Apple- Implementation Plan
Describe in some detail how the firm apple should go about implementing the strategic recommendation. Provide a timeline for implementation, a list of the resources or capabilities the company needs to acquire or develop, some assessment of costs involved (to the extent available financial information allows), the organizational/structural changes required and problems that might be encountered during the implementation. Talk in specifics. (HINT: If you recommend a merger or international strategy, for example, be sure to discuss how the structure/controls will have to change as a result!)
Provide a summary back-up plan. Discuss the conditions under which your strategic recommendation might not work. For example, does your strategic recommendation depend on the economic recovery or interest rates remaining low? If your strategic recommendation cannot be implemented as planned, then what would/could the company do?
(SalesForce)
Implementation Plan
Timeline: 1. Define your audit
a. Salesforce must determine which type of audit will be most beneficial to the company in its entirety, an internal audit or an external audit. External audits are
6
more costly than internal audits because of the time spent gathering all the necessary information and the monetary costs included in hiring a professional company to perform the audit. In comparison to the external audit, the internal audits procedures are a quicker process and the cheaper option for Salesforce. As a group, we have decided to do an external audit with Salesforce to add a perspective when analyzing the possible cyber security threats that may arise with the products and services that Salesforce provides. It is also important to list assets that may be most vulnerable and costly.
2. Define your threats a. After defining which audit has been chosen and listing the assets, Salesforce must
identify the assets that may be most vulnerable and identify possible threats to the most vulnerable assets. The reason for identifying the threats to the most vulnerable assets is important because those are the targets of the audit and may cost Salesforce the most money to repair. For example, the threats can be the security software selected to protect assets, employee mistakes or misuse of company assets, or an attack on Salesforce from a hacker. The threats to the selected assets may overlap, but every possible threat does need to be considered.
3. Assess current security performance a. Although the audit is external, it is important that Salesforce analyzes its current
security measures to ensure that the threats are not coming from an internal source and this additional information will additionally reinforce the data found in the external audit.
4. Prioritize (Risk scoring)
a. This step in the external audit of Salesforce is the most important step because it
will list the threats in the order that they should be prioritized. The threats that will be prioritized consider the current trends of cyber security attacks and industry relevant compromises. Salesforce will then evaluate these results to implement solutions.
5. Formulate security solutions a. Lastly, the list of threats to Salesforce cyber security is created and the process of
implementing the proper solutions can begin. These solutions can include employee training and reinforcing the company’s database.
Resources/capabilities Salesforce needs to acquire or develop:
As it stands, the main resource that Salesforce needs to acquire is a reputable cyber security firm. The better the cyber security firm, the higher quality the resource will be. A reputable cyber security firm will be able to assess most of their vulnerabilities and make sure that their security of their cloud service is improved. One company they can go with is Palo Alto Networks. They focus on securing enterprise and cloud systems as well as protection from future attacks and fast response (Palo Alto Networks, 2020). Since Salesforce operates cloud services, Palo Alto Networks can be a good fit for the company.
After the audit from the cyber security firm they choose to go with. They will then acquire the necessary information needed to improve their cybersecurity from the assessment the company
7
has given. The contents of the assessment will most likely be unique due to the differing methods that each cyber security firm does. The quality of the assessment will also be affected by how good the firm is. The better the cyber security firm, the more extensive their analysis will be and in turn the better the improvements that Salesforce can apply to their security systems.
Cost Assessments:
A cybersecurity audit price structure focuses on the procedure of a general, full analysis and assessment of Salesforce security. There are different penetration testing that is aimed to understand how the organization security functions, how to inform workers about it, and what needs to be done to prevent cyber crimes. The scope of the price for a large enterprise depends on which cybersecurity company Salesforce chooses. For instance, Palo Alto Networks offer a free 90 day assessment prior to deploying full services. Checkpoint Software Securities starts their trial with a free security assessment to learn about Salesforce’s security system before finding the main issues to work on. A large enterprise should expect to pay between $15,000 to $50,000 for a full security assessment, however, there are always additional fees depending on the issues involved in the analysis (Research, 2017).
Organizational/structural changes required:
Because Salesforce is a pioneer in its industry, it may be difficult for even the most knowledgeable 3r d party auditor to understand how the technology works and the culture within the company. Salesforce needs to designate a role to a person or a team to act as a liaison between both parties, to answer questions that arise and to support the audit company. They can help department heads prepare prior to the audit. They may also manage any suggestions or changes that the auditor provides afterwards. This team can be in charge of analyzing whether the changes are in alignment with the company’s mission and culture and enforcing the implementation, as necessary, of the changes suggested.
Potential Problems:
Since cloud computing is still relatively new, its security issues are new as well. Before the cloud, traditional audits consisted of two main components: internal and external. Internal auditing measures the company’s own risk management by grading its security measures and protocols, as well as auditing the employees. The external segment focuses on how well the company is meeting industry regulations and laws. In the past, traditional IT audits have succeeded at maintaining consumer confidence and confidentiality.
However, with this newfound shift preference towards cloud computing, there comes novel problems. With cloud computing, more users have access to the domain which leaves more room for error or theft. Additionally, with cloud computing comes the unique challenge that CSP’s (cloud service providers) must provide their clients access anywhere they have an internet connection in the world, while simultaneously safeguarding their information at all times. Therefore, in order to properly audit a CSP, the security company must be extremely familiar with cloud technology and how it operates. This includes knowing the cloud system’s specific constitution and delivery method. This expertise ensures that auditors test the appropriate
8
security measures and do not overlook any of the top five security factors- scope, complexity, scale, colocation, encryption, and transparency (Aiken, 2015). Therefore, Salesforce must take all of these factors into consideration when selecting the most appropriate third-party auditing company. Failure to select the most competent one could lead to security breaches, stolen information, bad publicity, and a loss of consumer trust which may never be recuperated.
Back-up plan:
Our strategic recommendation is contingent on Salesforce’s clients caring enough about the company’s efforts. If there isn’t a constant rallying effort to get Salesforce to improve their security, then they run the risk of their clients not seeing a security update as one of sufficient value. In the event that the company doesn’t find the results they were looking for, Salesforce might try a marketing stunt to help raise awareness of the importance of such an update. We mentioned above that an alternative strategic option might be for Salesforce to hire hackers to test the weaknesses of their proprietary systems, à la Google’s strategy of doing the same. Despite this option being a legitimate way to make necessary improvements across their software network, Salesforce might instead try to lean into this strategy as a simple marketing campaign. If they publicize this enough, potential clients might become interested in Salesforce’s resource and sagacity and recognize the net benefit of a strong security system — one which even experienced hackers would have trouble getting into.