Need the work in THIRTY HOURS. Write a 6-8 page report(APA format) as stated in the attachments. Make sure you understand the work before bidding.

profileQen-nah
project_1outline_of_enterprise_security_policy.docx

Outline for Enterprise IT Security Policy 1

Introduction

The main goal of this paper is to give an overview of client Enterprise IT Security Policy and its necessities associated with IT Security Policy. This outline is comprise of 15 different Enterprise areas name Access Control, Application Development, Asset Management, Business Operations, Communications, Compliance, Corporate Governance, Customers, Incident Management, IT Operations, Outsourcing, Physical/Environmental, Policies & Procedures, Privacy, IT Security Program Implementation. All fifteen Enterprise areas have some sort of possible threats related to client Enterprise. I have provided two possible solutions to lessen the risks involved within an organization (Karat, 2009).

Overview

The United States Army is the part of armed forces. The primary mission of United States Army is to provide full control on land territory in the incident of war and to support military operations. The United States Army is situated all over the world to defend and support United States. The United States Army is involved wide spread in humanitarian to combative efforts because of its presence in different geographical regions across the globe. There is a strong system that is in place for United Stated Army to communicate all over the world and to carry its missions successfully. The US Army information system infrastructure is made of laptops, computers, servers, satellite phones and other system devices. The United States have an ongoing cyber security programs to protect organization information system resources (Sliman, 2009).

Access Control

Access controls help organization to limit who can access to what information. Even the authorized users with in the United States Army have to use soft and hard token in addition to their username and password to access resources. If employees leave their desks without locking their computers, it can pose a serious threat to organization.

a) Use of System lock after specific time of inactivity.

b) Use of system lock after 5 failed login attempts.

Application Development

Application development is an important process in an organization. It is a process that is used to develop new functionalities and make changes to existing functionalities. Security plays an important role in developing application (NIST Releases Cybersecurity Framework, 2014).If the application has not been tested properly, it can compromise the organization integrity.

a) Use of system and penetration testing will help find the vulnerabilities within the system and to take steps to secure the system.

b) Involving of security team with the development process to ensure all necessary security is implemented during application development.

Asset Management

Asset Management plays an important role in managing organization assets. The organization assets include buildings, data, desktops, laptops, different types of software and platforms (Kerner, 2014). If organization assets are not properly monitored, it can result in compromise organization confidentiality. Use of external system in order to transfer United States Army information can result in integrity issue since data is transmitting through outside system.

a) Use of tracking system to maintain organization inventory

b) Use of cyber security policy when information transmits through external entity

Business Operations

1. The Business operations play important role in business readiness and prioritizing of work within the organization. Business operations come up with plan in the event of natural disaster or data breach (Gymnopoulos, 2005). The supply chain plays vital role in confidentiality and integrity of an organization.

a) Use of supply chain resources for delivering of items

b) Use of developing policy and techniques to communicate with organizational individual to address roles and responsibilities.

Communications

Communication is the key to success for any organization. In the event of any problem, instance response time play a vital role in addressing the issue. The capability of incident response time should be tested in order to judge its capability.

a) Use of instance response testing to improve its efficiency and fill any potential gaps

b) Use online system to handle all the incidents and also keep record

Compliance

Compliance plays an important role in an organization from integrity stands point. If employees do not align themselves with organization compliance policy, it can result in compromise of organization integrity.

a) Use of mandatory compliance training for all employees

b) Use of audit system to make sure employees adhere to organization compliance policy

Corporate Governance

Corporate governance plays an important role in balancing between different departments within the organization. There could be potential risks of integrity and confidentiality issues in absence of corporate governance.

a) Use of corporate Governance policies to create balance within different departments

b) They also conduct IT risk analysis and assessments and then make sure there are solutions in place to mitigate the risks

Customers

Customers play an important role in using organization resources. The United States Army personals use information system to access their employee portal to do certain tasks.

a) Use of secure login when logging into information systems

b) Use of encryption when system involves in transmitting data

Incident Management

Incident management reduces the possibility of losing important personal information and also it stops unauthorized people to access confidential information which they do not have permission to see it.

a) Use of reporting for suspected incident so that damage can be controlled

b) Ensure security of IT systems so that important information can be processed

IT Operations

IT operations deliver facilities to their customers in order to maintain business within an organization. IT operations department keep the business devices in control and it safeguards important information.

a) It should be obeying organization rules and government rules

b) Use of physical security to protect IT devices

Outsourcing

Outsourcing plays an important role in reducing overall organization’s costs. It helps grow organization in different part of world. Outsourcing helps organization to acquire skillful resources but it can also pose serious threat to the integrity if changes are not properly documented.

a) Bring a mechanism to document changes which are being made to company products

b) Different type of testing involve to detect defects

Physical/Environmental

Physical/environmental plays an important role in protecting the company assets physically and it depends on ecological dynamics and physical presence of assets. If organization is lacking proper physical security measures, an unauthorized access leads to compromise on confidentiality.

a) Use of access cards and badges to physically access the organization

b) Use of fire alarms and sensors in all the buildings

Policies & Procedures

Policies and procedures are back bone of an organization. Without following policies and procedures an organization can never achieve success. Policies and procedures ensure that all movements are done within the restrictions established by them.

a) Create a standardized policies and procedures structure which is reviewed by all board members

b) Implement standardized policies and procedures structure to minimize potential problems

Privacy

Privacy is very important in handling information of its employees and customers. Privacy laws should be in place in dealing individuals personal information. Maintaining privacy of employees may result in potential confidentiality risks.

a) Create an organization privacy policy program to ensure privacy in all matters

b) Use of privacy risk assessment to discover potential policy risks and take necessary steps to overcome those risks

IT Security Program Implementation

The main objective of an IT security program implementation is to secure the confidentiality, integrity and availability of an organization system and information. The IT security program refers to execution of overall security program within an organization.

a) Create roles for individuals accessing business IT systems

b) Implement roles to protect IT security program

References

Karat, J., Karat, C., Bertino, E., Li, N., Ni, Q., Brodie, C., & ... Reeder, R. W. (2009). Policy framework for security and privacy management. IBM Journal Of Research & Development, 53(2), 4:1-4:14

Sliman, L., Biennier, F., & Badr, Y. (2009). A security policy framework for context-aware and user preferences in e-services. Journal Of Systems Architecture, 55(4), 275-288. doi:10.1016/j.sysarc.2008.12.001

NIST Releases Cybersecurity Framework. (2014). Computer & Internet Lawyer, 31(5), 27.

Kerner, S. M. (2014). 'Cybersecurity Framework' From NIST Outlines Security Risks. Eweek, 2.

Gymnopoulos, L., Tsoumas, V., Soupionis, I., & Gritzalis, S. (2005). A generic grid security policy reconciliation framework.Internet Research, 15(5), 508-517. 

1