EDMG_600 Wk 7/8 Final Ass 10 Pages

profileDrAwesome
LASTWEEKFEEDBACK.doc

Running head: CYBER SECURITY 1

CYBER SECURITY/EMERGENCY MANAGEMENT POLICY 2

The term "Running head" is formatted as Running head:

Cyber Security/Emergency Management Policy

American Public University (EDMG 600)

Dr. Darrell Dantzler

05/09/2018

Cyber Security/Emergency Management Policy

Begin the paper with an introduction of your topic. An introduction has an attention getter, purpose or thesis statement, and an overview. An attention getter can begin with any of the 6 ways: (1) Anecdote, (2) Question, (3) Quotation, (4) Humor, (5) Shocking Statistic, or a (6) combination of them ( http://classroom.synonym.com/5-types-attention-getters-essays-2877.html ). After you introduce the topic, state the purpose of the paper. The purpose can be as simple as restating the objective of the assignment. The purpose of this paper is to (state purpose). (Overview) The paper will address the following: (List topics)

Part 1

After reading Moore at al. (2010), Goodyear, Portillo, Goerdel & Williams (2010) and Deloitte-NASCIO (2013), develop a cyber security/EM Policy Analytical model in which you will recommend and justify the most effective way to manage emergency management related cyber security issues at the state level.

Cyber Security

Cybercrimes are increasingly becoming more common in all sectors in the world. This has made cyber security a top agenda for everyone in the world. This has resulted in the conventions and creation of agencies and structures that will facilitate cyber security (Deloitte-NASCIO. 2013, p 16). According to the author, a number of cyber laws have been formulated and more are being formulated to handle this challenge. For this matter, protecting our companies from various incidences of cyber-crimes, we will need to formulate clear and organised policies that will pit every structure in place to check the menace (Deloitte-NASCIO. 2013, p 34). Since internet is a gala for vast information in which everyone and business navigate through, with different intentions, protecting personal and company sensitive information is increasingly becoming a challenge (Moore et al., 2010, p 56). Cyber security policy will try to track the paths of the internet users in order to control their navigation and keep it on the recommended or acceptable tracks. Allowing internet users to deviate from the pre-determined and acceptable paths, as are stipulated in the policy, will lead to discrepancy in the use of information on the internet thus risking accessibility and sharing of sensitive information without permission (illegal). When personalised or sensitive information reached the public pages of the internet, it becomes irretrievable and loses secrecy. This is the major concern of most governments. Hackers have been able to exploit the Operating System (OS) of people’s computers, accessing and leaving the gathered information in the public domain and attackers (Goodyear et al., 2010, p 36).

Cyber security/Emergency Management Policy

A number of policies need to be put in place to bar internet user and the hackers from accessing, gathering and sharing personalized or sensitive information to the public or exposing it to the hackers. Most citizens are not conscious of the existing cyber security policies and so still believe that it is the work of the government to ensure internet is free from hackers and that their information is safe.

Policies Recommendation

The policies I will recommend are, educational or capacity building among the internet users’ policy, the continuous cyber security research framework, incident response, personal device use, email, data sharing and security of devices policy.

Justification of Policies

As a government with such a challenge, the most profound policy will be education awareness policy. Educational program will be aimed at sensitizing individuals about their specific roles in cyber security and personalized or sensitive information protection (Goodyear et al., 2010, p 45). Educational campaigns can also be used to create awareness about information encryption, sharing and other sensitive cyber security concerns in order to help them become more conscious internet users who understand the detrimental effects of not taking measures to secure sensitive information from hackers. This is especially good in this times as the world of social media, e-commerce and digitization of most of the sectors in the world is taking place. Most of this information will need to be protected and kept at bay from the attackers (Deloitte-NASCIO. 2013, p 12).

Establishment of a continuous cyber security framework is important and will help to critically look into the emerging techniques and the recurrent trends in cyber security and also assist in the designing emergency management systems that will reduce the damage in the event the attack occurs (Moore et al., 2010, 48). The framework will ensure a specialized plan is put in place in order to address cyber security concerns. It will facilitate local and state level cyber security structural formulation, establishment of cyber security agreements, coordinating all state entities to realize synergy as they work together and involvement of the private sector in order to fight the wide scope and growing cyber security concerns (Goodyear et al., 2010, p 24). This will facilitate sharing of cyber security information (attack and threats information) thus pooling together resources to fight the cyber risks and reduce the damages associated with it. According to Goodyear et al. (2010, p 25), formation of a partnership between the private sector and the public sector and coordinating the federal resources and the state will be paramount.

Incident response policy will facilitate federal and national awareness of their responsibilities in use of intervention tools in the response towards a cyber-attack. The policy will level communication grounds and establish a formidable structure in order to alleviate breakdown in outreach program about cyber threats and response actions during an attack in order to achieve high responses and quick action. Response policy to address agency tactic gaps and lack of intervention tools and will also enforce other tactical responses. It will enhance roles of the state, federal agencies, managers and facilitate efficient decision making process among the agencies during the attack (Goodyear et al., 2010, p 29).

