Running Head: IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g 1
IT 552: Final Project
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 2
Table of Contents
Executive Summary ................................................................................................................... 3
Proposal Introduction ............................................................................................................... 4
Security Policies Development ................................................................................................. 6
Continuous Monitoring Plan .................................................................................................. 15
Communication Plan ............................................................................................................... 19
Conclusion ............................................................................................................................... 25
References ............................................................................................................................... 26
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 3
Executive Summary
In the digitalized era, cyber threats can any side and cripple the Information
Technology ecosystem of an organization. In order to be well equipped against unknown
threats and risks, business entities spend huge volumes of finance so that they can
safeguard themselves against sophisticated threats and attacks in the virtual setting. Mainly
businesses invest money to introduce robust defense and detection mechanisms so that
cyber attackers can be kept at a distance.
As per the case relating to Multiple Unite Security Assurance (MUSA)
Corporation, its security posture is low. One of the main reasons for the poor security
model can be attributed to the human factors that operate in the organizational setting
(Glaspie & Karwowski, 2017). As per numerous researchers, in many cases, human factors
botch up the IT security setting of an organization. Due to their intentional or unintentional
error, unauthorized users gain an access into the system which ultimately compromises the
security (Nobles, 2018).
A number of policies have been presented here that can help to address vital
security issues that can arise in the prevailing organizational context due to human factors.
By implementation of such policies, business organizations can be empowered to enhance
their security posture. The effective management of cybersecurity model will only be
possible if the security policies are taken into consideration the security threats and risks
that arise due to the involvement of the human factors (Nobles, 2018). A robust
communication plan has been designed for Multiple Unite Security Assurance (MUSA)
Corporation which will help to addresses and summarize the importance of a security
awareness program.
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 4
Proposal Introduction
Purpose
In the dynamic and unpredictable business setting, it is necessary for organizations
to have a robust cyber security model so that they can be well equipped against online
threats and risks. This security awareness program proposal of Multiple Unite Security
Assurance (MUSA) Corporation has been presented here so that the existing poor security
posture can be strengthened (Bada, Sasse & Nurse, 2019). The present security posture of
MUSA is low as it is exposed to a high level of cyber threats and risks that can cripple the
IT ecosystem of the firm and the business operations.
The fundamental purpose of the security awareness program proposal is to help
Multiple Unite Security Assurance (MUSA) Corporation to upgrade the existing security
posture so that it can function in a safe and secure manner. At present, the employees do
not have proper cybersecurity awareness training and this naturally adversely influences
the security climate within the MUSA organization (Bada, Sasse & Nurse, 2019). Due to
their lack of adequate skills and technical expertise, they are unable to take suitable actions
against different kinds of online threats and attacks. This proposal intends to empower the
organizational personnel of MUSA so that they will be in a position to deal with different
kinds of attacks and threats that can hamper the business activities and processes.
Security Posture
As per the risk assessment of the organization, it lacks a proper cybersecurity
program in place that can help it to be well prepared to deal with external or internal
threats that can arise on the online platform. As the human factors that operate in the
business setting do not have the technical skills and they have not been trained properly by
the organization, it faces numerous risks and uncertainties in the digital environment (Nabi,
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 5
2018). This proposal relating to security awareness program of MUSA has been designed
so that the existing gaps in its security system can be filled and the firm’s security posture
can be improved to a significant degree (The Components of a Successful Security
Awareness Program, 2019).
Human Factors
The proposal would also help MUSA to take care of a number of organizational
factors that come into play and contribute to the unhealthy security culture in the business
entity. For instance, it will encompass the relevant security policies, tools, and techniques
that can be implemented in the organizational setting to strengthen the security approach.
In addition to this, the proposal would focus on the technical training needs of the
employees so that they would be in a better position to identify varying kinds of cyber
threats and take necessary actions so that the security model of the firm would not be
compromised (Alotaibi et al., 2016). Thus the intention of the security awareness program
proposal is to make the employees aware of various kinds of security elements that can be
introduced or implemented to strengthen the cybersecurity infrastructure of Multiple Unite
Security Assurance Corporation. It would also help to constructively mold the factors that
come into play and increase the vulnerability of the business in the cyber setting.
Organizational Factors
A total of ten security gaps have been presented in the security posture of the
business entity that needs to be addressed on an urgent basis. Some of the main security
concerns that have been included in this security awareness proposal are the lack of annual
cybersecurity awareness training for the employees, the absence of suitable configuration
change management policy, and the lack of intrusion detection or prevention system. In
addition to this, MUSA does not analyze or collect logs. The absence of media access
control policy adds to the security concerns of the business undertaking. In the
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 6
unpredictable technological setting, MUSA does not have encryption or hashing which can
control the data flow as well as the unauthorized alteration of data. These are some of the
major security concerns that the firm faces in an unpredictable technological setting. The
business entity has the opportunity to introduce in place Vulnerability assessment model
which will be able to assess the security posture status of the business undertaking
(Öğütçü, Testik & Chouseinoglou, 2016).
