Individual Project Unit: Security Policies

profilemrgblaesrqel
week_2.docx

Week 2

1.0 Data Classification Schema

The information and data assets pertinent to Acme Toys, Inc. needs to be classified based on risks related with stored or processed data. Those of highest risk require the strongest protection level to hamper compromise while those with less risk need proportionately lower protection.

1.1 Public

This include information and data implicitly or explicitly permitted for dissemination to public with no restrictions. The distribution can be done freely without any emergent harm to the Acme Toys, Inc. organization, individuals or affiliates. This security program classify the following data as being public since they are less sensitivity with no unauthorized disclosure;

a. the Acme Toys, Inc. website (which is the main source of advertisement for the products),

b. department general description,

c. opening and closing schedules for departments,

d. toys/products’ catalogue and

e. Press release.

1.2 Internal

This level includes data/information intended for the internal business of the Acme Toys, Inc. This includes data restricted to the specific departments such as the manufacturing and sales departments with legitimate needs. These data are unavailable to parties outside the Acme Toys, Inc. community and have potential impact to the organization but with moderate sensitivity. These data include;

a. employees salary records

b. employees’ departmental user account information

c. sales records on daily basis (only pertinent to users in the sales department)

d. raw materials vendors’ information

e. stock information

f. directory information of employees except whose requesting non-disclosure

g. network transaction logs

1.3 Confidential

This defines data for is highly sensitive and is intended for specific persons with explicit authorization required to access information. The unauthorized of such information would lead to adverse impact on the organization business, such information classified from the organization include;

a. Individuals personal privacy

b. Compliance with the state and federal laws. This is specifically important for the R&D department which is highly secured.

c. Regulations and the vendor’s contracts.

2.0 Existing frameworks

2.1 Network segmentation

The network is divided into segments. Each department has its own network segment or subnet. This would act as a potential framework for implementing the security program into groups of manageable units.

2.2 Client-server Architecture

The fact that the network architecture of the organization is server-based would be advantageous to the implementation of the security program. This is because server-based architecture would enable easy management and centralization of network resources and distributed applications and hence easy implementation of security measures. For instance, if a network group policy is applied to the server, then the policy would apply to this specific

2.3 Separation of sensitive departments

The R&D department has its own independent network different form the other departments. This is a good framework of deploying an independent security policy that is more advanced and aware of the security sensitivity of the delicate R&D department network.

3.0 Need for Management Support

Reliable experience is the backbone for the structuring of security program in the Acme Toys, Inc. Network. Without it, it would be remarkably tiresome and leading to inaccurate development of the security program. The management has been the pioneer to the development of the network architecture of the organization. Mind you, they are the ones who have been using the systems. Therefore, there is need for the management support to be involved in the security program.

3.1 Source of Information

Firstly, the management know the pros and cons of the system and hence acting as an existing source of information which is readily available with less effort. Having used the network day-in-day-out would definitely infer that weaknesses and strengths in the security measures of the organization’s systems are observable. The management may have been receiving complaints and undesirable conditions from the users. Therefore, they would provide a valuable information about the security of the organization’s systems.

3.2 Source of finance

Expenditure guarantee and financing of the security program is in the hands of the management. The budget strap of the organization would determine the amount of effort applied in the program as well as the expanse of the security technology and measures invested in the organization. If the management is willing to invest much in security, then a promising thru output of the security program would be achieved. Hence the need of management support is very crucial for the success of the security program.

3.4 Necessary for evaluation

Making the organization feel that they are part and person of their own security is strikingly important reason as to why the management support is crucial in the security program. This is because it would apparently result to relatively more satisfaction at the completion of the security program than when the task of developing the security program is solely on the shoulders of the experts. This would mean that during the development and implementation of the security program, the management would provide its own opinion and most of the task would be done sweeting the needs of the management.

For instance, an expert may technically feel comfortable with a certain security measure because according to the expert it is efficient in preventing threats. However, the management would fill that the measure is more complicated to handle and it would compromise the ease of use for the organization’s users. Therefore, the management’s view should be importantly be taken into consideration in order to bring up satisfaction of the security program. Thus the management support is crucial for the success of the security program.

3.5 Important in the implementation

Training the workforce on how to use and implement the security program makes the management support very crucial. This is because when incorporated in the development of the security program, the management would provide a good platform in training the rest of the users on configuring the security program. For instance, they would provide good schedule of time for its users to indulge in a training - which can be part time. Also, they can arrange seminars and symposium of bringing awareness of the security program.

4.0 Reporting Methods

4.1 Statistical reporting

The user’s views about the current security conditions of the organization and the viability of the proposed security program would be summarized from the questioner’s findings. For instance, the number of users complaining on cases of security threats of the workstation accounts and servers file directories can be recorded down on paper and the statistics presented to the management. This would indicate the progress of the security program in its stage off gathering information.

4.2 Report Writing

Reports on the progress of the security program can be developed and printed then presented to the management. The reports can be in form of written paragraphs or short notes which describe about how the security program has been advancing. For instance, the list of security equipment, recommendations and feasibility study of the security program can be written in a report format, edited and published for the management to read. Also, the softcopy of the report can be communicated through using email and social media such as Facebook and twitter.

4.3 Direct communication

Direct verbal communication with the management about the security program can be a good way of reporting. The persons involved in the security program can communicate to the management through table sitting, phone call or video conferencing and discuss the progress of the security program.