Work for BravoBrains ONLY

profileveneco02
answer_to_discussion_reponses_needed.docx

Answer to discussion reponses needed (Full Paragraph 7-8 Sentences)

Discussion 1

Propose three ways to ensure that cooperation occurs across security functions when developing a strategic plan. Select what you believe is the most effective way to promote collaboration and explain why. 

Lessons can be learned from the United States military and its efforts to build “effective partner capabilities” with other nations, many times with frustrating results (Ross, 2016, p. 26). Ross (2016) points out that in the past the U.S. military has judged capability based too much on the partner nation’s tools on hand, and not enough on the “minimal operator training” (p. 26).  In the development and enactment of any strategic plan, collaboration and successful implementation of security functions can only occur if users have the appropriate tools and users know how to use those tools appropriately. The next component necessary to ensure cooperation is “clearly defined objectives” (Ross, 2016, p. 26). This gives everyone a common set of goals, creates a team atmosphere, and avoids frustration that can build up when people feel they are working at cross purposes. A third way to ensure a successful collaboration is to perform a risk analysis that takes into account all of the systemic factors “that could threaten the long-term viability of capability-generation efforts” before launching the strategic plan (Ross, 2016, p. 28). This preemptive measure identifies possible issues so management can address them before problems arise.

Explain what may happen if working cultures are overlooked when developing a strategy. Recommend one way to prevent working cultures from being overlooked.

Trumpolt (2008) asserts working culture has been researched for many years and in depth studies show “that proper recognition of employees in the workplace . . . [yields] significant benefits” for the employees and the employer (n. p.) Employees feel a higher level of job satisfaction when they see their efforts at work are being recognized and appreciated. Employees who feel appreciated are more engaged in their work and employers benefit from employees who are interested in the business and its success (Trumpolt, 2016). To prevent working cultures from being overlooked, an acknowledgment of the importance of working culture should be a part of daily operations, visible in the day-to-day work environment. An employee of the month poster on the breakroom bulletin board would be one example. 

Discussion 2

Provide three examples that demonstrate how security can be instilled within the Systems Development Life Cycle (SDLC). Provide two examples on what users may experience with software products if they are released with minimal security planning.

The following are three examples of security measures that can be instilled within the Systems Development Life Cycle (SDLC):

1 During the Development/Acquisition Phase of the SDLC a risk assessment is done and a security plan is developed. That security plan includes a security categorization so levels of security for different documents based on sensitivity can be established (Radack, 2009).

2 Once system categorization is complete, a baseline of minimum security needs should be established and the necessary security controls acquired and implemented (Radack, 2009).

3 Configuration management (CM) tests and monitoring should be an ongoing part of security measures to document changes or interruptions to the security plan (Radack, 2009).

Software products released with minimal security planning leave the end-users susceptible to numerous threats. Some are relatively harmless, such as a slowing down of their computers; other threats are more malicious, such as spear phishing or other vector attacks.

Suggest three ways that application security can be monitored and evaluated for effectiveness. Choose what you believe to be the most effective way and discuss why.

Application security can be monitored and evaluated for effectiveness at the outset by instituting rules regarding the software allowed to be used within the company. For instance, only software created with embedded security such as Microsoft’s Trustworthy Computing Security Development Lifecycle (or SDL) would be approved for use on company computers. Another company, The Software Engineering Institute (SEI), offers Team Software Process (TSP), which is more than software with built-in security. TSP includes “a framework, a set of processes, and disciplined methods for applying software engineering principles at the team and individual level” (Davis, 2006, n. p.). SEI also takes the end-user into account by including training in “security awareness . . . for developers” (Davis, 2006, n. p.). A third option for application monitoring and evaluation would be the implementation of a Software Security Framework (SSF). This three step framework includes, Governance, Intelligence, and SDL Touchpoints, and is based on core development principles (Davis, 2006). The most effective method of monitoring and evaluating applications would be to use the TSP framework, tools, and training.