Running Head: IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
IT 552 : Continuous Monitoring Plan
SNHU
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
Introduction
A continuous monitoring plan is necessary as it can help to keep a check on the
security control model that has been designed and implemented in the organizational
setting. This plan fundamentally lays out the foundation for regularly and consistently
monitoring the organization against malicious activities and intentional as well as
unintentional threats. In order to make sure that the monitoring plan is effective and
serves the desired purpose, it is necessary to focus on a number of elements such as the
core features of the work setting, the work plan, and employee readiness. In Multiple
Unite Security Assurance (MUSA) Corporation, there is the need to establish a properly
functional continuous monitoring plan so that the various security gaps that exist in the
organizational setting can be effectively addressed.
Work Settings
In the work setting, a wide range of factors come into play that can adversely
impact the work ambiance. Some of the most common elements are the non-
implemented security protocols, poorly implemented management policies, and other
distractions and obstacles. It is necessary to take the necessary steps by the managers
and the management team so that such negative elements which increase the security
vulnerability of the firm can be kept at a distance.
The management must take careful measures to ensure that all the security protocols
and policies are systematically implemented throughout the firm. Such a step is a
necessity as it will help the organization in the long run to have better control over its
costs, risks and system network (Five tips for managing project change requests, 2019).
The major changes that take place in the IT setting must be carefully documented and
recorded so that they can be assessed as per requirement. Some of the key steps that
need to be followed while introducing a major change in the organization include:
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
• A request must be made so that a change can be introduced. It needs to be
documented clearly.
• The change log has to be updated in a timely manner so that no details will be
skipped. The key elements that will be altered have to be written down in this
simple document. e e e
• The proper assessment of the change request is an important step. It will
basically help to develop a sense of urgency. In the case of MUSA, it is
extremely vital to introduce the necessary changes so that the quality of security
can be upgraded.
• The thorough assessment of the change against the set criteria is of paramount
importance. It will assist in deciding whether the change has to be rejected or
approved
• The final step basically involves the decision that is taken regarding the approval
or the rejection of the change. During this stage, the outcome has to be
communicated to the key stakeholders so that they will be aware of the changes
that have been introduced in MUSA to strengthen the security model (Five tips
for managing project change requests, 2019).
The obstacles such as distractions can be managed by making sure that the
organizational personnel get the requisite space and time to focus on their job. The
managers and supervisors must interact and engage with the subordinates to get to know
of the key factors and elements that bother the employees and adversely impact their
performance (Mark, Czerwinski & Iqbal, 2018).
MUSA has to make sure that the management policies are properly implemented
and executed throughout the organization (5 bad practices that hinder your security, and
how to improve it | TechBeacon, 2019). It will play a vital role to make sure that
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
security violations can be curtailed to a possible extent. Some of the negative practices
that must be eliminated at once in the organizational setting are as follows:
• Sharing of common sensitive passwords throughout the entity
• Allowing unauthorized users in the secured and restricted read of the organization
• Ineffective implementation of the intrusion detection system (IDS) and intrusion
prevention system (IPS)
• Continuing to use outdated technological approaches
These are some of the practices that need to be avoided at any cost on MUSA so
that the security posture can be improved. Similarly, the firm has to introduce robust
security training for its employees so that they will be empowered to take the necessary
steps to improve the level of security of the entity. The firm must implement both
software and hardware firewalls so that a secure layer can be created which will keep
unauthorized users at a distance.
Work Planning and Control
The work and processes that are conducted in MMUSA must be strategically
planned and controlled as they can have a major implication on the performance and
productivity of the organizational personnel. Some of the key aspects that must be
carefully taken into consideration while planning and controlling the work include the
job-related stress and pressure, time factor, the difficulty level of the assigned work and
ineffective task planning.
Some of the key strategies that can be introduced in MUSA for addressing job pressure,
time factors, task difficulty, routine alteration and lack of knowledge and skills are
introducing proper training sessions, implementing mandatory vacation policy and
conducting ‘vulnerability assessment’ on a frequent basis.
Training sessions
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5
MUSA must take the necessary steps so that the technical knowledge and
expertise of its employees can be upgraded on a regular basis. By providing them
training and development opportunities, the employees would be encouraged to perform
better. They would be able to play an active role to mitigate the risks that arise in the
IT setting of MUSA. This element must be included in the work planning as it would
have a positive implication on the productivity of the employees.
Mandatory vacation policy
MUSA must introduce mandatory vacation policy so that employees will take
holiday to get a break from the hectic work schedule. It will help them to manage their
work-related stress and pressure (Three Reasons Your Company Should Make Vacation
Mandatory, 2019). This policy can also play a key role to improve the security
framework of the entity. This is because it will help the firm to keep a check on insider
fraud (Slack, 2019). e e
Conducting regular vulnerability assessment
By carrying out regular vulnerability assessment, MUSA would be able to keep a
tab on the security aspect of its network and computer system. Such an evaluation
process must be conducted on public holidays so that the day to day work processes
would not be affected because of the security procedure.
Employee Readiness
Employees are the most critical asset of an entity. So their well-being, moral and
satisfaction must be the top priority of MUSA. It can introduce a number of strategic
approaches so that it would be in a position to address issues relating to inattentiveness,
high level of stress and anxiety, boredom and fatigue, and work-related illness or injury.
Only of the employees are mentally and physically fit and ready, they would be able to
optimally contribute to the performance and security framework of MUSA.
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 6
In order to manage a high level of stress, boredom, and fatigue, MUSA must
introduce mandatory vacation policy. By taking a break from the work, employees
would be able to focus on their personal health and well-being (Three Reasons Your
Company Should Make Vacation Mandatory, 2019). The managers must have a one-on-
one interaction with the subordinates so that they could share their concerns that make
them anxious.
An employee readiness program must be introduced so that the employees could actively
participate in the dynamic organizational setting. This could positively impact the
employee turnover of MUSA. Innovative engagement activities could be introduced such
as group discussions, events, and games so that no employee would get bored. A
healthy work environment must be created by taking into account the health and well-
being of the organizational personnel.
References
5 bad practices that hinder your security, and how to improve it | TechBeacon. (2019).
Retrieved from https://techbeacon.com/enterprise-it/5-bad-practices-hinder-your-
security-how-improve-it
Five tips for managing project change requests. (2019). Retrieved from
https://www.computerweekly.com/opinion/Five-tips-for-managing-project-change-
requests
Mark, G., Czerwinski, M., & Iqbal, S. T. (2018, April). Effects of Individual Differences
in Blocking Workplace Distractions. In Proceedings of the 2018 CHI Conference
on Human Factors in Computing Systems (p. 92). ACM.
Slack, Q. (2019). Why vacation at tech companies should be mandatory: better code,
happier people. Retrieved from https://about.sourcegraph.com/blog/why-vacation-at-
tech-companies-should-be-mandatory-better-code-happier-people
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 7
Three Reasons Your Company Should Make Vacation Mandatory. (2019). Retrieved
from https://www.forbes.com/sites/amberjohnson-jimludema/2018/06/05/three-
reasons-your-company-should-make-vacation-mandatory/#5bc85c2638ec