i just need second part of the proyect the MS Project

profilevazuez5
review_of_google.docx

REVIEW OF GOOGLE’S CYBER SECURITY POLICY

NAME

INSTRUCTOR’S NAME

COURSE TITLE

DATE

Introduction

Google is a global leader in technology and is the most popular search engine in the world. Its technologies mostly rely on cloud computing offering services like Gmail, Google Docs, Google Calendar, Google App Engine, Google Cloud Storage, You tube among many others.

Users are able to access these technologies from many devices ranging from desktop computers and mobile phones. These services can also be accessed from almost any location on earth. These services are also having many users who share information that is confidential and sensitive in nature.

As a result there presents itself a great need for the protection of this information on a real time basis.

Cyber Security Policies

The Google cyber security policies cover a wide array of topics that touch on security. These policies must be adhered to by each and every employee in the organization. These policies cover topic such as accounts, data and physical security among other internal sensitive information.

The internet crimes are extremely dynamic and change very rapidly. This calls for the need to periodically train the staff on how to handle data, use the internet safely, and operate from remotely safe locations among other uses like safe use of social technologies.

In line with keeping the policy requirements that are in place Google has various departments that deal with security concerns of various natures and even how to deal with breaches or suspected breaches to help mitigate their overall adverse effects that may be experienced by the business.

These departments include:

1. Organizational Security

Several teams focus on information security, global security auditing and compliance. In addition to these is a physical security team that protects the hardware. The information security team establishes the security perimeter and maintains the internal defensive systems in the organization. They also develop internal processes for security review and customized security infrastructure. The global security auditing and compliance team ensures that there is a statutory and regulatory compliance on a global scale. The physical security team is charged with ensuring that the organization’s premises are well guarded.

2. Data Asset Management.

Google’s data assets include customers, end user assets and corporate data assets. For the personnel handling the data there is compliance to procedures and guidelines by the security team.

3. Access Control

This deals with authentication and authorization controls that are designed to keep away unauthorized personnel from accessing data assets. This includes identification of users and employees when using Google’s resources. Approvals are limited to one’s status according to job description and type of user.

4. Physical and environmental security

This covers physical security, environmental controls, power, climate and temperature, and fire detection and suppression. The policies and regulation are to provide a secure environment within which infrastructure is housed away from unauthorized personnel.

5. Infrastructure security

The security policies are made to deal with threats and management of infrastructure management procedures. Activities like malware prevention, monitoring, vulnerability management, incident management; network security, transport layer security and operating system security are covered under infrastructure security.

6. System development and Maintenance

The implications of the Google applications, systems and services throughout the project’s entire life cycle are secured appropriately with risks and concerns being identified. The security approach is adaptive and evolves with future threats.

7. Disaster recovery and business continuity

Where the damage has already occurred mitigation has to be done so that service delivery is not interrupted. Google implements disaster recovery programs for all its data centers on a regular basis.

Having cyber security policies is not only beneficial for any organization, but has now become a compulsory addition into the management of an organization as a result of the many cyber related threats that exist with the growing need to incorporate technology in businesses. Where this need is neglected the consequences may be severe to irreparable for any business.

Some of the consequences associated with lack of sufficient cyber security measures include:

· Loss or access to confidential customer information in unauthorized hands like in the case of bank account details as was witnessed with Chase bank and many other banks around the world.

· Paralysis of entire organizational operations and access to government websites has been witnessed. This literally brings operations to a halt on a large scale thereby having serious consequences on economies.

· Another common practice is the theft of identities especially to customers of social media platforms. This creates a situation where one loses control to their own profiles and transactions can take place in their identity without them being aware of it.

· Irreparable damage can occur to reputable businesses as in the case of Target breach where the company was forced to pay up to $148 million for compromising customer records. Even if the a company is able to settle its legal issues the consumer confidence might in some cases be unable to be restored.

· For large organizations, where policies on cyber security are not effective, there is a likelihood of chaos in the operations of the organization especially in gray areas where overlaps may occur. For example, certain information may have relevance to more than one department. As such this information is vulnerable to falling in the wrong hands.

It is therefore imperative for all businesses to invest in the security of its cyber related activities and the need is even greater as the magnitude of the business impact becomes great.

Reference

Google’s approach to IT security. A Google white paper

http://investor.google.com/corporate/code-of-conduct.htm

http://www.google.com/intl/en/about/corporate/company/security.html.