Policy 5
Please don’t give me a two to three sentence replies. It has to look bulky. At least 8 to 10 sentences. Thank you
Reply needed 1
Health Information
One of Red Clay Renovations main avenues of business is renovating homes to accommodate someone’s medical condition or disability. In order for Red Clay Renovation to accomplish that task we need to collect, store and transmit health information which means we must comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. The Security Rule requires appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information (The Security Rule, n.d.). DHS’s Risk Management Fundamentals will help Red Clay Renovations manage the risk associated with the collection, storage and transmission of protected health information.
Risk Assessment
One of the recommendations in Risk Management Fundamentals is to conduct a risk assessment to identify the internal and external threats to a process or system. Threat is a natural or man-made occurrence, individual, entity, or action that has or indicates the potential to harm life, information, operations, the environment, and/or property” (Security, 2011). The process of collecting health information has numerous internal as well as external threats. One of the external threats is hacker with malicious intent to steal data. One of the internal threats to health information is an employee who mishandles the information or shares the information with someone that should not have access. To threats associated with the collection and storage of health information Risk Management Fundamentals can be used to create new polices and train employees.
Polices and Training
Once a risk assessment is complete we can use Risk Management Fundamentals to create new polices and train employees. To reduce external risk to health information a policy can be created that requires all health information to be encrypted when transmitted, stored or accessed. Encrypted information can only be view by those with the encryption key which means if hacker’s manage to steal the data they will never be able decrypt it. A training program can be developed to reduce the internal risk. The training program will teach employees how to handle protected health information, who can access protected health information and what to do if unauthorized personal gain access to protected health information.
Pros and Cons of Risk Management Fundamentals
Risk Management Fundamentals can be adapted and used in any organization as a risk management strategy. Risk Management Fundamentals has multiple organizational risk categories and has a continues risk management process that starts with the assessment of risk and ends with the evaluation as well as monitoring of implemented alternatives. The cons of Risk Management Fundamentals is that it was created to assess risk related to the security of the country so adapting the doctrine to an organization such as Red Clay Renovations may not be easy. A lot of the terminology is not transferable because of the reason that was just mentioned.
Conclusion
Adopting a good risk management strategy such as DHS’s Risk Management Fundamentals is beneficial to Red Clay Renovations. Risk Management Fundamental will help us develop a strategy to protect our processes such as the collection of health information by reducing internal and external risk. Risk Management Fundamentals can help us develop polices and training to stop hackers and reduce the chances of an employee violating HIPPA Security Rule. Risk Management Fundamentals has some pros and cons but the pros outweigh the cons. To better protect our organizations processes and systems I suggest we use DHS’s Risk Management Fundamentals as a guide to creating our own risk management strategy.
King, V. J. (2016, March 30). Red Clay Renovations. A Case Study for CSIA 413.
Security, D. o. (2011, April). Risk Management Fundamentals. Retrieved from DHS: https://www.dhs.gov/xlibrary/assets/rma-risk-management-fundamentals.pdf
U.S. Department of Health & Human Services. (n.d.). The security rule. Retrieved from http://www.hhs.gov/hipaa/for-professionals/security/
Reply needed 2
Introduction:
Due to the increasing risks associated with cyber security and the growth of cyber-attacks, it becomes necessary for Red Clay Renovations to implement current risk management strategies suggested by federal government branches such as the Department of Defense. As most network penetrations in the past were said to originate due to human error, it becomes necessary to address individual accountability as a risk management strategy along with the concept of culture shift (Department of Defense, 2015). As network users and providers, it becomes the responsibility of individuals to do whatever we can to protect the networks in which we operate (Department of Defense, 2015). In this case, it becomes necessary for the senior leadership of Red Clay Renovations to provide employees with a solid understanding of how their actions impact the company’s operations and what constitutes a successful risk management strategy. This document will assess ways in which the current cybersecurity culture can be transformed by improving individual-specific performances of employees (Department of Defense, 2015). As high-level risks are often communicated to shareholders in an annual meeting and the Annual Report to Investors, it might also be beneficial to discuss the aforementioned criteria that can cause advanced risks to Red Clay Renovations especially as they relate to cyber-attacks within the meeting (King, 2016, p. 6). The purpose of this briefing paper is to utilize the Department of Defense Cybersecurity Culture and Compliance Initiative to understand the focus of culture shift and individual accountability as risk management strategies.
