IMPLEMENTION PLAN
IDI Access Control Project
hill incorporated, llc
Implementation Planning
VERSION HISTORY
|
Version # |
Implemented By |
Revision Date |
Comments |
|
1.0 |
Shawn Harris |
04-19-2016 |
|
|
1.1 |
Shawn Harris |
04-19-2016 |
|
TABLE OF CONTENTS
1 .1 Purpose of Implementation Planning 4
1 .2 Implementation Objectives 4
2.0 Roles and Responsibilities 5
3.1 Roles and Responsibilities 7
Appendix A: Implementation Planning approval 13
1.0 Introduction
Purpose of Implementation Planning
The purpose of the implementation planning is to increase security and security policies for Hill Incorporated, update the hardware and software, better the network. The company wants to develop a multi-year phased approach to have all the sites on the same hardware and software platform. Hill Incorporated is also under pressure for several of its competitors in the logistics industry. The competitive market is driving Hill Incorporated to improve its routes, delivery methods, fleet vehicles, and other facets of its business to increase profits and to reduce cost. Updating the hardware and software will help the company reach the goals that they are trying to achieve.
Implementation Objectives
· Increase security and security policies to Data Center, Brazil, and Poland
· Update all the hardware and software
· All the sites have the same hardware and software platforms
· Better the network
Assumptions
· That we will be on a deadline
· That we will have to stay on budget
· We will have to follow all guidelines and compliance laws
Constraints
· Construction on any of the buildings
· Security Policies that already in place
2.0 Planning
The potential impacts of completing all the designed solution will increase productivity in the company. The internet speeds will increase to a faster and more reliable network. The company will experience less downtime due to the SLA with the Internet Provider. This is ensure the company will stay up and running. The company network security will also increase, which means there is a less of a chance of attackers on the network. All this potential impacts will help the company which in the long run will help the business make more money.
Roles and Responsibilities
Senior Management
· Ultimately responsible for all organizational risk, including information technology (IT)
· Develops strategic initiatives associated with risk and risk management
· Ensures necessary resources are applied effectively
· Assigns and manages risk management responsibilities throughout the organization
· Assesses and incorporates results of risk assessment into decision making
IT Management
· Supports the organization’s information systems
· Responsible for planning, budgeting, and performing information systems security
· Works with individuals and organizations to ensure proper implementation of risk management plan
· Adheres to risk management plan, compliance requirements, and audits
· Develops business continuity, disaster recovery, and incident response plans
System and Information Owners
· Responsible for ensuring that proper controls are in place
· Responsible for changes to the IT systems
· Approve changes to systems
· Understand and support the risk management process
Functional Management
· Responsible for business operations and IT procurement
· Makes trade-off decisions regarding system security
· Enables achievement of risk management goals
Information Security (IS) Management
· Includes IT security program managers and computer security managers
· Responsible for organization’s security program, including risk management
· Introduces appropriate structures and methodologies to help identify, evaluate, and minimize risk
· Acts as consultants, independent of IT; this may be outsourced
Security Awareness Trainers
· Provide training to users of IT systems throughout the organization
· Develop appropriate training materials
· Incorporate risk assessment into training
IT Personnel
· End-user support
· Internal systems and network administration,
· IT physical & logical security administration
· External systems support (Ex: Web administration)
· External security (may include performance checks)
· Staging and test environment administration
Project Manager
· Planning and Defining Scope
· Activity Planning and Sequencing
· Resource Planning
· Developing Schedules
· Time Estimating
· Cost Estimating
· Developing a Budget
· Documentation
· Creating Charts and Schedules
· Risk Analysis
· Managing Risks and Issues
· Monitoring and Reporting Progress
· Team Leadership
· Strategic Influencing
· Business Partnering
· Working with Vendors
· Scalability, Interoperability and Portability Analysis
· Controlling Quality
· Benefits Realization
Team Members
· understanding the purpose and objectives of the project
· ensuring a correct balance between project and non-project work
· working to timescales and within cost constraints
· reporting progress against plan
· producing the deliverables/products to agreed specifications
· reviewing key project deliverables/products
· identifying issues
· identifying risks associated with the project
· working together as a team
· contributing towards successful communication
· contributing towards positive motivation
3.0 Implementing
The Hill Incorporated Implementation Plan provides an outline of activities and steps that are necessary to ensure that the project’s product is available for use by its end-users as originally planned.
