Illustration and Examples of Policies, Standards, Guidelines, and Procedures (Reserve for Brilliant Answers Only)

profilegao1279
IT647DueNowUpdatedFile.docx

Part 1

Chapter 4 - Illustration and Examples of Policies, Standards, Guidelines, and Procedures

Assessment Overview:

Being able to differentiate between the different levels and ideologies in cybersecurity is paramount to a strong security strategy for any company or organization.  As a security specialist, you will be called on to implement different policies, standards, guidelines, and procedures.  More than likely you will be tasked to craft and develop ones for your employer.  In order to be able to accomplish this task successfully, you must be able to know the difference between the different realms.

The assessment for Chapter 4 is to reference the illustration on the bottom of page 179 in the textbook.  Using the definitions provided, you are to find real-world examples of each category.  It is preferred you make a copy of the triangle illustration and add your examples to the triangle illustration.  Along with your diagram, provide a 1-page paper on what is the most important category (in your opinion) in the diagram and why.  Think in terms of security for a medium-sized company...would it be policies, procedures, guidelines, or standards. If you come to the conclusion it would be a mix of these different aspects, but them in rank order -- from most to least important.  

Format Instructions:

Be sure to cite your references using APA style guidelines.  

You can build your triangle using Powerpoint, Visio, or any other drawing software you feel comfortable with. 

It is best to embed your illustration into your paper. 

Part 2

Assessment:

Creating an Internal IT Audit Team Remember that an IT audit is only as good as the team that performs the actual work. You will practice creating an internal IT audit team in this module. As you consider your team you need to address the follow items:

1. Identify the focus for the team

2. Select key positions from which to fill your team

3. Identify key traits or skill sets to look for in members

4. Consider outside assistance such as consultants

5. Make an argument for or against co-sourcing

6. Determine how these audits will add value to the organization

Your assignment is to write a 3 to 4 page paper that addresses each step above. Your paper must include at least two different sources (use credible sources such as peer-reviewed articles, expert blogs, and the textbook, for example). Your well-written response should be formatted according to current APA guidelines, with any sources properly cited.

Part 3

Compare and Contrast US Laws to EU Laws

Assessment Overview:  For this assessment, you are to find 2 US laws and compare/contrast them to 2 EU or UK laws.  Think about the ramifications of not following the laws. Also, discuss what problems the US is facing with the enforcement of their laws and regulations in place.  How is the US enforcing its laws and in your opinion are the sanctions and punishments harsh enough for the crimes being committed? 

A Venn diagram may be helpful in your research and outline.  Please feel free to add to your paper or any other diagram which assists you in writing the essay.

(For one of the EU laws, please consider the newest law which took effect back in May of 2018, the General Data Protection Regulation (GDPR).  You do not have to use the GDPR though.)

Format Instructions:

Write a 2-3 page paper comparing and contrasting 2 US laws to 2 EU laws.  As well as addressing the other areas mentioned in the aforementioned paragraph.

Be sure to cite your references using APA style guidelines

Part 4

Read the Sequential Label and Supply Company (SLS) case study on pages 1 and 2.

Use the information from Chapter 1 (and other references if you wish) to answer the questions below (from page 45 in Textbook):

1. Do you think this event was caused by an insider or an outsider? In your opinion, which is worse, an insider attack or an outsider attack. Explain your answer and back your opinion with scholarly references.

2. Other than installing virus and worm control software, what can SLS do to prepare for the next incident? Think in terms of balancing information security with access to the data.

3. Do you think this attack was the result of a virus or a worm? Does it really matter?  Which one is worse in your opinion? Explain your answer.

Format Instructions:

Be as thorough as you can for each question. Write in a narrative style format; however, ensure you properly label each question so they do not just run into each other.