Running Head: CYBER SECURITY POLICY ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab 1
IT-659-Q1436: Assignment 5-2
SNHU
CYBER SECURITY POLICY ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab 2
Introduction
The Cybersecurity Policy that has been designed for the Maersk business is
based on the three core pillars namely confidentiality, integrity and availability. The
security policy has been made so that the shipping concern could adapt to the
evolving technological infrastructure and safeguard itself as well as it key
stakeholders in the best way possible. It would have a major implication on the
decisions that would be taken by Maersk and the direction in which it would move
in the dynamic industrial setting (Paloaltonetworks.com, 2018). The main features of
the Maersk’s cybersecurity policy have been highlighted here. The extent to which
there is compliance with the prevailing U.S. cyber laws has been ascertained. The
process in which it could minimize the Maersk’s risks and vulnerabilities has been
discussed. Ultimately, the key security policy sections relating to privacy has been
highlighted.
Maersk’s Cybersecurity Policy
In order to safeguard Maersk’s confidentiality, integrity, and availability of the
organization’s data, the Cybersecurity Policy of the shipping business would highlight
the core elements namely the purpose and scope of the policy. It would act as the
building block of the cybersecurity that would safeguard the digital assets of the
concern (Resources.infosecinstitute.com, 2018). The fundamental objectives of the
policy would be highlighted that would revolve around maintaining the confidentiality
of the business data and information, keeping the organizational information intact
and making the same available to the authorized users only.
The user access controls and authorization details would be a key element in
the policy that would safeguard the sensitive business applications against
unauthorized users. Similarly, the resource access logs would be included in the
CYBER SECURITY POLICY ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab 3
cybersecurity policy so that all kinds of activity logs could be closely monitored and
scrutinized. Any form of access violations would be reported within minutes so that
necessary actions could be taken. The classification of the business data would be
highlighted in the document so that a clear distinction could be made between the
high-risk class, confidential class and class public. The details relating to the security
training and responsibilities of the personnel would also be incorporated in the policy
(Resources.infosecinstitute.com, 2018). These features of Maersk’s Cybersecurity
Policy would make sure that it could defend itself from similar previous cyberattack.
Compliance with current U.S. cyber laws
The current cybersecurity of the U.S. has been designed to safeguard the
computer networks, systems and information, promote American prosperity by
strengthening the digital economy and foster the domestic innovative environment,
and grow the American influence by extending the key principle of secure and
reliable internet (Bush, 2009). The cybersecurity policy of Maersk has been designed
by keeping in mind the current cyber laws that are followed in the country so that
a safe and secure virtual platform can be designed and the digital components of the
business can be efficiently managed. The NoPetya attack that crippled the shipping
business was an eye opener for Maersk and the new elements have been
incorporated in the firm’s security document so that the chances of the cybercrimes
could be restricted to a possible extent. The security policy has been framed in
accordance with the current cyber laws of the U.S. so that cyber safety of Maersk
could be upgraded to a significant extent (Whitehouse.gov, 2018, p 3).
Interpretation of security issues and risks in the workplace
The core elements that have been introduced in the cybersecurity policy of
the business would empower the undertaking as well as the personnel to keep a tab
CYBER SECURITY POLICY ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab 4
on the computer network. The robust training that would be provided to the
employees would make sure that they could act in a conscious and careful manner
so that they could act as check checks and filters that could control and/or contain
the unauthorized access in the online business context. Similarly, the allocation of
the specific roles and responsibilities in the organizational context would eliminate
the chances of ambiguity and protect the business against vulnerabilities that could
arise (SAFETY4SEA, 2018). This approach would safeguard the firm against the
former attack “NoPetya” that had crippled its shipping business. It would act as a
major barrier against unauthorized access and the improper use of business systems
of Maersk.
Security Policy Sections
The core sections of the security policy of the undertaking would focus on the
confidentiality and privacy of the digital data of Maersk, the authenticity and
integrity of the online business data and information and the easy access of the data
to the authorized individuals in the organizational context. The confidentiality section
would make sure that the communication approaches that are used by the business
such as the emails and social media platforms would not give any scope to the
cyber attackers or cyber hackers to gain unauthorized access into the online business
platform. ab
In order to maintain the integrity of the data of the shipping concern, the
policy would clearly specify that only the departmental heads would have access to
the high-end data of the organization (Whitehouse.gov, 2018, p 17). The accessibility
and availability of the organizational data of the shipping business Maersk would be
managed by adopting a systematic model. The employees could gain access to
sensitive business information only via their superiors. In other words, they would
CYBER SECURITY POLICY ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab 5
not have a direct access to the key business information of Maersk. This section has
been incorporated in the cybersecurity policy of the concern so that the limited
number of check points could be monitored on a daily or weekly basis by the IT
team (Whitehouse.gov, 2018, p 17). These sections have been included in the policy
to design a secure online platform for Maersk.
Confidentiality
Integrity
Availability
The communication
approaches within Maersk
would be frequently
monitored to strengthen the
level of security and
privacy.
The clear and distinct details
about the authorized users
would be shared so that only
departmental heads could
access sensitive organization
information.
The employees would
not have a direct access
to the sensitive business
data and they could
access it only through
their supervisors or
departmental heads.
Source: (Whitehouse.gov, 2018, p 16)
Conclusion
The cybersecurity policy has been designed so that the level of confidentiality,
integrity and safety of Maersk could be possible. The policy has been designed in
accordance with the existing cyber laws so that the risk and vulnerability of the
shipping business could be mitigated in the best possible manner. The core policies
of the cybersecurity model of Maersk have been structured by taking into account
the wide range of operational activities that are carried out by the firm. Similarly,
the ethical considerations have been taken into account so that could arise due to
social media use and affect the privacy of the stakeholders of the Maersk entity.
CYBER SECURITY POLICY ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab
ab ab ab ab ab a ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab ab a ab ab ab ab ab ab ab ab 6
References
Bush, G. W. (2009). The national security strategy of the United States of America.
Wordclay.
Paloaltonetworks.com. (2018). What is an IT Security Policy? - Palo Alto Networks.
Retrieved from https://www.paloaltonetworks.com/cyberpedia/what-is-an-it-security-
policy
Resources.infosecinstitute.com. (2018). Key Elements of an Information Security
Policy. (2018). Retrieved from https://resources.infosecinstitute.com/key-elements-
information-security-policy/#gref
Safety4sea. (2018). Maersk Line: Surviving from a cyber-attack. Retrieved from
https://safety4sea.com/cm-maersk-line-surviving-from-a-cyber-attack/
Whitehouse.gov. (2018). National Cyber Strategy of the United States of America.
Retrieved from https://www.whitehouse.gov/wp-content/uploads/2018/09/National-
Cyber-Strategy.pdf