IT 549 Milestone Four Guidelines and Rubric
IT 549 Milestone Four Guidelines and Rubric One of the most important aspects of information assurance is ensuring that proper policies and procedures are established within an organization . Without proper policies and procedures, there would be no order. By implementing appropriate statements of policy and developing effective procedures, IT administrators ensure that incidents can be appropriately responded to, and that individuals within the organization understand their roles within the information assurance plan. Individuals in an organization would not be able to adequately understand their roles without the establishment of these statements of policy. Prompt: In Module Seven, you will submit your plan pertaining to statements of policy. You will establish protocols and mitigating factors to the organization. Justify how the disaster response protocols will mitigate the threats to and vulnerabilities of the organization. You will fo cus on disaster and incident response protocols as well as access control. Assess your proposed method for maintaining the success of the plan going forward. Justify how your method will ensure the ongoing effectiveness of the information assurance plan. Specifically, the following critical elements must be addressed:
IV. Statements of Policy
a) Develop appropriate incident response protocols to respond to the various threats and vulnerabilities identified within the organization. b) Justify how the incident response protocols will mitigate the threats to and vulnerabilities of the organization. Support your justification with
information assurance research and best practices. c) Develop appropriate disaster response protocols to respond to the various threats and vulnerabilities identified within the organization. d) Justify how the disaster response protocols will mitigate the threats to and vulnerabilities of the organization. Support your justification with
information assurance research and best practices. e) Develop appropriate access control protocols that provide an appropriate amount of protection while allowing users to continue to operate
without denial of service. f) Justify your access control protocols. Support your justification with information assurance research and best practices. g) Recommend a method for maintaining the information assurance plan once it has been established. h) Justify how your maintenance plan will ensure the ongoing effectiveness of the information assurance plan. Support your justification with
information assurance research and best practices.
Rubric Guidelines for Submission: Your paper must be submitted as a three - to four-page Microsoft Word document with double spacing, 12-point Times New Roman font, one-inch margins, and at least three sources cited in APA format.
Critical Elements Proficient (100%) Needs Improvement (75%) Not Evident (0%) Value
Incident Response Protocols
Devel ops appropri ate i nci dent res pons e protocol s to res pond to
the vari ous threats and vul nerabi l ities i denti fied
Devel ops i nci dent res pons e protocol s to res pond to the
vari ous threats and vul nerabi l ities i denti fied, but they are not al l appropriate or do
not res pond to al l the threats and vul nerabi l iti es
Does not devel op i nci dent res pons e protocol s
12
Justification of Incident Response
Protocols
Logi cal l y justi fies how the i nci dent res pons e protocol s wi l l mi ti gate the threats to and
vul nerabi l ities of the organi zation wi th s upport from i nformati on as s urance res earch and bes t practi ces
Jus ti fi es how the i nci dent res pons e protocol s wi l l mi ti gate the threats to and vul nerabi l iti es
of the organi zati on wi th mi ni mal s upport from i nformati on as s urance res earch and bes t practi ces , or jus ti ficati on i s
i l l ogi cal
Does not jus ti fy how the i nci dent res pons e protocol s wi l l mi ti gate the threats to and vul nerabi l iti es
of the organi zati on
12
Disaster Response Protocols
Devel ops appropri ate di s aster res pons e protocol s to res pond to the vari ous threats and vul nerabi l ities i denti fied
Devel ops di s aster res pons e protocol s to res pond to the vari ous threats and vul nerabi l ities i denti fied, but
they are not al l appropriate or do not res pond to al l the threats and vul nerabi l iti es
Does not devel op di s as ter res pons e protocol s
12
Justification of
Disaster Response Protocols
Logi cal l y justi fies how the
di s as ter res pons e protocol s wi l l mi ti gate the threats to and vul nerabi l ities of the organi zation wi th s upport from i nformati on
as s urance res earch and bes t practi ces
Jus ti fi es how the di s aster
res pons e protocol s wi l l mi ti gate the threats to and vul nerabi l iti es of the organi zati on wi th mi ni mal s upport from i nformati on
as s urance res earch and bes t practi ces , or jus ti ficati on i s i l l ogi cal
Does not jus ti fy how the di s as ter
res pons e protocol s wi l l mi ti gate the threats to and vul nerabi l iti es of the organi zati on
12
Access Control Protocols
Devel ops appropri ate acces s control protocol s that provi de an
appropri ate amount of protecti on whi l e al l owi ng us ers to conti nue to operate wi thout deni al of s ervi ce
Devel ops acces s control protocol s , but they do not
provi de an appropri ate amount of protecti on whi l e al l owi ng us ers to conti nue to operate wi thout deni al of s ervi ce
Does not devel op acces s control protocol s
12
Justification of
Access Control Protocols
Logi cal l y justi fies the acces s
control protocol s wi th s upport from i nformati on as s urance res earch and bes t practi ces
Jus ti fi es the acces s control
protocol s wi th mi ni mal s upport from i nformati on as s urance res earch and bes t practi ces , or jus ti fi cation i s i llogical
Does not jus ti fy the acces s
control protocol s
12
Method for
Maintaining the Information
Assurance Plan
Recommends a comprehens i ve
method for mai ntai ni ng the i nformati on as s urance pl an once i t has been es tabl i s hed
Recommends a method for
mai ntai ni ng the i nformati on as s urance pl an once i t has been es tabl i s hed but recommendati ons are not ful l y
devel oped
Does not recommend a method
for mai ntai ni ng the i nformati on as s urance pl an once i t has been es tabl i s hed
12
Justification of Maintenance Plan
Logi cal l y justi fies how the mai ntenance pl an wi l l ens ure the ongoi ng effecti venes s of the
i nformati on as s urance pl an wi th s upport from i nformati on as s urance res earch and bes t practi ces
Jus ti fi es how the mai ntenance pl an wi l l ens ure the ongoi ng effecti venes s of the i nformati on
as s urance pl an wi th mi ni mal s upport from i nformati on as s urance res earch and bes t practi ces , or jus ti ficati on i s
i l l ogi cal
Does not jus ti fy how the mai ntenance pl an wi l l ens ure the ongoi ng effecti venes s of the
i nformati on as s urance pl an
12
Articulation of Response
Submi s s i on has no major errors rel ated to ci tati ons , grammar, s pel l i ng, s yntax, or organi zati on
Submi s s i on has major errors rel ated to ci tati ons , grammar, s pel l i ng, s yntax, or organi zati on that negati vel y i mpact readabi lity
and arti cul ation of mai n i deas
Submi s s i on has criti cal errors rel ated to ci tati ons , grammar, s pel l i ng, s yntax, or organi zati on that prevent unders tandi ng of
i deas
4
Earned Total 100%