Running Head: IT 552 f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
IT 552 : Final Project Milestone 4
SNHU
IT 552
2
Introduction
A robust communication plan has been designed for Multiple Unite Security
Assurance (MUSA) Corporation which will help to addresses and summarize the importance
of a security awareness program. The role of the communication model would be of
paramount importance as it would enable the employees of the business undertaking to get a
detailed insight into how security could strengthen its Information Technology ecosystem.
The designed communication plan encompasses a number of messaging strategies which
could ensure that the key stakeholders would be able to understand, buy into, and support the
continuous improvement of the proposed security awareness program.
The thorough engagement would play a vital role to influence a culture that gives due
importance to IT security. In fact, the communication plan could enhance the success of the
organization as it would assist to convince diverse stakeholders of the entity to support the
healthy security culture. The communication plan is designed in a simple and effective
manner so that it could make sense for both technical as well as the non-technical audience. f
Overview
The security posture of MUSA is quite low so there is the need to introduce a new and
improved security awareness program. In order to make the new security model work, one of
the basic things that must be taken into consideration is the communication plan. The role of
a security communication plan is of paramount importance as it can help the employees to
take necessary steps so that the high quality of security can be maintained in the best possible
manner (Bashay, 2019). The document acts as a guide which can increase the overall
awareness of the workfare in MUSA on various security aspects. The primary objective of
IT 552
3
the communication plan is to safeguard the Confidentiality, Integrity, and Availability of the
digital resources and information of the business entity.
The communication plan sheds light on a number of messaging strategic approaches
that can help MUSA to share details on the new security model. It would also help the
organizational personnel to get a detailed idea about their exact roles and responsibilities to
execute the plan (Where The World Talks Security | RSA Conference, 2019).
Messaging Strategies
While designing a suitable messaging strategic framework, it is necessary to identify
the important areas that the specific communication message will address. Some of the main
areas include cyber laws, the cost associated with security breaches in the organizational
setting, personally identifiable information (PII) breaches, the need of security awareness
and the implication of awareness programs on the security posture and culture of the business
organization. The effectiveness of MUSA’s new security awareness model will largely
depend on the lines of communication that are established by the business undertaking. The
management of MUSA must constantly evaluate the internal communication approach so that
the organizational personnel can be constantly informed of the best security practices that can
be implemented to handle different kinds of security threats.
Implementing different communication methods for different stakeholders
MUSA must ensure that the communication channels and methods that are introduced
to increase the level of awareness of the security model can serve the purpose. Thus the use
of communication approaches must be different when MUSA interacts with different internal
stakeholders such as employees, IT professionals, senior management team and non-IT
members. For example, while sharing a message on security with non-technical members,
video presentations could be used. But while sharing a message with members from the IT
IT 552
4
department, emails or memo could be used (Where The World Talks Security | RSA
Conference, 2019, p 6). f
In order to implement a holistic and integrated messaging strategy that meets the
needs of all the internal personnel, MUSA could partner with its communication team. Such
an approach would be beneficial as the individuals would help to enhance the messaging
approaches so that information reaches all the target audience within the business setting
(Where The World Talks Security | RSA Conference, 2019, p 24).
High level of transparency
In order to enhance the importance of the security awareness plan, the messaging
strategy must be transparent and uniform in nature. Transparency initiatives must be the key
focus of MUSA so that carefully designed so that all the employees would be on the same
page and they would have uniform knowledge on the security model of the business entity.
By making the information transparent, the employees across various departments of the
business entity would understand how their actions and duties could impact the security
posture of the firm. In fact, a transparent communication approach could bridge the trust gap
between the IT department and the non-IT department of Multiple Unite Security Assurance
Corporation. True transparency is not merely about giving information to the organizational
personnel within the organizational setting. The messaging strategy should be designed in
such a manner so that the information could be properly understood by the employees
without any kind of confusion or ambiguity (Gontovnikas, 2019).
Focus on the language of the message
Technology is a field which not many people are totally aware of. So while spreading
an important message about the security strategy, technical jargons must not be used by
Information Technology managers. This is an important aspect that MUSA must keep in
mind so that the message that is being communicated by it can be understood in a clear
IT 552
5
manner by all the intended audience irrespective of the department in which they function.
According to E Kelly Hansen, the Chief Executive Officer of Neohapsis Inc., the language of
IT cannot be easily understood by non-IT professionals. So in order to deal with this issue,
simple English language must be used while communicating about the security awareness
program and its importance in the organizational setting. The wrong use of language would
naturally encourage to stop paying attention to the message as it would be going over their
heads. So simple and understandable language needs to be used so that professionals from
both the IT and non-IT department could understand the relevance of the security awareness
program (News, Tips, and Advice for Technology Professionals - TechRepublic, 2019).
