company's viewpoint but from the customer/user perspectives.

There are eight steps in this project. Begin by reviewing the project scenario, and then proceed to Step 1.

Transcript audio

Policy Analysis

After introducing yourself as the newly hired cybersecurity analyst, you look around the conference table at the others in your meeting. This multidisciplinary policy development team includes employees from HR, IT, finance and legal.

After introductions are complete, Brian, an attorney from the legal department, begins to speak: “Upper management has tasked this team with reviewing the internet usage policy, acceptable usage policy, and privacy policy. These are the types of policies that we encounter when we are required to sign or click the ‘I Agree’ box as we turn on our business computers or purchase software.”

Brian continues, “We will each need to consider our perspectives and roles on this team throughout the policy development process. We need to balance the writing of the revised policies from the standpoint of the customer and or user while considering business goals. This also means that we will each need to keep in mind aspects such as protecting corporate data, ensuring customer privacy, corporate due diligence, and legal or regulatory compliance respective to our areas of expertise.”

Brian turns to you and says, "Since these three policies are focused on cybersecurity, you will conduct the initial review. Begin by evaluating and rewriting each policy. Then prepare a cover letter summarizing the justifications, including your written evaluation. Please have this ready for our next meeting one week from today.."

Your work will be evaluated using the competencies listed below.

1.1: Organize document or presentation clearly in a manner that promotes understanding and meets the requirements of the assignment.

1.5: Use sentence structure appropriate to the task, message and audience.

2.4: Consider and analyze information in context to the issue or problem.

7.3: Evaluate enterprise cybersecurity policy.

Project 1: Policy Analyses

Step 1: Explore the Cybersecurity Policy Process

Before you begin revising the policies assigned to you, you will need to understand the cybersecurity policy process. First, explore a fictional scenario of insider data sabotage for an example of the ill effects of improper or nonexistent policies. Then read about cybersecurity policies to learn about policies, procedures, and standards as well as how these policies affect the roles and responsibilities throughout the organization. Finally, explore the process of policy creation to guide you through your assignment.

Project 1: Policy Analyses

Step 2: Explore the Components of a Proper Policy

After your exploration of the cybersecurity policy process in the previous step, you are ready to study the requisite policy components of a well-written and implementable policy that will facilitate compliance. Take note of these components as you will apply them to your own policy revisions in the later steps.

Cybersecurity Policy Components

Cybersecurity policies are critical to establishing and maintaining security of networks and data, communicating expectations to employees, and determining consequences for actions. Such policies represent an expression of expectations. Here are the key elements of a good cybersecurity policy:

Definitions, which explain terms in the context of the organization's mission and culture.

Access to computers and data, which explains the processes for gaining access privileges and approvals, and the expectations regarding use of company IT assets. Password expectations would also be established herein.

Use of external (e.g., mobile) devices, to include any restrictions on use of outside devices on internal company IT assets.

Security procedures, explaining the reporting requirements should malicious acts be discovered.

Internet use, to include acceptable use policy and what, if any, filtering might be used. This policy also explains personal use of the Internet on work-related computers.

Data storage and recovery, defining storage requirements (length of time, type of data to be stored), and the expectations regarding recovering from unexpected outages or losses.

Remote access, which explains expectations regarding remote access to company IT assets, and expectations regarding that privilege.

Auditing, which describes frequency and type of review for cybersecurity and IT assets.

Training, which explains requirements for maintaining or learning skills or policies needed for cybersecurity.

Step 3: Identify Evaluation Criteria or Performance Measures

Now that you have identified the components of a proper cybersecurity policy, you will need to identify policy evaluation criteria for the cybersecurity policy. Refer to applicable government and industry cybersecurity standards.

In some cases, you may need to consider criminal or civil liability issues, and thus evaluation criteria may emanate from the judicial guidance. You will apply these criteria to your own policy revisions in the later steps.

Policy Evaluation Criteria

The development and implementation of an enterprise cybersecurity policy is a complex and arduous undertaking. Once the policy is in place, it must be evaluated in accordance with an established process. That process governs the following:

the frequency of evaluation

the criteria on which the policy is assessed

who is responsible for the evaluation

Frequently, organizations across all sectors must comply with a higher-level entity: for instance, an umbrella organization, as often seen in governmental agencies; a governing or accrediting body, as might be the case in professional practices; or the parent company of a subsidiary. When the higher-level entity and the subject organization are regulated by different laws and regulations, either because of geography or because of other distinctions between the two organizations, the evaluation of existing policies develops an additional layer of complexity.

The criteria that serve as the basis for the policy evaluation may be quantitative or qualitative. Either type can be binary, in which the standard simply is or is not met, or may be evaluated along a range of levels. Standards and their methods of assessment must be clearly delineated, in order to enable clear and objective evaluation on the prescribed schedule.

Numerous tools are used to report findings and facilitate planning. One of these is a Kiviat chart, which uses a graphing system to plot values against a radial grid. The Kiviat chart enables analysts to visually map out current levels of compliance compared to a predetermined goal.

Cybersecurity Standards

In today's world, our interactions with various networks are innumerable. Users must place their trust in the owners of those networks to keep their personal and identifiable data secure and private. The network owners must also protect their own assets—proprietary product information, financial details, personally identifiable information entrusted to them, and other valuable data may become targets for theft, corruption, sabotage, or other malfeasance.

