Principles of Management

profilemarmaydec
UnitVIII.pdf

BBA 3602, Principles of Management 1

Course Learning Outcomes for Unit VIII Upon completion of this unit, students should be able to:

1. Analyze the impact of change and innovation in organizational processes.

10. Apply managerial skills, principles, and decision-making strategies to the implementation of business best practices.

Reading Assignment In order to access the following resource(s), click the link(s) below: Brown, T. (2015). A primer on data security. The CPA Journal, 85(5), 58–62. Retrieved from

https://libraryresources.columbiasouthern.edu/login?url=http://search.ebscohost.com/login.aspx?direc t=true&db=bth&AN=102909750&site=ehost-live&scope=site

Juels, A., & Oprea, A. (2013). New approaches to security and availability for cloud data. Communications of

the ACM, 56(2), 64–73. Retrieved from https://libraryresources.columbiasouthern.edu/login?url=http://search.ebscohost.com/login.aspx?direc t=true&db=bth&AN=88141518&site=ehost-live&scope=site

Kerner, S. M. (2014, November 8). Home Depot breach expands, privilege escalation flaw to blame. Eweek.

Retrieved from https://libraryresources.columbiasouthern.edu/login?url=http://search.ebscohost.com/login.aspx?direc t=true&db=bth&AN=99375134&site=ehost-live&scope=site

Kerr, P., DeAngelis, D., & Brown, T. (2014). Five questions to ask before a data breach occurs. Journal of

Health Care Compliance, 16(6), 27–30, 70–71. Retrieved from https://libraryresources.columbiasouthern.edu/login?url=http://search.ebscohost.com/login.aspx?direc t=true&db=bth&AN=99225452&site=ehost-live&scope=site

Selvam, A. (2013). Keeping networks secure requires aggressiveness, compliance. Modern Healthcare,

43(45), 26. Retrieved from https://libraryresources.columbiasouthern.edu/login?url=http://search.ebscohost.com/login.aspx?direc t=true&db=bth&AN=92013697&site=ehost-live&scope=site

Link, A., & Siegel, D. (2007). Innovation, entrepreneurship, and technological change. New York, NY:

Oxford University Press. Retrieved from http://site.ebrary.com/lib/columbiasu/detail.action?docID=10194234&p00=innovation%2C+entrep reneurship%2C+technological+change

UNIT VIII STUDY GUIDE

Managing Information Systems Security

BBA 3602, Principles of Management 2

UNIT x STUDY GUIDE

Title

Unit Lesson YouTube Video for Unit VIII Click here to view the video for Unit VIII (1m 29s).

Click here to access a PDF of the video transcript. You may recall a 2014 attack on Home Depot’s information systems when customers’ credit card information was stolen. Information system security was, in fact, a Home Depot sustainment effort—as was true for nearly all organizations by 2014. Home Depot’s unfortunate experience seems to have followed the sharpening of intruders’ hacking skills combined with Home Depot leaders’ decisions to invest in a certain amount of protection. A number of breaches in this specific attack were not initially reported to the public. The following was later reported:

Third-party access was breached by an attacker, so that's one point of failure. The privilege escalation issue is the second. The undetected malware itself is the third point of failure. Finally, the fact that the data was taken out from the network without detection is the icing on the cake. (Kerner, 2014, para. 10)

Information Systems Security Managers in the present Information Age have an added responsibility to protect their organizations that their predecessors in the previous Industrial Age did not have: supervising the security of their information systems. Continuing our comparison with managerial responsibilities in an earlier era, supervisors in the pre- Internet past would be highly suspicious of visitors to their business who wanted access to employees’ personnel files or unannounced strategy plans of the firm. What purpose would permitting this serve, they may have asked, other than something nefarious and criminal? It is the same today in the Information Age as it pertains to our organizations’ information systems. Technology-based information systems security today means security from a range of threats. It involves effective security safeguards against unauthorized access. In particular, protection should be from not just access but reading, copying, transferring, denial of further service, disruption, destruction, unauthorized changes in stored data or process programming, and all hoaxes purporting these acts or something not listed here. Those of us who used personal computers and were connected to the Internet in the 1990s may recall a simpler period of community information systems use. Viruses and malware were emerging but were still rather rare compared to what exists today. Most computer and Internet users did not have virus-scanning or malware-blocking programs on their computers, though these were starting to be marketed, reflecting a growing need. After all, there were not that many Internet sites to surf, and most were of informational or academic interest (this was destined to change!). For the most part, no one minded if employees inserted their own floppy disks (a depiction which is the origin of the SAVE symbol on a number of document systems) into organizational system terminals (personal-sized computers on the Internet, a local network, or both) so they could perhaps create formatted greeting cards, letters, or family investment spreadsheets. Inevitably, though, even more malware and viruses were introduced into organizational systems from these practices. At present, this practice is often banned, and computer USB ports and CD drives are disabled except for limited functions.

