Policy 4
Please don’t give me a two to three sentence replies. It has to look bulky. At least 8 to 10 sentences. Thank you
Reply needed 1
Introduction:
The responsibility of a chief information security officer (CISO) is such that they own the accountability for the successful implementation of the security strategy for the company they work for (Cho, 2003, p. 5). CISO’s must also improve security policies as the need to update them arises based on the increasing cyber-threats within the security field (Cho, 2003, p. 5). One such security policy that requires modification is the company’s social media policy. Specifically, this policy should be altered so that field office employees and managers, including Reality Media Services staff are restricted in what they post about Red Clay Renovations and the services that are provided at each field office (Dorrian, 2016a, para. 2). Information about Red Clay Renovations as it relates to social media use is such that the company acquired “Reality Media Services,” which is an organization that creates video files for any and all projects initiated by Red Clay Renovations (Dorrian, 2016b, p. 4). This relates to social media use as Reality Media Services “provides Web design and social media services for Red Clay Renovations to promote its services” (Dorrian, 2016b, p. 5). The purpose of this briefing statement is to develop a strategy which would help the CISO communicate the newly developed policy to the intended audience, which in this case are the company’s field office employees and managers.
Analysis:
The current social media policy does not have many limitations, in that it permits its employees to essentially communicate whatever they want about the field office to the public. However, miscommunication not only puts the company’s reputation at risk but it also has the capability to make the Chief Information Security Officer look bad as it is their responsibility to update security policies as needed. This is why the current social media policy will be altered so that field office employees and managers know their limitations in providing company related information to the public. The new social media policy will also educate employees and managers on good security practices so that they do not expose the company to additional risk (IDG Enterprise Marketing, 2016). However, the Chief Information Security Officer (CISO) should ensure that their social media limitations do not invade the right of individuals as it is protected by the government (Meister, 2013, para. 6). For example, “according to a January ruling by the National Labor Relations Board, it’s legal to vent about your employer (on a personal account) if you’re speaking on behalf of a group and are looking to improve your job conditions” (Meister, 2013, para. 5). However, the CISO can limit field office employees and managers from venting about their respective employers if they are doing so from a company-owned social media account.
It will also be helpful if the new social media policy included the negative effects inappropriate dialogue could cause for the individual posting from the account. For example, a popular British entertainment company named HMV had a Twitter account for their company profile that was managed by their Community Manager (Meister, 2013, para. 2). The company was going through downsizing which means they began to lay off individuals, one of which was the community manager that was running the company’s account (Meister, 2013, para. 2). That being said, it is obvious where this story goes next. The community manager tweeted things like “Mass execution, of loyal employees who love the brand,” “We’re tweeting live from HR where we’re all being fired! Exciting!” and “Just overheard our Marketing Director (he’s staying, folks) ask ‘how do I shut down Twitter?” ‘#hmvXFactorFiring” (Meister, 2013, para. 2). In this case, the company’s ex-community manager fails to realize that this will also damage their reputation as the next job they would like to interview for will see their tweets and most likely deem them unfit for the job (Meister, 2013, para. 7).
To step aside from all the rules regarding the use of social media on company accounts, it is also necessary to address the different strategies that the Chief Information Security Officer can use which would help his new social media policy reach the audience in its entirety. There are distinct strategies that can be utilized, however, I personally believe the most effective is to have a face-to-face meeting with the field office employees and managers in which they are given the ability to question the policy being implemented (Dorrian, 2016a, para. 4). I think forcing employees to perform certain actions without explaining the reasoning not only draws the employees away from performing the action but it also does not establish a sense of trust between both individuals. I believe this is a convenient way in which the CISO can effectively and efficiently get his point across and maintain the attention of the field office staff. Additional strategies include but are not limited to printing copies of the policy and placing them on bulletin boards so employees can view them in their work environment, sending an e-mail of the policy to respective personnel, and providing field office staff with a link to a website in which they can view the social media policy and its requirements so that they can reference that before they post something from the company’s social media account (Dorrian, 2016a, para. 4). The CISO can also allow staff to participate in social media training and awareness programs so that they can “encourage employers to use new technology for team-building and for collaborating across geographies, while making clear what the appropriate limits are to that use” (Meister, 2013, para. 12).