To guard against these attacks, organizations must develop and implement sound cybersecurity policies. Fortunately, standards exist to guide companies toward best practices in various aspects of policy development, as well as to comply with cybersecurity regulations in relevant jurisdictions. Professional organizations such as the Institute of Electrical and Electronics Engineers (IEEE) and the International Organization for Standardization (ISO) have published guidelines that can inform policy development. In addition, NIST has developed a framework to guide organizations in developing cybersecurity standards.

The standards are designed to address every aspect of cybersecurity. Guidelines exist regarding user accounts, internal and external communications, physical and virtual security of servers and other network equipment, audit and compliance reviews, user awareness and training, methods of addressing risks, procedures for minimizing damage in the event of a breach, and notification requirements.

A thorough investigation into the relevant and applicable standards is a critical step in the formation of cybersecurity policies for any organization.

Project 1: Policy Analyses

Step 4: Rewrite the Current Acceptable Use Policy

In the first three steps, you reviewed the process of creating security policies, reviewed components of a proper policy, and identified evaluation criteria to measure against existing policies. Now, you are ready to analyze and revise your own organization's policies. Such analysis is likely to be qualitative for some aspects, quantitative for other aspects, and a hybrid for still other aspects of the policy. As such, your choice of measures and analytical techniques must be reasonable and justifiable.

Begin reviewing and updating the first of three security policies for your own organization. Review your organization's current policies, with attention to its acceptable use policy. Determine what changes are necessary and note your suggested changes on the Policy Changes Matrix. Rewrite two to three sections of the acceptable use policy that may be in question and provide justification for your suggested modifications.

The new policy and the Policy Changes Matrix will be attached to the final assignment. Submit the new policy and table for feedback.

Submission for Revised Acceptable Use Policy

Previous submissions

0

Drop files here, or click below.

Submission for Policy Changes Matrix

Previous submissions

0

Drop files here, or click below.

Step 5: Rewrite the Current Internet Use Policy

In the previous step, you revised the acceptable use policy for your organization. Now, you will review and update the second of the three security policies for your organization. Review the details of your organization's current policies, with attention to its internet use policy. Determine what changes are necessary and note your suggested changes on the Policy Changes Matrix. Rewrite two to three sections of the Internet use policy that may be in question and provide justification for your suggested modifications.

The new policy and the Policy Changes Matrix will be attached to the final assignment. Submit the new policy and table for feedback.

Submission for Revised Internet Use Policy

Previous submissions

0

Drop files here, or click below.

Submission for Policy Changes Matrix

Previous submissions

0

Drop files here, or click below.

Step 6: Rewrite the Current Company Privacy Policy

You have just revised the internet use policy, and now you will review and update the last of the three security policies for your organization. Review your organization's current policies, with attention to its privacy policy. Determine what changes are necessary and note your suggested changes on the Policy Changes Matrix. Rewrite two to three sections of the privacy policy that may be in question and provide justification for your suggested modifications.

The new policy and the Policy Changes Matrix will be attached to the final assignment. Submit the new policy and table for feedback.

Submission for Revised Privacy Policy

Previous submissions

0

Drop files here, or click below.

Submission for Policy Changes Matrix

Previous submissions

0

Drop files here, or click below.

Step 7: Write the Cover Letter

After completing the revision process of the acceptable use policy, the internet policy, and the privacy policy in the previous three steps, you will need to prepare a cover letter summarizing the justifications for your suggested modifications for the next team meeting. This cover letter (maximum two pages) will provide an explanation for the Policy Changes Matrix. Address the letter to the CEO, IT, and HR directors. Justifications should be in line with the business goals.

Submit your cover letter and table for feedback.

Submission for Cover Letter

Previous submissions

0

Drop files here, or click below.

Submission for Policy Changes Matrix

Previous submissions

0

Drop files here, or click below.

Project 1: Policy Analyses

Step 8: Write the Policy Revisions Evaluation

Now that you have completed your analysis and revision of the three policies, provide a written evaluation of your organization's cybersecurity policy to present at the next team meeting.

Your evaluation should examine the completeness and compliance of the organization's cybersecurity policy. Consider your organization and organization-related interests as you create your evaluation, and consider other aspects, such as how to prevent the failure of the cybersecurity policy.

Complete the following tasks as you write your evaluation:

Differentiate among the various concepts of enterprise cybersecurity.

Develop a high-level implementation plan for enterprise cybersecurity policies.

Assess the major types of cybersecurity threats faced by modern enterprises (assessing risk).

Discuss the principles that underlie the development of an enterprise cybersecurity policy framework.

Articulate clearly and fairly others' alternative viewpoints and the basis of reasoning.

Identify significant, potential implications, and consequences of alternative points of view.

Evaluate assumptions underlying other analytical viewpoints, conclusions, and/or solutions.

Attach the cover letter, revisions, and Policy Changes Matrix, and submit.

Check Your Evaluation Criteria

Before you submit your assignment, review the competencies below, which your instructor will use to evaluate your work. A good practice would be to use each competency as a self-check to confirm you have incorporated all of them. To view the complete grading rubric, click My Tools, select Assignments from the drop-down menu, and then click the project title.

1.1: Organize document or presentation clearly in a manner that promotes understanding and meets the requirements of the assignment.

1.5: Use sentence structure appropriate to the task, message and audience.

2.4: Consider and analyze information in context to the issue or problem.

7.3: Evaluate enterprise cybersecurity policy.

Submission for Policy Revisions Evaluation

Previous submissions

0

Drop files here, or click below.