IMPLEMENTION PLAN

profilesdotholla
harris_individual_template.docx

IDI Access Control Project

hill incorporated, llc

Implementation Planning

VERSION HISTORY

Version #

Implemented

By

Revision

Date

Comments

1.0

Shawn Harris

04-19-2016

1.1

Shawn Harris

04-19-2016

TABLE OF CONTENTS

1.0 Introduction 4

1 .1 Purpose of Implementation Planning 4

1 .2 Implementation Objectives 4

1 .3 Assumptions 4

1 .4 Constraints 4

2.0 Planning 4

2.0 Roles and Responsibilities 5

3.0 Implementing 7

3.1 Roles and Responsibilities 7

3.2 Hardware Changes 11

3.3 Software Changes 11

3.4 Security Changes 11

3.5 Employee Requirements 12

3.6 Authenication Changes 12

3.7 Network Changes 12

Appendix A: Implementation Planning approval 13

1.0 Introduction

Purpose of Implementation Planning

The purpose of the implementation planning is to increase security and security policies for Hill Incorporated, update the hardware and software, better the network. The company wants to develop a multi-year phased approach to have all the sites on the same hardware and software platform. Hill Incorporated is also under pressure for several of its competitors in the logistics industry. The competitive market is driving Hill Incorporated to improve its routes, delivery methods, fleet vehicles, and other facets of its business to increase profits and to reduce cost. Updating the hardware and software will help the company reach the goals that they are trying to achieve.

Implementation Objectives

· Increase security and security policies to Data Center, Brazil, and Poland

· Update all the hardware and software

· All the sites have the same hardware and software platforms

· Better the network

Assumptions

· That we will be on a deadline

· That we will have to stay on budget

· We will have to follow all guidelines and compliance laws

Constraints

· Construction on any of the buildings

· Security Policies that already in place

2.0 Planning

The potential impacts of completing all the designed solution will increase productivity in the company. The internet speeds will increase to a faster and more reliable network. The company will experience less downtime due to the SLA with the Internet Provider. This is ensure the company will stay up and running. The company network security will also increase, which means there is a less of a chance of attackers on the network. All this potential impacts will help the company which in the long run will help the business make more money.

Roles and Responsibilities

Senior Management

· Ultimately responsible for all organizational risk, including information technology (IT)

· Develops strategic initiatives associated with risk and risk management

· Ensures necessary resources are applied effectively

· Assigns and manages risk management responsibilities throughout the organization

· Assesses and incorporates results of risk assessment into decision making

IT Management

· Supports the organization’s information systems

· Responsible for planning, budgeting, and performing information systems security

· Works with individuals and organizations to ensure proper implementation of risk management plan

· Adheres to risk management plan, compliance requirements, and audits

· Develops business continuity, disaster recovery, and incident response plans

System and Information Owners

· Responsible for ensuring that proper controls are in place

· Responsible for changes to the IT systems

· Approve changes to systems

· Understand and support the risk management process

Functional Management

· Responsible for business operations and IT procurement

· Makes trade-off decisions regarding system security

· Enables achievement of risk management goals

Information Security (IS) Management

· Includes IT security program managers and computer security managers

· Responsible for organization’s security program, including risk management

· Introduces appropriate structures and methodologies to help identify, evaluate, and minimize risk

· Acts as consultants, independent of IT; this may be outsourced

Security Awareness Trainers

· Provide training to users of IT systems throughout the organization

· Develop appropriate training materials

· Incorporate risk assessment into training

IT Personnel

· End-user support

· Internal systems and network administration,

· IT physical & logical security administration

· External systems support (Ex: Web administration)

· External security (may include performance checks)

· Staging and test environment administration

Project Manager

· Planning and Defining Scope

· Activity Planning and Sequencing

· Resource Planning

· Developing Schedules

· Time Estimating

· Cost Estimating

· Developing a Budget

· Documentation

· Creating Charts and Schedules

· Risk Analysis

· Managing Risks and Issues

· Monitoring and Reporting Progress

· Team Leadership

· Strategic Influencing

· Business Partnering

· Working with Vendors

· Scalability, Interoperability and Portability Analysis

· Controlling Quality

· Benefits Realization

Team Members

· understanding the purpose and objectives of the project

· ensuring a correct balance between project and non-project work

· working to timescales and within cost constraints

· reporting progress against plan

· producing the deliverables/products to agreed specifications

· reviewing key project deliverables/products

· identifying issues

· identifying risks associated with the project

· working together as a team

· contributing towards successful communication

· contributing towards positive motivation

3.0 Implementing

The Hill Incorporated Implementation Plan provides an outline of activities and steps that are necessary to ensure that the project’s product is available for use by its end-users as originally planned.