BBA 3602, Principles of Management 3

UNIT x STUDY GUIDE

Title

Many organizations (including the U.S. government) matched growing systems security protection policies with programs of increasingly structured training. Organizations often appointed a systems security manager or assigned these responsibilities to the organization’s information technology (IT) department. The latter choice is often efficient. IT personnel, with their mastery of how networks function with a given array of equipment, tend to easily grasp how and why intrusion and protection programs work. As systems security managers continued to monitor the systems under their responsibility, they also looked ahead in the industry and its literature for improvements and updates to their protection systems, and alerts on new and emerging threats. Meanwhile, organizations began to require all computer users (and eventually all organizational members) to attend periodic systems security trainings or

certifications. These organizational policies usually include warnings that causing a breach in systems security is a violation that could result in additional training or administrative action in organizational response. Today, using organizational computers for personal work has become, if not impossible, more difficult as organizations try to isolate their systems from breaches. Present Day Information Security Does an information system security program (of virus ware protection, IT monitoring, or employee training) solve a manager’s problems? Events in recent times suggest that the challenge of protecting organizational information systems is never completely overcome. In the future, managers will be purchasing and replacing

protective software, maintaining and updating related policies, and watching (or delegating the watching) for future threats or unintended consequences of other policy changes. What might happen if a new HR records system software was adopted, but it was incompatible with existing virus ware/malware protection software, and it slipped out of its present protective umbrella? The organization might soon have no personnel records or records that were extensively damaged. Information systems can automatically safeguard against a variety of threats. The problem is that the natural and human elements of global society have, so far, kept this aspect of organizational management under a constant seesaw of threat introduction/countermeasures shielding that maintains a hazardous environment for organizational automated systems. Physical Threats Whatever can damage the physical plant (and

people) where information systems hardware or cables are located poses a threat that requires a combination of protection and incident/disaster planning to provide systems security. Countermeasures to physical threats begin with planning to acquire or build a structure with strength and secure (locking) doors that will withstand most risks of earthquakes, floods, heavy rains, lightning and power surge threats, and wildfires. Structures must also withstand human threats of breaking and entering, vandalism, or riot-induced destruction. Even disease running rampant among organizational members and their families may pose an indirect threat as the

U.S. Marine Corps Gen. Peter Pace, vice chairman of the Joint Chiefs of Staff, shakes hands and gives coins to a group of soldiers and Marines at an Internet cafe in Bagram, Afghanistan, July 12, 2005. (Cullen, 2005)

Savannah River Nuclear Solutions, LLC (SRNS) board of directors has provided $1.5M to enable Savannah River National Laboratory (SRNL) access to several high speed research and university computer networks, the most noteworthy being the “National Lambda Rail” (NLR), all part of a $30M commitment by SRNS’ parent companies to reinvest profits that will benefit SRNL and SRNS site operations at the Savannah River Site (Department of Energy, 2012)

BBA 3602, Principles of Management 4

UNIT x STUDY GUIDE

Title

number of available network users during the workday begins to diminish, reducing collective efficiency. Countermeasures include such efforts as fire prevention, public health campaigns, and key control, linking together several functions with information systems security. Stakeholder Threats Linked in some ways to physical threats, this threat approaches information systems from insiders: the organization’s own members and others who have had past or occasional access to a terminal of the information system. This might include ex-employees, retirees, suppliers, service personnel, customers, and visitors. As opposed to the physical threats such as rain and leaky roofs causing damage, stakeholder threats are on a personal level with people—properly or maliciously—using the information systems. Also, the overall threat is multifaceted. A well-meaning employee can make a simple mistake and accidentally or carelessly introduce a virus into the system. Therefore, information systems security personnel need an effective level of interpersonal and social skills to properly manage protections from this range of threats. Countermeasures include making an investment, and sometimes an extensive one, in a network virus and malware protection software package. A good investment will be in a package that is as encompassing of threat protection as practicable for the cost, and includes constant monitoring and version updates as a means of keeping pace with advancements in attack measures. Computers may be protected with a user ID and password (and the stronger these are in character diversity, the better), an encrypted employee card, or both. When such a card is issued when entering the organization and collected upon departure, it reduces access from anyone but current employees and contractor stakeholders. The information systems security team may need office

