Running Head: IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 1
IT 552: Final Project
SNHU
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 2
Table of Contents
Executive Summary .................................................................................................................. 3
Proposal Introduction ............................................................................................................... 4
Security Policies Development ................................................................................................ 6
Continuous Monitoring Plan .................................................................................................. 15
Communication Plan .............................................................................................................. 20
Conclusion ............................................................................................................................... 26
References ............................................................................................................................... 27
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 3
Executive Summary
In the digitalized era, cyber threats can any side and cripple the Information
Technology ecosystem of an organization. In order to be well equipped against unknown
threats and risks, business entities spend huge volumes of finance so that they can
safeguard themselves against sophisticated threats and attacks in the virtual setting.
Mainly businesses invest money to introduce robust defense and detection mechanisms
so that cyber attackers can be kept at a distance.
As per the case relating to Multiple Unite Security Assurance (MUSA)
Corporation, its security posture is low. One of the main reasons for the poor security
model can be attributed to the human factors that operate in the organizational setting
(Glaspie & Karwowski, 2017). As per numerous researchers, in many cases, human
factors botch up the IT security setting of an organization. Due to their intentional or
unintentional error, unauthorized users gain an access into the system which ultimately
compromises the security (Nobles, 2018).
A number of policies have been presented here that can help to address vital
security issues that can arise in the prevailing organizational context due to human
factors. By implementation of such policies, business organizations can be empowered to
enhance their security posture. The effective management of cybersecurity model will
only be possible if the security policies are taken into consideration the security threats
and risks that arise due to the involvement of the human factors (Nobles, 2018). A
robust communication plan has been designed for Multiple Unite Security Assurance
(MUSA) Corporation which will help to addresses and summarize the importance of a
security awareness program.
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 4
Proposal Introduction
Purpose
In the dynamic and unpredictable business setting, it is necessary for
organizations to have a robust cyber security model so that they can be well equipped
against online threats and risks. This security awareness program proposal of Multiple
Unite Security Assurance (MUSA) Corporation has been presented here so that the
existing poor security posture can be strengthened (Bada, Sasse & Nurse, 2019). The
present security posture of MUSA is low as it is exposed to a high level of cyber
threats and risks that can cripple the IT ecosystem of the firm and the business
operations.
The fundamental purpose of the security awareness program proposal is to help
Multiple Unite Security Assurance (MUSA) Corporation to upgrade the existing security
posture so that it can function in a safe and secure manner. At present, the employees
do not have proper cybersecurity awareness training and this naturally adversely
influences the security climate within the MUSA organization (Bada, Sasse & Nurse,
2019). Due to their lack of adequate skills and technical expertise, they are unable to
take suitable actions against different kinds of online threats and attacks. This proposal
intends to empower the organizational personnel of MUSA so that they will be in a
position to deal with different kinds of attacks and threats that can hamper the business
activities and processes.
Security Posture
As per the risk assessment of the organization, it lacks a proper cybersecurity
program in place that can help it to be well prepared to deal with external or internal
threats that can arise on the online platform. As the human factors that operate in the
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 5
business setting do not have the technical skills and they have not been trained properly
by the organization, it faces numerous risks and uncertainties in the digital environment
(Nabi, 2018). This proposal relating to security awareness program of MUSA has been
designed so that the existing gaps in its security system can be filled and the firm’s
security posture can be improved to a significant degree (The Components of a
Successful Security Awareness Program, 2019).
Human Factors
The proposal would also help MUSA to take care of a number of organizational
factors that come into play and contribute to the unhealthy security culture in the
business entity. For instance, it will encompass the relevant security policies, tools, and
techniques that can be implemented in the organizational setting to strengthen the
security approach. In addition to this, the proposal would focus on the technical training
needs of the employees so that they would be in a better position to identify varying
kinds of cyber threats and take necessary actions so that the security model of the firm
would not be compromised (Alotaibi et al., 2016). Thus the intention of the security
awareness program proposal is to make the employees aware of various kinds of
security elements that can be introduced or implemented to strengthen the cybersecurity
infrastructure of Multiple Unite Security Assurance Corporation. It would also help to
constructively mold the factors that come into play and increase the vulnerability of the
business in the cyber setting.
Organizational Factors
A total of ten security gaps have been presented in the security posture of the
business entity that needs to be addressed on an urgent basis. Some of the main security
concerns that have been included in this security awareness proposal are the lack of
annual cybersecurity awareness training for the employees, the absence of suitable
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 6
configuration change management policy, and the lack of intrusion detection or
prevention system. In addition to this, MUSA does not analyze or collect logs. The
absence of media access control policy adds to the security concerns of the business
undertaking. In the unpredictable technological setting, MUSA does not have encryption
or hashing which can control the data flow as well as the unauthorized alteration of
data. These are some of the major security concerns that the firm faces in an
unpredictable technological setting. The business entity has the opportunity to introduce
in place Vulnerability assessment model which will be able to assess the security
posture status of the business undertaking (Öğütçü, Testik & Chouseinoglou, 2016).
