Running Head: IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 1
IT 552 : Final Project Milestone 4
SNHU
IT 552
2
Introduction
A robust communication plan has been designed for Multiple Unite Security
Assurance (MUSA) Corporation which will help to addresses and summarize the
importance of a security awareness program. The role of the communication model
would be of paramount importance as it would enable the employees of the business
undertaking to get a detailed insight into how security could strengthen its Information
Technology ecosystem. The designed communication plan encompasses a number of
messaging strategies which could ensure that the key stakeholders would be able to
understand, buy into, and support the continuous improvement of the proposed security
awareness program.
The thorough engagement would play a vital role to influence a culture that
gives due importance to IT security. In fact, the communication plan could enhance the
success of the organization as it would assist to convince diverse stakeholders of the
entity to support the healthy security culture. The communication plan is designed in a
simple and effective manner so that it could make sense for both technical as well as
the non-technical audience. e
Overview
The security posture of MUSA is quite low so there is the need to introduce a
new and improved security awareness program. In order to make the new security model
work, one of the basic things that must be taken into consideration is the communication
plan. The role of a security communication plan is of paramount importance as it can
help the employees to take necessary steps so that the high quality of security can be
maintained in the best possible manner (Bashay, 2019). The document acts as a guide
which can increase the overall awareness of the workfare in MUSA on various security
aspects. The primary objective of the communication plan is to safeguard the
IT 552
3
Confidentiality, Integrity, and Availability of the digital resources and information of the
business entity.
The communication plan sheds light on a number of messaging strategic
approaches that can help MUSA to share details on the new security model. It would
also help the organizational personnel to get a detailed idea about their exact roles and
responsibilities to execute the plan (Where The World Talks Security | RSA Conference,
2019).
Messaging Strategies
While designing a suitable messaging strategic framework, it is necessary to
identify the important areas that the specific communication message will address. Some
of the main areas include cyber laws, the cost associated with security breaches in the
organizational setting, personally identifiable information (PII) breaches, the need of
security awareness and the implication of awareness programs on the security posture
and culture of the business organization. The effectiveness of MUSA’s new security
awareness model will largely depend on the lines of communication that are established
by the business undertaking. The management of MUSA must constantly evaluate the
internal communication approach so that the organizational personnel can be constantly
informed of the best security practices that can be implemented to handle different kinds
of security threats.
Implementing different communication methods for different stakeholders
MUSA must ensure that the communication channels and methods that are
introduced to increase the level of awareness of the security model can serve the
purpose. Thus the use of communication approaches must be different when MUSA
interacts with different internal stakeholders such as employees, IT professionals, senior
management team and non-IT members. For example, while sharing a message on
IT 552
4
security with non-technical members, video presentations could be used. But while
sharing a message with members from the IT department, emails or memo could be
used (Where The World Talks Security | RSA Conference, 2019, p 6). e
In order to implement a holistic and integrated messaging strategy that meets the
needs of all the internal personnel, MUSA could partner with its communication team.
Such an approach would be beneficial as the individuals would help to enhance the
messaging approaches so that information reaches all the target audience within the
business setting (Where The World Talks Security | RSA Conference, 2019, p 24).
High level of transparency
In order to enhance the importance of the security awareness plan, the messaging
strategy must be transparent and uniform in nature. Transparency initiatives must be the
key focus of MUSA so that carefully designed so that all the employees would be on
the same page and they would have uniform knowledge on the security model of the
business entity. By making the information transparent, the employees across various
departments of the business entity would understand how their actions and duties could
impact the security posture of the firm. In fact, a transparent communication approach
could bridge the trust gap between the IT department and the non-IT department of
Multiple Unite Security Assurance Corporation. True transparency is not merely about
giving information to the organizational personnel within the organizational setting. The
messaging strategy should be designed in such a manner so that the information could
be properly understood by the employees without any kind of confusion or ambiguity
(Gontovnikas, 2019).
Focus on the language of the message
Technology is a field which not many people are totally aware of. So while
spreading an important message about the security strategy, technical jargons must not
IT 552
5
be used by Information Technology managers. This is an important aspect that MUSA
must keep in mind so that the message that is being communicated by it can be
understood in a clear manner by all the intended audience irrespective of the department
in which they function. According to E Kelly Hansen, the Chief Executive Officer of
Neohapsis Inc., the language of IT cannot be easily understood by non-IT professionals.
So in order to deal with this issue, simple English language must be used while
communicating about the security awareness program and its importance in the
organizational setting. The wrong use of language would naturally encourage to stop
paying attention to the message as it would be going over their heads. So simple and
understandable language needs to be used so that professionals from both the IT and
non-IT department could understand the relevance of the security awareness program
(News, Tips, and Advice for Technology Professionals - TechRepublic, 2019).
