1 / 9100%
Running Head: IT 552 ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad a ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad
ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad 1
IT 552 : Final Project Milestone 4
IT 552
2
Introduction
A robust communication plan has been designed for Multiple Unite Security
Assurance (MUSA) Corporation which will help to addresses and summarize the
importance of a security awareness program. The role of the communication model
would be of paramount importance as it would enable the employees of the business
undertaking to get a detailed insight into how security could strengthen its
Information Technology ecosystem. The designed communication plan encompasses a
number of messaging strategies which could ensure that the key stakeholders would
be able to understand, buy into, and support the continuous improvement of the
proposed security awareness program.
The thorough engagement would play a vital role to influence a culture that
gives due importance to IT security. In fact, the communication plan could enhance
the success of the organization as it would assist to convince diverse stakeholders of
the entity to support the healthy security culture. The communication plan is
designed in a simple and effective manner so that it could make sense for both
technical as well as the non-technical audience. ad
Overview
The security posture of MUSA is quite low so there is the need to introduce
a new and improved security awareness program. In order to make the new security
model work, one of the basic things that must be taken into consideration is the
communication plan. The role of a security communication plan is of paramount
importance as it can help the employees to take necessary steps so that the high
quality of security can be maintained in the best possible manner (Bashay, 2019).
The document acts as a guide which can increase the overall awareness of the
workfare in MUSA on various security aspects. The primary objective of the
IT 552
3
communication plan is to safeguard the Confidentiality, Integrity, and Availability of
the digital resources and information of the business entity.
The communication plan sheds light on a number of messaging strategic
approaches that can help MUSA to share details on the new security model. It
would also help the organizational personnel to get a detailed idea about their exact
roles and responsibilities to execute the plan (Where The World Talks Security |
RSA Conference, 2019).
Messaging Strategies
While designing a suitable messaging strategic framework, it is necessary to
identify the important areas that the specific communication message will address.
Some of the main areas include cyber laws, the cost associated with security
breaches in the organizational setting, personally identifiable information (PII)
breaches, the need of security awareness and the implication of awareness programs
on the security posture and culture of the business organization. The effectiveness of
MUSA’s new security awareness model will largely depend on the lines of
communication that are established by the business undertaking. The management of
MUSA must constantly evaluate the internal communication approach so that the
organizational personnel can be constantly informed of the best security practices that
can be implemented to handle different kinds of security threats.
Implementing different communication methods for different stakeholders
MUSA must ensure that the communication channels and methods that are
introduced to increase the level of awareness of the security model can serve the
purpose. Thus the use of communication approaches must be different when MUSA
interacts with different internal stakeholders such as employees, IT professionals,
senior management team and non-IT members. For example, while sharing a message
IT 552
4
on security with non-technical members, video presentations could be used. But while
sharing a message with members from the IT department, emails or memo could be
used (Where The World Talks Security | RSA Conference, 2019, p 6). ad
In order to implement a holistic and integrated messaging strategy that meets
the needs of all the internal personnel, MUSA could partner with its communication
team. Such an approach would be beneficial as the individuals would help to
enhance the messaging approaches so that information reaches all the target audience
within the business setting (Where The World Talks Security | RSA Conference,
2019, p 24).
High level of transparency
In order to enhance the importance of the security awareness plan, the
messaging strategy must be transparent and uniform in nature. Transparency
initiatives must be the key focus of MUSA so that carefully designed so that all the
employees would be on the same page and they would have uniform knowledge on
the security model of the business entity. By making the information transparent, the
employees across various departments of the business entity would understand how
their actions and duties could impact the security posture of the firm. In fact, a
transparent communication approach could bridge the trust gap between the IT
department and the non-IT department of Multiple Unite Security Assurance
Corporation. True transparency is not merely about giving information to the
organizational personnel within the organizational setting. The messaging strategy
should be designed in such a manner so that the information could be properly
understood by the employees without any kind of confusion or ambiguity
(Gontovnikas, 2019).
Focus on the language of the message
IT 552
5
Technology is a field which not many people are totally aware of. So while
spreading an important message about the security strategy, technical jargons must
not be used by Information Technology managers. This is an important aspect that
MUSA must keep in mind so that the message that is being communicated by it
can be understood in a clear manner by all the intended audience irrespective of the
department in which they function. According to E Kelly Hansen, the Chief
Executive Officer of Neohapsis Inc., the language of IT cannot be easily understood
by non-IT professionals. So in order to deal with this issue, simple English language
must be used while communicating about the security awareness program and its
importance in the organizational setting. The wrong use of language would naturally
encourage to stop paying attention to the message as it would be going over their
heads. So simple and understandable language needs to be used so that professionals
from both the IT and non-IT department could understand the relevance of the
security awareness program (News, Tips, and Advice for Technology Professionals -
TechRepublic, 2019).
