Running Head: CYBER SECURITY POLICY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
IT-659-Q1436: Assignment 5-2
SNHU
CYBER SECURITY POLICY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f 2
Introduction
The Cybersecurity Policy that has been designed for the Maersk business is based on
the three core pillars namely confidentiality, integrity and availability. The security policy
has been made so that the shipping concern could adapt to the evolving technological
infrastructure and safeguard itself as well as it key stakeholders in the best way possible. It
would have a major implication on the decisions that would be taken by Maersk and the
direction in which it would move in the dynamic industrial setting (Paloaltonetworks.com,
2018). The main features of the Maersk’s cybersecurity policy have been highlighted here.
The extent to which there is compliance with the prevailing U.S. cyber laws has been
ascertained. The process in which it could minimize the Maersk’s risks and vulnerabilities
has been discussed. Ultimately, the key security policy sections relating to privacy has been
highlighted.
Maersk’s Cybersecurity Policy
In order to safeguard Maersk’s confidentiality, integrity, and availability of the
organization’s data, the Cybersecurity Policy of the shipping business would highlight the
core elements namely the purpose and scope of the policy. It would act as the building block
of the cybersecurity that would safeguard the digital assets of the concern
(Resources.infosecinstitute.com, 2018). The fundamental objectives of the policy would be
highlighted that would revolve around maintaining the confidentiality of the business data
and information, keeping the organizational information intact and making the same available
to the authorized users only.
The user access controls and authorization details would be a key element in the
policy that would safeguard the sensitive business applications against unauthorized users.
Similarly, the resource access logs would be included in the cybersecurity policy so that all
kinds of activity logs could be closely monitored and scrutinized. Any form of access
CYBER SECURITY POLICY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f 3
violations would be reported within minutes so that necessary actions could be taken. The
classification of the business data would be highlighted in the document so that a clear
distinction could be made between the high-risk class, confidential class and class public.
The details relating to the security training and responsibilities of the personnel would also be
incorporated in the policy (Resources.infosecinstitute.com, 2018). These features of Maersk’s
Cybersecurity Policy would make sure that it could defend itself from similar previous
cyberattack.
Compliance with current U.S. cyber laws
The current cybersecurity of the U.S. has been designed to safeguard the computer
networks, systems and information, promote American prosperity by strengthening the
digital economy and foster the domestic innovative environment, and grow the American
influence by extending the key principle of secure and reliable internet (Bush, 2009). The
cybersecurity policy of Maersk has been designed by keeping in mind the current cyber laws
that are followed in the country so that a safe and secure virtual platform can be designed and
the digital components of the business can be efficiently managed. The NoPetya attack that
crippled the shipping business was an eye opener for Maersk and the new elements have been
incorporated in the firm’s security document so that the chances of the cybercrimes could be
restricted to a possible extent. The security policy has been framed in accordance with the
current cyber laws of the U.S. so that cyber safety of Maersk could be upgraded to a
significant extent (Whitehouse.gov, 2018, p 3).
Interpretation of security issues and risks in the workplace
The core elements that have been introduced in the cybersecurity policy of the
business would empower the undertaking as well as the personnel to keep a tab on the
computer network. The robust training that would be provided to the employees would make
sure that they could act in a conscious and careful manner so that they could act as check
CYBER SECURITY POLICY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f 4
checks and filters that could control and/or contain the unauthorized access in the online
business context. Similarly, the allocation of the specific roles and responsibilities in the
organizational context would eliminate the chances of ambiguity and protect the business
against vulnerabilities that could arise (SAFETY4SEA, 2018). This approach would
safeguard the firm against the former attack “NoPetya” that had crippled its shipping
business. It would act as a major barrier against unauthorized access and the improper use of
business systems of Maersk.
Security Policy Sections
The core sections of the security policy of the undertaking would focus on the
confidentiality and privacy of the digital data of Maersk, the authenticity and integrity of the
online business data and information and the easy access of the data to the authorized
individuals in the organizational context. The confidentiality section would make sure that
the communication approaches that are used by the business such as the emails and social
media platforms would not give any scope to the cyber attackers or cyber hackers to gain
unauthorized access into the online business platform. f
In order to maintain the integrity of the data of the shipping concern, the policy would
clearly specify that only the departmental heads would have access to the high-end data of the
organization (Whitehouse.gov, 2018, p 17). The accessibility and availability of the
organizational data of the shipping business Maersk would be managed by adopting a
systematic model. The employees could gain access to sensitive business information only
via their superiors. In other words, they would not have a direct access to the key business
information of Maersk. This section has been incorporated in the cybersecurity policy of the
concern so that the limited number of check points could be monitored on a daily or weekly
basis by the IT team (Whitehouse.gov, 2018, p 17). These sections have been included in the
policy to design a secure online platform for Maersk.
CYBER SECURITY POLICY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f 5
Confidentiality
Integrity
Availability
The communication
approaches within Maersk
would be frequently monitored
to strengthen the level of
security and privacy.
The clear and distinct details
about the authorized users would
be shared so that only
departmental heads could access
sensitive organization
information.
The employees would not
have a direct access to the
sensitive business data and
they could access it only
through their supervisors or
departmental heads.
Source: (Whitehouse.gov, 2018, p 16)
Conclusion
The cybersecurity policy has been designed so that the level of confidentiality,
integrity and safety of Maersk could be possible. The policy has been designed in accordance
with the existing cyber laws so that the risk and vulnerability of the shipping business could
be mitigated in the best possible manner. The core policies of the cybersecurity model of
Maersk have been structured by taking into account the wide range of operational activities
that are carried out by the firm. Similarly, the ethical considerations have been taken into
account so that could arise due to social media use and affect the privacy of the stakeholders
of the Maersk entity.
CYBER SECURITY POLICY f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f
f f f f 6
References
Bush, G. W. (2009). The national security strategy of the United States of America. Wordclay.
Paloaltonetworks.com. (2018). What is an IT Security Policy? - Palo Alto Networks.
Retrieved from https://www.paloaltonetworks.com/cyberpedia/what-is-an-it-security-
policy
Resources.infosecinstitute.com. (2018). Key Elements of an Information Security Policy.
(2018). Retrieved from https://resources.infosecinstitute.com/key-elements-
information-security-policy/#gref
Safety4sea. (2018). Maersk Line: Surviving from a cyber-attack. Retrieved from
https://safety4sea.com/cm-maersk-line-surviving-from-a-cyber-attack/
Whitehouse.gov. (2018). National Cyber Strategy of the United States of America. Retrieved
from https://www.whitehouse.gov/wp-content/uploads/2018/09/National-Cyber-
Strategy.pdf