Running Head: Rules of Behavior 1
IT 552 : Assignment 3-2: Rules of Behavior
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g 2
The security document presents the rules that must be followed by the employees
of the organization. The 15 rules should act as the guideline and shape the activities that
the employees carry out on the network. The rules have been designed as a number of
violations in form of lack of locking of the workstations, downloading of illegal music,
establishing a connection with personal devices to the organization's computers, spending
too much time on social media, and download pornography to the organization's computer
have been observed (Information Security – National Rules Of Behavior, 2019).
Rules
1. The network of the organization must be used only to carry out official work. No
personal work must be conducted on the organization’s network. g
2. It is mandatory to lock the workstation when it is not in use or when the employee
is not in his or her place. After the day’s work, the employees need to log off from
the system.
3. Do not open emails or links that have been provided by suspicious sources as it
could increase the network vulnerability
4. Only use the authorized devices that are available for official work. Do not use
personal devices on the network.
5. Do not download any non-official or illegal content such as music, images or video
files on the organization’s network. Do not use social media sites on official
computer systems.
6. Change the passwords of your official computer systems once every 90 days and do
not share the same with anyone.
7. No addition, modification or removal of any kind of hardware accessory or the
network to any organizational computer must be done.
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g 3
8. Al the confidential information pertaining to the clients, customers or business must
be carefully encrypted on mobile computer systems.
9. Do not install any kind of free software on the internet.
10. Strictly comply with the specific terms of the software licenses. Only authorized
and licensed software must be installed on the organizational computer systems.
11. Do not make any kind of alterations to the operating system or the security-related
software that has been installed in the official systems.
12. Without appropriate and prior authorization do not make an attempt to gain access
into any electronic audit trails that might exist in your assigned official computer
device.
13. Do not apprehend copies of configuration or security information from any official
computing resource for your personal or unauthorized use.
14. Be accountable for all kinds of activities that have been carried out and initiated
using your user account details.
15. Access only the information or the computer systems for which you have been
granted access by the official authorities (INFORMATION SECURITY –
NATIONAL RULES OF BEHAVIOR, 2019).
The basic rules need to be properly understood by all the employees of the entity so
that they can act in an accountable and responsible manner while using the organizational
network. The Rules of Behaviour must be received by them and duly signed. It would
imply that they have carefully gone through the security document and have understood
their responsibilities that have been highlighted above. g g g
Types of training to prevent violations
In order to prevent the violations from occurring in the future, a number of training
approaches need to be initiated in the organizational setting. It is necessary to provide
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g 4
proper training to the organizational personnel so that they can get a detailed insight into
the applicable data security practices. The employees must be provided with web-based
training so that they could reach the IT personnel instantly when they identify any kind of
a security threat. g A specific area of training must revolve around wireless networks so that
the employees could carefully carry out the official work on the network. The high degree
of awareness on these technical aspects would be useful for the employees to act in a
responsible manner while working on the official network of the organization.
In order to make the training more effective in nature, useful reminders or tips
could be provided on the screens of the users when they login to the system. For example,
they must be reminded in advance to change the passwords of their system (5 Types of
Trainings on Information Security Awareness, 2019). The training activities must be
carried out on a regular basis so that the employees can be well aware of the changing
technical elements that they need to focus on while using the organizational network.
Similarly, training can also be provided in the form of visual aids as it would make them
more conscious about behaviour relating to leaving the systems unattended and
downloading of illegal files and content. Thus such a holistic training approach would be
necessary to prevent violations in the future.
Proactively striving for compliance with these behaviours
In order to proactively strive for compliance with the behaviours that have been
highlighted here, it is necessary to communicate with the employees about the adverse
impact of cyber security threats and attacks. The management must try to develop an
organizational culture that revolves around Information Technology security. Such an
approach would make sure that every member of the organization understands the
significance of robust security of the network and the information system (6 ways to
develop a security culture in your organization, 2019). A healthy IT security culture would
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g 5
act as the foundation for the firm and it would encourage the employees to act as
responsible individuals on the network of the organization.
The proper connection between the human factors and the information security is
necessary in the organizational context as it would involve the management and employees
to strengthen the security model of the organizational network. Thus it is necessary to
involve the employees from all the levels of organization in the IT security approach so
that the can work in a cohesive manner to mold their behavior to act in a sensible manner.
The various rules that have been presented in the security document can be
effectively enforced throughout the business undertaking by involving the management as
well as the employees. The proper communication of the IT security model must be
highlighted so that the employees can follow the laid down rules and prohibit from doing
the activities that could jeopardize the network of the business entity. g g g g
IT 552 g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g g
g g g g g g g g g g g g g g g g g g g g g g g 6
References
6 ways to develop a security culture in your organization. (2019). Retrieved from
https://techbeacon.com/security/6-ways-develop-security-culture-top-bottom
5 Types of Trainings on Information Security Awareness. (2019). Retrieved from
https://blog.commlabindia.com/elearning-design/information-security-awareness-
training
Information Security – National Rules Of Behavior. (2019). Retrieved from
https://www.epa.gov/sites/production/files/2015-09/documents/cio-2150-p-21-0.pdf