The Rookie Chief Information Security Officer
Points: 200 Term Paper: The Rookie Chief Information Security Officer
Criteria
Unacceptable
Below 60% F
Meets Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A Part 1: Organization Chart
1ai. Use Visio or an Open Source alternative, such as Dia, to create an organization chart in which you illustrate the roles that will be required to ensure design, evaluation, implementation, and management of security programs for the organization. Weight: 5%
Did not submit or incompletely used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you illustrated the roles that will be required to ensure design, evaluation, implementation, and management of security programs for the organization.
Insufficiently used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you illustrated the roles that will be required to ensure design, evaluation, implementation, and management of security programs for the organization.
Partially used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you illustrated the roles that will be required to ensure design, evaluation, implementation, and management of security programs for the organization.
Satisfactorily used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you illustrated the roles that will be required to ensure design, evaluation, implementation, and management of security programs for the organization.
Thoroughly used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you illustrated the roles that will be required to ensure design, evaluation, implementation, and management of security programs for the organization.
1aii. Use Visio or an Open Source alternative, such as Dia, to create an organization chart in which you clearly identify the reporting structure for roles such as IT Security Compliance Officer, Security Manager, CIO, CISO, IT Security Engineer, Privacy Security Professional, and IT Procurement Specialist. Weight: 5%
Did not submit or incompletely used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you clearly identified the reporting structure for roles such as IT Security Compliance Officer, Security Manager, CIO, CISO, IT Security Engineer, Privacy Security Professional, and IT Procurement Specialist.
Insufficiently used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you clearly identified the reporting structure for roles such as IT Security Compliance Officer, Security Manager, CIO, CISO, IT Security Engineer, Privacy Security Professional, and IT Procurement Specialist.
Partially used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you clearly identified the reporting structure for roles such as IT Security Compliance Officer, Security Manager, CIO, CISO, IT Security Engineer, Privacy Security Professional, and IT Procurement Specialist.
Satisfactorily used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you clearly identified the reporting structure for roles such as IT Security Compliance Officer, Security Manager, CIO, CISO, IT Security Engineer, Privacy Security Professional, and IT Procurement Specialist.
Thoroughly used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you clearly identified the reporting structure for roles such as IT Security Compliance Officer, Security Manager, CIO, CISO, IT Security Engineer, Privacy Security Professional, and IT Procurement Specialist.
1aiii. Use Visio or an Open Source alternative, such as Dia, to create an organization chart in which you list the types of resources required to fulfill the each forensic
Did not submit or incompletely used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you listed the types of
Insufficiently used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you listed the types of resources
Partially used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you listed the types of resources
Satisfactorily used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you listed the types of resources
Thoroughly used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you listed the types of resources
duty of the organization below each of the roles you identified. Weight: 5%
resources required to fulfill the each forensic duty of the organization below each of the roles you identified.
required to fulfill the each forensic duty of the organization below each of the roles you identified.
required to fulfill the each forensic duty of the organization below each of the roles you identified.
required to fulfill the each forensic duty of the organization below each of the roles you identified.
required to fulfill the each forensic duty of the organization below each of the roles you identified.
1aiv. Use Visio or an Open Source alternative, such as Dia, to create an organization chart in which you align your organization chart to reflect the Department of Homeland Security (DHS) Essential Body of Knowledge’s three (3) areas of information security: physical security professional, privacy professional, and procurement professional. Provide comments and comparisons on how your organizational chart fosters these three (3) values. Weight: 10%
Did not submit or incompletely used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you aligned your organization chart to reflect the Department of Homeland Security (DHS) Essential Body of Knowledge’s three (3) areas of information security: physical security professional, privacy professional, and procurement professional; did not submit or incompletely provided comments and comparisons on how your organizational chart fosters these three (3) values.
Insufficiently used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you aligned your organization chart to reflect the Department of Homeland Security (DHS) Essential Body of Knowledge’s three (3) areas of information security: physical security professional, privacy professional, and procurement professional; insufficiently provided comments and comparisons on how your organizational chart fosters these three (3) values.
Partially used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you aligned your organization chart to reflect the Department of Homeland Security (DHS) Essential Body of Knowledge’s three (3) areas of information security: physical security professional, privacy professional, and procurement professional; partially provided comments and comparisons on how your organizational chart fosters these three (3) values.
Satisfactorily used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you aligned your organization chart to reflect the Department of Homeland Security (DHS) Essential Body of Knowledge’s three (3) areas of information security: physical security professional, privacy professional, and procurement professional; satisfactorily provided comments and comparisons on how your organizational chart fosters these three (3) values.