The security concerns of Multiple Unite Security Assurance Corporation that have
been identified here not only jeopardize the online sustainability of the business
undertaking but it also has an adverse implication on the morale of the employees
(Korpela, 2015). Due to the high level of security issues that the business encounters on
a usual basis, the level of employee turnover is high and it impacts the profitability and
performance of the business as well. The security awareness program proposal for
MUSA has been designed so that the employees can be empowered to identify the
various online threats and risks that can adversely impact their Information Technology
ecosystem.
Security Policies Development
Proposal for mitigating security threats that arise due to human factors
A perfect security awareness model has been presented here so that it would help
to mitigate the threats that are posed by the human factors to the organization’s security
posture. The proposal that has been designed for the business entity encompasses a total
of ten security policies that would enable the firm to fill the security gaps that currently
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 7
exist and weaken the security posture of MUSA (Threats to Security, 2019). The
policies have been crafted so that the organization would be in a position to address
unintentional threats as well as intentional threats or social engineering. The policies that
have been designed also focus on the quality of data flow so that it could not be
tampered with.
As per the strategy that has been presented here, the cybersecurity threats that
arise before the entity can be categorized into two types namely unintentional threats
and intentional threats. The unintentional threats can be defined as the threats that arise
due to human errors or computer failure (Threats to Security, 2019). The intentional
threats are the ones that arise on the online platform due to various kinds of malicious
elements such as viruses, theft of data, denial of service attack and other factors that
have been malicious intent. The security policies have been strategically framed so that
the existing security gaps can be addressed in an effective manner. c
Policies
A. Protection against unintentional threats
The following security policies have been proposed here would help Multiple Unite
Security Assurance Corporation to safeguard itself against various kinds of unintentional
threats that arise due to human factors and adversely impact the security if the
organization.
Changes in the remote access mechanism
The remote access is a policy that can enable employees of an organization to
work remotely or work from their home. This policy might be employee friendly but at
the same time, it gives rise to a number of security concerns as unauthorized users have
the opportunity to gain access into the organizational network. The employees that work
remotely can gain access into the organizational system from anywhere at any time.
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 8
There is the possibility that these individuals will unintentionally make blunders while
surfing the internet. Such an innocent error on part of the employees working remotely
can have a detrimental implication on the business entity. For example, in case the
employees, click on the link of a malicious site from their personal computer,
unauthorized attackers could gain entry into their systems and compromise the security,
integrity, and confidentiality of the organizational data.
In order to deal with the cybersecurity threats that arise due to the remote access
policy, there is the need to activate remote access feature that is present in the firewall.
It would make sure that the employees working remotely can gain access in a safe and
secure manner by making use of the Secure Sockets Layer Virtual Private Network
feature (What is SSL VPN (Secure Sockets Layer virtual private network)? - Definition
from WhatIs.com, 2019). By using this security feature, the origination’s personnel
would be in a position to create safe access to the MUSA’s system when they are
working from home. The employees could also use their mobile devices to work
remotely in a safe working environment after the implementation of the security policy
(Remote Access: The Pros and Cons of Virtual Private Networking | macchina.io Blog,
2019).
Introduction of encryption or hashing
Encryption and/or hashing are regarded to be some of the most basic security
measures that business undertakings need to implement so that the level of security of
their IT infrastructure can be strengthened to a certain degree. This policy has been
proposed so that the security could be strengthened whether the organizational data is
ready for transmission, it is in the process of transmission or it has already been
transmitted. Data encryption would be made mandatory so that it could deter malicious
parties from gaining unauthorized access into sensitive business information. The
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 9
encryption process would basically make use of algorithms which would convert ta into
unique codes. The computers that have the right key would be able to crack these codes
and put them into the original form. There are two types of encryption methods
including symmetric key and public key (or asymmetric). In the former method, the
same key is used or installed in both the systems that are responsible for receiving and
transmitting the information. The public key encryption, on the other hand, utilizes two
sets of keys simultaneously namely a private key and a public key to strengthen the
security level. In the business context of MUSA, the asymmetric encryption could be
introduced to strengthen the security level (Encryption and Its Importance to Device
Networking, 2019).
Similarly, hashing has also been introduced in the security policy. The hash
methods like Secure Hash Algorithms (SHA-1, SHA-2, and SHA-3) could be employed
so that the integrity of the organizational data could be maintained and strengthened
(Secure Hash Algorithms | Brilliant Math & Science Wiki, 2019). These algorithms are
designed with strong encryptions so that they can effectively respond to online cyber-
attacks. This tool would enable the firm to keep a tab on any kind of modification or
tampering of the data that has been transmitted or received. For example, in case there
is even a slight change in any text file, the hash value of the modified file will be
different from the original hash value. Thus the organization will come to know that
data has been tampered with (Secure Hash Algorithms | Brilliant Math & Science Wiki,
2019). These methods would facilitate the business entity to have a stronger control over
the data flow and thus capture any kind of unauthorized alteration of data.
