This is Part 1 of the Key Assignment. Your draft will cover all of the objectives from Weeks 1–3 along with the new topics and objectives for Week 4.

profilemrgblaesrqel
unit42.doc

Running head: INFORMATION SECURITY STRATEGY FOR COMPANY 1

INFORMATION SECURITY STRATEGY FOR COMPANY 4

Information Security Strategy for Company

Student’s Name

Course

Date

Information Security Strategy for Company

The business-critical information of the IFG includes its customers' information, employees' information, and its payroll system. The success of IFG has been contributed mainly by the involvement of their loyal customers. Protecting the information of their customers is a top priority as this is their critical information. Glow-Foods, one of the companies of IFG organization, is a leader when it comes to the involvement of customers in their business. It has asked their customers to upload pictures of themselves while drinking one of the company's products, Green Tea Shake, on the Glow-Foods website. Also, Glow-Foods has encouraged their customers to send a coupon off their favorite Glow-Foods product to a friend. Such information of their customers remains a top priority to the organization. IFG has many employees and the information employees become a critical point to the organization. Personal details of the employees should remain confidential and not disclosed to anyone outside the organization. This means that this information is critical to the organization and thus must be protected at all times. The organization's payroll and confidentiality go hand in hand. The financial data used in the payroll process remain critical information to the organization. the information needs to remain confidential to the firm.

Most organizations in the world do face a lot of vulnerabilities. IFG being of these large organizations do face a lot of vulnerabilities. They may be in form of IT security risks, physical, cultural or procedural risks. These risks pose a great damage to the company. Due to the increased use of technology such as computers and social media, vulnerabilities such as hacking are one of the great risks that the organization faces. IFG has increased the use of social media such as Facebook and Twitter to market their products. They even do interact with their customers through their website where they ask them to upload pictures of themselves drinking or eating their products. This makes it become an easy target for hackers who can easily hack its social media accounts and leak important information. Physical vulnerabilities may be caused by burglars or even the employees themselves. Employees at sometimes are a threat to the organization if they start practicing unethical practices such as stealing from the company. Procedural vulnerabilities are those risks that the organization faces due to changes in the environment. Epidemics in certain areas may lead to poor sales of the organization's products.

The IFG organization has set up appropriate human resource and IT security policies and practices. These policies and practices are to help the IFG organization to manage its employees and creating better strategies to manage its IT. These policies are to help curb vulnerabilities such cybersecurity which can lead to the leakage of important information. The human resource policies enable training of employees on cybersecurity thus enabling them to create strong passwords, not using their personal gadget to carry out work activities, and avoiding keylogger and phishing scams. The HR policies do hold employees accountable if they violate any of the rules on technology. The organization has also set up various physical security policies and practices to increase security. Physical security is the foundation when it comes to IT security (Mo, Kim, Brancik, Dickinson, Lee, Perrig & Sinopoli, 2012). Installation of surveillance cameras is one of the first steps that IFG has taken to increase security. They able to identify easily anyone with malicious intentions. Locking of rooms that contain vulnerable devices is a practice that the organization has applied. The organization has employed a lot of security guards so as to ensure that there is safety in the workplace. The organization has applied the use of antivirus on all its systems to improve the security ecosystem. Antiviruses are to prevent malware and viruses that cause a scrutiny of the systems used. Programs that prevent unauthorized personnel from accessing the organization's information and also that monitor the activities that take place in the organization's network have been installed. Over 50% of the activities in the organization are automated. These activities include packaging of food and management of employee and customers' records.

The organization needs to create a more interactive website that enables them to get more feedback from the customers. This will enable them to interact with more clients which will help in making marketing plans in the near future. They need to implement the use of cloud computing as this will enable the IT team to scale while linking with the company's databases (Mell & Grance, 2011). Setting up more and effective HR and IT policies will enable them to overcome cybersecurity. These policies will enable to close the gaps between IT and business enterprise.

Mell, P., & Grance, T. (2011). The NIST definition of cloud computing.

Mo, Y., Kim, T. H. J., Brancik, K., Dickinson, D., Lee, H., Perrig, A., & Sinopoli, B. (2012). Cyber–physical security of a smart grid infrastructure. Proceedings of the IEEE, 100(1), 195-209.