The security concerns of Multiple Unite Security Assurance Corporation that have
been identified here not only jeopardize the online sustainability of the business
undertaking but it also has an adverse implication on the morale of the employees
(Korpela, 2015). Due to the high level of security issues that the business encounters on a
usual basis, the level of employee turnover is high and it impacts the profitability and
performance of the business as well. The security awareness program proposal for MUSA
has been designed so that the employees can be empowered to identify the various online
threats and risks that can adversely impact their Information Technology ecosystem.
Security Policies Development
Proposal for mitigating security threats that arise due to human factors
A perfect security awareness model has been presented here so that it would help to
mitigate the threats that are posed by the human factors to the organization’s security
posture. The proposal that has been designed for the business entity encompasses a total of
ten security policies that would enable the firm to fill the security gaps that currently exist
and weaken the security posture of MUSA (Threats to Security, 2019). The policies have
been crafted so that the organization would be in a position to address unintentional threats
as well as intentional threats or social engineering. The policies that have been designed
also focus on the quality of data flow so that it could not be tampered with.
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 7
As per the strategy that has been presented here, the cybersecurity threats that arise
before the entity can be categorized into two types namely unintentional threats and
intentional threats. The unintentional threats can be defined as the threats that arise due to
human errors or computer failure (Threats to Security, 2019). The intentional threats are
the ones that arise on the online platform due to various kinds of malicious elements such
as viruses, theft of data, denial of service attack and other factors that have been malicious
intent. The security policies have been strategically framed so that the existing security
gaps can be addressed in an effective manner. g
Policies
A. Protection against unintentional threats
The following security policies have been proposed here would help Multiple Unite
Security Assurance Corporation to safeguard itself against various kinds of unintentional
threats that arise due to human factors and adversely impact the security if the
organization.
Changes in the remote access mechanism
The remote access is a policy that can enable employees of an organization to work
remotely or work from their home. This policy might be employee friendly but at the same
time, it gives rise to a number of security concerns as unauthorized users have the
opportunity to gain access into the organizational network. The employees that work
remotely can gain access into the organizational system from anywhere at any time. There
is the possibility that these individuals will unintentionally make blunders while surfing the
internet. Such an innocent error on part of the employees working remotely can have a
detrimental implication on the business entity. For example, in case the employees, click
on the link of a malicious site from their personal computer, unauthorized attackers could
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 8
gain entry into their systems and compromise the security, integrity, and confidentiality of
the organizational data.
In order to deal with the cybersecurity threats that arise due to the remote access
policy, there is the need to activate remote access feature that is present in the firewall. It
would make sure that the employees working remotely can gain access in a safe and secure
manner by making use of the Secure Sockets Layer Virtual Private Network feature (What
is SSL VPN (Secure Sockets Layer virtual private network)? - Definition from
WhatIs.com, 2019). By using this security feature, the origination’s personnel would be in
a position to create safe access to the MUSA’s system when they are working from home.
The employees could also use their mobile devices to work remotely in a safe working
environment after the implementation of the security policy (Remote Access: The Pros and
Cons of Virtual Private Networking | macchina.io Blog, 2019).
Introduction of encryption or hashing
Encryption and/or hashing are regarded to be some of the most basic security
measures that business undertakings need to implement so that the level of security of their
IT infrastructure can be strengthened to a certain degree. This policy has been proposed so
that the security could be strengthened whether the organizational data is ready for
transmission, it is in the process of transmission or it has already been transmitted. Data
encryption would be made mandatory so that it could deter malicious parties from gaining
unauthorized access into sensitive business information. The encryption process would
basically make use of algorithms which would convert ta into unique codes. The
computers that have the right key would be able to crack these codes and put them into the
original form. There are two types of encryption methods including symmetric key and
public key (or asymmetric). In the former method, the same key is used or installed in both
the systems that are responsible for receiving and transmitting the information. The public
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 9
key encryption, on the other hand, utilizes two sets of keys simultaneously namely a
private key and a public key to strengthen the security level. In the business context of
MUSA, the asymmetric encryption could be introduced to strengthen the security level
(Encryption and Its Importance to Device Networking, 2019).
Similarly, hashing has also been introduced in the security policy. The hash
methods like Secure Hash Algorithms (SHA-1, SHA-2, and SHA-3) could be employed so
that the integrity of the organizational data could be maintained and strengthened (Secure
Hash Algorithms | Brilliant Math & Science Wiki, 2019). These algorithms are designed
with strong encryptions so that they can effectively respond to online cyber-attacks. This
tool would enable the firm to keep a tab on any kind of modification or tampering of the
data that has been transmitted or received. For example, in case there is even a slight
change in any text file, the hash value of the modified file will be different from the
original hash value. Thus the organization will come to know that data has been tampered
with (Secure Hash Algorithms | Brilliant Math & Science Wiki, 2019). These methods
would facilitate the business entity to have a stronger control over the data flow and thus
capture any kind of unauthorized alteration of data.
