Policy 8

profileJohn_matt
replies_needed.docx

Please don’t give me a two to three sentence replies. It has to look bulky. At least 8 to 10 sentences. Thank you

Reply needed 1

Introduction:                 

     Although information security audits were not very common in the past, they are becoming significant to implement as the increasing connectivity of the Internet grows in today’s day and age (Hayes, 2003, para. 1). “An information security audit is one of the best ways to determine the security of an organization's information without incurring the cost and other associated damages of a security incident” (Hayes, 2003, para. 1). One classification of these types of audits are in relation to employee awareness of IT security policies. As humans are said to be the weakest link in security due to their lack of knowledge of security policies and procedures, it becomes pertinent to ensure their familiarity with the implemented IT security policies and how they play an important role in upholding the security posture of an organization. Red Clay’s employee handbook is an example of a security policy that employees must adhere to. The policies within this handbook include the Acceptable Use Policy, Bring Your Own Device (BYOD) policy, and the Digital Media Sanitization, Reuse, & Destruction Policy. The purpose of this briefing statement is to inform Red Clay’s IT Governance Board of the purpose of auditing employees’ awareness of IT security policies along with specific information pertaining to the audit itself. By inspecting employee awareness of these policies, Red Clay Renovations can ensure to a certain extent that their employees did not cause the security breach to initiate as they had been well informed of the policies beforehand; however, if the breach is said to have originated from an internal employee, the employee would be unable to deny the fact that they were not aware of the security policy as they would have had to sign the Employee Handbook, thus acknowledging the fact that they will adhere to the stated policies.

Analysis:

     The purpose of this type of security audit is to emphasize the importance of employee awareness as it relates to security concerns and the way in which they are to mitigate the effects of these concerns (Auditing Department of Winnipeg, 2008, p. 26). Keeping Red Clay’s technical environment and personnel in mind, the Chief Information Officer, Erwin Carrington will be the designated individual that will conduct the audit (King, 2016, p. 3). As its name implies, the employee awareness of IT security policies audit will cover generic rules such as whether or not employees are aware of the policies present within the employee handbook, if they know their obligations under their policies, and to understand major improvement opportunities (Dorrian, 2016, p. 1). “To maintain a comprehensive awareness and training program, the organization must develop an awareness and training plan, acquire awareness and training materials, implement the plan, and complete ongoing maintenance of the awareness and training materials” (Auditing Department of Winnipeg, 2008, p. 26). This audit will be conducted on Friday, October 14, 2016 at all of Red Clay’s office locations, including the Baltimore field office, the Philadelphia field office, the Operations Center in Owings Mills, and the Wilmington office (King, 2016, p. 4). The audit will be conducted via an online forum in which employees will be presented with a minimum of 10 multiple choice questions that will assess their understanding of IT security policies (Dorrian, 2016, p. 1). Employees would be more willing to participate in the survey if it is kept anonymous as it will enable them to answer honestly without putting their job at risk (Auditing Department of Winnipeg, 2008, p. 18). The questions presented will allow the IT Governance Board to understand the approximate percentage of employees that understand Red Clay Renovations’ security operations, and in what aspects they must further educate their employees in (Auditing Department of Winnipeg, 2008, p. 21).

Summary:

     The purpose of this audit plan is to emphasize employee awareness of IT security policies as employees play a major role in the proper functioning of an organization; thus, they must be aware of their duties as it relates to upholding security measures for Red Clay Renovations (Auditing Department of Winnipeg, 2008, p. 7). The IT Governance Board must understand the need for such an audit plan as they bear the responsibility of “considering all matters related to the acquisition, management, and operation of the company’s information technology resources” (King, 2016, p. 1). Lastly, the most suitable way in which this audit could be conducted is if employees are required to complete a survey that will ask the employees a series of security related questions. These questions include but are not limited to assessing whether or not employees have the ability to successfully respond to a common occurrence of events that can lead to a security threat if not handled properly, and if they are aware of the security department heads for their organization (Auditing Department of Winnipeg, 2008, p. 22). This determination can help the IT Governance Board identify what their employees are and are not aware of, and they can educate them based on the results of the survey. The aforementioned facts prove that information security audits are important to maintain the security posture of an organization.