Analysis:
In simple terms, culture shift is defined as “lasting changes to the shared ways of thinking, beliefs, values, procedures, and relationships of the stakeholders” (Personalize Learning, 2013, para. 7). As previously mentioned, Red Clay Renovations is seeing a massive increase in the number of risks it has to deal with on a daily basis. As such, it becomes necessary to address distinct strategies that can be implemented to effectively manage these risks. Red Clay Renovations engages in a three-step risk management process that includes identifying risks, determining the specific impacts of each risk, identifying respective treatments based on risk severity, and implementing an appropriate risk management strategy (King, 2016, p. 6). It is the responsibility of the Chief Information Security Officer (CISO) and the IT Governance Board to identify, assess, and manage risks which is why this paper is directed towards these officials (King, 2016, p. 6).
Culture shift as a cybersecurity risk management strategy refers to “shifting cybersecurity cultural norms from the most senior leaders down to the unit and individual level” (Department of Defense, 2015, p. 2). Every person that operates within Red Clay’s network must understand individual behaviors they must adapt to in an effort to better protect the critical infrastructure of the company. These individual behaviors are classified as operational excellence principles, the first of which is integrity. Integrity is defined as the honest etiquette of employees as it relates to admitting the mistakes that they have made which they believe have had a negative effect on company operations. Reporting these mistakes to their supervisors can help with risk management as training can be provided to all staff members so the inherited mistake does not become a trend in the future (Department of Defense, 2015, p. 3). “When integrity is strong in an organization, people deliberately refuse to compromise security for convenience, and much less time is spent on analysis to find the source of a problem” (Department of Defense, 2015, p. 3). The second operational excellence principle which holds the other principles together is called “level of knowledge.” This knowledge guides the daily behaviors of employees on networks and how they can help mitigate risk (Department of Defense, 2015, p. 3). It also allows employees to recognize when an inaccurate action is taken and to take appropriate measures when it is determined that an implemented procedure is not followed in its entirety (Department of Defense, 2015, p. 3). Training should be provided to individuals so that they are frequently reminded of their role as an employee of Red Clay Renovations. This knowledge helps individuals address threats appropriately based on the situation at hand, thus helping manage risks effectively (Department of Defense, 2015, p. 3). The third principle to implement is procedural compliance as it is necessary for employees to utilize official procedures rather than attempting to perform the same steps in a faster way as this can compromise the security of the network (Department of Defense, 2015, p. 3). Formality and backup is a principle that addresses risk by working as a team and ensuring that the incident is addressed in a timely fashion (Department of Defense, 2015, p. 4). Lastly, employees must possess a questioning attitude so that they look to interpret the source of a threat, what caused the threat, and how they can mitigate the threat, rather than having a mindset that accepts the fact that a threat occurred and there is nothing else to do (Department of Defense, 2015, p. 4).
The aforementioned characteristics serve to be pros of culture shift and individual accountability. Specifically, these advantages are such that changing the norm of cybersecurity culture would help in reducing the number of risks that organizations have to deal with on a daily basis. Mandating that employees sit in training sessions so that they understand the significance of the role they play for the company’s secure operations can better protect an organization’s networks from risk. In essence, pros of individual accountability and culture shift include having a well-established workforce, reducing risks, increasing knowledge levels, increasing client base, improving the company’s reputation, and having adequate staff that support each other in times of success and distress. There can also be cons of culture shift and individual accountability. For example, individuals may feel as though there is too much pressure on them as one minor mistake can allow for the security of the organization to be compromised. Additionally, even though employees are said to inform upper management if they believe they have made a mistake, it might be difficult for higher-level staff to manage the requests appropriately. Hence, insufficient resources, cyber material gap, and the requirement of sufficient investment can also be cons of culture shift and individual accountability (Department of Defense, 2015, p. 6).
Summary:
The culture shift that should occur is such that employees should report the errors they have made as it helps develop a trustworthy and reliable environment, and individuals that have refrained from informing their managers of their mistakes should be penalized (Department of Defense, 2015, p. 3). Furthermore, employees must be provided with security awareness training so that they understand and accept the fact that their presence plays a significant role in the overall security posture of the organization and they must follow certain set standards to mitigate the effects of risks. “On a daily basis, our workforce unintentionally puts mission-critical information systems at risk by treating them as though they are not vulnerable to adversary exploitation” (Department of Defense, 2015, p. 2). Hence, senior management must begin to create a culture shift which looks to reinforce individual accountability as it relates to helping protect Red Clay’s network from risks.
