1 / 7100%
Running Head: CYBER SECURITY POLICY aaa aaa aaa aa aaa aaa aaa aaa aaa aaa a aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa a aaa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa a a aaa aaa aa aaa aaa aaa aaa aaa aa aaa aaa aaa aa aaa 1
IT-659-Q1436: Assignment 5-2
CYBER SECURITY POLICY aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa a aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa 2
Introduction
The Cybersecurity Policy that has been designed for the Maersk business
is based on the three core pillars namely confidentiality, integrity and
availability. The security policy has been made so that the shipping concern
could adapt to the evolving technological infrastructure and safeguard itself as
well as it key stakeholders in the best way possible. It would have a major
implication on the decisions that would be taken by Maersk and the direction
in which it would move in the dynamic industrial setting (Paloaltonetworks.com,
2018). The main features of the Maersk’s cybersecurity policy have been
highlighted here. The extent to which there is compliance with the prevailing
U.S. cyber laws has been ascertained. The process in which it could minimize
the Maersk’s risks and vulnerabilities has been discussed. Ultimately, the key
security policy sections relating to privacy has been highlighted.
Maersk’s Cybersecurity Policy
In order to safeguard Maersk’s confidentiality, integrity, and availability of
the organization’s data, the Cybersecurity Policy of the shipping business would
highlight the core elements namely the purpose and scope of the policy. It
would act as the building block of the cybersecurity that would safeguard the
digital assets of the concern (Resources.infosecinstitute.com, 2018). The
fundamental objectives of the policy would be highlighted that would revolve
around maintaining the confidentiality of the business data and information,
keeping the organizational information intact and making the same available to
the authorized users only.
The user access controls and authorization details would be a key
element in the policy that would safeguard the sensitive business applications
CYBER SECURITY POLICY aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa a aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa 3
against unauthorized users. Similarly, the resource access logs would be included
in the cybersecurity policy so that all kinds of activity logs could be closely
monitored and scrutinized. Any form of access violations would be reported
within minutes so that necessary actions could be taken. The classification of
the business data would be highlighted in the document so that a clear
distinction could be made between the high-risk class, confidential class and
class public. The details relating to the security training and responsibilities of
the personnel would also be incorporated in the policy
(Resources.infosecinstitute.com, 2018). These features of Maersk’s Cybersecurity
Policy would make sure that it could defend itself from similar previous
cyberattack.
Compliance with current U.S. cyber laws
The current cybersecurity of the U.S. has been designed to safeguard the
computer networks, systems and information, promote American prosperity by
strengthening the digital economy and foster the domestic innovative environment,
and grow the American influence by extending the key principle of secure and
reliable internet (Bush, 2009). The cybersecurity policy of Maersk has been
designed by keeping in mind the current cyber laws that are followed in the
country so that a safe and secure virtual platform can be designed and the
digital components of the business can be efficiently managed. The NoPetya
attack that crippled the shipping business was an eye opener for Maersk and
the new elements have been incorporated in the firm’s security document so
that the chances of the cybercrimes could be restricted to a possible extent. The
security policy has been framed in accordance with the current cyber laws of
CYBER SECURITY POLICY aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa a aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa 4
the U.S. so that cyber safety of Maersk could be upgraded to a significant
extent (Whitehouse.gov, 2018, p 3).
Interpretation of security issues and risks in the workplace
The core elements that have been introduced in the cybersecurity policy
of the business would empower the undertaking as well as the personnel to
keep a tab on the computer network. The robust training that would be
provided to the employees would make sure that they could act in a conscious
and careful manner so that they could act as check checks and filters that
could control and/or contain the unauthorized access in the online business
context. Similarly, the allocation of the specific roles and responsibilities in the
organizational context would eliminate the chances of ambiguity and protect the
business against vulnerabilities that could arise (SAFETY4SEA, 2018). This
approach would safeguard the firm against the former attack “NoPetya” that had
crippled its shipping business. It would act as a major barrier against
unauthorized access and the improper use of business systems of Maersk.
Security Policy Sections
The core sections of the security policy of the undertaking would focus on
the confidentiality and privacy of the digital data of Maersk, the authenticity
and integrity of the online business data and information and the easy access of
the data to the authorized individuals in the organizational context. The
confidentiality section would make sure that the communication approaches that
are used by the business such as the emails and social media platforms would
not give any scope to the cyber attackers or cyber hackers to gain unauthorized
access into the online business platform.
CYBER SECURITY POLICY aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa a aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa 5
In order to maintain the integrity of the data of the shipping concern, the
policy would clearly specify that only the departmental heads would have access
to the high-end data of the organization (Whitehouse.gov, 2018, p 17). The
accessibility and availability of the organizational data of the shipping business
Maersk would be managed by adopting a systematic model. The employees
could gain access to sensitive business information only via their superiors. In
other words, they would not have a direct access to the key business
information of Maersk. This section has been incorporated in the cybersecurity
policy of the concern so that the limited number of check points could be
monitored on a daily or weekly basis by the IT team (Whitehouse.gov, 2018, p
17). These sections have been included in the policy to design a secure online
platform for Maersk.
Confidentiality
Integrity
Availability
The communication
approaches within Maersk
would be frequently
monitored to strengthen
the level of security and
privacy.
The clear and distinct
details about the authorized
users would be shared so
that only departmental heads
could access sensitive
organization information.
The employees would
not have a direct
access to the sensitive
business data and they
could access it only
through their supervisors
or departmental heads.
Source: (Whitehouse.gov, 2018, p 16)
Conclusion
The cybersecurity policy has been designed so that the level of
confidentiality, integrity and safety of Maersk could be possible. The policy has
been designed in accordance with the existing cyber laws so that the risk and
CYBER SECURITY POLICY aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa a aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa 6
vulnerability of the shipping business could be mitigated in the best possible
manner. The core policies of the cybersecurity model of Maersk have been
structured by taking into account the wide range of operational activities that
are carried out by the firm. Similarly, the ethical considerations have been taken
into account so that could arise due to social media use and affect the privacy
of the stakeholders of the Maersk entity.
References
Bush, G. W. (2009). The national security strategy of the United States of
America. Wordclay.
Paloaltonetworks.com. (2018). What is an IT Security Policy? - Palo Alto
Networks. Retrieved from https://www.paloaltonetworks.com/cyberpedia/what-is-
an-it-security-policy
Resources.infosecinstitute.com. (2018). Key Elements of an Information Security
Policy. (2018). Retrieved from https://resources.infosecinstitute.com/key-elements-
information-security-policy/#gref
CYBER SECURITY POLICY aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa a aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa aaa
aaa aaa aaa aaa aaa aaa aaa aaa aaa aa aaa aa aaa aaa aaa aaa aa aaa aaa aaa aaa aaa aaa aaa aaa 7
Safety4sea. (2018). Maersk Line: Surviving from a cyber-attack. Retrieved from
https://safety4sea.com/cm-maersk-line-surviving-from-a-cyber-attack/
Whitehouse.gov. (2018). National Cyber Strategy of the United States of
America. Retrieved from https://www.whitehouse.gov/wp-
content/uploads/2018/09/National-Cyber-Strategy.pdf
Students also viewed