Conducting regular checks and auditing of user accounts
At present, one of the major security gaps that have been identified in the MUSA
organization relates to the fact that the logs of the employees are not collected or analyzed.
There is the need to introduce a robust auditing protocol so that the accounts of all the
organizational personnel of MUSA would be thoroughly checked and scrutinized. For
instance, this security policy could be applied once in a quarter or once every six months
so that the safety and security of the accounts could be maintained. While conducting the
audit process of the user accounts, it is necessary to take in to account a number of aspects
such as whether the account is active or inactive (disabled). For example, both these
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 10
accounts could be targeted by online attackers so that they could gain unauthorized access
into the organization’s system.
Some of the key settings and properties that must be considered while
implementing the security policy relating to the auditing of user accounts include checking
of the login scripts, the activity of the workstations and the frequency of change of
passwords. The audit procedure would help Multiple Unite Security Assurance (MUSA)
Corporation to determine the real-time status of the accounts of the users. For example, in
case an account that has been disabled for a long time is active the Information
Technology team must take necessary actions to check the activity. g Similarly, in case, an
employee or user has failed to change or update his or her password in more than six
months, he must be notified to do the same on an urgent basis. This security policy would
be of vital importance as it would encourage the employees of the firm to take necessary
security measures at the individual level. Employees of the firm would try to take the
necessary steps at their individual level so that the existing security gaps could be
effectively addressed.
Introduction of media access control policy
A robust media access control policy could be introduced in the business setting to
secure the connections on the online platform. In the current times, a large number of
business activities are taking place in open virtual spaces such as social media platforms
which is increasing the vulnerability of the organization. In order to give a tough fight to
cybercriminals, it is necessary to have in place suitable media access control policies and
guidelines which would guide the employees while carrying out online business activities.
The policy would play a critical role to strengthen the firm’s security system and address
the existing security gaps. This is because; the employees would be able to carry out
activities in a careful and conscious manner so that online hackers would not get the scope
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 11
to gain unauthorized access into the network (Media Access Control Security Overview -
TechLibrary - Juniper Networks, 2019). For example, the firm could use a single login id
on social media platforms to design its social media marketing strategy. In case a second
user id is created or used, the same could be blocked for security reasons. Similarly,
MUSA could also implement Data Loss Prevention (DLP) tools so that it could keep a tab
on the flow of the sensitive information in the corporate network (What is Data Loss
Prevention (DLP)? A Definition of Data Loss Prevention, 2019).
Implementation of configuration change management policy
Change management refers to the formal process of making some kind of change in
the Information Technology system of an organization. In MUSA, a configuration change
management policy could be implemented so that the processes relating to change could be
effectively controlled. The policy could have a constructive implication on the security
model of the organization. For example, the security policy would make sure that the
integrity of the existing policies and codes is in place. In addition to this, the new policy
would help to identify security flaws. It would act as a baseline that could be used for
comparing the technical codes after any changes have been introduced in the IT system.
The policy would be necessary for improving the security of the firm as it would make
sure that there exists compliance with the minimum acceptable system configuration
requirements (IT0125 - Configuration Management, 2019, p 1). The policy could
safeguard MUSA against malicious threats and risk that could arise in the virtual
environment of the company.
B. Social Engineering
Social engineering can be defined as the act of tricking someone so that he or she
will make security blunders which can ultimately have an adverse impact on the security
model. In the case of Multiple Unite Security Assurance Corporation, the following
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 12
policies have been designed so that protection against social engineering could be possible
(What is Social Engineering | Attack Techniques & Prevention Methods | Imperva, 2019).
In the current times, online hackers are using sophisticated tools so that they can con
professionals to disclose sensitive information such as passwords. The security policies can
help MUSA to be well equipped against such kinds of online threats.
Providing annual cybersecurity awareness training
One of the basic steps is that the organization must design a robust annual cyber
security awareness training program so that its employees in all the departments would be
empowered to handle a tricky situation. As the name suggests, the training program would
be conducted on a yearly basis so that every time, the employees would be able to handle
sophisticated online threats. The training would encompass basis security concepts such as:
❖ Do not download attachments from unknown parties.
❖ Do not open the emails and messages that are in spam mail.
❖ Do not open emails that have been sent by unknown parties.
In addition to this, the annual cybersecurity awareness training would also involve
technical concepts that the users need to understand so that the security of the organization
could be strengthened. For instance, MUSA could introduce educational resources relating
to cybersecurity training and conduct regular tests. Only after the employees of MUSA
would be able to pass these tests, they would gain access to the firm’s system and network.
