Managing security information systems
Case-4 Managing and assessing information and security policy
Assignment Overview
The Information Security Blueprint is the basis for the design, selection, and implementation of all security program elements. The blueprint builds on top of the organization's information security policies and it is a scalable, upgradeable, comprehensive plan to meet the organization’s current and future information security needs. The blueprint is a detailed version of the information security framework, which is an outline of the overall information security strategy for the organization and a roadmap for planned changes to the information security environment of the organization. Security education and training is an important part of the Information Security Blueprint.
Case Assignment
Assignment Expectations
Describe your results. Put them in a table describing the training program and cost. You will assess the programs in terms of time, money, and effectiveness. Summarize with a discussion of the key characteristics for Web security and training programs.
Background Readings:
Read Chapters 13 to 16 Andress, Jason and Winterfeld, Steve (2014). Cyber warefare: Techniques, tactics and tools for security practitioners. Syngress, Waltham, Ma. (ISBN: 9780124166721). Available in the Trident Online Library.
Read chapters 1, 2, and 3 Chappel, M. Ballad, B., Balad, T. and Bnks, E.K. (2014). Access control, authentication, and public key infrastructure. Jones and Barlett Learning, 2nd Edition
Chapters 6 and 7 Gordon, A. (2015). Official (ISC)2 guide to the CISSP CBK, Fourth Edition, CRC Press.
Business Continuity and Disaster Recovery https://www.youtube.com/watch?v=W3GdGemRGXo
Business Continuity Planning and Disaster Recovery https://www.youtube.com/watch?v=vGND4tvzVYg
Developing a Disaster Recover and Business Plan. https://www.youtube.com/watch?v=gQCTkX4M3VY