Information Technology Importance In Strategic Planning
Please make your response posts substantive. A substantive post will do at least TWO of the following: Ask an interesting, thoughtful question pertaining to the topic Provide an outside source (for example, an article from the UC Library) that applies to the topic, along with additional information about the topic or the source (please cite properly in APA) At least one scholarly source should be used in the initial discussion thread. Be sure to use information from your readings and other sources from the UC Library. Use proper citations and references in your post. APA format, 150 words each. Discussion 1) The reality is that all the cyber physical security systems also contain a human component from their design and implementation through to deployment, usage, maintenance, evolution and decommissioning. Within this complex socio-technical system all three components are not only potential points of weakness but may also attack maliciously any other component (Frey et al.,2016). However, the sheer scale, velocity of adoption and pervasiveness of the IoT presents, combined with on-system resource limitations, fundamental challenges to software engineering and how best to ensure the safety and security of the IoT. Recently new methods are analyzed to the role of latent design conditions in impacting security perceptions of operators in industrial control systems and highlighted the challenges posed by smart CPS, notably their emergent design arising from dynamic aggregation of a range of devices and services and the focus on automation that aims to “hide” complexity models from the users. Whilst usability is considered a key non-functional requirement during software engineering and there is a body of research on usable security, emergent design and automation pose key challenges with regards to security behaviors in smart CPS (Kohn et al.,2000). Security measures are designed in five principles for security ergonomics within smart CPS be developed collaboratively by the software engineering, human factors and security communities. Proactive security ergonomic design, not reactive remedy. Design should encourage secure behaviors. By default, secure non-erroneous user behaviors are encouraged and where possible enforced, Non-alignment by default (Schneier, 2016). As human error is inevitable, security ergonomic design should prevent alignment of active error and latent failures. External design validation. Standard software development practices such as automated and unit testing can help with this validation although care must be taken that these themselves are not biased. References: S. Frey, A. Rashid, A. Zanutto, J. Busby and K. Follis, "On the role of latent design conditions in cyber-physical systems security", Proceedings of the 2nd International Workshop on Software Engineering for Smart Cyber-Physical Systems, pp. 43-46, 2016. L. T. Kohn, J. M. Corrigan, M. S. Donaldson et al., To err is human: building a safer health system, National Academies Press, vol. 6, 2000. B. Schneier, Security economics of the internet of things, 2016, [online] Available: https://www.schneier.com/blog/archives/2016/10/security_econom_1.html. Discussion 2) Should organizations invest in physical security? Physical security is essential in organizations since it protects the company’s assets, information, people, buildings, facilities, sites, and premises. Nevertheless, it’s worth investing in since it is essential to safeguard the availability of resources, integrity, and confidentiality (Moses & Rowe, 2016). Furthermore, physical security facilitates comprehensive accountability and security for the overall company. It also ensures that the organization’s information is secure from natural calamity and human misuses such as espionage, vandalism, and sabotage. Technology, procedures, and people are integrated to design a successful physical security system effectively. Hence, the objectives, characteristics, evaluation, and analysis of the system should be measured before design. Furthermore, the models available for the design of physical security are technical, administrative, and physical controls. Technical controls major on access control, which entails various layers of security (Lalonde, 2018). The measures that can be applied to safeguard the organization include audit systems, intrusion detection, and smart-cards. Moreover, the administrative controls encompass measures to design and control physical attacks based on on-site planning, location, and design of business facilities. The countermeasures that can be applied include facility planning methods employed to distinguish the systematic relationship between applications and connections in business. Physical controls restrict access to the organization’s facilities, which has numerous layers of protection of non-employees and employees based on their access level. The countermeasures to ensure physical controls include setting up a fence around the facility, protect entry doors with card readers, and ensuring employees use badge authorization to access the facility. Moreover, CCTV surveillance is an effective method to provide physical security outside and inside the business facility (Jason & Gigliotti, 2017). References Jason, R., & Gigliotti, R. (2017). Approaches to Physical Security. Research Gate, 67-84. Lalonde, M. (2018). Combining Strengths: Cyber and Physical Security Convergence. Research Gate. Moses, S., & Rowe, D. (2016). Physical Security and Cybersecurity: Reducing Risk by Enhancing Physical Security Posture through Multi-Factor Authentication and other Techniques. International Journal for Information Security Research, 667-676.