Introduction of intrusion detection/prevention system
An intrusion detection/ prevention system could be introduced in Multiple Unite
Security Assurance Corporation so that it could thoroughly examine the traffic of the
network. This system would be set behind the firewall so that it could detect and prevent
‘vulnerability exploits’. Vulnerability exploits can come in the form of malicious input and
could compromise the security of the IT infrastructure of the business. g By introducing this
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 13
layer of security, harmful content could be filtered out (What is an Intrusion Prevention
System? - Palo Alto Networks, 2019). The intrusion detection system would be responsible
to scan the network traffic and report back on any identified threats or risks. The intrusion
prevention system could be employed as it would help to carefully analyze and take
suitable actions on the network traffic flow of MUSA. By introducing these tools, the
security system of the firm could be improved and harmful elements in the network could
be identified.
Adoption of mandatory vacation policy
Multiple Unite Security Assurance (MUSA) Corporation could implement a
mandatory vacation policy which would require its employees to take leaves on a yearly
basis. Such a policy would have a direct impaction on the security model that is
implemented in the business setting. A mandatory vacation policy could play a key role in
the organizational context, as the firm would be able to detect fraudulent activities. The
policy would force all employees including the suspicious employees to take leave. So
they would have less amount of time with them to use their position in the firm to conduct
activities with malicious intention (Time off to discover fraud - FSS, 2019). During the
vacation time of suspicious employees, the management of the company could carry out
checks of the Information Technology infrastructure so that malicious behavior could be
identified.
Segregation of duties
Segregation of duties would act as one of the key concepts of internal control that
could positively impact the security of the IT system. By creating specific responsibilities
and duties that each and every employee has to perform in the business setting, the
management of MUSA could make sure that unwanted threats or risks and conflicts of
interests could be avoided (Behr, 2019). The fundamental objective of the policy would be
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 14
to disseminate the business activities and linked privileges so that the security model could
be strengthened. Such a policy would make sure that the employees would use their
workstations in a responsible manner so that no one can use their computer systems to do
any work without their prior knowledge. This regulatory mandate would have a direct
impact on the IT security of MUSA. The proper categorization and division of work
would be a major step towards a safe and secure IT system as the employees would take
ownership of their duties and act in a responsible manner. It could minimize the
vulnerability of MUSA in the virtual setting (Behr, 2019).
Personally identifiable information breaches
Personally, identifiable information could be introduced so that any data or
information could be used for the purpose of identifying particular organizational personnel
in MUSA. Private data could be saved by the company so that it would be in a position to
identify the individuals that are responsible for a data breach incident. This policy would
make sure that MUSA has the power to take necessary action or precautionary action to
safeguard itself from unauthorized access, data loss or theft (Behr, 2019). This is a vital
security policy that could be implemented at the organizational level so that specific
measures could be taken to tackle data security breaches and incidents.
Ensuring a sound connection between the data sender and the data receiver
In order to make sure that there exist a sound and secure connection between a data
sender and a data receiver, it is necessary to keep a number of security instruments in
place such as firewall, intrusion detection/ prevention system and antivirus. Such security
tools would play a key role to address the security concerns and establish a safe
environment where communication between a data sender and a data receiver could take
place. Similarly, the use of encryptions or hashing would also play a critical role. This is
because these security approaches would make sure that the data that is being received or
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 15
transmitted cannot be tampered with or altered from its intended meaning (Behr, 2019).
These security measures would be of paramount importance for MUSA as they could
strengthen the security infrastructure and limit the scope of online attackers to alter the
sensitive data or information relating to the business. Thus in order to address the issue
relating to poor communication on the IT platform of MUSA, it is necessary to encrypt all
the messages so that its real meaning could only be deciphered by the intended user. g g g g g g
g g g g g
Continuous Monitoring Plan
A continuous monitoring plan is necessary as it can help to keep a check on the
security control model that has been designed and implemented in the organizational
setting. This plan fundamentally lays out the foundation for regularly and consistently
monitoring the organization against malicious activities and intentional as well as
unintentional threats. In order to make sure that the monitoring plan is effective and serves
the desired purpose, it is necessary to focus on a number of elements such as the core
features of the work setting, the work plan, and employee readiness. In Multiple Unite
Security Assurance (MUSA) Corporation, there is the need to establish a properly
functional continuous monitoring plan so that the various security gaps that exist in the
organizational setting can be effectively addressed.
Work Settings
In the work setting, a wide range of factors come into play that can adversely
impact the work ambiance. Some of the most common elements are the non-implemented
security protocols, poorly implemented management policies, and other distractions and
obstacles. It is necessary to take the necessary steps by the managers and the management
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 16
team so that such negative elements which increase the security vulnerability of the firm
can be kept at a distance.