Starting the communication from the top
The security awareness program could have a major impact on the existence and
sustainability of the business entity. So before communicating about the same, it is necessary
to initiate the communication from the top. This would mean that the leaders and decision-
makers would act as the starting point of the communication. The visible backing of the
leader of Multiple Unite Security Assurance (MUSA) Corporation would encourage the
employees from all across the firm to participate in the approach (News, Tips, and Advice for
Technology Professionals - TechRepublic, 2019). The evidence of executive stewardship
would be of paramount importance in the business context to adopt an interactive and
engaging communication approach. Similarly, the IT professionals in the business setting
must take the initiative to make the leaders and senior managers understand the significance
of the security awareness model which could constructively influence the security posture of
MUSA.
Streamlining the communication model
The security success program of MUSA could be successful throughout the business
entity only if a uniform and streamlined communication network would be deployed. There
IT 552
6
is the need to constantly evaluate and align the internal communication channels so that the
employees across all the departments of the firm would be able to understand how the
security model could have implications on them, their department and the entire business
entity (News, Tips, and Advice for Technology Professionals - TechRepublic, 2019). The
proper flow of information on the security program would keep the employees on their toes.
They would be encouraged to adopt safe practices which could restrict the adverse
implications on the security aspect of MUSA.
Security culture
A healthy security culture is the need of the hour at Multiple Unite Security
Assurance Corporation so that its security posture could be improved. In order to effectively
promote a healthy security culture throughout the business setting, a number of approaches
could be implemented.
Focus on awareness – The management of the business entity must focus on making
the employees aware of the significance of having a robust and healthy security culture. For
example, for developers and testers that functions in the IT department, an application
security awareness approach could be employed. It would help to carefully evaluate the
seriousness of a security threat and take necessary actions to deal with it (6 ways to develop a
security culture in your organization, 2019).
Deployment of leadership-driven cyber governance model – In order to encourage a
healthy security culture, the active involvement of senior managers and leaders would be
indispensable in the organizational context of MUSA. Their participation would influence the
employees at all the levels of MUSA to focus on their individual roles and duties so that they
could contribute to enhancing the level of security in the business setting (Four Tips for
Building a Strong Security Culture in Your Organization, 2019). Thus the strong
IT 552
7
commitment by the top management of MUSA would help to convince diverse stakeholders
of MUSA to strengthen the healthy security culture.
Clear documentation of security policies – Establishment of clear and well-defined
security policies and guidelines would act as the cornerstone of a healthy security culture.
Thus in MUSA, the new security policies must be clearly documented so that they would
guide the employees while conducting the day to day business activities and processes (Four
Tips for Building a Strong Security Culture in Your Organization, 2019).
Providing adequate training to the staff members – The management of MUSA must ensure
that the employees get the necessary training to understand the relevance of security in the
unpredictable IT setting. Such an approach would be of paramount importance as it would
assist in fostering a healthy security culture among the employees (Four Tips for Building a
Strong Security Culture in Your Organization, 2019).
Conclusion
The role of a well-planned communication and messaging strategy would be
extremely vital to improving the security posture of MUSA. The various strategic elements
that have been encompassed in the communication plan include the proper implementation of
varying communication methods for different stakeholders, maintaining a high level of
transparency, high focus on the language of the message, starting the communication from
the top and streamlining the overall communication model. There is an urgent need to make
the diverse stakeholder of MUSA understand the importance of a healthy security culture.
Various approaches that could be introduced to promote a healthy security culture include the
focus on awareness, deployment of leadership-driven cyber governance model, clear
documentation of security policies and providing necessary training to the employees.
IT 552
8
References
6 ways to develop a security culture in your organization. (2019). Retrieved 19 July 2019,
from https://techbeacon.com/security/6-ways-develop-security-culture-top-bottom
Bashay, F. (2019). What Is the CIA Triangle and Why Is It Important for Cybersecurity
Management?. Retrieved 19 July 2019, from https://www.difenda.com/blog/what-is-
the-cia-triangle-and-why-is-it-important-for-cybersecurity-management
Four Tips for Building a Strong Security Culture in Your Organization. (2019). Retrieved 19
July 2019, from https://blog.netwrix.com/2018/06/28/four-tips-for-building-a-strong-
security-culture-in-your-organization/
Gontovnikas, M. (2019). Cybersecurity Shouldn’t Be a Secret: Why Transparency Matters.
Retrieved 19 July 2019, from https://auth0.com/blog/cybersecurity-shouldnt-be-a-
secret/
News, Tips, and Advice for Technology Professionals - TechRepublic. (2019). Retrieved 19
July 2019, from https://www.techrepublic.com/article/success-strategies-for-security-
awareness/
Where The World Talks Security | RSA Conference. (2019). Retrieved 19 July 2019, from
https://www.rsaconference.com/writable/presentations/file_upload/hum-t09-building-a-
strategic-plan-for-your-security-awareness-program.pdf
IT 552
9