Discussion on business management and security risks
See word document on 2 questions
Minimum words = 150
2 years ago
10
Week1-Discussion.docx
BusinessRead.pdf
Week1-Discussion.docx
Welcome to Padgett-Beale and your first week as a management intern.
The Chief of Staff will be hosting a working lunch this week for your group of interns. In addition to the usual introductions and "getting to know you" discussions, you've been advised that there will be a discussion of the following article.
https://securityintelligence.com/seasonal-employee-security-risks-present-danger-proactive-defense/
Each intern has been asked to write and bring a discussion paper containing their written responses to the following questions:
· What steps can (should) managers take to reduce security risks associated with hiring seasonal or temporary employees? (Consider whether or not the Secure Computer User training course would be appropriate for these employees.)
· How can managers show leadership in the area of cybersecurity defenses and best practices?
Consider the ways in which these types of companies are likely to use seasonal employees and the types of digital assets / information to which these temporary employees may have access.
BusinessRead.pdf
CSIA 300: Cybersecurity for Leaders and Managers
1
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
Why do Businesses Need Security?
There are many different types of businesses. Each one needs security in some form. In this reading, we will explore the reasons why a business needs to have someone or some group within the business that is responsible for security.
Types of Businesses
A sole proprietorship is a simple form of business in which the owner is personally responsible for the business’s ac�vi�es (including debts) (Entrepreneur Staff, 2017b). The business may have a trade name but it does not have a legal iden�ty separate from its owner. In this form of business, the owner’s personal knowledge of cybersecurity issues and solu�ons will be very important.
A partnership is a form of business in which two or more individuals own the business (Entrepreneur Staff, 2017a). Partners contribute resources to the business (“investments”) and then share any resul�ng profits or losses. Partnership agreements state how those profits or losses will be distributed among the owner. Such agreements also provide for management and authority over the day-to-day opera�ons of the business. A partnership will also need some form of governance structure to guide decision making about how the business will be operated (strategies, goals, policies, etc.). At least one of the partners involved in daily opera�ons will need to have cybersecurity knowledge.
A corpora�on (Investopedia, 2017) is a legally recognized en�ty (owned or controlled by a group of people) that enjoys many of the rights, responsibili�es, and du�es as are granted under the law to a person. The corpora�on’s rights, responsibili�es, and du�es exist separately from those of the corpora�on’s owners. The documents of incorpora�on provide structure to the company’s governance by outlining key roles and responsibili�es. The members of the Board of Directors and the senior leaders / managers of the company all need to have some familiarity with cybersecurity related principles, prac�ces, threats and risks.
Reasons Why Businesses Need Security
Asset Protection (Traditional & Digital Assets)
Businesses exist to make a profit. They do this by crea�ng and selling products and services. Business assets are resources used by the organiza�on to produce the goods and services it will sell or to provide suppor�ng services required to operate the business (Kovacich & Halibozek, 2003).
An asset is a possession (item or object) that has value. This value must be protected against harm or loss.
Digital assets are informa�on assets that exist only in digital form (electronically stored informa�on). These assets are stored on digital media and are accessed / used via digital
CSIA 300: Cybersecurity for Leaders and Managers
2
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
devices. The term is used to refer to files, so�ware, and firmware. Digital assets may also be physical assets (when they exist in stored form) or they may be classified as intangible assets.
Physical assets include buildings, land, property, etc. Computer hardware and infrastructures are physical assets.
Intangible assets include such things as intellectual property, trade secrets, brand recognition, reputation and good will.
Thus, we have our first reason that businesses need security – to protect business assets. Asset security consists of those measures taken by the business to protect its assets from harm or loss. This harm or loss may be caused by insiders (e.g. employees), outsiders (criminals, compe�tors), and extraordinary events (force majeure) or acts of God. Business assets that must be protected against loss or harm include:
• buildings and facili�es, equipment and furnishings • business processes • computer systems • financial instruments and cash (money) • informa�on (databases, documents, and files) • inventory (completed products, parts, and supplies) • networks and infrastructures • personnel (skilled workforce) • intellectual property (e.g., patents, trade secrets, plans, and strategies) • reputa�on
Informa�on and informa�on systems are assets. Informa�on is an asset because the organiza�on must spend money to obtain it so that the informa�on can be used to produce goods and services. Examples of valuable informa�on assets include recipes or formulas, customer and vendor lists, sales plans, and marke�ng strategies. An informa�on system is an asset because each component of the system costs money to purchase or replace. Note: Businesses may also be holders or custodians of informa�on belonging to others. This informa�on must also be protected from harm or loss.