Thoroughly used Visio or an Open Source alternative, such as Dia, to create an organization chart in which you aligned your organization chart to reflect the Department of Homeland Security (DHS) Essential Body of Knowledge’s three (3) areas of information security: physical security professional, privacy professional, and procurement professional; thoroughly provided comments and comparisons on how your organizational chart fosters these three (3) values.
Part 2: Request for Proposal (RFP) Plan
2a. Develop a Request for Proposal (RFP) plan to solicit qualified vendors that could partner with your internal team to deliver optimum IT service delivery. The RFP Plan should contain qualifying criteria of potential vendors and the responsibilities of the vendor once the contract is awarded. As part
Did not submit or incompletely developed a Request for Proposal (RFP) plan to solicit qualified vendors that could partner with your internal team to deliver optimum IT service delivery. The RFP Plan should contain qualifying criteria of potential vendors and the responsibilities
Insufficiently, as part of the plan, described at least two (2) perspectives that need to be closely monitored within the contract.
Partially, as part of the plan, described at least two (2) perspectives that need to be closely monitored within the contract.
Satisfactorily, as part of the plan, described at least two (2) perspectives that need to be closely monitored within the contract.
Thoroughly, as part of the plan, described at least two (2) perspectives that need to be closely monitored within the contract.
of the plan, describe at least two (2) perspectives that need to be closely monitored within the contract. Weight: 10%
of the vendor once the contract is awarded; did not submit or incompletely, as part of the plan, described at least two (2) perspectives that need to be closely monitored within the contract.
2b. Develop a Request for Proposal (RFP) plan to solicit qualified vendors that could partner with your internal team to deliver optimum IT service delivery. The RFP Plan should contain qualifying criteria of potential vendors and the responsibilities of the vendor once the contract is awarded. As part of the plan, give your perspective on at least two (2) methods that could be used to evaluate and develop a qualified trusted supplier list. Weight: 10%
Did not submit or incompletely developed a Request for Proposal (RFP) plan to solicit qualified vendors that could partner with your internal team to deliver optimum IT service delivery. The RFP Plan should contain qualifying criteria of potential vendors and the responsibilities of the vendor once the contract is awarded; did not submit or incompletely, as part of the plan, gave your perspective on at least two (2) methods that could be used to evaluate and develop a qualified trusted supplier list.
Insufficiently, as part of the plan, gave your perspective on at least two (2) methods that could be used to evaluate and develop a qualified trusted supplier list.
Partially, as part of the plan, gave your perspective on at least two (2) methods that could be used to evaluate and develop a qualified trusted supplier list.
Satisfactorily, as part of the plan, gave your perspective on at least two (2) methods that could be used to evaluate and develop a qualified trusted supplier list.
Thoroughly, as part of the plan, gave your perspective on at least two (2) methods that could be used to evaluate and develop a qualified trusted supplier list.
Part 3: Physical Security Plan
3a. Recommend a physical security plan that could be used to protect sensitive areas such as telecom rooms, employee only areas, and manufacturing facilities in which you include at least three (3)
Did not submit or incompletely recommended a physical security plan that could be used to protect sensitive areas such as telecom rooms, employee only areas, and manufacturing facilities in which
Insufficiently recommended a physical security plan that could be used to protect sensitive areas such as telecom rooms, employee only areas, and manufacturing facilities in which you
Partially recommended a physical security plan that could be used to protect sensitive areas such as telecom rooms, employee only areas, and manufacturing facilities in which you included at
Satisfactorily recommended a physical security plan that could be used to protect sensitive areas such as telecom rooms, employee only areas, and manufacturing facilities in which you
Thoroughly recommended a physical security plan that could be used to protect sensitive areas such as telecom rooms, employee only areas, and manufacturing facilities in which you included at
specific methods. Weight: 10%
you included at least three (3) specific methods.
included at least three (3) specific methods.
least three (3) specific methods.
included at least three (3) specific methods.
least three (3) specific methods.
Part 4: Enterprise Information Security Compliance Program
4a. Establish an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you describe specific plans and control objectives that could be adopted to address the known issues. Weight: 5%
Did not submit or incompletely established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you described specific plans and control objectives that could be adopted to address the known issues.
Insufficiently established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you described specific plans and control objectives that could be adopted to address the known issues.
Partially established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you described specific plans and control objectives that could be adopted to address the known issues.
Satisfactorily established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you described specific plans and control objectives that could be adopted to address the known issues.