Conducting regular checks and auditing of user accounts
At present, one of the major security gaps that have been identified in the
MUSA organization relates to the fact that the logs of the employees are not collected
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 10
or analyzed. There is the need to introduce a robust auditing protocol so that the
accounts of all the organizational personnel of MUSA would be thoroughly checked and
scrutinized. For instance, this security policy could be applied once in a quarter or once
every six months so that the safety and security of the accounts could be maintained.
While conducting the audit process of the user accounts, it is necessary to take in to
account a number of aspects such as whether the account is active or inactive (disabled).
For example, both these accounts could be targeted by online attackers so that they
could gain unauthorized access into the organization’s system.
Some of the key settings and properties that must be considered while
implementing the security policy relating to the auditing of user accounts include
checking of the login scripts, the activity of the workstations and the frequency of
change of passwords. The audit procedure would help Multiple Unite Security Assurance
(MUSA) Corporation to determine the real-time status of the accounts of the users. For
example, in case an account that has been disabled for a long time is active the
Information Technology team must take necessary actions to check the activity.
Similarly, in case, an employee or user has failed to change or update his or her
password in more than six months, he must be notified to do the same on an urgent
basis. This security policy would be of vital importance as it would encourage the
employees of the firm to take necessary security measures at the individual level.
Employees of the firm would try to take the necessary steps at their individual level so
that the existing security gaps could be effectively addressed.
Introduction of media access control policy
A robust media access control policy could be introduced in the business setting
to secure the connections on the online platform. In the current times, a large number of
business activities are taking place in open virtual spaces such as social media platforms
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 11
which is increasing the vulnerability of the organization. In order to give a tough fight
to cybercriminals, it is necessary to have in place suitable media access control policies
and guidelines which would guide the employees while carrying out online business
activities.
The policy would play a critical role to strengthen the firm’s security system and
address the existing security gaps. This is because; the employees would be able to
carry out activities in a careful and conscious manner so that online hackers would not
get the scope to gain unauthorized access into the network (Media Access Control
Security Overview - TechLibrary - Juniper Networks, 2019). For example, the firm
could use a single login id on social media platforms to design its social media
marketing strategy. In case a second user id is created or used, the same could be
blocked for security reasons. Similarly, MUSA could also implement Data Loss
Prevention (DLP) tools so that it could keep a tab on the flow of the sensitive
information in the corporate network (What is Data Loss Prevention (DLP)? A
Definition of Data Loss Prevention, 2019).
Implementation of configuration change management policy
Change management refers to the formal process of making some kind of change
in the Information Technology system of an organization. In MUSA, a configuration
change management policy could be implemented so that the processes relating to
change could be effectively controlled. The policy could have a constructive implication
on the security model of the organization. For example, the security policy would make
sure that the integrity of the existing policies and codes is in place. In addition to this,
the new policy would help to identify security flaws. It would act as a baseline that
could be used for comparing the technical codes after any changes have been introduced
in the IT system. c The policy would be necessary for improving the security of the firm
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 12
as it would make sure that there exists compliance with the minimum acceptable system
configuration requirements (IT0125 - Configuration Management, 2019, p 1). The
policy could safeguard MUSA against malicious threats and risk that could arise in the
virtual environment of the company.
B. Social Engineering
Social engineering can be defined as the act of tricking someone so that he or she
will make security blunders which can ultimately have an adverse impact on the security
model. In the case of Multiple Unite Security Assurance Corporation, the following
policies have been designed so that protection against social engineering could be
possible (What is Social Engineering | Attack Techniques & Prevention Methods |
Imperva, 2019). In the current times, online hackers are using sophisticated tools so that
they can con professionals to disclose sensitive information such as passwords. The
security policies can help MUSA to be well equipped against such kinds of online
threats.
Providing annual cybersecurity awareness training
One of the basic steps is that the organization must design a robust annual cyber
security awareness training program so that its employees in all the departments would
be empowered to handle a tricky situation. As the name suggests, the training program
would be conducted on a yearly basis so that every time, the employees would be able
to handle sophisticated online threats. The training would encompass basis security
concepts such as:
❖ Do not download attachments from unknown parties.
❖ Do not open the emails and messages that are in spam mail.
❖ Do not open emails that have been sent by unknown parties.
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 13
In addition to this, the annual cybersecurity awareness training would also involve
technical concepts that the users need to understand so that the security of the
organization could be strengthened. For instance, MUSA could introduce educational
resources relating to cybersecurity training and conduct regular tests. Only after the
employees of MUSA would be able to pass these tests, they would gain access to the
firm’s system and network.