The security measures required to protect business assets are determined by iden�fying the assets that require protec�on and then assessing the specific threats and vulnerabili�es (for each asset or type of asset) that are present in the organiza�on’s opera�ng environment.
Legal and Regulatory Compliance
Businesses must comply with laws and regula�ons set forth by certain governments and government agencies (Reynolds, 2010). Some�mes, it can be difficult to determine which laws or regula�ons apply and in what circumstances they apply. Businesses need the advice and services of atorneys or corporate
CSIA 300: Cybersecurity for Leaders and Managers
3
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
counselors to provide guidance in making such determina�ons. It is important to have competent legal counsel for areas where the business is at risk or may face penal�es for non compliance. Cybersecurity requirements imposed by laws or regula�ons are an area where specialized legal counsel may be required.
Key concepts from law that affect business opera�ons are due diligence and duty of care (Reynolds, 2010). Due diligence is the obliga�on to be conscien�ous in performing your du�es. In some uses, this term refers specifically to func�ons related to contracts and acquisi�ons. Duty of care is the obliga�on to be aten�ve and to avoid causing harm. Leaders and managers need to understand cybersecurity principles, prac�ces, threats, and risks in order to meet their obliga�ons under both due diligence and duty of care.
Integrating Security with Business Operations
Businesses can be described as systems of people, processes, policies, and technologies and the interconnec�ons / rela�onships between these components (ISACA, 2009). These components can also be viewed as assets, which have value to the organiza�on. Each component, each rela�onship between components requires some level of protec�on from harm or loss. Thus, the need for security throughout the system is pervasive and should be approached in a holis�c manner.
Figure 1. Systems View of an Organiza�on
Working with the en�re system at once can be a daun�ng task especially when greater levels of detail are required. Breaking the system down into smaller chunks is an obvious solu�on but, how should those chunks be defined? One organizing strategy, used by business analysts, is to divide the organiza�on into func�onal areas. Within each func�onal area, we can iden�fy the components of the system that operate within the func�onal area and those components which are cross-cu�ng (apply to mul�ple func�onal areas at the same �me. Dividing the business into func�onal areas will also allow us to analyze and assess security needs within each area. A�er the needs in each area are considered, we can iden�fy cross-cu�ng or system-wide security requirements and gaps. Finding commonali�es allows
CSIA 300: Cybersecurity for Leaders and Managers
4
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
us to iden�fy ways to reduce costs and improve efficient alloca�on of resources to deliver required levels of security.
Business Functions
The day-to-day business opera�ons of organiza�ons are typically organized into five func�onal areas (see figure 1). Each func�onal area is supported by business processes and assets. As business becomes e- business and commerce becomes e-commerce, businesses must reevaluate their security programs to ensure that the confiden�ality, integrity, and availability of business processes and assets are protected against threats (sources of harm or loss). The figure below shows the five func�onal areas typically found in the day-to-day opera�ons and ac�vi�es of an organiza�on. No�ce that “security” is a separate business func�on yet is fully integrated within the business enterprise. Security both supports and is supported by the other func�onal areas of the business.
Figure 2. Day-to-Day Business Opera�ons
Accounting and Finance Functions
The accoun�ng and finance func�ons of a business include:
• accoun�ng and bookkeeping • budget prepara�on and monitoring • fiscal analysis and repor�ng • sales or other financial transac�on processing
Security is required for devices and informa�on systems which process or provide access to financial informa�on. Required security func�ons include providing authen�ca�on, authoriza�on, and nonrepudia�on for access to and use of both physical and digital assets containing financial informa�on.