The management must take careful measures to ensure that all the security protocols
and policies are systematically implemented throughout the firm. Such a step is a necessity
as it will help the organization in the long run to have better control over its costs, risks
and system network (Five tips for managing project change requests, 2019). The major
changes that take place in the IT setting must be carefully documented and recorded so
that they can be assessed as per requirement. Some of the key steps that need to be
followed while introducing a major change in the organization include:
• A request must be made so that a change can be introduced. It needs to be
documented clearly.
• The change log has to be updated in a timely manner so that no details will be
skipped. The key elements that will be altered have to be written down in this
simple document. g g g
• The proper assessment of the change request is an important step. It will basically
help to develop a sense of urgency. In the case of MUSA, it is extremely vital to
introduce the necessary changes so that the quality of security can be upgraded.
• The thorough assessment of the change against the set criteria is of paramount
importance. It will assist in deciding whether the change has to be rejected or
approved
• The final step basically involves the decision that is taken regarding the approval or
the rejection of the change. During this stage, the outcome has to be communicated
to the key stakeholders so that they will be aware of the changes that have been
introduced in MUSA to strengthen the security model (Five tips for managing
project change requests, 2019).
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 17
The obstacles such as distractions can be managed by making sure that the
organizational personnel get the requisite space and time to focus on their job. The
managers and supervisors must interact and engage with the subordinates to get to know of
the key factors and elements that bother the employees and adversely impact their
performance (Mark, Czerwinski & Iqbal, 2018).
MUSA has to make sure that the management policies are properly implemented and
executed throughout the organization (5 bad practices that hinder your security, and how to
improve it | TechBeacon, 2019). It will play a vital role to make sure that security
violations can be curtailed to a possible extent. Some of the negative practices that must be
eliminated at once in the organizational setting are as follows:
• Sharing of common sensitive passwords throughout the entity
• Allowing unauthorized users in the secured and restricted read of the organization
• Ineffective implementation of the intrusion detection system (IDS) and intrusion
prevention system (IPS)
• Continuing to use outdated technological approaches
These are some of the practices that need to be avoided at any cost on MUSA so that
the security posture can be improved. Similarly, the firm has to introduce robust security
training for its employees so that they will be empowered to take the necessary steps to
improve the level of security of the entity. The firm must implement both software and
hardware firewalls so that a secure layer can be created which will keep unauthorized users
at a distance.
Work Planning and Control
The work and processes that are conducted in MMUSA must be strategically
planned and controlled as they can have a major implication on the performance and
productivity of the organizational personnel. Some of the key aspects that must be
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 18
carefully taken into consideration while planning and controlling the work include the job-
related stress and pressure, time factor, the difficulty level of the assigned work and
ineffective task planning.
Some of the key strategies that can be introduced in MUSA for addressing job pressure,
time factors, task difficulty, routine alteration and lack of knowledge and skills are
introducing proper training sessions, implementing mandatory vacation policy and
conducting ‘vulnerability assessment’ on a frequent basis.
Training sessions
MUSA must take the necessary steps so that the technical knowledge and expertise
of its employees can be upgraded on a regular basis. By providing them training and
development opportunities, the employees would be encouraged to perform better. They
would be able to play an active role to mitigate the risks that arise in the IT setting of
MUSA. This element must be included in the work planning as it would have a positive
implication on the productivity of the employees.
Mandatory vacation policy
MUSA must introduce mandatory vacation policy so that employees will take
holiday to get a break from the hectic work schedule. It will help them to manage their
work-related stress and pressure (Three Reasons Your Company Should Make Vacation
Mandatory, 2019). This policy can also play a key role to improve the security framework
of the entity. This is because it will help the firm to keep a check on insider fraud (Slack,
2019). g g
Conducting regular vulnerability assessment
By carrying out regular vulnerability assessment, MUSA would be able to keep a
tab on the security aspect of its network and computer system. Such an evaluation process
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 19
must be conducted on public holidays so that the day to day work processes would not be
affected because of the security procedure.
Employee Readiness
Employees are the most critical asset of an entity. So their well-being, moral and
satisfaction must be the top priority of MUSA. It can introduce a number of strategic
approaches so that it would be in a position to address issues relating to inattentiveness,
high level of stress and anxiety, boredom and fatigue, and work-related illness or injury.
Only of the employees are mentally and physically fit and ready, they would be able to
optimally contribute to the performance and security framework of MUSA.
In order to manage a high level of stress, boredom, and fatigue, MUSA must
introduce mandatory vacation policy. By taking a break from the work, employees would
be able to focus on their personal health and well-being (Three Reasons Your Company
Should Make Vacation Mandatory, 2019). The managers must have a one-on-one
interaction with the subordinates so that they could share their concerns that make them
anxious.
