Module 4

profilegotervm20q3
module_4_mileston_2.docx

Running Head: SECURITY POLICIES DEVELOPMENT 1

SECURITY POLICIES DEVELOPMENT 2

Assignment: 4-2 Final Project Milestone Two: Security Policies Development

Terri Y. Hudson

Southern New Hampshire University – IT 552

November 18, 2016

Introduction

Internet threats come into sight with vast speed and robustness. They are appearing in a revolutionary complexity making business assets in organizational security posture vulnerable to malicious attacks. It is necessary for organizations to develop security policies against security gaps such as; lack of security awareness, lack of proper configuration policies to reduce a previous access to a system or network or company’s data with intent which is malicious in nature. Social engineering attacks and the training to fight phishing. Access control policies serve as planned solutions to such issues to increase the confidentiality of data in an organizational system. The security systems include; access control, network security policy, physical security, user account policies, information security policy, information protection policy, security engineering, photo identification policy, remote access policy and virtual security policy. The procedures identification is according to the following mitigation strategies:

i. Training and human factor strategies

This plans include the awareness of the insider threat through training and heightened motivation to avoid the inside threat. Through training, workers become informed and wary of their surroundings. Training employees to recognize phishing, therefore, preserving information by avoiding fake messages, emails which are created with a malicious intent to look similarly as official ones. Personal information will remain sacred as spoofing will not be possible. Employees will be more aware of the presentation in a manner that is seen intimidating and official encouraging a person’s action. Employees without this knowledge will be prone to attacks. The encouragement of adherence to guidelines and policies engenders the process standard discipline. Inadequate procedures and poor communications cause data to be altered from its original form changing its intended meaning

Organizations need to train the employees on the improvement of risk cognitive biases and awareness conduct. This will remove the security gap of perception deficit affecting decision making. Improvement of software usability to lessen the possibility of human system induced error is one way of minimizing the threat. This will ensure there is a flow of data sent and received and it does not tamper with the original form. This serves as a configuration change in the management reducing unintentional threats (Carnegie Mellon University, 2013).

Enhancing the inclusion of insider threat which creates a form of awareness to the employees against accidental insider intrusion eliminates the gap of lack of security awareness. The continuous training of employees to maintain skills and knowledge correctly and to enforce the requirements of compliance between the employee and the relevant executive senior officers in regards to the compliance with workplace policies. The system entity that creates the data provided and controls the information (Dominick, 2016). Another way to improve intentional threats is through motivation to eliminate insider risks.

ii. Strategies that deploy use of defensive automation tools

Use of better software to detect bogus emails prevents the provision of username and passwords to cyber criminals so that they have ease of access to company’s data. Prevention of ransomware infection which may appear to be phishing emails containing malicious attachments and pop-up advertisements reduces the security lapses.

Data loss prevention software deployment is a defensive automation tool where it recognizes email practices and promiscuous harmful sites which act as a form of media protection. Use of a vast range of effective firewalls, antivirus software, and anti-malware software so that data interruption does not occur in the organization system. The team should also ensure extreme emergency deployment of remote memory wipe in lost organizational equipment with a vast amount of data exposing the vulnerability to intentional and unintentional malicious intent for

iii. High level in organizations practices

The unintentional threat in a corporate system structure, where anyone who has previously had authorized access to a network, data or system with malicious intent can create harm or increase the chance of further future damage to the integrity of the organization. Accessibility and confidentiality for an organization existing information system to mitigate such threats involve a high-level hierarchy in the organization which must be practiced to prevent frequent attacks. Work planning and control whereby the organizational heads should ensure the employees are ready to perform the required tasks by management regarding values, cognitive factors, fatigue and boredom, injury and illness, effects of hormonal and drug related do not interfere with the security functionality of an organization

Job pressures, task difficulties, poor work planning practice, time factors, change in routine are the key personal identifier information breaches. Also, the degree of the work setting, poor management skills, poor practices in security and insufficient resources contribute enormously to data breaches. This can be avoided in: reviewing management practices to be at par with the consideration of tasks. Improving the flow of data by establishing communication and following procedures to maintain work setting productive environment making distractions minimal. This policies and strategies are the solutions to intentional human threats and unintentional threats to enhance the security functionality.

References

Carnegie Mellon University. (2013). Unintentional Insider Threats: AFoundational Study. CERT Division.

Dominick, J. (2016, March 18). Information Security Policy. Jamaica: Data Governance Steering Committee.