Prepare A Business Continuity IT Security Policy
Running head: IT SECURITY POLICY
IT SECURITY POLICY 4
Enterprise IT Security Policy Outline
IT Security Policy
Introduction
Enterprise IT security is a vital aspect especially when it comes to the protection of information assets. This is more so when these assets can be classified as of strategic national importance, otherwise regarded as critical infrastructure. From historical data, to current operations data, future plans and the systems that house these data, IT security is necessary to prevent them from being compromised by external parties. Enterprise IT security encompasses a wide range of areas in a bid to ensure that the implementation is done holistically without leaving room for potential malicious parties. One of the most important critical infrastructures is that belonging to NASA.
NASA Overview
The National Aeronautics and Space Administration is a federal government agency responsible for the American civilian space flight program and research. Established under the National Aeronautics and Space Act in 1958, NASA has conducted all federally funded civilian space programs and the corresponding research into the field. Apart from the manned and unmanned missions to space, it has also contributed in the building of the International Space Station, and its research has gone on to contribute to a myriad of consumer and industrial applications. The Jet Propulsion Laboratory is a division of NASA based in California that is responsible research and development mostly in robotic spacecraft. The center also operates the agency’s current fleet of robotic spacecraft. The information contained at this facility is vast and of great importance to NASA. This includes information on its current operations, plans for future development as well the trove of ground-breaking research being conducted by its team of scientists. To fully protect this vast information requires the implementation of a robust enterprise IT security policy that fully appreciates the importance of this facility and the necessity for its protection (“The Jet…”).
Policy Outline
1. Access Control
Under the framework core, Access Control is a category that falls under the function of protection. It mostly involves limiting access to cyber resources only to those who have prior authorization to do so. Implementing this will include:
a) Assigning user privileges according to responsibility. A robotics operator would not need to access the future strategic plans to adequately perform their duties.
b) Single User Sign-in for all user profiles. This will prevent multiple users from using the same credentials to access the resources (“Framework...,” 2014).
2. Application Development
Application development can be done to improve existing systems by adding functionalities onto them or building entirely new applications. Whichever reason, it is important that whatever application is being developed that it will not jeopardize the specific network by creating loopholes. The following policies address this.
a) Rigorous application testing before testing. This rids the applications of any and all buds that might otherwise endanger the system.
b) Peer review. This ensures that more people get to appraise the application before it is deployed (“Framework...,” 2014).
3. Asset Management
Asset management is largely about identifying the components of the system and inventorying them according to their functions and their criticality to the operations of the organization. While a communication mechanism within the system is important, it is not as important as the database hosting vast amounts of research on robotics. The exact policies include:
a) Mapping out the data flow. This provides knowledge on how data moves which is important when troubleshooting network problems.
b) Inventorying all hardware and software on a regular basis. This monitoring not only ensures they are up to date but also that none of them is being misused. (“CIS Critical...”)
4. Business Operations
JPL is a division of a federal government agency. As such, its operations are required to conform to the functions set out for NASA under the National Aeronautics and Space Act. Policies include:
a) Strictly sticking to the roles of JPL as set out for it. Doing this ensures that whatever activities being conducted not only adhere to the law but also does not expose sensitive data to those not authorized, even in government.
b) Following the set out official procedures within NASA whenever there is major decision to be made. While some departmental heads in private entities might enjoy total control over their duties, the same can’t be said of a government institution (“Framework...,” 2014).
5. Communications
Communication comes into an enterprise security policy two-fold. This is during the response to a crisis to ensure correcting reporting and coordination of various stakeholders in managing the crisis. It also applies in managing the aftermath of the crisis through public relations exercises. The following are necessary:
a) Establishing clear and coherent reporting mechanisms within the organization. This ensures information is gathered more efficiently.
b) Having a designated communications team. This ensures that any information being released is from a single point and talking in different voices that might create entropy (“Framework...,” 2014)
6. Compliance
Given the sensitive nature of the work being done by the JPL team, it is necessary that all of its employees be vetted under Federal Information Processing Standards 201 also known as FIPS 201. It is only after complying with this are employees then allowed to continue working for the lab. The policies for this are:
a) Knowing and understanding the rules and regulations on cyber-security. This way, no one falls prey to the pitfalls of ignorance and its corresponding mistakes.