hours, a help desk call center, or both so that employees can seek their help or rapidly report a problem with the network or individual computers. This section may also be responsible for conducting information systems security training and certifying employees and stakeholders. Hackers and Criminals If found to be someone other than stakeholders known to the organization, hackers and criminals are intruders ranging from nuisance-makers to lawbreakers. Some forms of hacking are not against the law (yet) in some places, but, hackers may try to crack systems or parts of them. They may try to steal passwords as a prank, eavesdrop out of curiosity, and report their hacking to the organization as a civic duty and attempt to be helpful, or any combination of the above. Criminals are more malicious. They may try to gain access to information security systems to steal personal information, cause denial of service, stalk or blackmail users, or prepare for

kidnapping, murder, bribery, fraud, theft, or vandalism against organizational members, linking this category at times with that of physical threats. Organizations may be protected from these threats with the same regime of protection emplaced against stakeholder threats, with the added assessments when intrusions may be associated with hacking or intended and planned criminal acts. Competitors, Hostile Belligerents, Media, and Litigants This category groups a wide range of threats with somewhat aligned interests. Competitor organizations may benefit from learning trade secrets or unpublished strategies by the organization owning the information. If stepping into criminal practice, a competitor may decide there is a benefit if the organization’s databanks, including the “cloud,” are damaged. Hostile belligerents may include foreign governments, political organizations, or terrorists, magnifying their threat to attempt the same acts as described above with greater support of more funding and formal permissions. Media actors may try to expose information for a story; litigants may try to gain more insight to help their own pending court cases. As with hacking and criminals, an information systems security protection regime and regimen considers all intrusions or unauthorized use to be forbidden, so an organization may be protected against all these human-caused threats with the same package investment.

U.S. Marine Forces Reserve scored a 100 percent on physical facility security during a Command Cyber Readiness Inspection conducted by the Defense Information Security Agency at Marine Corps Support Facility New Orleans, LA. (Edwards,2013)

BBA 3602, Principles of Management 5

UNIT x STUDY GUIDE

Title

The Future As can be seen with the 2014 Home Depot incident, investment in an information systems security protection regime does not end a manager’s concern and may not be enough. An organization’s leaders may not make a good decision on how much protection to invest in or against what threats, and, over time, threats evolve as innovation and change in available technology may make a new intrusion attempt feasible. Managers can best address the future by, as with all other facets of management, accepting that change will occur and being aware that a good security arrangement may be less effective in the near future. It will be prudent, therefore, to allocate funds for future system security protection and do research to learn what protection will be good to adopt and why. The organization’s future is at

stake in the information system security effort as much as it is in sales, funding, recruiting, and other areas considered vital to organization sustainment. With optimism and preparation, managers can succeed at this. All the best to managers monitoring information systems security!

References Andersson18824. (2015). Syrian.hacker [Image]. Retrieved from

https://commons.wikimedia.org/wiki/File:Syrian.hacker.jpg Cullen, D. (2005). Internet cafe inside Bagram Air Base [Image]. Retrieved from

https://commons.wikimedia.org/wiki/File:Internet_cafe_inside_Bagram_Air_Base.jpg Department of Energy. (2012). SRNS Parent Companies Provide $30M in Profits to Benefit National

Laboratory and Site Operations (7597412268) [Image]. Retrieved from https://commons.wikimedia.org/wiki/File:SRNS_Parent_Companies_Provide_$30M_in_Profits_to_Be nefit_National_Laboratory_and_Site_Operations_%287597412268%29.jpg

Edwards, T. (2013). U. S. Marine Forces Reserve scored a 100 percent on physical facility security during a

Command Cyber Readiness Inspection conducted by the Defense Information Security Agency at Marine Corps Support Facility 130521-M-IU921-961 [Image]. Retrieved from https://commons.wikimedia.org/wiki/File:U._S._Marine_Forces_Reserve_scored_a_100_percent_on_ physical_facility_security_during_a_Command_Cyber_Readiness_Inspection_conducted_by_the_De fense_Information_Security_Agency_at_Marine_Corps_Support_Facility_130521-M-IU921-961.jpg

Kerner, S. M. (2014, November 8). Home Depot breach expands, privilege escalation flaw to blame.

Retrieved from http://www.eweek.com/security/home-depot-breach-expands-privilege-escalation- flaw-to-blame.html

The Syrian Electronic Army (SEA) is a group of computer hackers who support the government of Syrian President Bashar al-Assad. (Andersson18824, 2015)