Introduction of intrusion detection/prevention system
An intrusion detection/ prevention system could be introduced in Multiple Unite
Security Assurance Corporation so that it could thoroughly examine the traffic of the
network. This system would be set behind the firewall so that it could detect and
prevent ‘vulnerability exploits’. Vulnerability exploits can come in the form of malicious
input and could compromise the security of the IT infrastructure of the business. By
introducing this layer of security, harmful content could be filtered out (What is an
Intrusion Prevention System? - Palo Alto Networks, 2019). The intrusion detection
system would be responsible to scan the network traffic and report back on any
identified threats or risks. The intrusion prevention system could be employed as it
would help to carefully analyze and take suitable actions on the network traffic flow of
MUSA. By introducing these tools, the security system of the firm could be improved
and harmful elements in the network could be identified.
Adoption of mandatory vacation policy
Multiple Unite Security Assurance (MUSA) Corporation could implement a
mandatory vacation policy which would require its employees to take leaves on a yearly
basis. Such a policy would have a direct impaction on the security model that is
implemented in the business setting. A mandatory vacation policy could play a key role
in the organizational context, as the firm would be able to detect fraudulent activities.
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 14
The policy would force all employees including the suspicious employees to take leave.
So they would have less amount of time with them to use their position in the firm to
conduct activities with malicious intention (Time off to discover fraud - FSS, 2019).
During the vacation time of suspicious employees, the management of the company
could carry out checks of the Information Technology infrastructure so that malicious
behavior could be identified.
Segregation of duties
Segregation of duties would act as one of the key concepts of internal control
that could positively impact the security of the IT system. By creating specific
responsibilities and duties that each and every employee has to perform in the business
setting, the management of MUSA could make sure that unwanted threats or risks and
conflicts of interests could be avoided (Behr, 2019). The fundamental objective of the
policy would be to disseminate the business activities and linked privileges so that the
security model could be strengthened. Such a policy would make sure that the
employees would use their workstations in a responsible manner so that no one can use
their computer systems to do any work without their prior knowledge. This regulatory
mandate would have a direct impact on the IT security of MUSA. The proper
categorization and division of work would be a major step towards a safe and secure IT
system as the employees would take ownership of their duties and act in a responsible
manner. It could minimize the vulnerability of MUSA in the virtual setting (Behr, 2019).
Personally identifiable information breaches
Personally, identifiable information could be introduced so that any data or
information could be used for the purpose of identifying particular organizational
personnel in MUSA. Private data could be saved by the company so that it would be in
a position to identify the individuals that are responsible for a data breach incident. This
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 15
policy would make sure that MUSA has the power to take necessary action or
precautionary action to safeguard itself from unauthorized access, data loss or theft
(Behr, 2019). This is a vital security policy that could be implemented at the
organizational level so that specific measures could be taken to tackle data security
breaches and incidents.
Ensuring a sound connection between the data sender and the data receiver
In order to make sure that there exist a sound and secure connection between a
data sender and a data receiver, it is necessary to keep a number of security instruments
in place such as firewall, intrusion detection/ prevention system and antivirus. Such
security tools would play a key role to address the security concerns and establish a safe
environment where communication between a data sender and a data receiver could take
place. Similarly, the use of encryptions or hashing would also play a critical role. This
is because these security approaches would make sure that the data that is being
received or transmitted cannot be tampered with or altered from its intended meaning
(Behr, 2019). These security measures would be of paramount importance for MUSA as
they could strengthen the security infrastructure and limit the scope of online attackers
to alter the sensitive data or information relating to the business. Thus in order to
address the issue relating to poor communication on the IT platform of MUSA, it is
necessary to encrypt all the messages so that its real meaning could only be deciphered
by the intended user. c c c c c c c c c c c
Continuous Monitoring Plan
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 16
A continuous monitoring plan is necessary as it can help to keep a check on the
security control model that has been designed and implemented in the organizational
setting. This plan fundamentally lays out the foundation for regularly and consistently
monitoring the organization against malicious activities and intentional as well as
unintentional threats. In order to make sure that the monitoring plan is effective and
serves the desired purpose, it is necessary to focus on a number of elements such as the
core features of the work setting, the work plan, and employee readiness. In Multiple
Unite Security Assurance (MUSA) Corporation, there is the need to establish a properly
functional continuous monitoring plan so that the various security gaps that exist in the
organizational setting can be effectively addressed.
Work Settings
In the work setting, a wide range of factors come into play that can adversely
impact the work ambiance. Some of the most common elements are the non-
implemented security protocols, poorly implemented management policies, and other
distractions and obstacles. It is necessary to take the necessary steps by the managers
and the management team so that such negative elements which increase the security
vulnerability of the firm can be kept at a distance.
