Security Policy Paper

profilesunhas
security_policy_paper_outline.docx

SOCIAL POLICY PAPER 1

SOCIAL SECURITY PAPER 1

CMIT320

Security Policy Paper

Week 3

Table of Contents

Introduction:

GDI background and given problem……………………………….…………………… 1

Important Assets for GDI…..……………………………………………………………. 2

Security Architecture for GDI…………………………………………………………… 3

Ten Possible Security Policies………………………………………………………. 4

Details and Rationale of the Ten Security Policies………………………………….. 5

Ten Security Policies that should be Applied to GDI……………………………….. 6

Conclusion……………………………………………………………………………..… 7

References……………………………………………………………………………….. 8

Outline of the paper

I. Introduction

a. Briefly discuss the background of GDI in depth.

b. A discussion about the given problem of the IT security, infrastructure, cost, among items.

II. Discuss the important assets of GDI that need to be fully protected

i. Asset identification: “Identity and quantify the company’s assets”

ii. Important assets include:

1. Computer network equipment

2. Data

3. Servers, printers

4. Routers, firewalls, switches, wireless devices, etc.

b. Access control methods: sensitivity, integrity, availability

c. Risk and threat assessment: “Identify and access the possible security vulnerabilities and threats”

d. Identify solutions and countermeasures: “Identify a cost-effective solution to protect assets”

III. Security architecture for the company

a. “The IT department should always have current diagrams of your overall network architecture on hand”

IV. A list of 20 or more policies that could be applied to this situation

a. User Account Policy

b. Audit Security Policy (SANS)

c. Email Security Policy (SANS)

d. Internet Security Policy (SANS)

e. Server Security Policy (SANS)

f. Wireless Security Policy (SANS)

g. Network Security Policy (SANS)

h. Physical Security Policy (SANS)

i. Remote Access Security Policy

j. Ethics Policy (SANS)

k. Privacy Policy

l. Incident Response Policy

m. Access Control Policy

n. Separation of Duties Policy

o. Password Policy

p. Data Retention Policy

q. Hardware Disposal and Data Destruction Policy

r. Documentation policy

V. Specific details and rationale of each policy from above

a. Ethics Policy – “User Education and Awareness Training”

b. Documentation policy- “Standards and Guidelines for Documentation, Data Classification, document retention and storage, document destruction, system architecture, logs inventory, change management and control documentation Network Security Policy- risk and threat assessment, vulnerabilities, threats, risk, impact, probabilities, natural disasters, equipment malfunction, intruders, malicious hackers, potential loss, and threat profiles

c. It also includes firewall, intrusion detection system, audits, etc.

d. Wireless Security Policy- Access point security, encryption protocols, MAC address filtering, VPN, etc.

e. Physical Security Policy- physical barriers, video surveillance and monitoring, lighting, locks, access logs, ID badges, man-trap

VI. Review the policies and select 12 important policies that can be applied to GDI

a. Network Security Policy

b. Internet Security Policy

c. Physical Security Policy

d. Ethics Policy

e. Remote Access Security Policy

f. Incident Response Policy

g. Hardware Disposal and Data Destruction Policy

h. Wireless Security Policy

i. Password Security Policy

j. Separation of Duties Policy

k. Privacy Policy

l. Server Security Policy

VII. Conclusion

a. Conclude discussion and proposal of the security policy document. This will be a conclusion based on the real aspects as discussed in the ouline

References

Include any references here with full citations. The references will be stated in the case of the final project. This will show all the sources of information that has been used in making the detailed research.