References
King, V. J. (2016, March 30). Red Clay Renovations: A case study for CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu
Personalize Learning. (2013, January 22). Culture shift: When the learner owns the learning. Retrieved from http://www.personalizelearning.com/2013/01/culture-shift-when-learner-owns-learning.html
United States. Department of Defense. (2015, September 28). Department of Defense cybersecurity culture and compliance initiative (DC3I). Retrieved from http://www.defense.gov/Portals/1/Documents/pubs/OSD011517-15-RES-Final.pdf
REPLY 3 Needed
Risk management is the systematic approach to address potential events that could have a negative impact on the overall function of a company or system. When you are conducting an effective risk management process, you are essentially de-risking your project, leading to a more stable and less stressful environment. By identifying and appropriately managing these risks, any unpleasant surprises and barriers can be reduced and other more positive opportunities can be discovered. In addition to resolving issues, risk management can reduce any "shooting from the hip" impulsive reactions because we have these problems have been addressed and plans have been developed and agreed upon. The end result is that you minimize the impacts of project threats and capture the opportunities that occur.
“Risk management is not an end in and of itself, but rather part of sound organizational practices that include planning, preparedness, program evaluation, process improvement, and budget priority development” (Homeland Security, 2011). Also, “standard risk management principles are not designed to promote uniformity or conformity; rather, they offer broad guidance that should be uniquely tailored for the specific needs of each organization” (Homeland Security, 2011). Some might think that having a singular risk management approach for all activities would be easier – why reinvent the wheel, right? However, by using the abundant logical and physical security controls within the risk management process, this allows us to narrow down how our overall infrastructure and any company-based specific systems and projects should be managed.
Here’s a breakdown of some of the overall pros and cons of using the risk management process (Sravani, 2016). Please note that there are several more “pros” versus “cons” line items from the source; the attempt is to highlight the ones that are more beneficial.
Pros Cons
a. Minimization and awareness of risks a. Complex calculations
b. Successful business strategies b. Unmanaged losses
c. Saving cost and time c. Depends on external entities
d. Protecting resources d. Difficulty in implementation
e. Values shareholders e. Potential threats
f. Regulatory compliance
g. Reduces impact and loss
h. Stability of earnings
Most projects are unique in their own way; it depends on location, monetary costs, its function, etc. However, as mentioned prior, using the risk management process provides a baseline of areas that are more or less common across the board. By keeping a basic template of areas to address on hand, this allows any of the decision-makers to have a starting point and immediately move forward with addressing any risks. And while some projects may take time and money to implement initially, any of the items listed in the “pros” column should show that this process will be beneficial to the company in the long run. “Ultimately risk management aims to establish and maintain a holistic view of risks across the enterprise, so capabilities and performance objectives are achieved via risk-informed resource and investment decisions” (MITRE, n.d.).
References:
Homeland Security. (2011). Risk management fundamentals: Homeland security risk management doctrine. Retrieved September 20, 2016, from https://www.dhs.gov/xlibrary/assets/rma-risk-management-fundamentals.pdf
MITRE. (n.d.). Risk management approach and plan. Retrieved September 20, 2016, from https://www.mitre.org/publications/systems-engineering-guide/acquisition-systems-engineering/risk-management/risk-management-approach-and-plan
Sravani. (2016). Advantage and disadvantage of risk management. Retrieved September 20, 2016, from http://content.wisestep.com/advantage-disadvantage-risk-management/
REPLY 4 needed
Risk Management Fundamentals
The purpose of this briefing paper is to help advise the senior leadership and corporate board of Red Clay Renovations on how to properly implement a single risk management process across all corporate operations. The company already uses a formal risk management process that involves risk identification, assessment of each risk’s potential impact, determination of appropriate risk treatments, and implementation of the risk management strategy. The company’s CISO is seeking to make improvements to the current risk management process. This document will provide a common understanding of risk management and the best improvements that can be made to the current framework.
Risk management is a method that allows Red Clay Renovations to apply better-quality information security decisions. DHS Risk Lexicon, 2010 Edition describes risk management as “the process for identifying, analyzing, and communicating risk and accepting, avoiding, transferring, or controlling it to an acceptable level considering associated costs and benefits of any actions taken.” There are various key business practices that Red Clay Renovations should apply to improve their information security. The company must engage risk management with active participation and commitment by its leadership (Homeland Security, 2011). If risk management practices are fully carried out, then all employees will attempt to successfully understand and apply risk management doctrines. All of the risk management approaches performed throughout the entire company does not need to be identical or consistent (Homeland Security, 2011). However, they should be able to properly compare risks throughout the company and ensure that risk management across all corporate operations can be conducted effectively.