Summary:
In her article regarding the content of social media policies, Jeanne Meister discusses a 5R strategy for what to post and what not to post on social media. These 5 strategies are not a comprehensive list but they are a good way to initiate the breakdown of the policy. The first R is reason which essentially refers to “reasonable” etiquette; next is that the individual posting must “represent” themselves so that it is evident who is providing the fact about the company; employees/managers would also have the “responsibility” of ensuring that their discussion topics are accurate and that they do not post anything illegal; employees must also “respect” themselves and others when posting on social media; lastly, a best practice when using social media is for employees/managers to practice “restraint” as they should always reread what they intend to post on social media before posting it (Meister, 2013, para. 15). While the Chief Information Security Officer should not in any way attempt to restrict field office employees or managers from using social media for their own personal life, they do have the ability to limit the way in which those employees or managers broadcast information about Red Clay Renovations publicly (Meister, 2013, para. 11).
References
Cho, M. (2003). Mixing technology and business: The roles and responsibilities of the chief information security officer. Retrieved from https://www.sans.org/reading-room/whitepapers/assurance/mixing-technology-business-roles-responsibilities-chief-information-security-of-1044
Dorrian, J. (2016a). Communicating policies to employees and managers in CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu
Dorrian, J. (2016b). Red clay renovations in CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu
IDG Enterprise Marketing. (2016, February 16). The CIO/CSO imperative: Strategic conversations, collaborative partnership & technology involvement. Retrieved from http://www.idgenterprise.com/resource/blog/the-ciocso-imperative-strategic-conversations-collaborative-partnership-technology-involvement/
Meister, J. (2013, February 7). To do: Update company’s social media policy ASAP. Retrieved from http://www.forbes.com/sites/jeannemeister/2013/02/07/to-do-update-companys-social-media-policy-asap/#5984522da10d
Reply needed 2
Eric Carpenter,
The ocean is large and can be broken down by location for example, North and South specific Ocean, and North and South Atlantic Ocean. The one thing each body of water has in common is they all combine to form one ocean. Red Clay Renovations has field offices in Baltimore and Philadelphia. Even though they bear Red Clay Renovations name, they both market and offer different services on social media at each field office. The purpose of this briefing is to present you with a strategy to restrict the freedoms that field offices have previously had with respect to establishing and managing their own branded social media accounts for marketing and communications about the services offered at each field office.
Social Media Management
A properly managed social media account can cause followers to leap from 61,500 to 73,350 (Meister, 2013). Reality Media Services (RMS) currently manages Red Clay Renovations social media account with a five person team who also does video production. It would be beneficial to have RMS manage the field offices social media account as well. There are currently nine out of 10 U.S. companies active on social networks (Holmes, 2015) and by having a single team manage all social media accounts the information will be uniform, clear as well as concise and not confuse customers as to how many Red Clay Renovations there are. Each field site can send RMS the special services that they offer and they can still be posted on the website. If a customer is requesting one of those special services then the request can be forwarded to the field office who will make contact with the customer at a later time.
Policy
A social media policy can do more than avert problems it can also raise the awareness of a brand (Henricks, 2011). Once the policy is created it must be printed and distributed to each field site. Once the field office receives a copy of the policy each employee at the site must sign for a copy of the policy stating they understand and will comply. Signed copies of the policy will be kept on file until an employee either retires or quits. If an employee violates this policy then they will face disciplinary actions.
Conclusion
To appear as one company RMS should manage all social media accounts. Field offices will still be allowed to advertise their special services but only after making a request through RMS. Once a social media policy is created, all employees will receive a copy which they must sign for. Red Clay Renovations is one organization, and by combining all the social media accounts our customers will see us as that just one body just like the ocean.
Henricks, M. (2011). Why You Need a Social Media Policy . Retrieved from Entrepreneur: https://www.entrepreneur.com/article/217813
Holmes, R. (2015). 5 Trends That Will Change How Companies Use Social Media In 2016. Retrieved from Fastcompany: https://www.fastcompany.com/3054347/the-future-of-work/5-trends-that-will-change-how-companies-use-social-media-in-2016
Meister, J. (2013). To Do: Update Company's Social Media Policy ASAP. Retrieved from Forbes: http://www.forbes.com/sites/jeannemeister/2013/02/07/to-do-update-companys-social-media-policy-asap/#6a56c541a10d
REPLY 3 Needed
Introduction
Red Clay Renovations currently handles and stores an immense amount of intellectual property and customer’s personal data. Many of the jobs that the company under takes require personal information to be collected and stored. This information is classified as Personal Health Information and Personal Identifiable Data. Red Clay uses the IS0 27001 standard however it has not been fully implemented within the company. It is pivotal to implement security standards within all levels of the company.
