@_ISSC_660 WK 8 Final Project Paper 10 Pages

profileDrAwesome
InformationAssurance_Assignment_.docx

Running Head: INFORMATION INSURANCE PLAN 1

INFORMATION ASSURANCE PLAN 4

Information Assurance Plan

n

U

04/13/2018

Overview of Information Assurance

Heavy Metal Engineering needs to protect all the information pertaining to the organization as well as customer’s data. In order for the organization to increase their offices and customer base worldwide, integration of the current trends in IT to the business processes is not an exceptional (Atallah, McDonough, Raskin & Nirenburg, 2001). However, the organization needs to put in place key strategies to mitigate the network security breaches which arise from unauthorized access to the company’s files. Sensitive documents also need to be protected against stealing hence proper security mechanisms should be implemented. Incorporating BYOD policy to the HME organization will need to be protected from stealing and from accessing unauthorized data. Besides, the organization's equipment needs to be protected from misuse by employees.

Plan and Framework

HME organization main objective is to secure information system and to provide integrity, confidentiality, and availability. Identifying a proper program that meets the security requirements designed to suit the mission criteria of the organization will be critical (Agyepong, I. A.,& Adjei, 2008). Establishing a policy within the organization will be part of the implementation plan in the information plan. Therefore, carrying out activities such as establishing roles and responsibilities of individuals, evaluating the ethical and legal considerations, analyzing threats and vulnerabilities along with establishing a proper framework within the organization will be part of the implementation strategy. The implementation framework will comprise of strategy formulation, implementation, and evaluation.

A complete risk mitigation strategy

Risk mitigation strategy will comprise of identifying the potential risks in the organization including the infrastructural and IT risks. The strategy will consist of identifying the impacts of the identified risks and prioritize them as high, moderate or low. Conducting a Cost-Benefit Analysis alongside every identified risk should be included along with monitoring, scheduling, and spending of the risks (Manuj & Mentzer, 2008). This should be performed in considerations to the mitigation techniques to every identified risk to evaluate whether proposed mitigation is necessary.

Accrediting body

The organization should consider the IT Governance Institute which will help in advancing the international standards and thinking in managing, controlling and directing enterprise’s information technology. The institute aims at achieving IT governance while supporting business goals and managing IT-related risks and opportunities (LAM, 2017).

An incident response and disaster recovery plan

Activities that have an impact on the organization information, as well as computer systems, include malware and intrusion. The disaster recovery plans which focus on larger events for instance terrorism, earthquakes and hurricanes are mutually inclusive to the incident responses in the organization (Atallah, McDonough, Raskin & Nirenburg, 2001). Expanding the type of events to consider while identifying risks is an important aspect. Including the members from every department within the organization and not just viewing the issues as IT related is an important aspect. In addition, performing time to time calculations when performing analysis on outages along with evaluating the impact on widespread outage affecting third parties will improve incident response and recovery plans.

References

LAM, K. W. (2017). INFORMATION AND COMMUNICATIONS SECURITY. Place of publication not identified: SPRINGER INTERNATIONAL PU.

Atallah, M. J., McDonough, C. J., Raskin, V., & Nirenburg, S. (2001, February). Natural language processing for information assurance and security: an overview and implementations. In Proceedings of the 2000 workshop on New security paradigms (pp. 51-65). ACM.

Agyepong, I. A., & Adjei, S. (2008). Public social policy development and implementation: a case study of the Ghana National Health Insurance scheme. Health policy and planning, 23(2), 150-160.

Manuj, I., & Mentzer, J. T. (2008). Global supply chain risk management strategies. International Journal of Physical Distribution & Logistics Management, 38(3), 192-223.