One of the aspects of the company’s risk management process that needs to be improved is the company’s security education, training, and awareness (SETA) program. The CISO has determined that the SETA activities have fallen into disuse due to the materials being out of date. Technology is constantly evolving and growing and this means that new risks are always increasing with it. The SETA program will be more successful if it is targeting the delivery of appropriate material to the relevant audience in a manner that is efficient and timely. Employees need to remain up to date on any new risks that are determined a possible threat to the company. A better way for SETA to be effective is to communicate security awareness training via multiple communication channels (Security Standards Council, 2014). This will improve the way individuals remember information that is presented to them.
There are various advantages for Red Clay Renovations adopting a single risk management process across all corporate operations. Risk management, overall, will help the give the company an understanding of the level of crisis during a security incident (Sravani, 2016). A recovery plan already put into place based on the type of risk incident occurring will allow employees to react calmly to the situation. Having an effective plan already in place will also prevent mistakes from occurring during the recovery process and will allow the company to bounce back in a quicker and more effective manner. Along with the advantages for adopting a single risk management process, there are also some disadvantages that may be involved. There is always the possibility of confusion or miscommunication of risk management processes across the company. Having a single risk management process means that all employees from every department need to be on the same page with what to do. This miscommunication may result in causing damaging effects to information security.
Red Clay Renovations will always face information security risks and it is essential that the appropriate strengths be applied to overcome them. It is important to ensure that the SETA program is providing knowledge and tools to employees that are up to date SETA’s communication should be considered a key principle in guaranteeing the success of employee awareness and training. The various pros associated with a single risk management process across all corporate operations ensure that this method can contribute to strengthening the company’s information security framework.
References
Homeland Security. (2011). Risk management fundamentals. Retrieved from https://www.dhs.gov/xlibrary/assets/rma-risk-management-fundamentals.pdf
Security Standards Council. (2014). Best practices for implementing a security awareness program. Retrieved from https://www.pcisecuritystandards.org/documents/PCI_DSS_V1.0_Best_Practices_for_Implementing_Security_Awareness_Program.pdf
Sravani. (2016). Advantage and disadvantage of risk management. Retrieved from http://content.wisestep.com/advantage-disadvantage-risk-management/
Follow-up replies needed 4
HI John,
Your introduction is well thought out and informative. I think it would have been beneficial if you would have placed the name of the DHS doctrine in your introduction. Your mention and elaboration on the principles that are contained within the doctrine adds a nice touch to that section of your briefing. I like how your risk management process section focuses on communication. Without communication a risk management strategy will not be effective. You did a good job of explaining what internal and external risk is. I think placing an example in that section will strengthen your briefing and help the senior leadership as well as corporate board understand risk a little better. Your conclusion is good but I think it would have been stronger if you would have summarized the entire briefing.
Follow-up replies needed 5
Colin, you provided a well-summarized critique of John’s comprehensive post. I agree with you in the sense that in the introduction section of his post, it would have been helpful if he stated the name of the policy at the same time he mentioned the Department of Homeland Security (DHS), as this would have helped senior executives identify the policy that Oluwatobi was referring to. He did a good job in discussing the principles associated with the Risk Management Doctrine provided by DHS as he went into extensive detail with the subject matter. I also liked the fact that he outlined the risk management process in specific steps as this allowed his analysis to be presented in an organized fashion. I agree with you in the sense that he should have provided examples of internal and external risk to allow the audience to better understand what constitutes which type of risk. For example, an internal risk can be classified as “financial stewardship, personnel reliability, and systems reliability,” (Department of Homeland Security, 2011, p. 13) whereas external risks include but are not limited to “natural disasters, malicious activity in cyberspace, and manmade accidents” (Department of Homeland Security, 2011, p. 13). These distinctions help identify the classification of the risk which is the second step in the risk management process. Great job on this critique!
References
United States. Department of Homeland Security. (2011, April). Risk management fundamentals. Retrieved from https://www.dhs.gov/xlibrary/assets/rma-risk-management-fundamentals.pdf
Replies needed 6
1. Why is it necessary for information systems management professionals to understand computer-based numbering systems and data formats?
