Recommend three countermeasures that could enhance the information security measures of an enterprise. Justify your recommendations
Running head: DISCUSSION
DISCUSSION 3
Week 1 Discussion: Cyber Security
(Student’s Name)
(Professor’s Name)
(Course Title)
(Date of Submission)
Discussion 1: Security Countermeasures and Strategic Governance
Recommend three countermeasures that could enhance the information security measures of an enterprise. Justify your recommendations
. Every organization stands a chance of losing its data to dangerous individuals if proper policies are not laid out. The following measures can help to curb the challenge
1. Laying down clear procedural measures. This method involves use of budges by the employees. Each employee is required to use a tag that identifies him or her in order to gain access to a particular room.
2. Physical measures – This involves securing computers in restricted areas. Access to such areas will be restricted by use of either strong door locks, employing security guards at the door or strong burglar proofing of the room
3. Technical methods – For the critical business systems, use of strong biometric authentication is a necessity to regulate people accessing information. With this method is easy to identify who accesses what king of information in which office. Other ways include use of intrusion detection systems like strong firewalls and data encryption.
With these three recommendations employed, an organization laying down clear policies adhering to these reduces chances of crimes that are in rise. Information will have been secured to a greater percentage.
· Propose three cyber security benefits that could be derived from the development of a strategic governance process. Select the benefit you find most important and explain why.
Strategic governance process can benefit cyber security in three major ways. These are;
1. Strategic governance process offers safer and more secure information. This is because a good strategic governance process will emphasize more on safety of data, its integrity, security, data quality, reliability and accessibility.
2. It reduces cost and effective risk management
3. It guarantees fast Business Intelligence Access.
Of the three benefits that cyber security accrues from strategic governance process, the first point is critical to cyber security. This is true considering greatest dangers data can face. Since data is the most expensive asset to an enterprise, its security, integrity and reliability has to be given a top priority.
Reference
Cloud computing: Business benefits with security, governance and assurance perspectives. Technical report, ISACA, 2009.
Discussion 2
· Categorize the roles described by the Information Technology Security Essential Body of Knowledge (EBK), in terms of executive, functional, and corollary competencies. Select two of these roles that you believe enhance the security countermeasures of an organization the most and justify your response.
Executive roles
Essential Body of Knowledge defines the following three executive roles within an organization;
1. Chief Information Officer
2. Information Security Officer
3. IT Security Compliance Officer
Functional Roles
These are the roles related to day-to-day operations In an organization. They include;
1. Digital forensics professional
2. It security Engineer
3. IT systems operation
4. IT security professional
Corollary Competencies
This category supports IT security roles rather than being involved in actual execution. They include;
1. Physical Security professional
2. Privacy Professional
3. Procurement Professional.
The two roles that enhance the security countermeasures most are executive and functional roles. Executive roles are responsible for decision making over security of the information system in addition to provision of finances. Functional roles on the other hand are tasked with the ability to develop and sustain information security system.
· Summarize, in your own words, how the recommendations and framework of the EBK can be adapted to a specific environment. Identify a process that can be used to validate relevant application of the EBK to a specific environment
Recommendations of and frameworks of EBK can be adapted to specific environment my merging them into policies and procedures that can be used to serve as a management framework. This framework can then be subjected to the environment where it is to be applied
The process that can be used to validate relevant application of EBK to specific environment is called Elimination Process which guides on the adoption and implementation of EBK model.
Reference
Y. Shi, K. Zhang, and Q. Li. A new data integrity veri_cation mechanism for saas. In F. Wang,
Z. Gong, X. Luo, and J. Lei, editors, Web Information Systems and Mining, 2010