An employee readiness program must be introduced so that the employees could actively
participate in the dynamic organizational setting. This could positively impact the
employee turnover of MUSA. Innovative engagement activities could be introduced such
as group discussions, events, and games so that no employee would get bored. A healthy
work environment must be created by taking into account the health and well-being of the
organizational personnel.
g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g Communication Plan
The thorough engagement would play a vital role to influence a culture that gives
due importance to IT security. In fact, the communication plan could enhance the success
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 20
of the organization as it would assist to convince diverse stakeholders of the entity to
support the healthy security culture. The communication plan is designed in a simple and
effective manner so that it could make sense for both technical as well as the non-technical
audience. g
Overview
The security posture of MUSA is quite low so there is the need to introduce a new
and improved security awareness program. In order to make the new security model work,
one of the basic things that must be taken into consideration is the communication plan.
The role of a security communication plan is of paramount importance as it can help the
employees to take necessary steps so that the high quality of security can be maintained in
the best possible manner (Bashay, 2019). The document acts as a guide which can increase
the overall awareness of the workfare in MUSA on various security aspects. The primary
objective of the communication plan is to safeguard the Confidentiality, Integrity, and
Availability of the digital resources and information of the business entity.
The communication plan sheds light on a number of messaging strategic
approaches that can help MUSA to share details on the new security model. It would also
help the organizational personnel to get a detailed idea about their exact roles and
responsibilities to execute the plan (Where The World Talks Security | RSA Conference,
2019).
Messaging Strategies
While designing a suitable messaging strategic framework, it is necessary to
identify the important areas that the specific communication message will address. Some of
the main areas include cyber laws, the cost associated with security breaches in the
organizational setting, personally identifiable information (PII) breaches, the need of
security awareness and the implication of awareness programs on the security posture and
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 21
culture of the business organization. The effectiveness of MUSA’s new security awareness
model will largely depend on the lines of communication that are established by the
business undertaking. The management of MUSA must constantly evaluate the internal
communication approach so that the organizational personnel can be constantly informed
of the best security practices that can be implemented to handle different kinds of security
threats.
Implementing different communication methods for different stakeholders
MUSA must ensure that the communication channels and methods that are
introduced to increase the level of awareness of the security model can serve the purpose.
Thus the use of communication approaches must be different when MUSA interacts with
different internal stakeholders such as employees, IT professionals, senior management
team and non-IT members. For example, while sharing a message on security with non-
technical members, video presentations could be used. But while sharing a message with
members from the IT department, emails or memo could be used (Where The World Talks
Security | RSA Conference, 2019, p 6). g
In order to implement a holistic and integrated messaging strategy that meets the
needs of all the internal personnel, MUSA could partner with its communication team.
Such an approach would be beneficial as the individuals would help to enhance the
messaging approaches so that information reaches all the target audience within the
business setting (Where The World Talks Security | RSA Conference, 2019, p 24).
High level of transparency
In order to enhance the importance of the security awareness plan, the messaging
strategy must be transparent and uniform in nature. Transparency initiatives must be the
key focus of MUSA so that carefully designed so that all the employees would be on the
same page and they would have uniform knowledge on the security model of the business
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 22
entity. By making the information transparent, the employees across various departments
of the business entity would understand how their actions and duties could impact the
security posture of the firm. In fact, a transparent communication approach could bridge
the trust gap between the IT department and the non-IT department of Multiple Unite
Security Assurance Corporation. True transparency is not merely about giving information
to the organizational personnel within the organizational setting. The messaging strategy
should be designed in such a manner so that the information could be properly understood
by the employees without any kind of confusion or ambiguity (Gontovnikas, 2019).
Focus on the language of the message
Technology is a field which not many people are totally aware of. So while
spreading an important message about the security strategy, technical jargons must not be
used by Information Technology managers. This is an important aspect that MUSA must
keep in mind so that the message that is being communicated by it can be understood in a
clear manner by all the intended audience irrespective of the department in which they
function. According to E Kelly Hansen, the Chief Executive Officer of Neohapsis Inc., the
language of IT cannot be easily understood by non-IT professionals. So in order to deal
with this issue, simple English language must be used while communicating about the
security awareness program and its importance in the organizational setting. The wrong use
of language would naturally encourage to stop paying attention to the message as it would
be going over their heads. So simple and understandable language needs to be used so that
professionals from both the IT and non-IT department could understand the relevance of
the security awareness program (News, Tips, and Advice for Technology Professionals -
TechRepublic, 2019).
Starting the communication from the top
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 23
The security awareness program could have a major impact on the existence and
sustainability of the business entity. So before communicating about the same, it is
necessary to initiate the communication from the top. This would mean that the leaders and
decision-makers would act as the starting point of the communication. The visible backing
of the leader of Multiple Unite Security Assurance (MUSA) Corporation would encourage
the employees from all across the firm to participate in the approach (News, Tips, and
Advice for Technology Professionals - TechRepublic, 2019). The evidence of executive
stewardship would be of paramount importance in the business context to adopt an
interactive and engaging communication approach. Similarly, the IT professionals in the
business setting must take the initiative to make the leaders and senior managers
understand the significance of the security awareness model which could constructively
influence the security posture of MUSA.