It is important for IT mangement professionals to understand computer-based numbering, especially now, because most modern computer systems represent numeric values using binary numbering systems- not decimals. By understanding how computers represent numbers, professionals can easily understand the limitations of their arithmetic. Binary numbers also appear everywhere in assembly language programs so it would be necessary for the professionals to fully understand how the system works and how to convert binaries to decimals and vice versa. Furthermore, understanding the data organization of bits, bytes, nibbles, etc. is just as vital for IT professionals.
2. At what level do you think it is important to understand the key numbering systems and data formats? Why?
At all levels it is important to understand these numbering systems and formats because there are many tasks that are done using them..it can be something as simle as basic arithmetic (+,-,*,/) to logical operations. At every level a professional should be knowledgable about the formats so that they can ask the right questions if they are unsure about how to complete a task. For example, CIOs are responsible for the overall technology strategy of their organizations information goals so at their level they should fully understand all numbering systems and data formats, while a security manager may develop programs to keep employees away from security threats. Both of these levels require a great understanding of the number systems and the data formats.
3. Which types/categories of information systems management professionals are likely to use this knowledge as a part of their daily activities? Why?
Different managers such as opertional and functional have varying information needs. Operations are usually managers at lower levels of the organization that are in charge of day-to-day business operations- it is likely that as a part of their daily activities. IT managers and project mangers are in charge of planning, coordinating, and directing computer-related activites as well as implementing computer systems to meet the goals of a company.
Reply needed 7
Information Systems is defined as a set of interrelated components that collect or retrieve, process, store, and distribute information (data) to support decision making and control in an organization. There are 3 activities that organizations need to achieve this. They are Input, Processing, and Output. In this day and age, the computer is heavily relied upon for these activities. Computer systems do not represent numeric values using the decimal system. Instead they use their own numbering system such as binary digit. The data format uses this type of computer numbering system. Computers accept the data, process it, and provide output for the use in the organization in various forms, e.g. reports, graphs, etc.
It is the responsibility of the Information Systems (IS) Managers to implement technology and to direct the work of systems and business analysts, developers, support specialists and other computer-related workers to ensure that the processing of data is efficient and reliable for use by the organization. It is important for all levels of IS managers to understand how computers represent number data formats and the computer numbering systems because it will help them make decisions regarding hardware, software, and storage needs for the organization’s data. The managers will be able to effectively communicate with the IT developers and staff. For example, when a discussion involves bitwords, the IS managers will know that the larger the bitword, the more storage is needed and the longer time it will take to process.
Each level of management needs different types of information to support their day-to-day decision-making needs. The data processed and outputted in the form of reports, charts, and graphs, etc. are valuable tools to get the managers the information they need to make the best strategic business decisions.
References:
Al-Mamary, Y.H, et al. (2014). The Meaning of Management Information Systems and its Role in Telecommunication Companies in Yemen. American Journal of Software Engineering, Vol. 2, pp. 22-25.
Null, L., & Lobur, J. (2015). The Essentials of Computer Organization and Architecture, (4th Ed.). Burlington, MA: Jones and Bartlett Learning.
Williams, B.K., & Sawyer, S.C. (2013). Hardware: The CPU & Storage. In Using Information Technology: A practical introduction to Computers & Communications (pp. 215-220). McGraw-Hill Companies.
Video: Introduction to Binary. Retrieved from https://www.youtube.com/watch?v=vpjhJJQLPq4
Reply needed 8
1 Why is it necessary for information systems management professionals to understand computer-based numbering systems and data formats?
Since information management professionals are part of the IT field, computer-based numbering systems and data formats are the core point of the IT part that one has to know in detail to perform. IS management professionals have to understand the software part of the computer? The computer uses the binary digits to allocate a storage for the units.
The other benefit of understanding computer-based systems management it will help them to know the remaining storage in the system. When IS professionals know in detail, they can direct information to the administrators’, developers and data analytics how many storage they have. Knowing this management will it will expedite the decision software and hardware decisions.
2 At what level do you think it is important to understand the key numbering systems and data formats? Why?
At all levels of the company is important to understand the key numbering systems and data formats. Nowadays many companies are aware that when they hiring, those people who have background knowledge and if they also have the knowledge about numbering systems and data formats. It keeps them more competitive and high demands is also there.
The knowledge of knowing numbering and data formats can also simplify the daily task. Because everyone will have binary knowledge and each bit counts for storage.
3.Which types/categories of information systems management professionals are likely to use this knowledge as a part of their daily activities? Why?
It is the programming part which needs knowledge and experience to keep our daily activities. Programmers are using more numbering and data formats which helps them to know the space remaining.