1 / 6100%
Running Head: Rules of Behavior 1
IT 552 : Assignment 3-2: Rules of Behavior
SNHU
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 2
The security document presents the rules that must be followed by the employees
of the organization. The 15 rules should act as the guideline and shape the activities that
the employees carry out on the network. The rules have been designed as a number of
violations in form of lack of locking of the workstations, downloading of illegal music,
establishing a connection with personal devices to the organization's computers, spending
too much time on social media, and download pornography to the organization's
computer have been observed (Information Security – National Rules Of Behavior,
2019).
Rules
1. The network of the organization must be used only to carry out official work. No
personal work must be conducted on the organization’s network. e
2. It is mandatory to lock the workstation when it is not in use or when the
employee is not in his or her place. After the day’s work, the employees need to
log off from the system.
3. Do not open emails or links that have been provided by suspicious sources as it
could increase the network vulnerability
4. Only use the authorized devices that are available for official work. Do not use
personal devices on the network.
5. Do not download any non-official or illegal content such as music, images or
video files on the organization’s network. Do not use social media sites on
official computer systems.
6. Change the passwords of your official computer systems once every 90 days and
do not share the same with anyone.
7. No addition, modification or removal of any kind of hardware accessory or the
network to any organizational computer must be done.
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 3
8. Al the confidential information pertaining to the clients, customers or business
must be carefully encrypted on mobile computer systems.
9. Do not install any kind of free software on the internet.
10. Strictly comply with the specific terms of the software licenses. Only authorized
and licensed software must be installed on the organizational computer systems.
11. Do not make any kind of alterations to the operating system or the security-
related software that has been installed in the official systems.
12. Without appropriate and prior authorization do not make an attempt to gain
access into any electronic audit trails that might exist in your assigned official
computer device.
13. Do not apprehend copies of configuration or security information from any
official computing resource for your personal or unauthorized use.
14. Be accountable for all kinds of activities that have been carried out and initiated
using your user account details.
15. Access only the information or the computer systems for which you have been
granted access by the official authorities (INFORMATION SECURITY –
NATIONAL RULES OF BEHAVIOR, 2019).
The basic rules need to be properly understood by all the employees of the entity
so that they can act in an accountable and responsible manner while using the
organizational network. The Rules of Behaviour must be received by them and duly
signed. It would imply that they have carefully gone through the security document and
have understood their responsibilities that have been highlighted above. e e e
Types of training to prevent violations
In order to prevent the violations from occurring in the future, a number of
training approaches need to be initiated in the organizational setting. It is necessary to
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 4
provide proper training to the organizational personnel so that they can get a detailed
insight into the applicable data security practices. The employees must be provided with
web-based training so that they could reach the IT personnel instantly when they
identify any kind of a security threat. A specific area of training must revolve around
wireless networks so that the employees could carefully carry out the official work on
the network. The high degree of awareness on these technical aspects would be useful
for the employees to act in a responsible manner while working on the official network
of the organization.
In order to make the training more effective in nature, useful reminders or tips
could be provided on the screens of the users when they login to the system. For
example, they must be reminded in advance to change the passwords of their system (5
Types of Trainings on Information Security Awareness, 2019). The training activities
must be carried out on a regular basis so that the employees can be well aware of the
changing technical elements that they need to focus on while using the organizational
network. Similarly, training can also be provided in the form of visual aids as it would
make them more conscious about behaviour relating to leaving the systems unattended
and downloading of illegal files and content. Thus such a holistic training approach
would be necessary to prevent violations in the future.
Proactively striving for compliance with these behaviours
In order to proactively strive for compliance with the behaviours that have been
highlighted here, it is necessary to communicate with the employees about the adverse
impact of cyber security threats and attacks. The management must try to develop an
organizational culture that revolves around Information Technology security. Such an
approach would make sure that every member of the organization understands the
significance of robust security of the network and the information system (6 ways to
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 5
develop a security culture in your organization, 2019). A healthy IT security culture
would act as the foundation for the firm and it would encourage the employees to act as
responsible individuals on the network of the organization.
The proper connection between the human factors and the information security is
necessary in the organizational context as it would involve the management and
employees to strengthen the security model of the organizational network. Thus it is
necessary to involve the employees from all the levels of organization in the IT security
approach so that the can work in a cohesive manner to mold their behavior to act in a
sensible manner.
The various rules that have been presented in the security document can be
effectively enforced throughout the business undertaking by involving the management
as well as the employees. The proper communication of the IT security model must be
highlighted so that the employees can follow the laid down rules and prohibit from
doing the activities that could jeopardize the network of the business entity. e e e e
IT 552 e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e
e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e e 6
References
6 ways to develop a security culture in your organization. (2019). Retrieved from
https://techbeacon.com/security/6-ways-develop-security-culture-top-bottom
5 Types of Trainings on Information Security Awareness. (2019). Retrieved from
https://blog.commlabindia.com/elearning-design/information-security-awareness-
training
Information Security – National Rules Of Behavior. (2019). Retrieved from
https://www.epa.gov/sites/production/files/2015-09/documents/cio-2150-p-21-0.pdf
Students also viewed