The management must take careful measures to ensure that all the security protocols
and policies are systematically implemented throughout the firm. Such a step is a
necessity as it will help the organization in the long run to have better control over its
costs, risks and system network (Five tips for managing project change requests, 2019).
The major changes that take place in the IT setting must be carefully documented and
recorded so that they can be assessed as per requirement. Some of the key steps that
need to be followed while introducing a major change in the organization include:
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 17
• A request must be made so that a change can be introduced. It needs to be
documented clearly.
• The change log has to be updated in a timely manner so that no details will be
skipped. The key elements that will be altered have to be written down in this
simple document. c c c
• The proper assessment of the change request is an important step. It will
basically help to develop a sense of urgency. In the case of MUSA, it is
extremely vital to introduce the necessary changes so that the quality of security
can be upgraded.
• The thorough assessment of the change against the set criteria is of paramount
importance. It will assist in deciding whether the change has to be rejected or
approved
• The final step basically involves the decision that is taken regarding the approval
or the rejection of the change. During this stage, the outcome has to be
communicated to the key stakeholders so that they will be aware of the changes
that have been introduced in MUSA to strengthen the security model (Five tips
for managing project change requests, 2019).
The obstacles such as distractions can be managed by making sure that the
organizational personnel get the requisite space and time to focus on their job. The
managers and supervisors must interact and engage with the subordinates to get to know
of the key factors and elements that bother the employees and adversely impact their
performance (Mark, Czerwinski & Iqbal, 2018).
MUSA has to make sure that the management policies are properly implemented
and executed throughout the organization (5 bad practices that hinder your security, and
how to improve it | TechBeacon, 2019). It will play a vital role to make sure that
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 18
security violations can be curtailed to a possible extent. Some of the negative practices
that must be eliminated at once in the organizational setting are as follows:
• Sharing of common sensitive passwords throughout the entity
• Allowing unauthorized users in the secured and restricted read of the organization
• Ineffective implementation of the intrusion detection system (IDS) and intrusion
prevention system (IPS)
• Continuing to use outdated technological approaches
These are some of the practices that need to be avoided at any cost on MUSA so
that the security posture can be improved. Similarly, the firm has to introduce robust
security training for its employees so that they will be empowered to take the necessary
steps to improve the level of security of the entity. The firm must implement both
software and hardware firewalls so that a secure layer can be created which will keep
unauthorized users at a distance.
Work Planning and Control
The work and processes that are conducted in MMUSA must be strategically
planned and controlled as they can have a major implication on the performance and
productivity of the organizational personnel. Some of the key aspects that must be
carefully taken into consideration while planning and controlling the work include the
job-related stress and pressure, time factor, the difficulty level of the assigned work and
ineffective task planning.
Some of the key strategies that can be introduced in MUSA for addressing job pressure,
time factors, task difficulty, routine alteration and lack of knowledge and skills are
introducing proper training sessions, implementing mandatory vacation policy and
conducting ‘vulnerability assessment’ on a frequent basis.
Training sessions
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 19
MUSA must take the necessary steps so that the technical knowledge and
expertise of its employees can be upgraded on a regular basis. By providing them
training and development opportunities, the employees would be encouraged to perform
better. They would be able to play an active role to mitigate the risks that arise in the
IT setting of MUSA. This element must be included in the work planning as it would
have a positive implication on the productivity of the employees.
Mandatory vacation policy
MUSA must introduce mandatory vacation policy so that employees will take
holiday to get a break from the hectic work schedule. It will help them to manage their
work-related stress and pressure (Three Reasons Your Company Should Make Vacation
Mandatory, 2019). This policy can also play a key role to improve the security
framework of the entity. This is because it will help the firm to keep a check on insider
fraud (Slack, 2019). c c
Conducting regular vulnerability assessment
By carrying out regular vulnerability assessment, MUSA would be able to keep a
tab on the security aspect of its network and computer system. Such an evaluation
process must be conducted on public holidays so that the day to day work processes
would not be affected because of the security procedure.
Employee Readiness
Employees are the most critical asset of an entity. So their well-being, moral and
satisfaction must be the top priority of MUSA. It can introduce a number of strategic
approaches so that it would be in a position to address issues relating to inattentiveness,
high level of stress and anxiety, boredom and fatigue, and work-related illness or injury.
Only of the employees are mentally and physically fit and ready, they would be able to
optimally contribute to the performance and security framework of MUSA.
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 20
In order to manage a high level of stress, boredom, and fatigue, MUSA must
introduce mandatory vacation policy. By taking a break from the work, employees
would be able to focus on their personal health and well-being (Three Reasons Your
Company Should Make Vacation Mandatory, 2019). The managers must have a one-on-
one interaction with the subordinates so that they could share their concerns that make
them anxious.
