CYB210_Week3Discussion Cybersecurity Issues for Business Travelers_post4

Is there anything else you׳d like to ask?
Our top-rated tutors can help you.

Click here to post a question
Related Documents
1 / 3100%
For: Mrs. R. Rose Padgett,
In this document she will be provided the discussion
points and recommendations for the up-and-coming management
meeting intended to address cybersecurity while conducting
business travel. The primary focus of the meeting is intended to
address concerns about identity theft and phishing attacks against
employees, managers, and executives while utilizing laptops, cell
phones, and other devices to connect to company resources and
data during travel.
She feels that at the center of any successful
business model is employing security in all aspects of daily
operations and ensuring personnel at all levels are informed and
trained on how to conduct remote business while traveling. Her
personal belief that accountability starts with training and
understanding is a valued concept and serves as the primary
focus for all employees. Her focus will be on empowering all
employees with the tools and knowledge required to conduct
daily operations safely and securely from all locations whether
local or remote.
Her recommendations focus on the training of all
employees as part of the company onboarding process and the
use of company issued laptop computers, cell phones, and other
devices as the only approved means of conducting company
business. Company onboarding should include of training and
familiarization on the recognition of cyber threats, identifying
phishing emails, and how to avoid identity theft. Employees
should also be introduced to all software-based applications
utilized by the company and how to interact with all aspects of
the provided IT related services and features. Employees should
also be issued a random-access key generator fob as part of the
onboarding process to assist in the authentication and access
process for multiple company resources. Upon completion of all
training both the supervisor and the employee should be required
to sign off on the company verification of training and
understanding form. Laptop computers should be provided by
the company and need to be utilized by all employees regardless
of the location for conducting business. Company laptops must
have all required software pre-loaded and be connected to the
local servers via a wired connection during in office operations
enabling the IT staff to push monthly antivirus updates and
patches over the wired network connections to ensure the most
up to date security software is installed. Bit locker should be
installed on all company computers to ensure drive encryption
and reduce the risk of data loss due to theft or loss of the
system. Employees should be issued an individual username,
password, and individual computer pin at the time of employment
and will be required to reset their passwords with a 16-digit
password consisting of upper- and lower-case letters, numbers,
and special characters at first login. Passwords will be required
to be changed every 90 days. After login, employees should
utilize Microsoft Outlook for all business emails to ensure email
encryption during all daily correspondence. They will be required
to sign-in to outlook utilizing multi-factor authentication
consisting of username, password, and randomly generated pin
prior to accessing email (Sophocles, 2019). Employees will need
to utilize multi-factor authentication to access the cloud-based
share drives for individual storage and company folders per their
pre-established access requirements at the time of hire.
Employees should be trained to establish a new network connect
each time they log on to their laptop and forget all connections
prior to logging out to ensure no open connections are
maintained. Prior to travel, employees will need to be issued a
company cell phone that has been pre-configured for improved
security by the IT department and be reminded that the device is
for business use only. While traveling, employees will need to
connect to the company servers via a company issued Wi-Fi
Hotspot or cellular phone hot spot to gain internet access. Hot
spot capable devices should be password protected at a minimum
for access. Employees will then need to connect to company
resources utilizing the pre-loaded and configured VPN software
and utilize multi-factor authentication for access (Says, 2018). As
a best practice, minimal data should be stored on the computer
hard drive or desktop while cloud-based storage is available.
References
EC-Council (2016). Certified Secure Computer User (CSCU)
Version 2 eBook (2nd Edition). International Council of E-
Commerce Consultants (EC Council).
https://evantage.gilmoreglobal.com/books/9781635671810
Sophocles Grafas. (2019).
Acrobat Accessibility Report
.
Www.cisa.gov.
https://www.cisa.gov/sites/default/files/publications/Cybersecurity-
While-Traveling-Tip-Sheet-122019-508.pdf
Says, T. T. (2018).
30+ Cybersecurity Tips for Travelers
. Infosec
Resources. https://resources.infosecinstitute.com/30-cybersecurity-
tips-for-travelers/#gref
Students also viewed