CSIA 300: Cybersecurity for Leaders and Managers
5
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
Addi�onal security services may also be required to ensure compliance with federal and state laws and
regula�ons (e.g., Gramm-Leach-Bliley Act, Sarbanes-Oxley Act, Fair Credit Repor�ng Act, etc.).
Commercial Functions
The commercial func�ons of a business include:
• sales • marke�ng and business intelligence • customer rela�onship management
Security needs for commercial func�ons include:
• protec�on of confiden�al business informa�on (client lists, sales/marke�ng plans, etc.), trade secrets, and other forms of intellectual property
• protec�on of customer and vendor informa�on (including personally iden�fiable informa�on) • provision of authen�ca�on, authoriza�on, and nonrepudia�on for access to and use of
informa�on systems involved in the collec�on, use, repor�ng, and storage of customer informa�on
Addi�onal security services may be required to comply with provisions federal and state laws regarding privacy, data breach repor�ng, and corporate transparency.
For marke�ng and business intelligence func�ons, the organiza�on may need to incorporate audi�ng and control func�ons to ensure that the informa�on collected about compe�tors does not violate the Economic Espionage Act or other applicable laws.
General and Functional Management Functions
According to Henri Fayol (Svenson, 1961), the management func�ons of a business include:
• Planning, organizing, and coordina�ng the work of the organiza�on • Alloca�ng and controlling resources (including budge�ng) • Monitoring and controlling (“commanding”) the work of the organiza�on
These management func�ons frequently involve decision-making ac�vi�es which require access to and the ability to benefit from a variety of informa�on that the organiza�on collects, processes, transmits, and stores (Tannenbaum, 1950). Such informa�on includes:
• business records • confiden�al business informa�on (client lists, sales/marke�ng plans, corporate strategies, etc.) • customer data (including personally iden�fiable informa�on) • financial data and forecasts
CSIA 300: Cybersecurity for Leaders and Managers
6
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
• plans and schedules • trade secrets • other forms of intellectual property
The informa�on and confiden�al business processes used in the general and func�onal management ac�vi�es of an organiza�on must be protected against unauthorized access or disclosure. Typically, this is done by pu�ng restric�ons in place which control access to informa�on and informa�on resources. These restric�ons must be balanced against legi�mate uses and disclosures of informa�on while communica�ng, coordina�ng, and collabora�ng as part of the day-to-day opera�ons of the business.
Security Functions
Security of the business, from assets to opera�ons and all the func�ons in between, is a shared responsibility for all managers and employees (Kovacich & Halibozek, 2003). This responsibility includes diligence in the performance of du�es under the duty of care (Reynolds, 2010). The reasonable person standard is used to determine if an individual has performed these responsibili�es with the same level of diligence and care that a conscien�ous person would put forth.
The effec�veness and efficiency of security func�ons are improved when there is a single manager with primary responsibility for these func�ons (Kovacich & Halibozek, 2003).
The security manager has both an opera�onal and a strategic role in the business and must use a great deal of influence and collabora�on to ensure coopera�on on security maters throughout the organiza�on (Kovacich & Halibozek, 2003). The security manager is usually supported by a dedicated organiza�on whose personnel are specifically trained in security administra�on, physical security, personnel security, opera�ons security, and informa�on security. The security manager is responsible for the establishment and management of the organiza�on’s security program. These responsibili�es include ensuring compliance with laws, regula�ons, and standards for corporate security. The security manager and suppor�ng security personnel are also trained in risk management, fraud deterrence, internal inves�ga�ons, con�ngency planning, disaster recovery, and crisis management.
The security func�ons of an organiza�on include (Kovacich & Halibozek, 2003):
• protect against harm or loss • detect atempts to cause harm or loss • react to events causing harm or loss • document incidents and responses • prevent by planning and implemen�ng security measures to prevent future incidents • assist in ensuring compliance with laws and regula�ons
The protec�on of business func�ons which depend upon cyberspace and digital assets which can be accessed from cyberspace has become an increasingly important area of responsibility for security
CSIA 300: Cybersecurity for Leaders and Managers
7
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
managers. A separate sub-specialty or func�onal area for security, Cybersecurity (Department of Homeland Security, 2017), has emerged as a result of this growing need.
