Critical analysis and replies needed
Please don’t give me a two to three sentence replies. It has to look burky. At least 7 to 8 sentences. Thank you
Reply needed 1
john,
I have noticed an increase in website asking for PIN confirmations and never really thought about it before. You explain the two-factor well and how it will protect the users. For me, I would wait to implement the new policy to facilitate discussions. It is vital to understand people who participate in the process inside and outside of government and collect their views of the policymaking (6 P’s of Policy, n.d.)
References
PolicyNL. (n.d.). Retrieved July 13, 2016, from http://www.policynl.ca/policydevelopment/ps.html
Reply needed 2
Michael Hollingsworth,
In the scenario presented and as you mentioned in your first sentence, security breech attempts has been occurring at a rapid pace. Knowing this, I agree that it is very necessary to implement a new policy but I have a contrasting opinion on waiting 90 days for public consultation.
90 days in a environment where attacks are plentiful is a long time to accept risk. I feel in this particular situation, you hit the "on" switch immediately and provide explanation to the public afterwards. If later its been realized that the new policy has been more damaging to business than the potential risk can be, then retract the policy. I think citizens will be more appreciative after the reasoning has been explained than they will be to learn their data was compromised during the 90 day voting period.
R,
E.W.
Reply needed 3
As local government officials there will be times you have to take an immediate action without allowing public comment (Stokes 2013). Due to the complex electronic environment in which we operate the first priority is to protect the safety and security of State information and resources which may require you to take immediate and significant steps to enhance the cybersecurity posture without the consensus from your constituents. When such an action is necessary it is critical to communicate to residents immediately.
Since there has been an increasing number of malicious cyber intrusion attempts against the Service Request System and a new cybersecurity policy had to be implemented which required placing access restrictions to the Online Services Website the communication strategy should include:
1. Modify systems and/or code to accept two-factor authentication
2. Develop website banner notifying users of policy change
3. Develop FAQs for new policy and PII collection and protection of information, and place on website
4. Develop registration form and place on website
5. Place a copy of the new policy on the website
6. Point to privacy policy on website
7. Notify current users of the policy change (utilize phone, email, text, social media, local media outlets, and snail mail) (Bast, Joseph L. 2001)
8. Setup a hotline to assist with reserving meeting rooms and ball fields until the reservation system is fully operational, and to answer questions.
Inform citizens that the new policy requires two-factor authentication (logon/password, PIN) in order to gain access to certain resources, and that they will have to register to obtain logon credentials. The registration form is located on the website; however, personal information will be required to complete the registration. The personal information required is: name, address, cell phone number, email address, data of birth, and the last four digits of the individual’s social security number. The PIN is sent to the cell phone number via text message or email each time an individual attempts to logon to the Service Request system. If the PIN is not entered correctly, the logon will fail and access to services will be denied. Once credentials have been verified access will be granted.
Let them know you are making steady progress and appreciate their patience and support during the transition. Inform them of the hotline that was setup to answer questions, and assist with reserving meeting rooms and ball fields until the reservation system is fully operational. Implementing two-factor authentication to State online resources is on the first step to securing information and assets. Then inform them of other improvements such as the implementation of a centrally managed capability to identify threats and respond to cyberattacks across the enterprise. Remind them that each one of us must do our part to guard against malicious actors and protect the security of the technology we use daily, and to be vigilant, change passwords regularly, apply system patches immediately, beware of email and other scams, cautiously share personal information, and practice good cybersecurity hygiene.
Tell them to visit and review the frequently asked questions section of the website <include web address> if they have anyone questions.
It is not necessary to suspend the implementation of the new policy since it was crucial to implement the changes immediately. The alternative would be to potentially be offline due to a breach which helps no one. Let constituents know that you will accept public comments for 30 days and setup a Town Hall meeting to address any issues raised during the public comment period, and to discuss how the policy can be improved midstream, and identify any unintended consequences or new issues that have arisen (PolicyNL 2013).