b) Coordinate with the Sector Coordinating Councils to review the Cyber-security Framework of the federal government (“Framework...,” 2014)
7. Corporate Governance
These are policies and procedures that need to be undertaken for the management of regulatory and operational requirements. They include:
a) Establishing an information security policy. This will cover all the information assets belonging to the organization.
b) Establishing information security roles and responsibilities for all employees. This should align with their roles internally (“CIS Critical...”).
8. Customers
These are policies are policies that implemented to govern and organization’s relationship with its customers. But all of JPL’s projects are for the benefit of NASA. Still, policies that can be implemented in this regard include:
a) Aligning with the overall NASA IT security policy. It creates organizational uniformity to avoid instances of confusion.
b) Establishing clear communication channels with the rest of NASA that serve to ensure further IT security. E.g. utilizing technology used in the rest of the agency and adopting those developed by others.
9. Incident Management
With admission that incidents can still happen, incident management policies are drawn to guide the organization on how best to mount a response. These include:
a) Developing incident containment processes. This deals with first stopping and incident following by activities that will lessen the effects of the incident.
b) Identifying new risks. Once they are identified and accepted, mitigation measures can then be prepared (“Framework...,” 2014).
10. IT Operations
Policies on IT operation largely deal with the conduct of activities like configuring databases, installing and managing applications, configuring networks and so forth. Policies include:
a) Assigning roles over such activities on the basis of the importance of the activity. The more importance of an activity, the more seniority attached to the role.
b) Establishing a monitoring mechanism. This will provide a continuous assessment of the hardware and software (“Framework...,” 2014).
11. Outsourcing
These policies are about the involvement of outside contractors to carry out functions that would otherwise have been done in-house but are not really central. It includes hardware maintenance among others. Policies are:
a) Subjecting contractors to the same rigorous vetting as employees. This will uphold the level of security already established.
b) Agreeing on an acceptable level of service that will maintain the already established security regime. This ensures that the services do not risk internal systems. (“Framework...,” 2014)
12. Physical/Environmental
These policies govern security in regard to the environment around the system and how it affects it. They include:
a) Taking regard for the environment. This relates to the impact of the system on the environment and how best to reduce it. E.g. efficient energy use.
b) Facility access controls. Largely deals with the security of the data center in regards to physical access of to it. Can involve use of keypad locks and biometric scanners.
13. Policies & Procedures
Policies and procedures govern how specific activities should be conducted. They ensure that regard to security is acknowledged at all times and the necessary steps taken to ensure so.
a) Employee code of conduct. This will obligate employees to always adhere to the set out rules on policies and procedures.
b) Management input. The contribution of the management in the drawing and maintenance of rules and procedures ensures that the overall goals of the organizations can be included (“CIS Critical...”).
14. Privacy
It is important that civil liberties not be trampled on in a quest for security. A right balance can be achieved by involving all stakeholders.
a) Notifying employees on all areas that will be under surveillance. This way, they are always aware of the security accorded to the various areas.
b) Demarcating applicable areas. This keeps the personal and professional aspects of employees separate (“CIS Critical...”).
15. IT Security Program Implementation
These policies dictate how these policies will be carried out within the entire organization. It largely deals with assigning responsibilities.
a) Stating each employee’s responsibility in the implementation process. This promotes clarity as everyone knows what they are required to do.
b) Drawing a security implementation schedule. Not only does it set timelines for completion of given tasks, it also promotes accountability by having those responsible adhere to those timelines (“CIS Critical...”).
Works Cited
Framework for Improving Critical Infrastructure Cybersecurity. (2014). Retrieved January 19, 2016, from http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf
CIS Critical Security Controls. Retrieved January 19, 2016, from https://www.sans.org/critical-security-controls
The Jet Propulsion Laboratory. Retrieved January 19, 2016, from http://www.jpl.nasa.gov/