Starting the communication from the top
The security awareness program could have a major impact on the existence and
sustainability of the business entity. So before communicating about the same, it is
necessary to initiate the communication from the top. This would mean that the leaders
and decision-makers would act as the starting point of the communication. The visible
backing of the leader of Multiple Unite Security Assurance (MUSA) Corporation would
encourage the employees from all across the firm to participate in the approach (News,
Tips, and Advice for Technology Professionals - TechRepublic, 2019). The evidence of
executive stewardship would be of paramount importance in the business context to
adopt an interactive and engaging communication approach. Similarly, the IT
professionals in the business setting must take the initiative to make the leaders and
senior managers understand the significance of the security awareness model which
could constructively influence the security posture of MUSA.
IT 552
6
Streamlining the communication model
The security success program of MUSA could be successful throughout the
business entity only if a uniform and streamlined communication network would be
deployed. e There is the need to constantly evaluate and align the internal communication
channels so that the employees across all the departments of the firm would be able to
understand how the security model could have implications on them, their department
and the entire business entity (News, Tips, and Advice for Technology Professionals -
TechRepublic, 2019). The proper flow of information on the security program would
keep the employees on their toes. They would be encouraged to adopt safe practices
which could restrict the adverse implications on the security aspect of MUSA.
Security culture
A healthy security culture is the need of the hour at Multiple Unite Security
Assurance Corporation so that its security posture could be improved. In order to
effectively promote a healthy security culture throughout the business setting, a number
of approaches could be implemented.
Focus on awareness – The management of the business entity must focus on
making the employees aware of the significance of having a robust and healthy security
culture. For example, for developers and testers that functions in the IT department, an
application security awareness approach could be employed. It would help to carefully
evaluate the seriousness of a security threat and take necessary actions to deal with it (6
ways to develop a security culture in your organization, 2019).
Deployment of leadership-driven cyber governance model – In order to encourage
a healthy security culture, the active involvement of senior managers and leaders would
be indispensable in the organizational context of MUSA. Their participation would
influence the employees at all the levels of MUSA to focus on their individual roles and
IT 552
7
duties so that they could contribute to enhancing the level of security in the business
setting (Four Tips for Building a Strong Security Culture in Your Organization, 2019).
Thus the strong commitment by the top management of MUSA would help to convince
diverse stakeholders of MUSA to strengthen the healthy security culture.
Clear documentation of security policies – Establishment of clear and well-
defined security policies and guidelines would act as the cornerstone of a healthy
security culture. Thus in MUSA, the new security policies must be clearly documented
so that they would guide the employees while conducting the day to day business
activities and processes (Four Tips for Building a Strong Security Culture in Your
Organization, 2019).
Providing adequate training to the staff members – The management of MUSA must
ensure that the employees get the necessary training to understand the relevance of
security in the unpredictable IT setting. Such an approach would be of paramount
importance as it would assist in fostering a healthy security culture among the
employees (Four Tips for Building a Strong Security Culture in Your Organization,
2019).
Conclusion
The role of a well-planned communication and messaging strategy would be
extremely vital to improving the security posture of MUSA. The various strategic
elements that have been encompassed in the communication plan include the proper
implementation of varying communication methods for different stakeholders,
maintaining a high level of transparency, high focus on the language of the message,
starting the communication from the top and streamlining the overall communication
model. There is an urgent need to make the diverse stakeholder of MUSA understand
the importance of a healthy security culture. Various approaches that could be
IT 552
8
introduced to promote a healthy security culture include the focus on awareness,
deployment of leadership-driven cyber governance model, clear documentation of
security policies and providing necessary training to the employees.
References
6 ways to develop a security culture in your organization. (2019). Retrieved 19 July
2019, from https://techbeacon.com/security/6-ways-develop-security-culture-top-
bottom
Bashay, F. (2019). What Is the CIA Triangle and Why Is It Important for Cybersecurity
Management?. Retrieved 19 July 2019, from https://www.difenda.com/blog/what-is-
the-cia-triangle-and-why-is-it-important-for-cybersecurity-management
Four Tips for Building a Strong Security Culture in Your Organization. (2019).
Retrieved 19 July 2019, from https://blog.netwrix.com/2018/06/28/four-tips-for-
building-a-strong-security-culture-in-your-organization/
Gontovnikas, M. (2019). Cybersecurity Shouldn’t Be a Secret: Why Transparency
Matters. Retrieved 19 July 2019, from https://auth0.com/blog/cybersecurity-shouldnt-
be-a-secret/
IT 552
9
News, Tips, and Advice for Technology Professionals - TechRepublic. (2019). Retrieved
19 July 2019, from https://www.techrepublic.com/article/success-strategies-for-
security-awareness/
Where The World Talks Security | RSA Conference. (2019). Retrieved 19 July 2019,
from https://www.rsaconference.com/writable/presentations/file_upload/hum-t09-
building-a-strategic-plan-for-your-security-awareness-program.pdf