 

 

References

Auditing Department of Winnipeg. (2008, June). Assessment of information security awareness. Retrieved from http://www.winnipeg.ca/audit/pdfs/reports/ITSecurityAwareness.pdf

Dorrian, J. (2016). Project #4: IT audit policy and plans in CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu

Hayes, B. (2003, May 25). Conducting a security audit: An introductory overview. Retrieved from http://www.symantec.com/connect/articles/conducting-security-audit-introductory-overview

King, V. J. (2016, March 30). Red Clay Renovations: A case study for CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu

Reply needed 2

Introduction

 

 Red Clay Renovations processes sensitive information such as Protected Health information that requires a certain level of protection (King, 2016). For example, The HIPPA Security Rule requires that appropriate administrative, physical and technical safeguards be put in place to ensure the confidentiality, integrity, and security of electronic protected health information (The Security Rule, n.d.). The Payment Card Industry Data Security Standard (PCI-DSS) standard requires organizations that process credit card transactions to assess, remediate, and report (PCI-SSC, 2010). Red Clay Renovations has created policies to ensure that this information receives the amount of security it needs to meet state and federal law as well as industry standards. The employee awareness of IT security policy was created to test employees to see if they were aware of the IT security policies in the employee handbook and to see if they knew their responsibilities under those policies. This test is necessary to ensure that Red Clay Renovations does not violate state, local or federal law as well as industry standards. Employees that have access to PHI, conduct credit card transactions or conducts credit checks must be aware of the agencies policy on how to handle that information, the laws that govern the use of that information as well as their responsibilities when handling that information. If an employee violates one of those laws, Red Clay Renovations will face the consequence and the employee will be disciplined in accordance with the established policy. This briefing will cover who will conduct the audit, what will be covered by the audit, when will the audit be conducted, where will the audit be conducted and how will the audit be conducted.

Analysis

The audit will be conducted by the IT staff who have created a ten question web based survey that can be taken online. Red Clay Renovations employees can take the test by logging into their workstations and accessing the companies’ intranet. The test can be taken from any Red Clay Renovation office that has internet access. The test will ask employees a series of questions to determine if they have received security and awareness training, read certain polices and to see if they are aware of their responsibilities when it comes to those polices. For example, Red Clay Renovations employees that handle PHI must read the companies policy on how to handle that information. Employees that handle PHI must ensure that it is protected when it is processed, stored or transmitted. The audit will be conducted annually and the results will be forwarded to the CIO and CISO.

Conclusion

The employee awareness of IT security policy is used to test employees awareness of key polices that protect Red Clay Renovations from being fined. The audit will be conducted by the IT staff who have created a web based survey. Employees will be required to take the survey once a year at any Red Clay Renovations office that has an internet connection. This policy will ensure employees are receiving security and awareness training that will make them aware of the latest malware and scams as well as protect the agencies reputation by ensuring employees handle sensitive information in the correct manner.

 

 

 

 

 

King, V. J. (2016, March 30). Red Clay Renovations. A Case Study for CSIA 413.

PCI DSS Quick Reference Guide Understanding the Payment Card Industry Data Security Standard version 2.0. (2010, October). Retrieved from PCI: https://www.pcisecuritystandards.org/documents/PCI SSC Quick Reference Guide.pdf

U.S. Department of Health & Human Services. (n.d.). The security rule. Retrieved from http://www.hhs.gov/hipaa/for-professionals/security/

REPLY 3 Needed

As security breaches continue to grow on a daily basis, employees are not confident in knowing organizational security policies which often times end up costing organizations millions of dollars’ due security awareness training. Moreover, an in adept Information Technology Department should be providing dynamic security and awareness training to employees but often time lacks organizational and managerial aspects of what material to cover, the time to properly train employees, or the training was never initiated. However, organizations fail to understand the repercussion of not training users on security policies which result in accidental damage to the company. In addition, to the blindside it also cost the organization client-trust issues and cost the organization business.

 Therefore, as employees perform their daily duties, they are often unaware that certain behaviors they are normally inclined to perform are often against security policies and procedures. In addition, companies and organizations often do you have in place certain security protocols and mechanisms to stop the behaviors which can include security incident event management (SIEM), deep packet inspection, internet content filtering, application control, and as mentioned awareness training upon other fortitudes to successfully inform employees of unauthorized behavior(ISO, 2016). Although, there should be audits of one’s network periodically of all applications being used either with or without shadow IT, it should be documented and taken into consideration that shadow IT policies often reflect security posture as a whole within the network.

The information presented in Red Clay Renovations does not construe an employee awareness of IT security policies(Valorie, 2016). Moreover, without the awareness of IT security policies, the organization as a whole faces dynamic repercussions of employee actions. According to SANSs “Security policy must adapt to changing needs within the organization. Personnel responsible for creating and maintaining the security policy must learn to recognize changes in technology that impact security and how those changes impact the organization and the people who work for the organization.”(SANS, 2001). Therefore, it is a vital aspect that the organization keeps abreast of new technologies, security practices, and provide use awareness training to employees while maintaining audits throughout the organization.