Roles and Responsibilities
Senior Management
· Ultimately responsible for all organizational risk, including information technology (IT)
· Develops strategic initiatives associated with risk and risk management
· Ensures necessary resources are applied effectively
· Assigns and manages risk management responsibilities throughout the organization
· Assesses and incorporates results of risk assessment into decision making
IT Management
· Supports the organization’s information systems
· Responsible for planning, budgeting, and performing information systems security
· Works with individuals and organizations to ensure proper implementation of risk management plan
· Adheres to risk management plan, compliance requirements, and audits
· Develops business continuity, disaster recovery, and incident response plans
System and Information Owners
· Responsible for ensuring that proper controls are in place
· Responsible for changes to the IT systems
· Approve changes to systems
· Understand and support the risk management process
Functional Management
· Responsible for business operations and IT procurement
· Makes trade-off decisions regarding system security
· Enables achievement of risk management goals
Information Security (IS) Management
· Includes IT security program managers and computer security managers
· Responsible for organization’s security program, including risk management
· Introduces appropriate structures and methodologies to help identify, evaluate, and minimize risk
· Acts as consultants, independent of IT; this may be outsourced
Security Awareness Trainers
· Provide training to users of IT systems throughout the organization
· Develop appropriate training materials
· Incorporate risk assessment into training
IT Personnel
· End-user support
· Internal systems and network administration,
· IT physical & logical security administration
· External systems support (Ex: Web administration)
· External security (may include performance checks)
· Staging and test environment administration
Project Manager
· Planning and Defining Scope
· Activity Planning and Sequencing
· Resource Planning
· Developing Schedules
· Time Estimating
· Cost Estimating
· Developing a Budget
· Documentation
· Creating Charts and Schedules
· Risk Analysis
· Managing Risks and Issues
· Monitoring and Reporting Progress
· Team Leadership
· Strategic Influencing
· Business Partnering
· Working with Vendors
· Scalability, Interoperability and Portability Analysis
· Controlling Quality
· Benefits Realization
Team Members
· understanding the purpose and objectives of the project
· ensuring a correct balance between project and non-project work
· working to timescales and within cost constraints
· reporting progress against plan
· producing the deliverables/products to agreed specifications
· reviewing key project deliverables/products
· identifying issues
· identifying risks associated with the project
· working together as a team
· contributing towards successful communication
· contributing towards positive motivation
Hardware Changes
Standardize policy of all computers for all location
standardize policy of all ipad & iphone for the management position
Enable remote wipe and require passwords on the phone as well as encryption in case the phone is lost or stolen
all devices of the network will have antivirus
all servers will have complex passwords
phone system upgraded to voip
purchase a t1 line
Software Changes
Unix Operating System Version 11x
UPGRADE LOGICSUITE
Integrate Routesim into shipping software and oracle
change shipping program to infor erp
standardize microsoft office 365 onto all workstations
update all patches for all systems
Security Changes
Alarm system
CCTV surveillance cameras
Security guard
ID badges
Complex Passwords
All server rooms will require a Pin & Token to enter
Security policy in spainsh & English
enable account auditing
develop an account auditing policy
all access request must have a subimission in wiring and approved by management
policy on intra-office romantic
Employee Requirements
All employees of Hill Incorporated will have to attend a security awareness training once a year provided by the IT Team. This training will have all information on security for all users such as password security. The users must be trained on how to avoid social engineering. A lot of attackers use this method to get important information out of users to hack into personal or company accounts. The users will be also taught how to avoid phishing from attackers. Attackers use many methods in order to obtain information from user without their knowledge. This is why all employees will be required to attend this training every year.
Authenication Changes
Pin & Token
Secure VPN for remote login
Single Sign On
Complex Password
Minimum & MAXmIUM PASSWORD History Policy
Network Changes
Upgrade to WPA2
Not broadcast ssid
Hire a technician that has strong Wan and lan background
Deploy 802.1x to only allow only approved computers on the network by mac address
upgrade the network connectivity by using gigabit switches and fiber connection to connect the swtiches
FInd a new isp and develop a sla to ensure less downtime.
create a seprate vpn for the public wifi
Appendix A: Implementation Planning approval
The undersigned acknowledge they have reviewed the Implementation Planning and authorize and fund the Integrated Distributors Incorporated project. The undersigned herby give the project manager the authority to apply the approved level of organizational resources to project activities. Changes to this Implementation Planning will be coordinated with and approved by the undersigned or their designated representatives.
|
|
Date: |
|
|
|
Print Name: |
|
|
|
|
Title: |
|
|
|
|
Role: |
|
|
|
|
Signature: |
|
Date: |
|
|
Print Name: |
|
|
|
|
Title: |
|
|
|
|
Role: |
|
|
|
|
Signature: |
|
Date: |
|
|
Print Name: |
|
|
|
|
Title: |
|
|
|
|
Role: |
|
|
|
Implementation Planning Page 14 of 14