Technical Functions
The technical func�ons of a business are those ac�vi�es, which directly or indirectly contribute to the conversion of inputs (raw materials and labor) into outputs (products and services which can be sold or otherwise converted into monetary value). These func�ons include:
• business opera�ons • product development and produc�on • purchasing and logis�cs • research and development
The security needs of each ac�vity area vary by the types and sensi�vity levels of the processes and informa�on required by the ac�vity and the degree to which each ac�vity interacts with or relies upon the external environment. These ac�vi�es require security protec�ons that ensure the confiden�ality, integrity, and availability of informa�on (data) and services. Many of these ac�vi�es also require audi�ng, monitoring, and control capabili�es (security services) that provide for nonrepudia�on of ac�ons taken by both insiders and external actors.
E-Business/E-Commerce Infrastructure
E-business and e-commerce infrastructures are built from capabili�es provided by the technical and commercial func�ons of a business. These infrastructures are then used to provide products and services that are either delivered in cyberspace or which are accessible from cyberspace (e.g. products ordered via an online ordering system). Special care must be taken to ensure that the data storage, processing, and transmission capabili�es (see figure 2) within the e-business and e-commerce infrastructure protect the confiden�ality, integrity, and availability of informa�on and services.
Figure 3. E-Business/E-Commerce Infrastructure
CSIA 300: Cybersecurity for Leaders and Managers
8
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
Cybersecurity and Businesses
Cybersecurity is a type of security that a business needs to have in place to protect its opera�ons and assets which exist in cyberspace or which can be accessed via computers, devices, and networks that have connec�ons into cyberspace. Put another way, Cybersecurity focuses primarily upon protec�ng and defending assets that exist in digital form or assets that receive, process, store, and transmit digital informa�on. Cybersecurity is also concerned with providing protec�on that ensures the confiden�ality, availability, and integrity of informa�on and informa�on based services which are accessed via the Internet. Cyberspace exists because enabling technologies such as the Internet provide global connec�ons between computers and between people using computers.
Figure 4. Cyberspace (the Internet)
References
Department of Homeland Security. (2017). Glossary. Retrieved from htps://niccs.us-cert.gov/glossary
Entrepreneur Staff. (2017a). Partnership. Retrieved from htps://www.entrepreneur.com/encyclopedia/partnership
Entrepreneur Staff. (2017b). Sole proprietorship. Retrieved from htps://www.entrepreneur.com/encyclopedia/sole-proprietorship
Investopedia. (2017). Corpora�on. Retrieved from htp://www.investopedia.com/terms/i/incorporate.asp
CSIA 300: Cybersecurity for Leaders and Managers
9
Copyright ©2020 by University of Maryland Global Campus. All Rights Reserved
ISACA. (2009). An introduction to the Business Model for Information Security. Retrieved from htp://www.isaca.org/knowledge-center/research/documents/introduc�on-to-the- businessmodel-for-informa�on-security_res_eng_0109.pdf
Kovacich, G. L., & Halibozek, E. P. (2003). The manager’s handbook for corporate security: Establishing and managing a successful assets protection program. Burlington, MA: Elsevier.
Reynolds, G. W. (2010). Ethics in information technology (3rd ed.). Boston, MA: Course Technology.
Svenson, A. L. (1961). Pioneers of management organiza�on theory. Management International 1(5/6), 115-130.
Tannenbaum, R. (1950). Managerial decision-making. The Journal of Business of the University of Chicago, 23(1), 22-39.
- Types of Businesses
- Reasons Why Businesses Need Security
- Asset Protection (Traditional & Digital Assets)
- Legal and Regulatory Compliance
- Integrating Security with Business Operations
- Business Functions
- Accounting and Finance Functions
- General and Functional Management Functions
- Security Functions
- Technical Functions
- E-Business/E-Commerce Infrastructure
- Cybersecurity and Businesses
- References