Information Assurance
Running head: 1
2
Information Assurance Introductions: Module 1
Tyrone Armstrong
IT549: Information Assurance
Southern New Hampshire University
Information Assurance Plan
The goals and of the Information Assurance plan are to help ensure the information is safe, confidential, has integrity and is readily available when required. The information assurance plan will also contribute to mitigating any security issues that the information system might face which might lead to the loss of data and information (Schou & Shoemaker, 2006). Where there are good mitigation plans, the system will be able to recover quickly back into a working condition in case it had failed in the first place. The safety of the stored data is another main reason why the information assurance plan is developed. This safety includes the protection of the data from persons who are not allowed to access it.
An information assurance plan has several benefits. The plans allow for the summarization of essential concepts in computing which affect the data integrity and security (Schou & Shoemaker, 2006). The plan also comes in handy when there is the need to trouble shoot, access or even configure hardware as well as manage files which affect data. The plan also makes use of relational database design technology to design the best data models for the database (Schou & Shoemaker, 2006). Another benefit that is associated with information assurance is the provision of development of business applications.
An effective plan would put into consideration the methodologies that are required to develop these applications. With this plan, information security threats as well as risks are managed properly. These are the required minimum objectives of an effective information assurance plan. Currently, the organization has a security policy for the information systems that guides how the data is handled. Notably, the company’s policy includes an encryption policy. This policy details the kind of encryption algorithms that are to be used when encrypting data (Cannoy & Salam, 2010). The policy also details the acceptable use of these algorithms. The organization also has a policy on acceptable use of computing services. This policy details how the staff members interact with the Information Technology equipment at the workplace.
Other policies that are currently contained in the information assurance policy of the organization include the ethics policy, the password construction and the password protection policy. The ethics policy encourages an open culture among the employee as they work in the business (Cannoy & Salam, 2010). On the other hand, the password construction policy details the regulations about how to construct a password. This is the particularly important factor regarding its direct impact on the security of the data in the company. Finally, the current information assurance policy includes the password protection policy. The policy details particularly how strong passwords are to be constructed.
There are certain aspects missing in the current information assurance policy which needs to be looked into. The policy needs to have a data breach policy. This particular policy will detail how the company will respond to a breach. The company’s vision and goal as it responds will pretty much direct the kind of responses employed in a case of a breach. With this policy, the company will remain focused and not react in a way that will be disadvantageous to itself. The company should also have a policy on disaster recovery. This policy will detail how the company will recover from possible information disasters by detailing how it will recover the IT systems, data as well as applications critical to the management and security of the company’s information (Vaughn, Henning & Siraj, 2003).
With the deficiencies that were in the current information assurance plan, the company would not have been able to recover the information efficiently. Matter of fact, it would not have been able to recover some information at all. Sadly enough, since there was no data breach policy in the first place, the company would not have mitigated, created systems and put hardware and software resources in place to prevent breaches. Nevertheless, the potential barriers to the implementation of the new plan include resistance by the staffs to change their mind about the policy. These staff members will have to be trained and educated on why it is important to implement these policies. They should also be involved as the policy is being incorporated into the current information assurance policy.
References
Cannoy, S. D., & Salam, A. F. (2010). A framework for health care information assurance policy and compliance. Communications of the ACM, 53(3), 126-131.
Schou, C., & Shoemaker, D. P. (2006). Information assurance for the enterprise: A roadmap to information security. McGraw-Hill, Inc..
Vaughn, R. B., Henning, R., & Siraj, A. (2003). Information assurance measures and metrics-state of practice and proposed taxonomy. In System Sciences, 2003. Proceedings of the 36th Annual Hawaii International Conference on (pp. 10-pp). IEEE.