Streamlining the communication model
The security success program of MUSA could be successful throughout the
business entity only if a uniform and streamlined communication network would be
deployed. There is the need to constantly evaluate and align the internal communication
channels so that the employees across all the departments of the firm would be able to
understand how the security model could have implications on them, their department and
the entire business entity (News, Tips, and Advice for Technology Professionals -
TechRepublic, 2019). The proper flow of information on the security program would keep
the employees on their toes. They would be encouraged to adopt safe practices which
could restrict the adverse implications on the security aspect of MUSA.
Security culture
A healthy security culture is the need of the hour at Multiple Unite Security
Assurance Corporation so that its security posture could be improved. In order to
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 24
effectively promote a healthy security culture throughout the business setting, a number of
approaches could be implemented.
Focus on awareness – The management of the business entity must focus on
making the employees aware of the significance of having a robust and healthy security
culture. For example, for developers and testers that functions in the IT department, an
application security awareness approach could be employed. It would help to carefully
evaluate the seriousness of a security threat and take necessary actions to deal with it (6
ways to develop a security culture in your organization, 2019).
Deployment of leadership-driven cyber governance model – In order to encourage a
healthy security culture, the active involvement of senior managers and leaders would be
indispensable in the organizational context of MUSA. Their participation would influence
the employees at all the levels of MUSA to focus on their individual roles and duties so
that they could contribute to enhancing the level of security in the business setting (Four
Tips for Building a Strong Security Culture in Your Organization, 2019). Thus the strong
commitment by the top management of MUSA would help to convince diverse
stakeholders of MUSA to strengthen the healthy security culture.
Clear documentation of security policies – Establishment of clear and well-defined
security policies and guidelines would act as the cornerstone of a healthy security culture.
Thus in MUSA, the new security policies must be clearly documented so that they would
guide the employees while conducting the day to day business activities and processes
(Four Tips for Building a Strong Security Culture in Your Organization, 2019).
Providing adequate training to the staff members – The management of MUSA must
ensure that the employees get the necessary training to understand the relevance of security
in the unpredictable IT setting. Such an approach would be of paramount importance as it
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 25
would assist in fostering a healthy security culture among the employees (Four Tips for
Building a Strong Security Culture in Your Organization, 2019).
Conclusion
The security policies that have been presented here must be introduced by Multiple Unite
Security Assurance (MUSA) Corporation so that it would be in a position to address the
security gaps that exist in its organization. The policies have been designed in a strategic
manner so that the firm would be in a position to deal with intentional threats as well as
unintentional threats that could arise before it. These policies would primarily empower
the business entity and its employees so that they could take necessary measures to protect
the security system. The policies that have been designed specifically revolve around
human errors that give an unfair advantage to unauthorized individuals and cyber attackers
in the virtual platform. These policies could be effective only if the employees would
follow them strictly in the organizational context. The role of a well-planned
communication and messaging strategy would be extremely vital to improving the security
posture of MUSA. The various strategic elements that have been encompassed in the
communication plan include the proper implementation of varying communication methods
for different stakeholders, maintaining a high level of transparency, high focus on the
language of the message, starting the communication from the top and streamlining the
overall communication model. There is an urgent need to make the diverse stakeholder of
MUSA understand the importance of a healthy security culture. Various approaches that
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 26
could be introduced to promote a healthy security culture include the focus on awareness,
deployment of leadership-driven cyber governance model, clear documentation of security
policies and providing necessary training to the employees.
References
Alotaibi, F., Furnell, S., Stengel, I., & Papadaki, M. (2016). A review of using gaming
technology for cyber-security awareness. Int. J. Inf. Secur. Res.(IJISR), 6(2), 660-666.
Bada, M., Sasse, A. M., & Nurse, J. R. (2019). Cyber security awareness campaigns: Why
do they fail to change behaviour?. arXiv preprint arXiv:1901.02672.
Öğütçü, G., Testik, Ö. M., & Chouseinoglou, O. (2016). Analysis of personal information
security behavior and awareness. Computers & Security, 56, 83-93.
Nabi, I. A. (2018). Growth analysis of cyber security awareness among mass people of
Bangladesh: a case study(Doctoral dissertation, Daffodil International University).
Korpela, K. (2015). Improving cyber security awareness and training programs with data
analytics. Information Security Journal: A Global Perspective, 24(1-3), 72-77.
