1 / 9100%
Running Head: IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g 1
IT 552 : Final Project Milestone 4
IT 552
2
Introduction
A robust communication plan has been designed for Multiple Unite Security
Assurance (MUSA) Corporation which will help to addresses and summarize the
importance of a security awareness program. The role of the communication model would
be of paramount importance as it would enable the employees of the business undertaking
to get a detailed insight into how security could strengthen its Information Technology
ecosystem. The designed communication plan encompasses a number of messaging
strategies which could ensure that the key stakeholders would be able to understand, buy
into, and support the continuous improvement of the proposed security awareness program.
The thorough engagement would play a vital role to influence a culture that gives
due importance to IT security. In fact, the communication plan could enhance the success
of the organization as it would assist to convince diverse stakeholders of the entity to
support the healthy security culture. The communication plan is designed in a simple and
effective manner so that it could make sense for both technical as well as the non-technical
audience. g
Overview
The security posture of MUSA is quite low so there is the need to introduce a new
and improved security awareness program. In order to make the new security model work,
one of the basic things that must be taken into consideration is the communication plan.
The role of a security communication plan is of paramount importance as it can help the
employees to take necessary steps so that the high quality of security can be maintained in
the best possible manner (Bashay, 2019). The document acts as a guide which can increase
the overall awareness of the workfare in MUSA on various security aspects. The primary
objective of the communication plan is to safeguard the Confidentiality, Integrity, and
Availability of the digital resources and information of the business entity.
IT 552
3
The communication plan sheds light on a number of messaging strategic
approaches that can help MUSA to share details on the new security model. It would also
help the organizational personnel to get a detailed idea about their exact roles and
responsibilities to execute the plan (Where The World Talks Security | RSA Conference,
2019).
Messaging Strategies
While designing a suitable messaging strategic framework, it is necessary to
identify the important areas that the specific communication message will address. Some of
the main areas include cyber laws, the cost associated with security breaches in the
organizational setting, personally identifiable information (PII) breaches, the need of
security awareness and the implication of awareness programs on the security posture and
culture of the business organization. The effectiveness of MUSA’s new security awareness
model will largely depend on the lines of communication that are established by the
business undertaking. The management of MUSA must constantly evaluate the internal
communication approach so that the organizational personnel can be constantly informed
of the best security practices that can be implemented to handle different kinds of security
threats.
Implementing different communication methods for different stakeholders
MUSA must ensure that the communication channels and methods that are
introduced to increase the level of awareness of the security model can serve the purpose.
Thus the use of communication approaches must be different when MUSA interacts with
different internal stakeholders such as employees, IT professionals, senior management
team and non-IT members. For example, while sharing a message on security with non-
technical members, video presentations could be used. But while sharing a message with
IT 552
4
members from the IT department, emails or memo could be used (Where The World Talks
Security | RSA Conference, 2019, p 6). g
In order to implement a holistic and integrated messaging strategy that meets the
needs of all the internal personnel, MUSA could partner with its communication team.
Such an approach would be beneficial as the individuals would help to enhance the
messaging approaches so that information reaches all the target audience within the
business setting (Where The World Talks Security | RSA Conference, 2019, p 24).
High level of transparency
In order to enhance the importance of the security awareness plan, the messaging
strategy must be transparent and uniform in nature. Transparency initiatives must be the
key focus of MUSA so that carefully designed so that all the employees would be on the
same page and they would have uniform knowledge on the security model of the business
entity. By making the information transparent, the employees across various departments
of the business entity would understand how their actions and duties could impact the
security posture of the firm. In fact, a transparent communication approach could bridge
the trust gap between the IT department and the non-IT department of Multiple Unite
Security Assurance Corporation. True transparency is not merely about giving information
to the organizational personnel within the organizational setting. The messaging strategy
should be designed in such a manner so that the information could be properly understood
by the employees without any kind of confusion or ambiguity (Gontovnikas, 2019).
Focus on the language of the message
Technology is a field which not many people are totally aware of. So while
spreading an important message about the security strategy, technical jargons must not be
used by Information Technology managers. This is an important aspect that MUSA must
keep in mind so that the message that is being communicated by it can be understood in a
IT 552
5
clear manner by all the intended audience irrespective of the department in which they
function. According to E Kelly Hansen, the Chief Executive Officer of Neohapsis Inc., the
language of IT cannot be easily understood by non-IT professionals. So in order to deal
with this issue, simple English language must be used while communicating about the
security awareness program and its importance in the organizational setting. The wrong use
of language would naturally encourage to stop paying attention to the message as it would
be going over their heads. So simple and understandable language needs to be used so that
professionals from both the IT and non-IT department could understand the relevance of
the security awareness program (News, Tips, and Advice for Technology Professionals -
TechRepublic, 2019).
