As a group, discuss the topics listed below on policy and procedure governance. Produce a 4–8 page paper with the results of your discussion. This paper will be added to the Information Technology (IT) Governance Policies and Procedures Manual that has al

profileMichelle_Michy
ITandInformationSecurityGovernance1.docx

Running head: IT GOVERNANCE POLICIES AND PROCEDURES 1

IT GOVERNANCE POLICIES AND PROCEDURES 9

IT Governance Policies and Procedures

Name

Institution

Contents IT Governance Policies and Procedures Manual Title Page 3 Business and IT Goals 4 Business Goals 4 IT Goals to Support the above Business Goals 5 Conflicts between the two Sets of Goals 5 Information Technology Governance and Information Security Governance 6 Summary 6 Similarities and Differences 6 Regulatory Requirements 6

IT Governance Policies and Procedures Manual Title Page

IT Governance: Policies & Procedures Manual, 2019 Edition  is the PMG Company’s apex reference tool used for decision-making to help the company in devising an information systems policy and procedure program uniquely tailored to the needs of the organization.

Other than extensive policies it provides, it is also a valuable resource that often issues information an individual may be in need of

IT Governance: Policies & Procedures   Manual provides unilateral access to blue print information that relates to:

· Policy and planning

· System security and accompanying documentation

· Systems analysis, design, and engineering

· And other intricate details pertaining to PMG information systems’ policy

LAST UPDATED

03/05/2019

FREQUENCY OF UPDATE

annual basis

COMPANY

PMG Company

Information security laws refer to the body of codes, legal rules, and standards that require one to protect information systems and information from all forms of unauthorized access. In the current data-driven economy, it is essential to comply with information security laws and regulations. Failure to comply often facilitates data breaches which results in costly sales and financial losses and leaks client's private information (Stoneburner, Goguen, & Feringa, 2002). When these breaches occur, they are likely to drain an individual's bank accounts, ruin lives and sink businesses. In addition, information security laws and regulations are essential because they benefit companies through;

Improved Security: IT security laws and regulations enhance an organization’s security measures by stipulating baseline requirements. As a result, business data-security levels remain consistent with the respective organization’s requirements. Compliance with the baseline requirements facilitates protection of data which improves security (Whitman & Mattord, 2013)

Reduced Losses: Information security laws and regulations improve security levels which help to reduce breaches which are costly to organizations. These costs are often associated with repair costs, legal fees and sales among others which can be avoided by complying with IT security laws and regulations. The costs related to the replacement of lost data and compromised information is an added cost to the organization.

Increased Control: Security laws and regulations provide an organization with increased control over employee mistakes, insider theft, and outside threats. Their ability to stay updated with activities and undertakings in the company increases control which promotes security.

Increased Trust: Security data increases customer confidence in the service provider. By promoting information control, security laws enable businesses to gain trust from their customers with regards to their information. Improved trust means that the business has access to increased businesses and promotions hence growth.

Interpret the impacts of information security laws and regulations on your information security program.

An efficient information security program at the PMG will facilitate the integrity, confidentiality, and availability of customer information and the company's essential data. Considering the increasing security incidents and breaches, it is crucial to comply with information security laws and regulations. This is important because, fundamental concepts of information security program such as privacy, integrity, confidentiality, authentication, and availability depend on the development, design, and implementation of technological processes and solutions which are the primary pillars security laws and regulations. This means that IT security laws and rules facilitate compliance with fundamental concepts of the information security program. Also, IT security laws and regulation will promote voluntary compliance with the requirements of the information security program such as the establishment of security benchmarks, compliance, and execution of the benchmarks.

List and describe the information security risks with attention to the organizational, governmental, and regulatory requirements that your organization may face.

Organizational Requirements

Today, many organizations have requirements to depend on uninterrupted connectivity which predisposes them to attacks on the internet infrastructure. Many organizations lack backup for information utilities due to the over dependency on the internet. As a result, these organizations are vulnerable to external threats on the company infrastructure, on the devices and employees. Other organizations often neglect the importance of configuring various security settings efficiently.

Regulatory Frameworks

While regulatory frameworks are intended to increase security, lack of encryption often facilitates attacks by external threats. This predisposes sensitive data to attacks when in transit and at rest. Besides, regulatory requirements are expensive and lengthy and can be tiresome causing organizations to evade them hence causing a security breach.

Governmental Requirements

Government regulations may cause information to suffer the loss of credibility, privacy, and confidentiality due to unauthorized access. The government may be authorized legal access in the event of suspicious dealings and fraudulent businesses. Instead of infringing on personal privacy, the government should improve security practices; restrict public disclosure of cybersecurity information and sensitive personal information. It should also provide funding to support cybersecurity initiatives and programs and promote activities that facilitate information security such as training, workforce and economic development.

Prepare Policies and Procedures to Address the Risks.

PMG Company should understand its extent on internet reliance to address risks of attacks that occur on a frequent basis. The company should also engage with external and internal stakeholders and regional bodies such as the government and regulatory bodies to create contingency plans in the event of a risk (Bulgurcu, Cavusoglu, & Benbasat, 2010). The company should also align the contingency plans of communication provider with organizational plans to ensure existing plans are addressed.

Define the baseline controls that will be used to measure the effectiveness of your strategy and describe how these data will be collected and used for auditing and improvement purposes.

The company aims at reducing related redundancies in the company to improve efficiency through proper use of database normalizations to make the best use of available storage. It can be controlled through proper use of foreign keys. The company also aims to eliminate duplicated groups in the individual tables and to identify every set of data with a different primary key. The company shall also create a separate table for all related sets of data to avoid data duplication. Data for this activity will be collected through control of available data for improvement and auditing purposes.

One Shortest Path First (OSPF) and Enhanced Interior Gateway Routing Protocol (EIGRP) strategy are intended to promote efficiency by reducing the cost of network maintenance by half. To measure the effectiveness and performance of this strategy, the company will analyze expenditure of the second fiscal quarter to show whether the company costs have reduced by half at the end of the second fiscal quarter (Whitman, & Mattord, 2013).  Data to analyze this strategy will be obtained by comprising various types of routers, networks, routes, areas, and protocols used in the OSPF.

References

Bulgurcu, B., Cavusoglu, H., & Benbasat, I. (2010). Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness. MIS Quarterly, 34(3), 523-548.

D'Arcy, J., Hovav, A., & Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse A deterrence approach. Information Systems Research, 20(1), 79-98.

Maras, M. H. (2015). Computer Forensics. Jones and Bartlett Learning.

Stoneburner, G., Goguen, A., & Feringa, A. (2002). Risk management guide for information technology systems. Nist special publication, 800(30), 800-30.

Whitman, M., & Mattord, H. (2013). Management of information security. Nelson Education.

.