The policy governing use of personal device will restrict the use of personal devices to access company information, unless it is a closely monitored and safely kept device. The devices should protected by passwords, will encourage the use of safe networks only, keep security software updated and upgraded and also ways to lock the devices when not in use (Moore at al., 2010, p 102).

Emailing and data sharing policy is a good policy that will ensure emailing, data sharing is monitored, including the protection of the devices being used. Moore at al. (2010, p 33), recommends that the company should put in place a policy that discourages opening of attachments sent to the company unless the source is known and is safe. The massagers will be prompted to identify the inconsistencies and identifies of the senders. Data sharing should only be done using the company network and lastly, a disciplinary action policy. A number of warnings, termination of employees and networks, evaluation and case-by-case assessment of the breach will be conducted (Goodyear et al., 2010, p 45).

References

Goodyear, M., Goerdel, H., Portillo, S., & Williams, L. (2010). Cybersecurity management in the states: The emerging role of chief information security officers. Retrieved from

Deloitte-NASCIO. (Date). “ 2014 Deloitte-NASCIO Cybersecurity Study: State Governments at Risk: Time to Move Forward,” Deloitte Developmental LLC, October 2014, http://www.nascio.org/publications/documents/Deloitte-NASCIOCybersecurityStudy_2014.pdf

Moore, T., Pym, D. J., & Ioannidis, C. (2010). Economics of information security and privacy. Springer.

Part 2 

After reading the article, respond to the following  four questions bellow. Separate each response with the sub-headed question statement):

Way forward for cyber security

According to me, cyber security need to be devolved to individual companies and internet users but at the same time monitored by both private and governmental agencies collaboratively (Jayawardane et al., 2015, p 23). This should be formulated in a clearly guided policy in which pre-determined super governing agreements will be entered into among the agencies in order to ensure every party plays its role. This will help pool resources and intervention tools together and fight a common battle through a common channel and thus reducing inter-agencies supremacy and tactical battles thus mitigating the effects of cyber incidences and reducing the threats (Carr, 2016, p 56).

Applicability of traditional regulatory model

Yes! A traditional model will work in this space. The model will bring together the federal and state governments on one table, and partner with the private sector to fight the common battle with a common goal (Jayawardane et al., 2015, p 46).

Need for a new cyber security model

Yes! A newer model to fight the 21st century cyber security issues need to be developed. This model should incorporate the traditional model with modifications due to the emerging cyber security challenges in which individual internet users should come in. the model should make it clear that the responsibility for cyber security in everyone’s. According to Clinton (2011, p 97), cyber space is rapidly changing and so the model to be developed should incorporate psychological and behavioral approaches in understanding the tactics of the cyber attackers and also include the tracking of the various serves with strictly monitored technologies

Government regulation

The government should regulate every internet user and the companies hosting web pages . The owners of the cyber space should also be closely monitored by the government (National Research Council Group, 2010, p 23).

A research question for further research

To conclude, we need to find out if the attackers have their cyber technology laboratory where they carry out attackers or are inside employees and therefore formulate a policy that will regulate employees’ movements or track the hackers’ cyber space.

Conclusion

Conclusions wrap up what you have been discussing in your paper. After moving from general to specific information in the introduction and body paragraphs, your conclusion should begin pulling back into more general information that restates the main points of your argument. Conclusions may also call for action or overview future possible research. The following outline may help you conclude your paper:

In a general way,

· Restate your topic and why it is important,

· Restate your thesis/claim,

· Address opposing viewpoints and explain why readers should align with your position,

· Call for action or overview future research possibilities.

References

Carr, M. (2016). Public–private partnerships in national cyber‐security strategies. International Affairs92(1), 43-62.

Clinton, L. (2011). A relationship on the rocks: industry-government partnership for cyber defense. Journal of Strategic Security4(2), 97.

Jayawardane, S., Larik, J. E., & Jackson, E. (2015). Cyber Governance: Challenges , Solutions, and Lessons for Effective Global Governance. The Hague Institute for Global Justice Policy Brief.

National Research Council. (2010). Proceedings of a Workshop on Deterring Cyber attacks: Informing Strategies and Developing Options for US Policy. National Academies Press.

�Your title line goes here. It shall be the Long title in Upper and Lower case, centered with no bold. The paper is introduced in this area with an attention getter, purpose/thesis statement, and overview of topics. See the APA Paper Template Provided in the Resources Area

�Nice job!

�Paragraph is not supported. It only has two sentences. More discussion or application is warranted here, or consider combining with other paragraphs

�This discussion is not comprehensive

�Nice Discussion

�Nice job!

�Great Discussion in the following paragraph

�Great job!

�Remove quotation marks from title.

�More In-depth Discussion is Warranted and More In-Depth Application is Warranted

�More In-depth Discussion is Warranted and More In-Depth Application is Warranted

�Why, how? Please apply your discussion

�Great research question(s) or ideas.

�include a conclusion

�Only capitalize the first letter of the first word of a title, the first word after a colon or a dash in the title, and proper nouns. Do not capitalize the first letter of the second word in a hyphenated compound word.

�Only capitalize the first letter of the first word of a title, the first word after a colon or a dash in the title, and proper nouns. Do not capitalize the first letter of the second word in a hyphenated compound word.