Individual Project Unit: Security Policies

profilemrgblaesrqel
it454_ip1.docx

Section 1 - Information Security Management 1

WEEK 1: INFORMATION SECURITY MANAGMENT

Acme Toys, Inc. Network,

[Brian Dennison]

IT454_IP1

1.0 Proposed Organization

Acme Toys, Inc. has been a leading manufacturer of toys. It has a new building which acts as the headquarters and house the company’s departments; marketing, accounting, distribution, sales, manufacturing, IT and the R&D departments. Apart from setting up the departments, the company has set up a big network that has enabled sharing of resources and communication between employees. Inside each department, there are numerous workstations which are connected to the department servers. Also, there is a main server that controls the entire servers. The servers have been delivering support for: Multiple processors, multiuser environment, large memory requirements and support of distributed applications.

In addition, the network should be able to support high-level, multiuser applications that will run simultaneously. The profiles of employees range from a sales executive who is not computer savvy to IT professionals and people in the R&D department who are technology savvy. Due to the diverse user profiles, the company also needs to consider the ease of use of the OS.

The IT department is in the process of planning its security program in order to secure the information of the organization. Although the entire company will be networked, a separate network is required for the R&D department because of security reasons. This department should be deployed with strong security technologies and procedures. In addition, the manufacturing department plans to expand its network within the next six months by fifty percent.

2.0 Principles of Security Management

2.1 People

Since the workforce of this organization consists of employees with different duties and levels of computer usage, then measures should be placed to control the access level of the systems on stored information. For instance, the sales executives are naïve to computer usage. Thus other than being able to have easy of access of information and in a summarized format, they should have less privileges of access. For instance, they should have permission to retrieve information but not modify. Therefore, they are required to act as clients to the servers who request recourses from the servers but with minimal modification to the information. As a result, the network is supposed to have procedures that provide higher abstraction at the pertinent clients.

On the other hand, the IT professionals need to access the network resources in dept. they would thus require more privileges of access to the architecture of the network. They should be able to perform activities such as network monitoring and control, add or remove network accounts and modify group policies of the network.

2.2 Technology

Apart from providing support of communication in the network, the technology applied in the organization should be able to provide security of the network resources. Furthermore, they should be up to date with the current world in order to cater for new issues and threats. (

Most importantly, the R&D department should have an exceptional.ly high security since it requires transaction of information which is very sensitive. The technology should ensure that information exchanges as well business transaction between the departments is trusted in terms of non-repudiation and authenticity.

2.3 Process

The activities pertaining the securing of the network should be well planned. Certain procedures should be deployed to regular check security threats, maintain the network and update servicing. This would ensure that the network safety is not jeopardized out of ignorance. For instance, IT professionals should regular be checking the network like assessing the data traffic to identify any irregularities of data packet transfer.

3.0 Project Management Role

In order to implement security management in Acme Toys, Inc. network, a systematic strategy should be designed. The project should be arranged into stages which range from the evaluation of the network to the implementation of methods for security management.

Apparently, the project management acts a big role of evaluating the current security measures of the organization. This would involve reviewing the existing ‘Information Security Management Policies’ to determine if they are still applicable in all the security areas of the organization. This ensures that all the security loopholes are identified and are ready to be solved

Secondly, the project management acts a role of planning the security measures to be assessed and established. This typically is involved where guidelines and time schedule are provided for the project scope. For instance, risk analysis and management of the network is performed.

Project management plays a role in the implementation of the security policies. In this stage, awareness is created to the network users about the new security policies. They are informed about how to implement such security policies. The awareness ensures that the users feel the responsibility of taking the security measure of the network in their hands. This would thus buffer the security of the network.

After this the evaluation of the network security policies achieved by the project should be performed. This involves carrying out regular internal and external audits of the IT systems. Also, self-assessment and reaction to security occurrences should be observed. Then maintenance is performed to learn and improve the security control measures. All these are the role of project management.

References

Tipton, H. F., & Krause, M. (2003). Information security management handbook. CRC Press.

Information Security Management. (n.d.). Retrieved February 28, 2016, from http://www.tutorialspoint.com/itil/information_security_management.htm