An employee readiness program must be introduced so that the employees could actively
participate in the dynamic organizational setting. This could positively impact the
employee turnover of MUSA. Innovative engagement activities could be introduced such
as group discussions, events, and games so that no employee would get bored. A
healthy work environment must be created by taking into account the health and well-
being of the organizational personnel.
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c Communication Plan
The thorough engagement would play a vital role to influence a culture that
gives due importance to IT security. In fact, the communication plan could enhance the
success of the organization as it would assist to convince diverse stakeholders of the
entity to support the healthy security culture. The communication plan is designed in a
simple and effective manner so that it could make sense for both technical as well as
the non-technical audience. c
Overview
The security posture of MUSA is quite low so there is the need to introduce a
new and improved security awareness program. In order to make the new security model
work, one of the basic things that must be taken into consideration is the communication
plan. The role of a security communication plan is of paramount importance as it can
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 21
help the employees to take necessary steps so that the high quality of security can be
maintained in the best possible manner (Bashay, 2019). The document acts as a guide
which can increase the overall awareness of the workfare in MUSA on various security
aspects. The primary objective of the communication plan is to safeguard the
Confidentiality, Integrity, and Availability of the digital resources and information of the
business entity.
The communication plan sheds light on a number of messaging strategic
approaches that can help MUSA to share details on the new security model. It would
also help the organizational personnel to get a detailed idea about their exact roles and
responsibilities to execute the plan (Where The World Talks Security | RSA Conference,
2019).
Messaging Strategies
While designing a suitable messaging strategic framework, it is necessary to
identify the important areas that the specific communication message will address. Some
of the main areas include cyber laws, the cost associated with security breaches in the
organizational setting, personally identifiable information (PII) breaches, the need of
security awareness and the implication of awareness programs on the security posture
and culture of the business organization. The effectiveness of MUSA’s new security
awareness model will largely depend on the lines of communication that are established
by the business undertaking. The management of MUSA must constantly evaluate the
internal communication approach so that the organizational personnel can be constantly
informed of the best security practices that can be implemented to handle different kinds
of security threats.
Implementing different communication methods for different stakeholders
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 22
MUSA must ensure that the communication channels and methods that are
introduced to increase the level of awareness of the security model can serve the
purpose. Thus the use of communication approaches must be different when MUSA
interacts with different internal stakeholders such as employees, IT professionals, senior
management team and non-IT members. For example, while sharing a message on
security with non-technical members, video presentations could be used. But while
sharing a message with members from the IT department, emails or memo could be
used (Where The World Talks Security | RSA Conference, 2019, p 6).
In order to implement a holistic and integrated messaging strategy that meets the
needs of all the internal personnel, MUSA could partner with its communication team.
Such an approach would be beneficial as the individuals would help to enhance the
messaging approaches so that information reaches all the target audience within the
business setting (Where The World Talks Security | RSA Conference, 2019, p 24).
High level of transparency
In order to enhance the importance of the security awareness plan, the messaging
strategy must be transparent and uniform in nature. Transparency initiatives must be the
key focus of MUSA so that carefully designed so that all the employees would be on
the same page and they would have uniform knowledge on the security model of the
business entity. By making the information transparent, the employees across various
departments of the business entity would understand how their actions and duties could
impact the security posture of the firm. In fact, a transparent communication approach
could bridge the trust gap between the IT department and the non-IT department of
Multiple Unite Security Assurance Corporation. True transparency is not merely about
giving information to the organizational personnel within the organizational setting. The
messaging strategy should be designed in such a manner so that the information could
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 23
be properly understood by the employees without any kind of confusion or ambiguity
(Gontovnikas, 2019).
Focus on the language of the message
Technology is a field which not many people are totally aware of. So while
spreading an important message about the security strategy, technical jargons must not
be used by Information Technology managers. This is an important aspect that MUSA
must keep in mind so that the message that is being communicated by it can be
understood in a clear manner by all the intended audience irrespective of the department
in which they function. According to E Kelly Hansen, the Chief Executive Officer of
Neohapsis Inc., the language of IT cannot be easily understood by non-IT professionals.
So in order to deal with this issue, simple English language must be used while
communicating about the security awareness program and its importance in the
organizational setting. The wrong use of language would naturally encourage to stop
paying attention to the message as it would be going over their heads. So simple and
understandable language needs to be used so that professionals from both the IT and
non-IT department could understand the relevance of the security awareness program
(News, Tips, and Advice for Technology Professionals - TechRepublic, 2019).
Starting the communication from the top
The security awareness program could have a major impact on the existence and
sustainability of the business entity. So before communicating about the same, it is
necessary to initiate the communication from the top. This would mean that the leaders
and decision-makers would act as the starting point of the communication. The visible
backing of the leader of Multiple Unite Security Assurance (MUSA) Corporation would
encourage the employees from all across the firm to participate in the approach (News,
Tips, and Advice for Technology Professionals - TechRepublic, 2019). The evidence of
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 24
executive stewardship would be of paramount importance in the business context to
adopt an interactive and engaging communication approach. Similarly, the IT
professionals in the business setting must take the initiative to make the leaders and
senior managers understand the significance of the security awareness model which
could constructively influence the security posture of MUSA.
