SEC 370 Course Project

profilerobnha2
week_5_you_decide.docx

Security 370 Web Security

DeVry University

Introduction

Developing a security policy for a mid-sized business is important to understand and define what malware is. Malware is a program that is unknowingly installed on a computer and performs undesirable functions. Malware programs are known to cause serious damage to operating systems by infecting computers in the same network and/or copying passwords and other login information. Malware can also be a virus; a virus is software that installs on the host computer then replicates itself and spreads to other devices. Adware is malicious software that displays advertisements when the computer is connected to the internet. Adware typically has financial support. Spyware is a type of clandestine application that secretly gathers information and either sales or trades it to a third party. There is also software that hijacks web browsers. These types of programs inject the web browser with advertisements, modifies the user’s profile and web browser settings. With that being said malware can modify the kernel of the OS making it increasingly difficult to get rid of them. Mid-sized businesses have to deal with competitors and the possibility of being attacked. Cyber criminals in the have more tools at their disposal to attempt to get what they want.

Security Policy

One of the primary functions of the I.T security policy is to describe how a company will strategize when dealing with malware, spyware, adware, and viruses since can crash a company’s network system as well as personal computers possibly resulting in lost productivity. Guidelines and restrictions should be well defined when handling employee conduct, employees visiting internet sites, downloading files and the use of BYOD (bring your own devices), and external storage devices. There are many programs and appliances available to make it easier to protect the company’s computers, servers and other network devices. Therefore there is a need for the organization from top management down to be sensitized on the type of damage that can caused by viruses and malware, adware, and spyware.

The IT department is all tasked with informing users with reasons why protecting data and systems against malware is important. It is important that employees follow all of the recommended guidelines and understand, the importance of network protection. An organization should inform its employees on the challenges the company may encounter if the network is compromised. There should be an emphasis on how the loss of critical information could adversely affect the company.

The local and federal governments provide laws and legislations for the company to prioritize and abide by them. Laws and legislations also applied to copyrights and patents which are used to protect and secure company secrets and private information.

Part of the company’s top level management job is to describe the security policy in detail to employees. Using communications between employees and management, employees are expected to abide by the security policy. All devices should have antivirus software installed, and the scanner should be run frequently. The consequences of not abiding by the I.T security policy should be well defined and communicated to the employees. If the employee has violated a company policy at any level it should be well communicated and any disciplinary actions should be enforced by the management.

The development of a successful policy allows the company to successfully mitigate possible or known vulnerabilities. Policy rules should be placed in a hierarchical order, highest having the most priority and the lowest having the least priority. Disciplinary actions will be administered according to the hierarchical principle.

The company should organize its security policies so employees can have easy access to them and written in a way that makes them easy to understand. Security policies can be placed on notice boards and made easily accessible from the company’s website.

Maintenance Schedule

A maintenance schedule should be included developed along with the security policy. Antivirus software will perform scheduled scans at the end of the business day. The antivirus software will be active at all times running in the background in case of a system breach. Antivirus software should be updated when new versions have been released, and every quarter.

The goal is to take a more aggressive approach to protecting against spyware. Spyware scans will be performed twice per day. The software will remain active during the night in case malicious software is scheduled to run after midnight. In addition to detecting the threat the software will track the source of the threat. The following programs should be considered when protecting a mid-sized company: AVG Antivirus Business Edition 2013, Symantec Endpoint Protection Small Business Edition 2013, Kaspersky Endpoint Security for Business Core, and Panda Cloud Office Protection (Williams, 2013).

Conclusion

Given the type of data that is stored on a network protection for mid-sized organizations is very important. Cybercriminals use malicious software to gain unauthorized access to computer and/or network information. The I.T security team should be prepared to protect the network against these threats. Protection plans or schedules are not foolproof but establishing them does help improve security.

References

Williams, M. (2013). Best business antivirus: 8 top paid security tools for small business.

Retrieved February 13, 2014 from http://www.techradar.com/us/news/software/applications/best-business-antivirus-8-top-paid-security-tools-for-small-business-1170097

IT policies & procedures. (2010). Retrieved from http://www.ehow.com

6