Therefore, in order to provide employee awareness of IT security policies, the Chief of Staff must design and draft an employee awareness training program while Information Technology Services will be trained on how to implement the solution to other offices. The training will cover the following:

· Security Policies

· Physical

· Building Access

· Shoulder Surfing

· Password Keeping

· Documentation Shredding – proper disposal of company material

· Social Engineering – whailing, vishing, exposing PII to unauthorized individuals

· Digital

· Threats – malware, viruses, malicious files

· E-mail – image attachments, file attachments, link clicking

· Mobile – mobile applications, e-mail, unknown contacts/text, SPAM

· Social Engineering – phishing, spear phising, spimming, spamming, vishing,

However, this is a very robust list and will be added on to as the organization sees fit. Moreover, the audits will be done every 6 months with certain employees within the information technology department going to each field off location. The training will be conducted in a class room with an instructor and will include quizzes and labs. Likewise, the employees will be graded on performance based, social based, and quizzed base tactics. If an employee fails to pass, the employee will have additional training until they understand the concepts via digital media and remediation training once a week until full understanding the material.

           

 

 

 

ISO. (2016). ISO/IEC 27001 - Information security management.

SANS. (2001). Security Awareness Training and Privacy.   Retrieved from https://www.sans.org/reading-room/whitepapers/awareness/security-awareness-training-privacy-394

Valorie, K. J. (2016). Red Clay Renovations Retrieved from

Follow-up replies needed 5

John,

I like the layout and content of your briefing, the only major suggestion I have would be to detail more about who will conduct the audit.  Companies now have the important choice to make between conducting an internal audit using their own training IT personnel, or contracting out to a dedicated audit company.  Both have pros and cons.  Internal audits take up more of a company's limited resources and time, but generally no one knows the intricacies of the processes like the employees who work on them, so the audit could be more detailed.  External companies would take the workload away from the company being audited, but would require a significant investment of money for more complex audits.  External companies may also not be as familiar with unique systems or processes, alternatively, their lack of familiarity could cause them to scrutinize those systems more, resulting in a more detailed audit.  The choice depends on the resources available to the company and their unique situation, but is a worthwhile decision to discuss when talking about conducting an audit for the company's IT security policies.

V/r,

Sam

Follow-up replies needed 6

John,

   Good assessment.  I opted for RCR to conduct their own internal audit, but have it validated by another organization within the company.  In this case it was the Office of Corporate Management.  Frankly, I like contracting out the work and am putting that option in my kit bag for future use.  Your assessment is correct -- external audits cost $$.  If RCR budgeted for it and had the cash to spend, it would be a good way to go.  There would, of course, have to be non-disclosure agreements in place between RCR and the auditing company to help protect the confidentiality of the results.

  Good luck with the final paper!  We're almost done!

V/R

Follow-up replies needed 7

Technology is every changing and, although the disk is a critical factor within the computer systems, it may well be substituted with other virtual cloud disks that can control can be allocated or shared with a remote user. It is good to take steps to understand why your computer is acting in a dysfunctional way therefore, you can narrow the problem as well fix it efficiently. 

Overall the problems usually exist because the requirement are not matched with the hardware, software, applications and cloud based applications. The size of the memory and, the speed of the processors are all integrated and, should be able to enforce a smoother systems performance.

Follow-up Replies needed 6

john

Hello john

Just like with computer "slowness" there are definitely many causes and fixes for I/O failures.

Follow-up Reply needed 7

I/O disk (hard drive) latency is a growing problem for computer sub-performance, more so than CPU and memory. There are few modern hard drives that have latency speeds under 13 milliseconds. In contrast RAM latency is usually about 5 nanoseconds, 2,000 times faster than the hard drive. This may not seem like a big deal until you want to use several apps at one time or several users are using a shared server. Pending operations go into a queue, even if your app only needs a single byte of data from the hard drive. Your request still has to wait its turn, thus slowing down your computer.

Janice

Reference:

Jones, N. (2009). Performance killer: Disk I/O. Retrieved from http://www.nathanaeljones.com/blog/2009/performance-killer-disk-io

Follow – up Reply needed 8

John,

Once again, you have done an excellent job in presenting good research and writing a clear, comprehensive report.

You correctly emphasized the importance of knowing the condition of the I/O aspects of the computer in trying to establish optimum standards of performance. Having I/O knowledge is a start baseline of where to go for improvements. Examining the questions of latency and an evenly distributed disk were also important aspects that I had not considered before. I am really glad that I read your report. You offered an array of new information to learn from.

Tim