Roles and Responsibilities

Senior Management

· Ultimately responsible for all organizational risk, including information technology (IT)

· Develops strategic initiatives associated with risk and risk management

· Ensures necessary resources are applied effectively

· Assigns and manages risk management responsibilities throughout the organization

· Assesses and incorporates results of risk assessment into decision making

IT Management

· Supports the organization’s information systems

· Responsible for planning, budgeting, and performing information systems security

· Works with individuals and organizations to ensure proper implementation of risk management plan

· Adheres to risk management plan, compliance requirements, and audits

· Develops business continuity, disaster recovery, and incident response plans

System and Information Owners

· Responsible for ensuring that proper controls are in place

· Responsible for changes to the IT systems

· Approve changes to systems

· Understand and support the risk management process

Functional Management

· Responsible for business operations and IT procurement

· Makes trade-off decisions regarding system security

· Enables achievement of risk management goals

Information Security (IS) Management

· Includes IT security program managers and computer security managers

· Responsible for organization’s security program, including risk management

· Introduces appropriate structures and methodologies to help identify, evaluate, and minimize risk

· Acts as consultants, independent of IT; this may be outsourced

Security Awareness Trainers

· Provide training to users of IT systems throughout the organization

· Develop appropriate training materials

· Incorporate risk assessment into training

IT Personnel

· End-user support

· Internal systems and network administration,

· IT physical & logical security administration

· External systems support (Ex: Web administration)

· External security (may include performance checks)

· Staging and test environment administration

Project Manager

· Planning and Defining Scope

· Activity Planning and Sequencing

· Resource Planning

· Developing Schedules

· Time Estimating

· Cost Estimating

· Developing a Budget

· Documentation

· Creating Charts and Schedules

· Risk Analysis

· Managing Risks and Issues

· Monitoring and Reporting Progress

· Team Leadership

· Strategic Influencing

· Business Partnering

· Working with Vendors

· Scalability, Interoperability and Portability Analysis

· Controlling Quality

· Benefits Realization

Team Members

· understanding the purpose and objectives of the project

· ensuring a correct balance between project and non-project work

· working to timescales and within cost constraints

· reporting progress against plan

· producing the deliverables/products to agreed specifications

· reviewing key project deliverables/products

· identifying issues

· identifying risks associated with the project

· working together as a team

· contributing towards successful communication

· contributing towards positive motivation

Hardware Changes

Standardize policy of all computers for all location

standardize policy of all ipad & iphone for the management position

Enable remote wipe and require passwords on the phone as well as encryption in case the phone is lost or stolen

all devices of the network will have antivirus

all servers will have complex passwords

phone system upgraded to voip

purchase a t1 line

Software Changes

Unix Operating System Version 11x

UPGRADE LOGICSUITE

Integrate Routesim into shipping software and oracle

change shipping program to infor erp

standardize microsoft office 365 onto all workstations

update all patches for all systems

Security Changes

Alarm system

CCTV surveillance cameras

Security guard

ID badges

Complex Passwords

All server rooms will require a Pin & Token to enter

Security policy in spainsh & English

enable account auditing

develop an account auditing policy

all access request must have a subimission in wiring and approved by management

policy on intra-office romantic

Employee Requirements

All employees of Hill Incorporated will have to attend a security awareness training once a year provided by the IT Team. This training will have all information on security for all users such as password security. The users must be trained on how to avoid social engineering. A lot of attackers use this method to get important information out of users to hack into personal or company accounts. The users will be also taught how to avoid phishing from attackers. Attackers use many methods in order to obtain information from user without their knowledge. This is why all employees will be required to attend this training every year.

Authenication Changes

Pin & Token

Secure VPN for remote login

Single Sign On

Complex Password

Minimum & MAXmIUM PASSWORD History Policy

Network Changes

Upgrade to WPA2

Not broadcast ssid

Hire a technician that has strong Wan and lan background

Deploy 802.1x to only allow only approved computers on the network by mac address

upgrade the network connectivity by using gigabit switches and fiber connection to connect the swtiches

FInd a new isp and develop a sla to ensure less downtime.

create a seprate vpn for the public wifi

Appendix A: Implementation Planning approval

The undersigned acknowledge they have reviewed the Implementation Planning and authorize and fund the Integrated Distributors Incorporated project. The undersigned herby give the project manager the authority to apply the approved level of organizational resources to project activities. Changes to this Implementation Planning will be coordinated with and approved by the undersigned or their designated representatives.

Signature:

Date:

Print Name:

Title:

Role:

Signature:

Date:

Print Name:

Title:

Role:

Signature:

Date:

Print Name:

Title:

Role:

Implementation Planning Page 14 of 14