What is ISO 27001
In the world of information security standards and structure are very important. The company’s current Information Security approach is inadequate. Utilizing the full guidance of ISO 27001 will improve our approach and mitigate risk. ISO 27001 is a set of guidelines for an organization to improve their Information Security Management System (ISO/ISC, 2013). These guidelines can be tailored to fit the needs of Red Clays security approach.
Why is ISO 27001 Necessary?
The need for Information System security controls have never been more prevalent then today. A high end hotel in Nashville recently revealed that its point of sale terminal had been comprised for the last three years (Kirk, 2016). Red Clays Current Information Security posture could expose us to the same risk. However, if the proper standards are implemented risk can be mitigated. There are multiple moving parts to a successful information security program. Alan Calder an expert in the ISO standards field stated that successful technology alone cannot ensure information security (2013). The requirements outlined in ISO 27001 will assist in developing an effective information security program.
ISO 27001 Requirements
There are several requirements to be fully certified ISO 27001compliant. These requirements include a solid information security policy, employee competence, security risk assessments, evidence assessments and management involvement (ISO/ISC, 2013). These requirements are designed to allow companies the ability to tailor their policies to meet there needs. Our needs would cover our local and remote sites as well as any subsidizers.
Summary
Red Clays current information security posture is in need of revision. This revision should include measures found in the ISO 20071 standards. These measures must be integrated into every policy and information security training. A solid Information Security program will reduce risk by putting standard procedures in place.
References
Calder, A. (2013). Information Security & ISO 27001. Retrieved September 6, 2016, from http://www.itgovernance.co.uk/files/Infosec_101v1.1.pdf
ISO/IEC 27001:2013 Information technology — Security techniques — Information security management systems — Requirements. (2013). Retrieved September 6, 2016, from http://www.iso27001security.com/html/27001.html
Kirk, J. (2016, September 5). Nashville Hotel Suffered POS Breach for Three Years. Retrieved September 6, 2016, from http://www.databreachtoday.com/news
REPLY 4 needed
Red Clay Renovation current social media policy is in need of revision. Currently our social media services are provided
by our Red Clay Services media division. The policy that currently in effect allows for the field offices to control much of
there on social media content. It is important that Red Clay Renovations continues to allow creativity and freedom within
our workforce. However, a recent Forbes article stated employers must train employees in the smart way to utilize social
media (Meister, 2013). We intend to train our employees on proper social media usage and to centralize our social media
operations.
Red Clay respects the opinions and input from all our employees. There will be office visits with question and answers
periods for all employees. It is our intention to communicate to the field offices the importance of brand consistency on
social media (Agrawal, n.d.). Developing a coherent brand consistency will make it easier for our customers to indentify
what services we provide.
Our change of policy will ensure that all employees still have input into Red Clays future. Our new policy will help us to
better identify what costumers really want. Social media experts state that we must also pay attention to what social
media sites customers use and how we measure their success (Brooks, 2010). Those outcomes are better measured by
centralized a social media team.
Red Clay Renovations and our subsidiaries intend to be the leader in social media promotion. We can only reach that
goal with everyone’s assistance. The leadership will continue to communicate policy change ideas to all our employees.
Continued input on these policy changes are welcomed.
References
Argawal, A. (n.d.). How to Keep Your Branding Consistent on Social Media. Retrieved September 12, 2016, from http://www.inc.com/aj-agrawal/importance-of-consistent-branding-across-social-media-platforms.html
Brooks, R. (2010, September 08). How to Develop a Social Media Content Strategy. Retrieved from http://www.socialmediaexaminer.com/how-to-develop-a-social-media-content-strategy/
Meister, J. (2013, February 07). To Do: Update Company's Social Media Policy ASAP. Retrieved September 12, 2016, from http://www.forbes.com/sites/jeannemeister/2013/02/07/to-do-update-companys-social-media-policy-asap/#6a40f086a10d
Follow-up replies needed 4
John,
I like how your discussion was succinct and to the point. I also really liked your introductory paragraph as you stated the significance of the form of communication when addressing a new policy to employees and managers. However, I noticed one weakness within your introduction that I would like to point out. Specifically, I noted that you did not directly state the purpose of your post which is not only a necessity for a briefing statement but it also helps readers understand what the following sections of your discussion will consist of (Dorrian, 2016, p. 1). For example, you could have stated that this discussion will present strategies in communicating a new social media policy to field office employees and managers. In other words, although you mentioned the significance of communication within your introductory paragraph, I think it would have been clearer if you explicitly stated the point of your post as well.
