1 / 7100%
INFORMATION ASSURANCE POLICY 1
Information Assurance Policy for Fisher Incorporated.
Liberty University
Studies in Information Security, CSIS 340
April 5, 2025
INFORMATION ASSURANCE POLICY 2
Overview
Information assurance is a critical part of an organization's overall security strategy,
focusing on the protection of information assets from various threats. It encompasses a range of
practices and technologies designed to ensure that information remains secure throughout its
lifecycle (Dazin, Cloud identity security 2024). This policy provides a comprehensive framework
that outlines the principles and processes necessary for effective information assurance. It
emphasizes the importance of safeguarding sensitive data against risks such as cyberattacks,
data breaches, and insider threats. By clearly defining the roles and responsibilities of
employees and stakeholders, the organization aims to cultivate a culture of security awareness
and proactive risk management. This approach not only reinforces the security posture of the
organization but also enhances its reputation and trustworthiness in the eyes of clients,
partners, and regulatory bodies. Ultimately, information assurance ensures that organizational
integrity is maintained while allowing effective and secure operations.
Purpose
The primary purpose of this information assurance policy is to establish a robust
framework for protecting sensitive information from unauthorized access, disclosure, alteration,
and destruction. This policy delineates specific roles and responsibilities for all personnel
involved in the safeguarding of information assets, ensuring that everyone understands their
obligations in maintaining security. Compliance with relevant laws, regulations, and standards is
a key focus, as it helps the organization avoid legal repercussions and maintain operational
integrity. What's more, the policy seeks to foster a secure environment for handling information
by promoting adherence to best practices in information security. This proactive stance not only
protects the organization's assets but also enhances its resilience against evolving cyber threats
and potential data breaches. By doing so, the organization empowers its personnel to contribute
INFORMATION ASSURANCE POLICY 3
effectively to its security objectives, forming a united front against information security
challenges.
Scope
This policy applies universally to all employees, contractors, and third-party service
providers who have access to the organization’s information systems. It covers a wide array of
information assets, including electronic data stored on servers, cloud services, and local devices,
as well as physical documents and records. Communication systems utilized within the
organization, such as email and messaging platforms, are also included within the policy's
purview. By encompassing all departments, business units, and operational functions, the policy
guarantees a cohesive and unified approach to information security across the organization. This
comprehensive scope is essential for mitigating risks and ensuring that all personnel are aligned
in their commitment to safeguarding information assets. Furthermore, understanding the
importance of such inclusivity reinforces the organization’s commitment to maintaining high
standards of information security in all aspects of its operations.
Policy Compliance
Compliance with this policy is not optional; it is mandatory for all employees and
stakeholders. The organization places significant emphasis on the seriousness of
noncompliance, as it can lead to critical security vulnerabilities. Disciplinary actions for
noncompliance may range from verbal or written warnings to mandatory re-training on
information assurance policies and practices. In severe cases, termination of employment or
contracts may occur. To ensure adherence to the policy, regular audits and assessments will be
conducted, evaluating compliance with established security protocols and procedures.
Employees are encouraged to report any suspected violations or incidents to the designated
INFORMATION ASSURANCE POLICY 4
security team promptly, fostering a culture of accountability and vigilance in information
security.
Furthermore, establishing clear channels for communication and reporting mechanisms serves
to enhance the organization’s ability to respond to security concerns swiftly, thereby minimizing
the chances of security incidents escalating to significant threats.
Related Standards
This policy is designed to align with and support compliance with several key standards
and regulations that govern information security. The ISO/IEC 27001 standard provides a
framework for establishing, implementing, maintaining, and continually improving an
information security management system (ISMS), setting forth requirements for risk
management and security controls to ensure organizations can effectively protect their
information assets. Additionally, NIST SP 800-53 offers a comprehensive set of security and
privacy controls for federal information systems and organizations, providing guidelines for
protecting sensitive information and supporting organizational security protocols(Free 2021
CISSP Study Guide (PDF)). The General Data Protection Regulation (GDPR) establishes strict
guidelines for the collection and processing of personal information of individuals within the
European Union, emphasizing the enhancement of data protection and privacy rights, which
organizations must comply with to avoid steep penalties. Furthermore, the Health Insurance
Portability and Accountability Act (HIPAA) establishes standards for protecting health
information, ensuring that healthcare organizations implement adequate measures to safeguard
sensitive patient data. By adhering to these standards, the organization strengthens its
information security posture and demonstrates its commitment to protecting sensitive
information while fostering trust among stakeholders.
INFORMATION ASSURANCE POLICY 5
Definition
To ensure clarity and consistency in the application of this policy, several key definitions
are provided. Information assurance refers to the practice of managing risks associated with the
use, processing, storage, and transmission of information, ensuring its integrity, confidentiality,
and availability. This holistic approach promotes overall data protection. Confidentiality is
defined as the principle that sensitive information is accessible only to authorized individuals,
thereby preventing unauthorized disclosure and protecting the privacy of individuals and the
organization. Integrity involves the maintenance of accuracy and completeness of information
and processing methods, which is crucial for decision-making within the organization, as it
ensures that information remains trustworthy. Finally, availability is the assurance that
authorized users have timely access to information and associated resources, a principle that is
vital for operational efficiencies, as it minimizes downtime and disruptions in service delivery.
Terms
The following terms are relevant to this policy and are defined as follows:
- Access Control: Mechanisms that restrict access to information and information systems
to authorized users only.
- Data Breach: An event where unauthorized access to sensitive information occurs,
potentially resulting in harm to individuals or the organization.
- Encryption: The process of converting information into a code to secure it from
unauthorized access.
INFORMATION ASSURANCE POLICY 6
- Incident Response: The coordinated approach to managing and mitigating the effects of
a security breach or cyberattack.
- Risk Assessment: The systematic process of identifying, evaluating, and prioritizing risks
to information assets to inform decision-making.
- User Awareness Training: Programs that educate employees about information security
policies, best practices, and the importance of safeguarding information.
References
Cannoy, S. D., Salam, A. F., & Salam, A. F. (2010). A framework for health care information
assurance policy and compliance. Communications of the ACM., 53(3), 126–131.
https://doi.org/10.1145/1666420.1666453
Slaughter, J., & Syed Shawon, M. R. (2011). Information Security Plan for Flight Simulator
Applications: https://doi.org/10.5121/ijcsit.2011.3301
Eilers, M. E. (2018). Information Security: What Is Management's Role? Management must
create an information security plan and ensure firm-wide adherence to it. Law Practice, 44(3),
40+. https://link.gale.com/apps/doc/A541045343/LT?
u=vic_liberty&sid=summon&xid=b0cfbc4a
Chan, H., & Mubarak, S. (2012). Significance of Information Security Awareness in the Higher
INFORMATION ASSURANCE POLICY 7
Education Sector. INTERNATIONAL JOURNAL OF COMPUTER APPLICATIONS, 60(10),
23–31. https://doi.org/10.5120/9729-4202
Murolo, S. B. (2019). Planning for data security. Journal of Accountancy, 228(4), 62+.
https://link.gale.com/apps/doc/A602462449/GBIB?u=vic_liberty&sid=summon&xid=3a5a5dc5
Dazin, M. (2024, June 2). Cloud identity security. Axiom Security.
https://axiom.security/cloudidentity-security/
Free 2021 CISSP Study Guide (PDF) – Download ebook. Netwrix. (n.d.).
https://www.netwrix.com/cissp_study_guide_pdf.html
Students also viewed