References:
Stokes, John (2013), DC Department of Parks and Recreation- National Park Service Fields Closed, Retrieved from: http://dpr.dc.gov/release/national-park-service-fields-closed
PolicyNL (2013), Newfoundland Labrador Canada-PolicyNL Events, Retrieved from: http://www.policynl.ca/policydevelopment/policyevents.html
Bast, Joseph L. (2001), The Heartland Institute- How Do We Change Public Policy? A Brief Overview of The Heartland Institute’s Choices of Tactics and Strategies, Retrieved from: http://explorersfoundation.org/archive/88t1.pdf
Reply needed 4
As internet has taken the predominant position in communication mediums and we are relying more and more on internet to accomplish day to day activities, like online shopping, banking, bill payments, education, and etc. Government is continuously striving to serve their citizen at their door steps, so by every day more services are provided over internet. These advancement has made a new virtual world over internet that we often refers as Cyberspace. Unfortunately, the criminal minds move to this new Cyberspace with us. Criminals have found the ways to break into the information residing and flowing in the Cyberspace like personal information, financial information, businesses information, and etc. In order for government to secure itself and its citizen against these Cyber threats, they have to implement measures to ensure Cybersecurity , in the same way government secure their physical infrastructure and valuables by hiring security guards, using cameras, and implementing other physical security measures.
One of the most common cyber crimes is hacking individual accounts. According to a CNN report, it is estimated in 2014 hacker exposed approximately 110 million Americans users personal information (Pagliery, 2014). In another study and survey conducted by Kaspersky, in 2015 one in four users have one of the their accounts hacked, hacker sending authorized messages from victims account, which some time including malicious link and etc (Kaspersky, 2015). According to same study survey, 32% of victims of hacking knew someone else who also got hacked. Hacker main target was users personal email, social media, and online banking/shopping accounts (Kaspersky, 2015). According to another article posted by New York post approximately 160,000 personal Facebook accounts are hacked per day (Callahan, 2015). All the aforementioned theistic are just a fraction of actual number of incident as most of the incidents goes unreported. However, all the such incidents have one thing common, failure of authentication system, regardless if the hackers just simply break the passwords or got access of victims password any other way.
In order to make authentication more secure government agencies are adopting two factor authentication(2FA) methodology. 2FA simply refers to a process that use 2 different method to positively identify a user (TechTarget, 2015). In most common form two factor can be something user have such as token, and something user know such as a pin number. If any of the two item are missing authentication of user identity is failed. 2FA authentication add an addition layer of security to authentication by making it necessary to have two separate factors for successful authentication , thus making it comparatively secure than traditional methods. However, before the 2FA can be implemented government must collect some personal information that can be used to positively established a user identity, e.g. name, address, cell phone number, email address, date of birth, and the last four digits of the individual's social security number and etc. Government collection of such information cause frustration among some individuals due the amount of information need to be provided, implicating invasion of privacy by collecting too much of individual's personal information.
How can the local government officials convince residents that this "invasion of privacy" (collection of personal information during account registration) is necessary and for their benefits?
While it is not comforting to provide too much personal information to any entity, however there are some occasion it's become a essential to provide such information. For example, if a doctor ask personal health questions and the patient refuse to answer, doctor cannot positively resolves the patient issues. Similarly, if the user of services provided by government do not provide necessary information essential to positively identify users identity on the first place then the system won't be properly implemented. Anyone can use someone else basic information to create an account and use services in the victim name. Without having a proper system for identification will make identity theft even easier and create already big issue even worst. According to Bureau of Justice Statistics(BJS), 7%, 21 million, of American citizens ages 16 and above fall victim of some sort of identity theft in 2014 alone (Harrel, 2015). Therefore, it is necessary for the government to collect enough information to positively identify an individual initially before issuing account for online services and ultimately reduce the number of security incident involve personal account hacking and identity theft.
Should the local government suspend implementation of the new policy for 90 days (180 days?) to allow members of the public to comment on the new policy? Why or Why not?
Government should suspend implementation of 2FA for minimum 90 days, so that public can be educated with the threats and possible impact from the threats. Any public program cannot be completely successful, unless majority public support the program. It will be a constant issue for government to deal with different litigation and lawsuits in regards to invasion of privacy, regardless of the end result. It will be in the favor of government to first get public on board before implementing the 2FA. Even though 2FA ultimately will benefit people, however, it is equally important to educate public with the reasons for the collection of extensive personal information to establish positive identification. While there always be some level of opposition, but if government educate people with aforementioned reasoning mostly people will understand and feel themselves part of the system, and that should be the ultimate goal of every government. Government should use all types of media to educate about the importance and the benefits of 2FA authentication and what need to be done to properly implement it. It is government who issue/associate social security, passport, and other personal information of an individual upon his/her birth, so it make no sense to feel invasion of privacy to share that information back with government to verify individual identity.
