1 / 6100%
Running Head: Rules of Behavior 1
IT 552 : Assignment 3-2: Rules of Behavior
SNHU
IT 552 ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 2
The security document presents the rules that must be followed by the
employees of the organization. The 15 rules should act as the guideline and shape
the activities that the employees carry out on the network. The rules have been
designed as a number of violations in form of lack of locking of the workstations,
downloading of illegal music, establishing a connection with personal devices to the
organization's computers, spending too much time on social media, and download
pornography to the organization's computer have been observed (Information Security
National Rules Of Behavior, 2019).
Rules
1. The network of the organization must be used only to carry out official work.
No personal work must be conducted on the organization’s network. ab
2. It is mandatory to lock the workstation when it is not in use or when the
employee is not in his or her place. After the day’s work, the employees
need to log off from the system.
3. Do not open emails or links that have been provided by suspicious sources as
it could increase the network vulnerability
4. Only use the authorized devices that are available for official work. Do not
use personal devices on the network.
5. Do not download any non-official or illegal content such as music, images or
video files on the organization’s network. Do not use social media sites on
official computer systems.
6. Change the passwords of your official computer systems once every 90 days
and do not share the same with anyone.
7. No addition, modification or removal of any kind of hardware accessory or
the network to any organizational computer must be done.
IT 552 ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 3
8. Al the confidential information pertaining to the clients, customers or business
must be carefully encrypted on mobile computer systems.
9. Do not install any kind of free software on the internet.
10. Strictly comply with the specific terms of the software licenses. Only
authorized and licensed software must be installed on the organizational
computer systems.
11. Do not make any kind of alterations to the operating system or the security-
related software that has been installed in the official systems.
12. Without appropriate and prior authorization do not make an attempt to gain
access into any electronic audit trails that might exist in your assigned official
computer device.
13. Do not apprehend copies of configuration or security information from any
official computing resource for your personal or unauthorized use.
14. Be accountable for all kinds of activities that have been carried out and
initiated using your user account details.
15. Access only the information or the computer systems for which you have
been granted access by the official authorities (INFORMATION SECURITY
NATIONAL RULES OF BEHAVIOR, 2019).
The basic rules need to be properly understood by all the employees of the
entity so that they can act in an accountable and responsible manner while using the
organizational network. The Rules of Behaviour must be received by them and duly
signed. It would imply that they have carefully gone through the security document
and have understood their responsibilities that have been highlighted above. ab ab a
Types of training to prevent violations
IT 552 ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 4
In order to prevent the violations from occurring in the future, a number of
training approaches need to be initiated in the organizational setting. ab It is necessary
to provide proper training to the organizational personnel so that they can get a
detailed insight into the applicable data security practices. The employees must be
provided with web-based training so that they could reach the IT personnel instantly
when they identify any kind of a security threat. A specific area of training must
revolve around wireless networks so that the employees could carefully carry out the
official work on the network. The high degree of awareness on these technical
aspects would be useful for the employees to act in a responsible manner while
working on the official network of the organization.
In order to make the training more effective in nature, useful reminders or
tips could be provided on the screens of the users when they login to the system.
For example, they must be reminded in advance to change the passwords of their
system (5 Types of Trainings on Information Security Awareness, 2019). The training
activities must be carried out on a regular basis so that the employees can be well
aware of the changing technical elements that they need to focus on while using the
organizational network. Similarly, training can also be provided in the form of visual
aids as it would make them more conscious about behaviour relating to leaving the
systems unattended and downloading of illegal files and content. Thus such a holistic
training approach would be necessary to prevent violations in the future.
Proactively striving for compliance with these behaviours
In order to proactively strive for compliance with the behaviours that have
been highlighted here, it is necessary to communicate with the employees about the
adverse impact of cyber security threats and attacks. The management must try to
develop an organizational culture that revolves around Information Technology
IT 552 ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 5
security. Such an approach would make sure that every member of the organization
understands the significance of robust security of the network and the information
system (6 ways to develop a security culture in your organization, 2019). A healthy
IT security culture would act as the foundation for the firm and it would encourage
the employees to act as responsible individuals on the network of the organization.
The proper connection between the human factors and the information security
is necessary in the organizational context as it would involve the management and
employees to strengthen the security model of the organizational network. Thus it is
necessary to involve the employees from all the levels of organization in the IT
security approach so that the can work in a cohesive manner to mold their behavior
to act in a sensible manner.
The various rules that have been presented in the security document can be
effectively enforced throughout the business undertaking by involving the management
as well as the employees. The proper communication of the IT security model must
be highlighted so that the employees can follow the laid down rules and prohibit
from doing the activities that could jeopardize the network of the business entity. a ab
IT 552 ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 6
References
6 ways to develop a security culture in your organization. (2019). Retrieved from
https://techbeacon.com/security/6-ways-develop-security-culture-top-bottom
5 Types of Trainings on Information Security Awareness. (2019). Retrieved from
https://blog.commlabindia.com/elearning-design/information-security-awareness-
training
Information Security National Rules Of Behavior. (2019). Retrieved from
https://www.epa.gov/sites/production/files/2015-09/documents/cio-2150-p-21-0.pdf
Students also viewed