Noncompliance of security policies
IT 552 Module Three Assignment Rubric The purpose of this assignment is to examine noncompliance of security policies and possible ways to handle these violations. In addition, students will develop a security policy document, called Rules of Behavior, in order to clarify the security policies. Prompt: The chief information security officer (CISO) reaches out to you again and complains about the interns who appear to be violating many security policies. They do not lock their workstations, download illegal music, connect their personal devices to the organization’s computers, spend too much time on social media, and even download pornography to the organization’s computers. The CISO asks you to address these violations by developing two-page security document (Rules of Behavior) stating at least 15 rules about what activities employees are not allowed to conduct on the network. See the Department of Justice RoB template as a sample. Additionally, write three supplementary paragraphs to discuss what types of training should occur in order to keep these violations from occurring in the future. How can you proactively aim for compliance with these behaviors? Specifically, the following critical elements must be addressed:
Address violations committed by the interns.
State at least 15 rules about network conduct.
Propose future training possibilities with three supplementary paragraphs.
Discuss how businesses can aim for compliance with behaviors. Guidelines for Submission: Your paper must be submitted as a two-page Microsoft Word document with double spacing, 12-point Times New Roman font, and one-inch margins. Your paper must include at least 15 rules regarding network conduct.
Critical Elements Proficient (100%) Needs Improvement (70%) Not Evident (0%) Value
Violations Addresses violations committed by the interns
Minimally addresses violations committed by the interns
Does not address violations committed by the interns
20
Network Conduct Rules
States rules about network conduct Insufficiently states rules about network conduct
Does not state rules about network conduct
20
Future Training Possibilities
Proposes future training possibilities with at least three supplementary paragraphs
Future training possibilities are discussed, but are lacking in detail or length
Future training possibilities are not discussed and/or are not evident
20
Aim For Compliance
Discusses how businesses can aim for compliance with behaviors
Discussion regarding aiming for compliance is minimally addressed
Discussion regarding the aim for compliance is not evident
20
Articulation of Response
Submission has no major errors related to citations, grammar, spelling, syntax, or organization
Submission has major errors related to citations, grammar, spelling, syntax, or organization that negatively impact readability and articulation of main ideas
Submission has critical errors related to citations, grammar, spelling, syntax, or organization that prevent the understanding of ideas
20
Earned Total 100%