Streamlining the communication model
The security success program of MUSA could be successful throughout the
business entity only if a uniform and streamlined communication network would be
deployed. c There is the need to constantly evaluate and align the internal communication
channels so that the employees across all the departments of the firm would be able to
understand how the security model could have implications on them, their department
and the entire business entity (News, Tips, and Advice for Technology Professionals -
TechRepublic, 2019). The proper flow of information on the security program would
keep the employees on their toes. They would be encouraged to adopt safe practices
which could restrict the adverse implications on the security aspect of MUSA.
Security culture
A healthy security culture is the need of the hour at Multiple Unite Security
Assurance Corporation so that its security posture could be improved. In order to
effectively promote a healthy security culture throughout the business setting, a number
of approaches could be implemented.
Focus on awareness – The management of the business entity must focus on
making the employees aware of the significance of having a robust and healthy security
culture. For example, for developers and testers that functions in the IT department, an
application security awareness approach could be employed. It would help to carefully
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 25
evaluate the seriousness of a security threat and take necessary actions to deal with it (6
ways to develop a security culture in your organization, 2019).
Deployment of leadership-driven cyber governance model – In order to encourage
a healthy security culture, the active involvement of senior managers and leaders would
be indispensable in the organizational context of MUSA. Their participation would
influence the employees at all the levels of MUSA to focus on their individual roles and
duties so that they could contribute to enhancing the level of security in the business
setting (Four Tips for Building a Strong Security Culture in Your Organization, 2019).
Thus the strong commitment by the top management of MUSA would help to convince
diverse stakeholders of MUSA to strengthen the healthy security culture.
Clear documentation of security policies – Establishment of clear and well-
defined security policies and guidelines would act as the cornerstone of a healthy
security culture. Thus in MUSA, the new security policies must be clearly documented
so that they would guide the employees while conducting the day to day business
activities and processes (Four Tips for Building a Strong Security Culture in Your
Organization, 2019).
Providing adequate training to the staff members – The management of MUSA must
ensure that the employees get the necessary training to understand the relevance of
security in the unpredictable IT setting. Such an approach would be of paramount
importance as it would assist in fostering a healthy security culture among the
employees (Four Tips for Building a Strong Security Culture in Your Organization,
2019).
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 26
Conclusion
The security policies that have been presented here must be introduced by Multiple
Unite Security Assurance (MUSA) Corporation so that it would be in a position to
address the security gaps that exist in its organization. The policies have been designed
in a strategic manner so that the firm would be in a position to deal with intentional
threats as well as unintentional threats that could arise before it. These policies would
primarily empower the business entity and its employees so that they could take
necessary measures to protect the security system. The policies that have been designed
specifically revolve around human errors that give an unfair advantage to unauthorized
individuals and cyber attackers in the virtual platform. These policies could be effective
only if the employees would follow them strictly in the organizational context. The role
of a well-planned communication and messaging strategy would be extremely vital to
improving the security posture of MUSA. The various strategic elements that have been
encompassed in the communication plan include the proper implementation of varying
communication methods for different stakeholders, maintaining a high level of
transparency, high focus on the language of the message, starting the communication
from the top and streamlining the overall communication model. There is an urgent
need to make the diverse stakeholder of MUSA understand the importance of a healthy
security culture. Various approaches that could be introduced to promote a healthy
security culture include the focus on awareness, deployment of leadership-driven cyber
governance model, clear documentation of security policies and providing necessary
training to the employees.
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 27
References
Alotaibi, F., Furnell, S., Stengel, I., & Papadaki, M. (2016). A review of using gaming
technology for cyber-security awareness. Int. J. Inf. Secur. Res.(IJISR), 6(2), 660-
666.
Bada, M., Sasse, A. M., & Nurse, J. R. (2019). Cyber security awareness campaigns:
Why do they fail to change behaviour?. arXiv preprint arXiv:1901.02672.
Öğütçü, G., Testik, Ö. M., & Chouseinoglou, O. (2016). Analysis of personal
information security behavior and awareness. Computers & Security, 56, 83-93.
Nabi, I. A. (2018). Growth analysis of cyber security awareness among mass people of
Bangladesh: a case study(Doctoral dissertation, Daffodil International University).
Korpela, K. (2015). Improving cyber security awareness and training programs with data
analytics. Information Security Journal: A Global Perspective, 24(1-3), 72-77.
