1 / 2100%
1. Do you agree or disagree with the author's assertions regarding
seasonal employees and cybersecurity risks in the workplace?
Why?
I certainly agree with the author’s assertion that seasonal
employees present a unique security risk. This is especially true
with regards to the employment positions of front desk agents,
night audit, and call center agents. These employees are regularly
exposed to a breadth of customer data such as the credit card
information, vehicle data, email addresses, phone numbers, and
home addresses. In addition to this information, these employees
also have direct contact with the customers and could use this
interaction to socially engineer additional information that could
assist in an identity hijack situation. For this reason, I agree that
there should be no reduction in the due diligence processes used
during hiring temporary employees in comparison to full-time
employees.
2. What steps can (should) managers take to reduce security risks
associated with hiring seasonal or temporary employees? (Consider
whether or not the Secure Computer User training course would
be appropriate for these employees.)
As mentioned before, I certainly believe that all the steps and
processes taken with vetting full time hires should also be applied
to temporary workers that have significant data or system exposure.
The hiring process should include a local background check in
addition to a thorough interview. Temporary employees should be
fully aware that the company is completely knowledgeable of the
security risks. The company should articulate those risks and
completely define how they are being monitored and possible
ramifications if the protocols are breached.
For those employees mentioned before that are exposed to
sensitive data (front desk agents, night audit, and call center agents)
additional training should be given on malware\viruses, internet
security, email phishing, and social engineering techniques. I believe
the Secure Computer User training course might be a bit overkill
and counterproductive in the volume of information that is
expected to be secured. Perhaps a “watered down” version of the
course that is geared specifically for the expected risk and exposure
would be more suitable.
3. How can managers show leadership in the area of cybersecurity
defenses and best practices?
Managers should take cybersecurity risks seriously and plan
appropriate training, develop situational awareness, and relay this
importance to all necessary employees in a serious manner.
Managers can best show leadership in the area of cybersecurity
defenses by relaying the proper level of importance that should be
granted to this serious risk and not presenting the tasks required as
just a simple task to be checked off. The training should also be
ongoing and continuous as situational threats evolve.
Students also viewed