Another improvement I would like to suggest is that I think you should have said which communication strategy you believe is the best fit for Red Clay Renovations. In other words, although you mentioned a number of different strategies, you didn’t exactly state which one you think should be used to communicate the new social media policy to field office employees and managers. Can you please tell me which strategy you believe would be the most effective? I see you mentioned that e-mail is a cheap way of getting the information across to the board; however, I personally do not think many employees would even bother to read an e-mail consisting of several pages of policy documentation. In my opinion, the best strategy is to call a face-to-face meeting in which field office employees and managers would be able to ask questions. Lastly, I see that you are missing a link for the second citation that you provided, by Jones. Per the syllabus, we are to use APA formatting and per the rubric, we are to cite references with no errors. After researching the APA formatting rules within UMUC’s website, I found that e-books found on the free web require the URL of the source (University of Maryland University College, 2016). In summary, I think you did a nice job as you addressed most of the requirements present for the discussion. However, I believe the minor discrepancies that I pointed out will improve the overall content of your post.
References
Dorrian, J. (2016). Expanded explanation for discussion question responses in CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu
University of Maryland University College. (2016). APA citation examples. Retrieved from http://www.umuc.edu/library/libhow/apa_examples.cfm#e-books
Follow-up replies needed 5
John,
I think adding some specificity about the implementation of distributing the policy would benefit as well. You are right. There are recommended uses, but the briefing statements intent is to declare a course of action. Give the executives an already completed method, and then get their approval. Then you can move on the intent of the briefing statement. You provided a very thorough critique. Another student used and overview and analysis split in his briefing statement. I don't think that is necessary, but defining the purpose of the policy, and then the intended methodology for distribution would clarify these briefing statements.
Respectfully,
Chris Lambert
Follow-up replies needed 6
Hello john,
I agree the best approach to knowing what is needed in your new computer is to recognize what you will be doing with it. The average person choosing a personal computer seems to always get sucked in by a sales person and buys more then what they really need. I’ve seen people that are doing nothing more than simple spread sheets and email have super computers that were made for gamers and people that are doing lots of graphics wonder why they are unable to run function they need, all because they don't have enough RAM, a big enough processor or something of this sort. I believe the top choses for the internal system components are RAM, hard disk,and I/O. Many people may not realize until after the purchase the externals they need/or want to hook up to the computer. This is why I add I/O to the list of three.
-Kandy Wilson
Follow-up replies needed 7
Hello John (and Group A),
Drisk drives, processing devices, and power supply are all important components that work together. One of the hardest issues to resolve from a support point is "complete slowness" since so many different things can cause the issue which you described in your post.
Follow-up replies needed 8
John,
I’m glad to see you mentioned the power supply. It is an important competent of the computer. Like you said in your post, the power supply ensures optimal temperature and supplies power to the computer. The power supply coverts alternating current (AC) from the wall electrical outlet to direct current (DC) which is used by your computer (Williams & Sawyer, 2013). Because the power supply provides electricity, it is important to protect your computer from power surges (spikes of high voltage) that can potentially “fry” the motherboard. Instead of plugging the computer directly into a wall electrical outlet, it should be plugged into a surge protector, voltage regulators, or a UPS (uninterruptible power supply) (Williams & Sawyer, 2013).
Nice post!
Janice
Follow-up replies needed 9
Oluwatobi,
I am very impressed with your mention of system requirements. This is the #1 problem not only with improperly designed hardware systems, but software applications also.
I do not agree, however, on listing the power supply. The power supply is not usually something that has a lot of flexibility in choice, as it is mostly dictated by the motherboard choice. The fan in the power supply does indeed help with temperature, but when computers went from 486 to Pentium, the heat sync and CPU fan were required additionally due to the immense heat produced by the CPU.
Sluggishness is almost always due to insufficient RAM. Although I have built dozens of computers in the past, I don’t have time for that anymore, and buy them instead. As such, I always ask what the maximum capacity of RAM is possible for that computer, and try to take it to its full capacity at purchase time. A frozen screen, a slow interface of any kind, or poor graphical or sound streaming, are almost always to RAM first and foremost.
You might want to re-visit your APA listings. Knowing and using APA format properly marks you as a professional and gives credence to your work, as opposed to making tiny errors and looking like an amateur. Take a look at https://owl.english.purdue.edu/owl/resource/560/06/ and note the TOC on left. It will direct you to the specific needs of your writing.
Tim
References
Why is RAM so important? (n.d.) Retrieved from
https://www.reference.com/technology/ram-important-9c91f15ab155f890