References
Harrel, E. (2015, September). Victims of Identity Theft, 2014. Retrieved July 14, 2016, from http://www.bjs.gov/content/pub/pdf/vit14_sum.pdf
Callahan, M. (2015, March 01). Big Brother 2.0: 160,000 Facebook pages are hacked a day. Retrieved July 14, 2016, from http://nypost.com/2015/03/01/big-brother-2-0-160000-facebook-pages-are-hacked-a-day/
Kaspersky. (2015, October 14). Kaspersky Lab reveals 25% of Internet users had an account hacked in 2015. Retrieved July 14, 2016, from https://press.kaspersky.com/files/2015/08/Kaspersky_Lab_Consumer_Security_Risks_Survey_2015_ENG.pdf?_ga=1.220308376.1847950604.1468478662
Pagliery, J. (2014, May 28). Half of American adults hacked this year. Retrieved July 14, 2016, from http://money.cnn.com/2014/05/28/technology/security/hack-data-breach/
TechTarget. (2015, March). What is two-factor authentication (2FA)? - Definition from WhatIs.com. Retrieved July 14, 2016, from http://searchsecurity.techtarget.com/definition/two-factor-authentication
Reply needed 5
1. a) What would have happened if you had not been monitoring the status of the project?
If I as the PM would not have been monitoring the status of the project, I would not have notice the minor and some major changes that could potentially negatively affect the project or cause the project to ultimately fail. You can’t have tasks especially on the critical path go unnoticed for any reason, whether the change is completing ahead of schedule or going over budget on that same task. Every task of a project is important in some way to the success or failure of that project, so it’s all important to monitor and keep track of.
1. b) Suppose that it is crucial that the project complete on time at all costs (e.g., a Mars mission launch window, which, if delayed, will cause the rocket to miss Mars entirely, and for which there is not another launch window for the next 3 years). However, with such a critical project, suppose that changes in actual performance occurred which greatly affected the duration of the project. What could you do about it?
Having a project that must complete on time all cost will require you to first look at what task can be cut or put on hold that won’t affect performance or the overall duration of the project. You will have to refocus your team and make sure that your customer is fully informed on what’s going on and your plan to move forward with the project. With such a limited amount of time to deal with the performance issues, you will more than likely have to bring in some personnel that you know will produce quality work while staying on schedule. However, I wouldn’t totally replace the old team. I would have several smaller teams that consisted of an old and new team member working together as an opportunity for some OJT.
1. c) Would taking these remedial actions depend on when you detected the changes? That is, do they require knowing in advance that there is going to be a slippage or speed-up of a task, or not?
Yes, since my actions involved additional personnel. No, I don’t feel that there would be a requirement for knowing in advance, because it’s not always possible to predict what will happen and when. As the PM it would make sense to have a few individuals on standby when working critical time sensitive protects to call just in case you need them or an emergency comes up and addition personnel or needed. If there was a slippage that I knew I would not able to recover from with my changes, I would definitely share that information with the stakeholders as well as the entire team.
1. d) What else should you do during project execution if such changes made a large change in project duration if there was nothing you could do to remediate it?
While working off of my original plan, I would still be looking into other options that may help to keep the project on schedule without experiencing any performance issues, while keeping other project tasks on scheduled as planned. I would like to think that there is always something that can be done to remediate the situation, whether by you are someone else. So I would use any resources available to me and even call in a favor to try and save the project.
1. e) What else should you do during project execution if such changes made a large change in project duration if you could successfully remediate it?
You have to act fast in whatever it is that you decide to do. It may come to the point where some major changes have to been made and the customer will have to decide what tasks are essential and which tasks can be scraped until a later date, if it comes down to it. You can’t stop pushing just because something becomes difficult or something comes up that you hadn’t anticipated or planned for. You have to work with what you have within the time constraints and budget that have been set. Knocking off smaller pieces of the project at a time, may still allow the project to stay on schedule.
Darnall, R., & Preston, J. (2010). Project Management from Simple to Complex.
Reply needed 6
a) What would have happened if you had not been monitoring the status of the project?
If I had not been monitoring the status of the project, some tasks could have thrown off the timeline and in relation the cost, of the entire project. This could potentially have led to unhappy stakeholders or the failure of the project as a whole.
b) Suppose that it is crucial that the project complete on time at all costs (e.g., a Mars mission launch window, which, if delayed, will cause the rocket to miss Mars entirely, and for which there is not another launch window for the next 3 years). However, with such a critical project, suppose that changes in actual performance occurred which greatly affected the duration of the project. What could you do about it?
