Running Head: SECURITY PROGRAM 1
SECURITY PROGRAM 3
Three level of security system
Halpert (2011) says that the standard of protection offered to the data available should be based on the sensitivity of the data to the operations of the firm. Data which is for general use should be considered as low sensitivity data. To safeguard the availability and integrity of the data, there is the need to have minimum level security. Low sensitivity data includes the annual financial statements. Data which is required for internal use should be considered as medium sensitivity data. For confidentiality and value retention of the data, there is the need to have authorised persons who can access and clear other use to access them. Medium sensitivity data includes internal projects reports. Data which is strategic should be considered as high sensitivity data. For the strategic purpose of data, persons who can access it are legally authorised. High sensitivity data includes contracts negotiations.
Discuss the need for management support
Management plays a critical role data protection system. According to Halpert (2011), managers help the information technology (IT) department establish the level of security that a kind of data requires. Managers are the persons who sanction spending in firms. Hence, management must be involved in approval of IT projects that will benefit the business through increased data security. That will ensure they factor in software upgrades, new hardware and training programmes for the IT experts.
Reporting ways that are used to inform management of the program state
Use of periodic data reviews on the security of the data is a way informing management of program state (Halpert, 2011). Software capabilities regarding the storage and expiry date are another way. Sporting advanced IT skills in the market is another way of communicating. The new legal, regulatory requirement is another way of communicating. Conducting data backups is another way of telling management the safety of data.
References
Halpert, Ben. (2011). Auditing Cloud Computing: A Security and Privacy Guide. Wiley