Starting the communication from the top
The security awareness program could have a major impact on the existence
and sustainability of the business entity. So before communicating about the same, it
is necessary to initiate the communication from the top. This would mean that the
leaders and decision-makers would act as the starting point of the communication.
The visible backing of the leader of Multiple Unite Security Assurance (MUSA)
Corporation would encourage the employees from all across the firm to participate in
the approach (News, Tips, and Advice for Technology Professionals - TechRepublic,
2019). The evidence of executive stewardship would be of paramount importance in
the business context to adopt an interactive and engaging communication approach.
IT 552
6
Similarly, the IT professionals in the business setting must take the initiative to
make the leaders and senior managers understand the significance of the security
awareness model which could constructively influence the security posture of MUSA.
Streamlining the communication model
The security success program of MUSA could be successful throughout the
business entity only if a uniform and streamlined communication network would be
deployed. There is the need to constantly evaluate and align the internal
communication channels so that the employees across all the departments of the firm
would be able to understand how the security model could have implications on
them, their department and the entire business entity (News, Tips, and Advice for
Technology Professionals - TechRepublic, 2019). The proper flow of information on
the security program would keep the employees on their toes. They would be
encouraged to adopt safe practices which could restrict the adverse implications on
the security aspect of MUSA.
Security culture
A healthy security culture is the need of the hour at Multiple Unite Security
Assurance Corporation so that its security posture could be improved. In order to
effectively promote a healthy security culture throughout the business setting, a
number of approaches could be implemented.
Focus on awareness – The management of the business entity must focus on
making the employees aware of the significance of having a robust and healthy
security culture. For example, for developers and testers that functions in the IT
department, an application security awareness approach could be employed. It would
help to carefully evaluate the seriousness of a security threat and take necessary
IT 552
7
actions to deal with it (6 ways to develop a security culture in your organization,
2019).
Deployment of leadership-driven cyber governance model – In order to
encourage a healthy security culture, the active involvement of senior managers and
leaders would be indispensable in the organizational context of MUSA. Their
participation would influence the employees at all the levels of MUSA to focus on
their individual roles and duties so that they could contribute to enhancing the level
of security in the business setting (Four Tips for Building a Strong Security Culture
in Your Organization, 2019). Thus the strong commitment by the top management
of MUSA would help to convince diverse stakeholders of MUSA to strengthen the
healthy security culture.
Clear documentation of security policies – Establishment of clear and well-
defined security policies and guidelines would act as the cornerstone of a healthy
security culture. Thus in MUSA, the new security policies must be clearly
documented so that they would guide the employees while conducting the day to
day business activities and processes (Four Tips for Building a Strong Security
Culture in Your Organization, 2019).
Providing adequate training to the staff members – The management of MUSA must
ensure that the employees get the necessary training to understand the relevance of
security in the unpredictable IT setting. Such an approach would be of paramount
importance as it would assist in fostering a healthy security culture among the
employees (Four Tips for Building a Strong Security Culture in Your Organization,
2019).
Conclusion
IT 552
8
The role of a well-planned communication and messaging strategy would be
extremely vital to improving the security posture of MUSA. The various strategic
elements that have been encompassed in the communication plan include the proper
implementation of varying communication methods for different stakeholders,
maintaining a high level of transparency, high focus on the language of the message,
starting the communication from the top and streamlining the overall communication
model. There is an urgent need to make the diverse stakeholder of MUSA
understand the importance of a healthy security culture. Various approaches that
could be introduced to promote a healthy security culture include the focus on
awareness, deployment of leadership-driven cyber governance model, clear
documentation of security policies and providing necessary training to the employees.
References
6 ways to develop a security culture in your organization. (2019). Retrieved 19 July
2019, from https://techbeacon.com/security/6-ways-develop-security-culture-top-
bottom
Bashay, F. (2019). What Is the CIA Triangle and Why Is It Important for
Cybersecurity Management?. Retrieved 19 July 2019, from
https://www.difenda.com/blog/what-is-the-cia-triangle-and-why-is-it-important-for-
cybersecurity-management
IT 552
9
Four Tips for Building a Strong Security Culture in Your Organization. (2019).
Retrieved 19 July 2019, from https://blog.netwrix.com/2018/06/28/four-tips-for-
building-a-strong-security-culture-in-your-organization/
Gontovnikas, M. (2019). Cybersecurity Shouldn’t Be a Secret: Why Transparency
Matters. Retrieved 19 July 2019, from https://auth0.com/blog/cybersecurity-
shouldnt-be-a-secret/
News, Tips, and Advice for Technology Professionals - TechRepublic. (2019).
Retrieved 19 July 2019, from https://www.techrepublic.com/article/success-
strategies-for-security-awareness/
Where The World Talks Security | RSA Conference. (2019). Retrieved 19 July 2019,
from https://www.rsaconference.com/writable/presentations/file_upload/hum-t09-
building-a-strategic-plan-for-your-security-awareness-program.pdf
Students also viewed