Starting the communication from the top
The security awareness program could have a major impact on the existence and
sustainability of the business entity. So before communicating about the same, it is
necessary to initiate the communication from the top. This would mean that the leaders and
decision-makers would act as the starting point of the communication. The visible backing
of the leader of Multiple Unite Security Assurance (MUSA) Corporation would encourage
the employees from all across the firm to participate in the approach (News, Tips, and
Advice for Technology Professionals - TechRepublic, 2019). The evidence of executive
stewardship would be of paramount importance in the business context to adopt an
interactive and engaging communication approach. Similarly, the IT professionals in the
business setting must take the initiative to make the leaders and senior managers
understand the significance of the security awareness model which could constructively
influence the security posture of MUSA.
Streamlining the communication model
IT 552
6
The security success program of MUSA could be successful throughout the
business entity only if a uniform and streamlined communication network would be
deployed. There is the need to constantly evaluate and align the internal communication
channels so that the employees across all the departments of the firm would be able to
understand how the security model could have implications on them, their department and
the entire business entity (News, Tips, and Advice for Technology Professionals -
TechRepublic, 2019). The proper flow of information on the security program would keep
the employees on their toes. They would be encouraged to adopt safe practices which
could restrict the adverse implications on the security aspect of MUSA.
Security culture
A healthy security culture is the need of the hour at Multiple Unite Security
Assurance Corporation so that its security posture could be improved. In order to
effectively promote a healthy security culture throughout the business setting, a number of
approaches could be implemented.
Focus on awareness – The management of the business entity must focus on
making the employees aware of the significance of having a robust and healthy security
culture. For example, for developers and testers that functions in the IT department, an
application security awareness approach could be employed. It would help to carefully
evaluate the seriousness of a security threat and take necessary actions to deal with it (6
ways to develop a security culture in your organization, 2019).
Deployment of leadership-driven cyber governance model – In order to encourage a
healthy security culture, the active involvement of senior managers and leaders would be
indispensable in the organizational context of MUSA. Their participation would influence
the employees at all the levels of MUSA to focus on their individual roles and duties so
that they could contribute to enhancing the level of security in the business setting (Four
IT 552
7
Tips for Building a Strong Security Culture in Your Organization, 2019). Thus the strong
commitment by the top management of MUSA would help to convince diverse
stakeholders of MUSA to strengthen the healthy security culture.
Clear documentation of security policies – Establishment of clear and well-defined
security policies and guidelines would act as the cornerstone of a healthy security culture.
Thus in MUSA, the new security policies must be clearly documented so that they would
guide the employees while conducting the day to day business activities and processes
(Four Tips for Building a Strong Security Culture in Your Organization, 2019).
Providing adequate training to the staff members – The management of MUSA must
ensure that the employees get the necessary training to understand the relevance of security
in the unpredictable IT setting. Such an approach would be of paramount importance as it
would assist in fostering a healthy security culture among the employees (Four Tips for
Building a Strong Security Culture in Your Organization, 2019).
Conclusion
The role of a well-planned communication and messaging strategy would be
extremely vital to improving the security posture of MUSA. The various strategic
elements that have been encompassed in the communication plan include the proper
implementation of varying communication methods for different stakeholders, maintaining
a high level of transparency, high focus on the language of the message, starting the
communication from the top and streamlining the overall communication model. There is
an urgent need to make the diverse stakeholder of MUSA understand the importance of a
healthy security culture. Various approaches that could be introduced to promote a healthy
security culture include the focus on awareness, deployment of leadership-driven cyber
governance model, clear documentation of security policies and providing necessary
training to the employees.
IT 552
8
References
6 ways to develop a security culture in your organization. (2019). Retrieved 19 July 2019,
from https://techbeacon.com/security/6-ways-develop-security-culture-top-bottom
Bashay, F. (2019). What Is the CIA Triangle and Why Is It Important for Cybersecurity
Management?. Retrieved 19 July 2019, from https://www.difenda.com/blog/what-is-
the-cia-triangle-and-why-is-it-important-for-cybersecurity-management
Four Tips for Building a Strong Security Culture in Your Organization. (2019). Retrieved
19 July 2019, from https://blog.netwrix.com/2018/06/28/four-tips-for-building-a-
strong-security-culture-in-your-organization/
Gontovnikas, M. (2019). Cybersecurity Shouldn’t Be a Secret: Why Transparency Matters.
Retrieved 19 July 2019, from https://auth0.com/blog/cybersecurity-shouldnt-be-a-
secret/
News, Tips, and Advice for Technology Professionals - TechRepublic. (2019). Retrieved
19 July 2019, from https://www.techrepublic.com/article/success-strategies-for-
security-awareness/
IT 552
9
Where The World Talks Security | RSA Conference. (2019). Retrieved 19 July 2019, from
https://www.rsaconference.com/writable/presentations/file_upload/hum-t09-building-a-
strategic-plan-for-your-security-awareness-program.pdf
Students also viewed