Thoroughly established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you described specific plans and control objectives that could be adopted to address the known issues.
4b. Establish an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you suggest at least three (3) information security policies that could be developed and practiced within the organization for data security assurance. Weight: 5%
Did not submit or incompletely established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you suggested at least three (3) information security policies that could be developed and practiced within the organization for data security assurance.
Insufficiently established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you suggested at least three (3) information security policies that could be developed and practiced within the organization for data security assurance.
Partially established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you suggested at least three (3) information security policies that could be developed and practiced within the organization for data security assurance.
Satisfactorily established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you suggested at least three (3) information security policies that could be developed and practiced within the organization for data security assurance.
Thoroughly established an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you suggested at least three (3) information security policies that could be developed and practiced within the organization for data security assurance.
4c. Establish an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in
Did not submit or incompletely established an enterprise information security compliance program that addresses the concerns of the board of
Insufficiently established an enterprise information security compliance program that addresses the concerns of the board of directors of the
Partially established an enterprise information security compliance program that addresses the concerns of the board of directors of the
Satisfactorily established an enterprise information security compliance program that addresses the concerns of the board of directors of the
Thoroughly established an enterprise information security compliance program that addresses the concerns of the board of directors of the
which you outline the steps you would take to define the security needs of the organization in terms of duties, staffing, training, and processes. Weight: 5%
directors of the organization in which you outlined the steps you would take to define the security needs of the organization in terms of duties, staffing, training, and processes.
organization in which you outlined the steps you would take to define the security needs of the organization in terms of duties, staffing, training, and processes.
organization in which you outlined the steps you would take to define the security needs of the organization in terms of duties, staffing, training, and processes.
organization in which you outlined the steps you would take to define the security needs of the organization in terms of duties, staffing, training, and processes.
organization in which you outlined the steps you would take to define the security needs of the organization in terms of duties, staffing, training, and processes.
Part 5: Risk Management Plan
5a. Develop a risk management plan in which you describe at least three (3) possible risk management efforts that could be used to assess threats and unknown issues. Weight: 5%
Did not submit or incompletely developed a risk management plan in which you described at least three (3) possible risk management efforts that could be used to assess threats and unknown issues.
Insufficiently developed a risk management plan in which you described at least three (3) possible risk management efforts that could be used to assess threats and unknown issues.
Partially developed a risk management plan in which you described at least three (3) possible risk management efforts that could be used to assess threats and unknown issues.
Satisfactorily developed a risk management plan in which you described at least three (3) possible risk management efforts that could be used to assess threats and unknown issues.
Thoroughly developed a risk management plan in which you described at least three (3) possible risk management efforts that could be used to assess threats and unknown issues.
5b. Develop a risk management plan in which you determine why defining priorities is an important part of the process when enumerating and having efficient risk control measures Weight: 5%
Did not submit or incompletely developed a risk management plan in which you determined why defining priorities is an important part of the process when enumerating and having efficient risk control measures
Insufficiently developed a risk management plan in which you determined why defining priorities is an important part of the process when enumerating and having efficient risk control measures
Partially developed a risk management plan in which you determined why defining priorities is an important part of the process when enumerating and having efficient risk control measures
Satisfactorily developed a risk management plan in which you determined why defining priorities is an important part of the process when enumerating and having efficient risk control measures
Thoroughly developed a risk management plan in which you determined why defining priorities is an important part of the process when enumerating and having efficient risk control measures
5c. Develop a risk management plan in which you suggest specific technical and management controls that could be enacted in order to monitor risks accurately. Weight: 5%
Did not submit or incompletely developed a risk management plan in which you suggested specific technical and management controls that could be enacted in order to monitor risks accurately.
Insufficiently developed a risk management plan in which you suggested specific technical and management controls that could be enacted in order to monitor risks accurately.
Partially developed a risk management plan in which you suggested specific technical and management controls that could be enacted in order to monitor risks accurately.
Satisfactorily developed a risk management plan in which you suggested specific technical and management controls that could be enacted in order to monitor risks accurately.
Thoroughly developed a risk management plan in which you suggested specific technical and management controls that could be enacted in order to monitor risks accurately.
6. 3 references Weight: 5%
No references provided
Does not meet the required number of references; all
Does not meet the required number of references;
Meets number of required references; all references high
Exceeds number of required references; all
references poor quality choices.
some references poor quality choices.
quality choices. references high quality choices.
7. Clarity, writing mechanics, and formatting requirements Weight: 10%
More than 8 errors present
7-8 errors present
5-6 errors present
3-4 errors present
0-2 errors present