Running Head: IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g 1
IT 552 : Continuous Monitoring Plan
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 2
Introduction
A continuous monitoring plan is necessary as it can help to keep a check on the
security control model that has been designed and implemented in the organizational
setting. This plan fundamentally lays out the foundation for regularly and consistently
monitoring the organization against malicious activities and intentional as well as
unintentional threats. In order to make sure that the monitoring plan is effective and serves
the desired purpose, it is necessary to focus on a number of elements such as the core
features of the work setting, the work plan, and employee readiness. In Multiple Unite
Security Assurance (MUSA) Corporation, there is the need to establish a properly
functional continuous monitoring plan so that the various security gaps that exist in the
organizational setting can be effectively addressed.
Work Settings
In the work setting, a wide range of factors come into play that can adversely
impact the work ambiance. Some of the most common elements are the non-implemented
security protocols, poorly implemented management policies, and other distractions and
obstacles. It is necessary to take the necessary steps by the managers and the management
team so that such negative elements which increase the security vulnerability of the firm
can be kept at a distance.
The management must take careful measures to ensure that all the security protocols
and policies are systematically implemented throughout the firm. Such a step is a necessity
as it will help the organization in the long run to have better control over its costs, risks
and system network (Five tips for managing project change requests, 2019). The major
changes that take place in the IT setting must be carefully documented and recorded so
that they can be assessed as per requirement. Some of the key steps that need to be
followed while introducing a major change in the organization include:
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 3
• A request must be made so that a change can be introduced. It needs to be
documented clearly.
• The change log has to be updated in a timely manner so that no details will be
skipped. The key elements that will be altered have to be written down in this
simple document. g g g
• The proper assessment of the change request is an important step. It will basically
help to develop a sense of urgency. In the case of MUSA, it is extremely vital to
introduce the necessary changes so that the quality of security can be upgraded.
• The thorough assessment of the change against the set criteria is of paramount
importance. It will assist in deciding whether the change has to be rejected or
approved
• The final step basically involves the decision that is taken regarding the approval or
the rejection of the change. During this stage, the outcome has to be communicated
to the key stakeholders so that they will be aware of the changes that have been
introduced in MUSA to strengthen the security model (Five tips for managing
project change requests, 2019).
The obstacles such as distractions can be managed by making sure that the
organizational personnel get the requisite space and time to focus on their job. The
managers and supervisors must interact and engage with the subordinates to get to know of
the key factors and elements that bother the employees and adversely impact their
performance (Mark, Czerwinski & Iqbal, 2018).
MUSA has to make sure that the management policies are properly implemented and
executed throughout the organization (5 bad practices that hinder your security, and how to
improve it | TechBeacon, 2019). It will play a vital role to make sure that security
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 4
violations can be curtailed to a possible extent. Some of the negative practices that must be
eliminated at once in the organizational setting are as follows:
• Sharing of common sensitive passwords throughout the entity
• Allowing unauthorized users in the secured and restricted read of the organization
• Ineffective implementation of the intrusion detection system (IDS) and intrusion
prevention system (IPS)
• Continuing to use outdated technological approaches
These are some of the practices that need to be avoided at any cost on MUSA so that
the security posture can be improved. Similarly, the firm has to introduce robust security
training for its employees so that they will be empowered to take the necessary steps to
improve the level of security of the entity. The firm must implement both software and
hardware firewalls so that a secure layer can be created which will keep unauthorized users
at a distance.
Work Planning and Control
The work and processes that are conducted in MMUSA must be strategically
planned and controlled as they can have a major implication on the performance and
productivity of the organizational personnel. Some of the key aspects that must be
carefully taken into consideration while planning and controlling the work include the job-
related stress and pressure, time factor, the difficulty level of the assigned work and
ineffective task planning.
Some of the key strategies that can be introduced in MUSA for addressing job pressure,
time factors, task difficulty, routine alteration and lack of knowledge and skills are
introducing proper training sessions, implementing mandatory vacation policy and
conducting ‘vulnerability assessment’ on a frequent basis.
Training sessions
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 5
MUSA must take the necessary steps so that the technical knowledge and expertise
of its employees can be upgraded on a regular basis. By providing them training and
development opportunities, the employees would be encouraged to perform better. They
would be able to play an active role to mitigate the risks that arise in the IT setting of
MUSA. This element must be included in the work planning as it would have a positive
implication on the productivity of the employees.
Mandatory vacation policy
MUSA must introduce mandatory vacation policy so that employees will take
holiday to get a break from the hectic work schedule. It will help them to manage their
work-related stress and pressure (Three Reasons Your Company Should Make Vacation
Mandatory, 2019). This policy can also play a key role to improve the security framework
of the entity. This is because it will help the firm to keep a check on insider fraud (Slack,
2019). g g
Conducting regular vulnerability assessment
By carrying out regular vulnerability assessment, MUSA would be able to keep a
tab on the security aspect of its network and computer system. Such an evaluation process
must be conducted on public holidays so that the day to day work processes would not be
affected because of the security procedure.
Employee Readiness
Employees are the most critical asset of an entity. So their well-being, moral and
satisfaction must be the top priority of MUSA. It can introduce a number of strategic
approaches so that it would be in a position to address issues relating to inattentiveness,
high level of stress and anxiety, boredom and fatigue, and work-related illness or injury.
Only of the employees are mentally and physically fit and ready, they would be able to
optimally contribute to the performance and security framework of MUSA.
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 6
In order to manage a high level of stress, boredom, and fatigue, MUSA must
introduce mandatory vacation policy. By taking a break from the work, employees would
be able to focus on their personal health and well-being (Three Reasons Your Company
Should Make Vacation Mandatory, 2019). The managers must have a one-on-one
interaction with the subordinates so that they could share their concerns that make them
anxious.
An employee readiness program must be introduced so that the employees could actively
participate in the dynamic organizational setting. This could positively impact the
employee turnover of MUSA. Innovative engagement activities could be introduced such
as group discussions, events, and games so that no employee would get bored. A healthy
work environment must be created by taking into account the health and well-being of the
organizational personnel.
References
5 bad practices that hinder your security, and how to improve it | TechBeacon. (2019).
Retrieved from https://techbeacon.com/enterprise-it/5-bad-practices-hinder-your-
security-how-improve-it
Five tips for managing project change requests. (2019). Retrieved from
https://www.computerweekly.com/opinion/Five-tips-for-managing-project-change-
requests
Mark, G., Czerwinski, M., & Iqbal, S. T. (2018, April). Effects of Individual Differences
in Blocking Workplace Distractions. In Proceedings of the 2018 CHI Conference on
Human Factors in Computing Systems (p. 92). ACM.
Slack, Q. (2019). Why vacation at tech companies should be mandatory: better code,
happier people. Retrieved from https://about.sourcegraph.com/blog/why-vacation-at-
tech-companies-should-be-mandatory-better-code-happier-people
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g 7
Three Reasons Your Company Should Make Vacation Mandatory. (2019). Retrieved from
https://www.forbes.com/sites/amberjohnson-jimludema/2018/06/05/three-reasons-your-
company-should-make-vacation-mandatory/#5bc85c2638ec