The Components of a Successful Security Awareness Program. (2019). Retrieved from
https://resources.infosecinstitute.com/components-successful-security-awareness-
program/
Behr, A. (2019). Separation of duties and IT security. Retrieved from
https://www.csoonline.com/article/2123120/separation-of-duties-and-it-security.html
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 27
Encryption and Its Importance to Device Networking. (2019). Retrieved from
https://www.lantronix.com/wp-content/uploads/pdf/Encryption-and-Device-
Networking_WP.pdf
Glaspie, H. W., & Karwowski, W. (2017, July). Human factors in information security
culture: A literature review. In International Conference on Applied Human Factors
and Ergonomics (pp. 269-280). Springer, Cham.
IT0125 - Configuration Management. (2019). Retrieved from
https://policy.tennessee.edu/wp-content/uploads//policytech/system-wide/it/IT0125-
Configuration-Management.pdf
Media Access Control Security Overview - TechLibrary - Juniper Networks. (2019).
Retrieved from https://www.juniper.net/documentation/en_US/junos-space-
apps/network-director3.3/topics/concept/macsec-understanding.html
Nobles, C. (2018). Botching Human Factors in Cybersecurity in Business Organizations.
HOLISTICA–Journal of Business and Public Administration, 9(3), 71-88.
Remote Access: The Pros and Cons of Virtual Private Networking | macchina.io Blog.
(2019). Retrieved from https://macchina.io/blog/security/remote-access-the-pros-and-
cons-of-virtual-private-networking/
Secure Hash Algorithms | Brilliant Math & Science Wiki. (2019). Retrieved from
https://brilliant.org/wiki/secure-hashing-algorithms/
Time off to discover fraud - FSS. (2019). Retrieved from
https://www.forensicstrategic.com/blog/time-off-to-discover-fraud
Threats to Security. (2019). Retrieved from https://www.cerias.purdue.edu/assets/pdf/k-
12/infosec_newsletters/03threats.pdf
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 28
What is SSL VPN (Secure Sockets Layer virtual private network)? - Definition from
WhatIs.com. (2019). Retrieved from
https://searchsecurity.techtarget.com/definition/SSL-VPN
What is Data Loss Prevention (DLP)? A Definition of Data Loss Prevention. (2019).
Retrieved from https://digitalguardian.com/blog/what-data-loss-prevention-dlp-
definition-data-loss-prevention
What is Social Engineering | Attack Techniques & Prevention Methods | Imperva. (2019).
Retrieved from https://www.imperva.com/learn/application-security/social-
engineering-attack/
What is an Intrusion Prevention System? - Palo Alto Networks. (2019). Retrieved from
https://www.paloaltonetworks.com/cyberpedia/what-is-an-intrusion-prevention-system-
ips
5 bad practices that hinder your security, and how to improve it | TechBeacon. (2019).
Retrieved from https://techbeacon.com/enterprise-it/5-bad-practices-hinder-your-
security-how-improve-it
Five tips for managing project change requests. (2019). Retrieved from
https://www.computerweekly.com/opinion/Five-tips-for-managing-project-change-
requests
Mark, G., Czerwinski, M., & Iqbal, S. T. (2018, April). Effects of Individual Differences
in Blocking Workplace Distractions. In Proceedings of the 2018 CHI Conference on
Human Factors in Computing Systems (p. 92). ACM.
Slack, Q. (2019). Why vacation at tech companies should be mandatory: better code,
happier people. Retrieved from https://about.sourcegraph.com/blog/why-vacation-at-
tech-companies-should-be-mandatory-better-code-happier-people
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 29
Three Reasons Your Company Should Make Vacation Mandatory. (2019). Retrieved from
https://www.forbes.com/sites/amberjohnson-jimludema/2018/06/05/three-reasons-your-
company-should-make-vacation-mandatory/#5bc85c2638ec
6 ways to develop a security culture in your organization. (2019). Retrieved 19 July 2019,
from https://techbeacon.com/security/6-ways-develop-security-culture-top-bottom
Bashay, F. (2019). What Is the CIA Triangle and Why Is It Important for Cybersecurity
Management?. Retrieved 19 July 2019, from https://www.difenda.com/blog/what-is-
the-cia-triangle-and-why-is-it-important-for-cybersecurity-management
Four Tips for Building a Strong Security Culture in Your Organization. (2019). Retrieved
19 July 2019, from https://blog.netwrix.com/2018/06/28/four-tips-for-building-a-
strong-security-culture-in-your-organization/
Gontovnikas, M. (2019). Cybersecurity Shouldn’t Be a Secret: Why Transparency Matters.
Retrieved 19 July 2019, from https://auth0.com/blog/cybersecurity-shouldnt-be-a-
secret/
News, Tips, and Advice for Technology Professionals - TechRepublic. (2019). Retrieved
19 July 2019, from https://www.techrepublic.com/article/success-strategies-for-
security-awareness/
Where The World Talks Security | RSA Conference. (2019). Retrieved 19 July 2019, from
https://www.rsaconference.com/writable/presentations/file_upload/hum-t09-building-a-
strategic-plan-for-your-security-awareness-program.pdf