In a situation of a critical nature, the Project Manager could speak with the Project Sponsor about adding employees to the project team to make up the time. The other option would be to trim the fat – cut out any non-essential components of the project, in order to complete the critical path on a timeline that would still leave the project viable.
c) Would taking these remedial actions depend on when you detected the changes? That is, do they require knowing in advance that there is going to be a slippage or speed-up of a task, or not?
Yes, these remedial actions would need to take place as early on in the project as possible in order to make the appropriate changes and still leave time to make arrangements for duration correction.
d) What else should you do during project execution if such changes made a large change in project duration if there was nothing you could do to remediate it?
If there was no way to change the tasks to improve duration, more employees would need to be hired in order to complete the tasks faster. If necessary, the new employees could split up with the veteran employees in order to utilize shift work in three eight hour sections.
e) What else should you do during project execution if such changes made a large change in project duration if you could successfully remediate it?
If it were possible to successfully remediate the project, the tasks that went over could be averaged with the tasks that went under in order to determine the true time remaining. The remaining tasks could then be worked simultaneously when possible in order to complete the project by the deadline.
Reply needed 7
a) What would have happened if you had not been monitoring the status of the project?
If I as the PM had not monitored the status of the project, the project would ultimately fail. The project would be over budget, finished out of scope and way behind scheduled which will lead to unnecessary financial burdens and unhappy stakeholders and employees. Obviously the project could finish, but it would be a failure no matter what.
b) Suppose that it is crucial that the project complete on time at all costs (e.g., a Mars mission launch window, which, if delayed, will cause the rocket to miss Mars entirely, and for which there is not another launch window for the next 3 years). However, with such a critical project, suppose that changes in actual performance occurred which greatly affected the duration of the project. What could you do about it?
A good project manager would track changes in the project and determine early if it is due to behavioral affect from project employees. The project manager should set some activities in place that could boost project team morale to help the team work faster and more efficiently. Also, bringing in extra employees with permission from the stakeholders will ensure that the project gets directed back on track and completed within scope, with a minor but critical deviation.
c) Would taking these remedial actions depend on when you detected the changes? That is, do they require knowing in advance that there is going to be a slippage or speed-up of a task, or not?
I believe that project managers should carry very important traits, and an important trait would be to remain flexible and expect the unexpected. This would better prepare the project manager mentally to ensure that changes are enacted immediately when needed. PM's should not be afraid of not knowing, they should be afraid of when the need arises, and not being prepared to make those crucial rash decisions.
d) What else should you do during project execution if such changes made a large change in project duration if there was nothing you could do to remediate it?
If project duration was extended beyond control during the execution phase, the project manager can start looking into actions that will enhance the rate at which tasks are completed, by either hiring more personnel, hiring interns to do some of the foot work for professionals, or even contracting out some of the tasking's to other companies who specialize in certain areas to take some of the work load off of the project team.
e) What else should you do during project execution if such changes made a large change in project duration if you could successfully remediate it?
As a project manager, I can start to gut the project to get rid of unnecessary tasks and cut time back off of certain tasking's to make team members complete them in a shorter time period to remain within the time constraint, but at a rate that will not hurt overall project scope and quality. Another method I as a project manager could use is, to join some tasking's together to be done simultaneously, rather then following a strict waterfall type of method. However, that could involve hiring more help to take some of the workload off of the primary project team.
Reply needed 8
Dmitriy Chekmenov,
The cliché, "You cant satisfy everyone" is beautifully demonstrated in the scenario used for this weeks discussion. Ironically the same thing citizens were irate about is the same thing the policy was put in place to protect them from, the invasion of privacy. If no policy was put in place and the lack of security measures resulted in stolen personal data, the government agency would have suffered the same scrutiny, citizens would have asked why more has not been done to protect their information.
In some cases, depending on the nature of the policy, It may not be much of a risk to suspend policy in order to consider public opinion. In most cases, when dealing with cyber security, it is important to implement policy a soon as possible mitigate the risk of data breech. In order to save face with customers, agency should consider offering reasoning.
R,
E.W.
Reply needed 9
Dmitriy,
References
Children's Privacy. (n.d.). Retrieved July 14, 2016, from https://www.ftc.gov/tips-advice/business-center/privacy-and-security/children's-privacy