CMGT/545v1
Risk
Assessment – C-Suite Group Tasks
Summary
Laws and regulation need to be considered as they help improve the information security strategy by
providing guidelines and best practices. Non-compliance with these regulations will result in severe penalty.
The act listed below are the laws and regulation that will impact the company.
National Institute of Standards and Technology (NIST)
oProvides a customizable guide on how to manage and reduce cybersecurity related risk by
combining existing standards, guidelines, and best practices. It also helps foster
communication between internal and external stakeholders by creating a common risk
language between different industries
Center for Internet Security Controls (CIS Controls)
oProtects assets and data from known cyber attack vectors.
International Organization for Standardization (ISO 27000 Family)
oProvides security requirements around the maintenance of information security
management systems through implementation of security controls.
Control Objectives for Information and Related Technologies (COBIT)
oHelps to manage information and technology governance by linking business and IT goals.
As cybercrime gets more sophisticated, we need to add an extra level of protection in the form of two-factor
authentication (2FA). Most of the companies have been implementing 2FA to provide an extra layer of
security. Hardware tokens, SMS text message and voice based, software tokens, push notification are
some forms of two-factor authentication.
KPI (Key Performance Indicator) is a measurable value that demonstrates how a company is achieving key
business objectives. DevOps Metrics track website and application performance and help quickly identify
and remove any bottlenecks in the process.
It’s a crucial need to provide security of the information system of the company. So, we have illustrated
various security controls associated with each component of the company information security plan which is
approved by upper management and is being enforced throughout the company. The information security
plan is the cornerstone for protecting the company’s assets an information.
1. Business Environment
oConnotes external forces, factors and institution that are beyond authority of a company like
customers, competitors, suppliers, contractors. As part of establishing the company’s
information security program, it is important to identify and document roles, responsibilities
and authorities of the stakeholders and other key players, key stakeholders.
2. Asset management
oIdentifies all hardware, software, systems and data that support a company’s information
systems.
3. Access control
oIt is designed to ensure that no one can access to an information asset without any
permission.
Copyright 2020 by University of Phoenix. All rights reserved.
Risk Assessment – C-Suite Group Tasks
CMGT/545 v1
Page 2 of 2
4. Baseline configuration
oEstablishing a configuration in which all systems need to adhere for maintaining a safe and
secure information infrastructure
5. Communication security
oFocuses on all digital communication within the company
6. Cryptography
oIt is the encryption of data and communication. The level of cryptography is used
corresponding to the level of risk and sensitivity of the information.
7. Information sanitization and destruction
oProtection of data on transit- when moving from one department to another department or
being transmitted to an external system
8. Human resource security
oCompany’s staff are the greatest asset but also the greatest threat to security. Hence, it is
important to conduct proper screening of staff members during interview and hiring
process, and also take account a staff member’s access privileges when terminating or
putting a staff member on disciplinary leave.
9. Physical and environment security
oProtect a company’s information infrastructure and maintain environmental condition that
support information system operation.
References
tcdi(2020). https://www.tcdi.com/information-security-compliance-which-regulations
(2015). https://www.pnnl.gov/main/publications/external/technical_reports/PNNL-25112.pdf
Copyright 2020 by University of Phoenix. All rights reserved.