Running Head: Rules of Behavior
1
IT 552 : Assignment 3-2: Rules of Behavior
Carlos Delapaz
SNHU
June 16,2019
IT 552 2
The security document presents the rules that must be followed by the employees of
the organization. The 15 rules should act as the guideline and shape the activities that the
employees carry out on the network. The rules have been designed as a number of violations
in form of lack of locking of the workstations, downloading of illegal music, establishing a
connection with personal devices to the organization's computers, spending too much time on
social media, and download pornography to the organization's computer have been observed
(Information Security – National Rules Of Behavior, 2019).
Rules
1. The network of the organization must be used only to carry out official work. No
personal work must be conducted on the organization’s network.
2. It is mandatory to lock the workstation when it is not in use or when the employee is
not in his or her place. After the day’s work, the employees need to log off from the
system.
3. Do not open emails or links that have been provided by suspicious sources as it could
increase the network vulnerability
4. Only use the authorized devices that are available for official work. Do not use
personal devices on the network.
5. Do not download any non-official or illegal content such as music, images or video
files on the organization’s network. Do not use social media sites on official computer
systems.
6. Change the passwords of your official computer systems once every 90 days and do
not share the same with anyone.
7. No addition, modification or removal of any kind of hardware accessory or the
network to any organizational computer must be done.
IT 552 3
8. Al the confidential information pertaining to the clients, customers or business must
be carefully encrypted on mobile computer systems.
9. Do not install any kind of free software on the internet.
10. Strictly comply with the specific terms of the software licenses. Only authorized and
licensed software must be installed on the organizational computer systems.
11. Do not make any kind of alterations to the operating system or the security-related
software that has been installed in the official systems.
12. Without appropriate and prior authorization do not make an attempt to gain access
into any electronic audit trails that might exist in your assigned official computer
device.
13. Do not apprehend copies of configuration or security information from any official
computing resource for your personal or unauthorized use.
14. Be accountable for all kinds of activities that have been carried out and initiated using
your user account details.
15. Access only the information or the computer systems for which you have been
granted access by the official authorities (INFORMATION SECURITY –
NATIONAL RULES OF BEHAVIOR, 2019).
The basic rules need to be properly understood by all the employees of the entity so that
they can act in an accountable and responsible manner while using the organizational
network. The Rules of Behaviour must be received by them and duly signed. It would imply
that they have carefully gone through the security document and have understood their
responsibilities that have been highlighted above.
Types of training to prevent violations
In order to prevent the violations from occurring in the future, a number of training
approaches need to be initiated in the organizational setting. AIt is necessary to provide proper
IT 552 4
training to the organizational personnel so that they can get a detailed insight into the
applicable data security practices. The employees must be provided with web-based training
so that they could reach the IT personnel instantly when they identify any kind of a security
threat. A specific area of training must revolve around wireless networks so that the
employees could carefully carry out the official work on the network. The high degree of
awareness on these technical aspects would be useful for the employees to act in a
responsible manner while working on the official network of the organization.
In order to make the training more effective in nature, useful reminders or tips could
be provided on the screens of the users when they login to the system. For example, they
must be reminded in advance to change the passwords of their system (5 Types of Trainings
on Information Security Awareness, 2019). The training activities must be carried out on a
regular basis so that the employees can be well aware of the changing technical elements that
they need to focus on while using the organizational network. Similarly, training can also be
provided in the form of visual aids as it would make them more conscious about behaviour
relating to leaving the systems unattended and downloading of illegal files and content. Thus
such a holistic training approach would be necessary to prevent violations in the future.
Proactively striving for compliance with these behaviours
In order to proactively strive for compliance with the behaviours that have been
highlighted here, it is necessary to communicate with the employees about the adverse impact
of cyber security threats and attacks. The management must try to develop an organizational
culture that revolves around Information Technology security. Such an approach would make
sure that every member of the organization understands the significance of robust security of
the network and the information system (6 ways to develop a security culture in your
organization, 2019). A healthy IT security culture would act as the foundation for the firm
IT 552 5
and it would encourage the employees to act as responsible individuals on the network of the
organization.
The proper connection between the human factors and the information security is
necessary in the organizational context as it would involve the management and employees to
strengthen the security model of the organizational network. Thus it is necessary to involve
the employees from all the levels of organization in the IT security approach so that the can
work in a cohesive manner to mold their behavior to act in a sensible manner.
The various rules that have been presented in the security document can be effectively
enforced throughout the business undertaking by involving the management as well as the
employees. The proper communication of the IT security model must be highlighted so that
the employees can follow the laid down rules and prohibit from doing the activities that could
jeopardize the network of the business entity.
IT 552 6
References
6 ways to develop a security culture in your organization. (2019). Retrieved from
https://techbeacon.com/security/6-ways-develop-security-culture-top-bottom
5 Types of Trainings on Information Security Awareness. (2019). Retrieved from
https://blog.commlabindia.com/elearning-design/information-security-awareness-
training
Information Security – National Rules Of Behavior. (2019). Retrieved from
https://www.epa.gov/sites/production/files/2015-09/documents/cio-2150-p-21-0.pdf