The Components of a Successful Security Awareness Program. (2019). Retrieved from
https://resources.infosecinstitute.com/components-successful-security-awareness-
program/
Behr, A. (2019). Separation of duties and IT security. Retrieved from
https://www.csoonline.com/article/2123120/separation-of-duties-and-it-security.html
Encryption and Its Importance to Device Networking. (2019). Retrieved from
https://www.lantronix.com/wp-content/uploads/pdf/Encryption-and-Device-
Networking_WP.pdf
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 28
Glaspie, H. W., & Karwowski, W. (2017, July). Human factors in information security
culture: A literature review. In International Conference on Applied Human
Factors and Ergonomics (pp. 269-280). Springer, Cham.
IT0125 - Configuration Management. (2019). Retrieved from
https://policy.tennessee.edu/wp-content/uploads//policytech/system-wide/it/IT0125-
Configuration-Management.pdf
Media Access Control Security Overview - TechLibrary - Juniper Networks. (2019).
Retrieved from https://www.juniper.net/documentation/en_US/junos-space-
apps/network-director3.3/topics/concept/macsec-understanding.html
Nobles, C. (2018). Botching Human Factors in Cybersecurity in Business Organizations.
HOLISTICA–Journal of Business and Public Administration, 9(3), 71-88.
Remote Access: The Pros and Cons of Virtual Private Networking | macchina.io Blog.
(2019). Retrieved from https://macchina.io/blog/security/remote-access-the-pros-and-
cons-of-virtual-private-networking/
Secure Hash Algorithms | Brilliant Math & Science Wiki. (2019). Retrieved from
https://brilliant.org/wiki/secure-hashing-algorithms/
Time off to discover fraud - FSS. (2019). Retrieved from
https://www.forensicstrategic.com/blog/time-off-to-discover-fraud
Threats to Security. (2019). Retrieved from https://www.cerias.purdue.edu/assets/pdf/k-
12/infosec_newsletters/03threats.pdf
What is SSL VPN (Secure Sockets Layer virtual private network)? - Definition from
WhatIs.com. (2019). Retrieved from
https://searchsecurity.techtarget.com/definition/SSL-VPN
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 29
What is Data Loss Prevention (DLP)? A Definition of Data Loss Prevention. (2019).
Retrieved from https://digitalguardian.com/blog/what-data-loss-prevention-dlp-
definition-data-loss-prevention
What is Social Engineering | Attack Techniques & Prevention Methods | Imperva.
(2019). Retrieved from https://www.imperva.com/learn/application-security/social-
engineering-attack/
What is an Intrusion Prevention System? - Palo Alto Networks. (2019). Retrieved from
https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-prevention-system-
ips
5 bad practices that hinder your security, and how to improve it | TechBeacon. (2019).
Retrieved from https://techbeacon.com/enterprise-it/5-bad-practices-hinder-your-
security-how-improve-it
Five tips for managing project change requests. (2019). Retrieved from
https://www.computerweekly.com/opinion/Five-tips-for-managing-project-change-
requests
Mark, G., Czerwinski, M., & Iqbal, S. T. (2018, April). Effects of Individual Differences
in Blocking Workplace Distractions. In Proceedings of the 2018 CHI Conference
on Human Factors in Computing Systems (p. 92). ACM.
Slack, Q. (2019). Why vacation at tech companies should be mandatory: better code,
happier people. Retrieved from https://about.sourcegraph.com/blog/why-vacation-at-
tech-companies-should-be-mandatory-better-code-happier-people
Three Reasons Your Company Should Make Vacation Mandatory. (2019). Retrieved
from https://www.forbes.com/sites/amberjohnson-jimludema/2018/06/05/three-
reasons-your-company-should-make-vacation-mandatory/#5bc85c2638ec
IT 552 c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c
c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c c 30
6 ways to develop a security culture in your organization. (2019). Retrieved 19 July
2019, from https://techbeacon.com/security/6-ways-develop-security-culture-top-
bottom
Bashay, F. (2019). What Is the CIA Triangle and Why Is It Important for Cybersecurity
Management?. Retrieved 19 July 2019, from https://www.difenda.com/blog/what-is-
the-cia-triangle-and-why-is-it-important-for-cybersecurity-management
Four Tips for Building a Strong Security Culture in Your Organization. (2019).
Retrieved 19 July 2019, from https://blog.netwrix.com/2018/06/28/four-tips-for-
building-a-strong-security-culture-in-your-organization/
Gontovnikas, M. (2019). Cybersecurity Shouldn’t Be a Secret: Why Transparency
Matters. Retrieved 19 July 2019, from https://auth0.com/blog/cybersecurity-shouldnt-
be-a-secret/
News, Tips, and Advice for Technology Professionals - TechRepublic. (2019). Retrieved
19 July 2019, from https://www.techrepublic.com/article/success-strategies-for-
security-awareness/
Where The World Talks Security | RSA Conference. (2019). Retrieved 19 July 2019,
from https://www.rsaconference.com/writable/presentations/file_upload/hum-t09-
building-a-strategic-plan-for-your-security-awareness-program.pdf