Review nists definition of an issue specific policy

Assignment Help HR Management
Reference no: EM131389521

Project : Manager's Deskbook

Company Background & Operating Environment

Use the assigned case study for information about "the company."

Policy Issue & Plan of Action

The Manager's Deskbook contains issue specific policies and implementation procedures which are required to mitigate risks to the company and to otherwise ensure good governance of the company's operations. The Chief Information Security Officer (CISO) and key CISO staff members held a kick-off meeting last week to identify issue specific policies which should be added to the company's policy system in the IT Governance category. The policies will be disseminated throughout the company by incorporating them into the Manager's Deskbook. The required issue specific policies are:

1. Data Breach Response Policy

2. Preventing / Controlling Shadow IT Policy

3. Management and Use of Corporate Social Media Accounts Policy

For the purposes of this assignment, you will create a policy recommendations briefing package (containing an Executive Summary and draft policies) and submit that to your instructor for grading.

Note: In a "real world" environment, the policy recommendations briefing package would be submitted to the IT Governance board for discussion and vetting. After revisions and voting, a package containing the accepted policies would be sent to all department heads and executives for comment and additional vetting. These comments would be combined and integrated into the policies and sent out for review again.

It usually takes several rounds of review and comments before the policies can be sent to the Chief of Staff's office for forwarding to the Corporate Governance Board. During the review & comments period, the policies will also be subjected to a thorough legal review by the company's attorneys. Upon final approval by the Corporate Governance Board, the policies will be adopted and placed into the Manager's Deskbook. This entire process can take 9 to 12 months, if not longer.

Your Task Assignment

As a staff member supporting the CISO, you have been asked to research and then draft an issue specificpolicy for each of the identified issues. These policies are to be written for MANAGERS and must identify the issue, explain what actions must be taken to address the issue (the company's "policy"), state the required actions to implement the policy, and name the responsible / coordinating parties (by level, e.g. department heads, or by title on the organization chart). After completing your research and reviewing sample policies from other organizations, you will then prepare an "approval draft" for each issue specific policy.

• The purpose of each issue specific policy is to address a specific IT governance issue that requires cooperation and collaboration between multiple departments within an organization.

• Each issue specific policy should be no more than two typed pages in length (single space paragraphs with a blank line between).

• You will need to be concise in your writing and only include the most important elements for each policy.

• You may refer to an associated "procedure" if necessary, e.g. a Procedure for Requesting Issuance of a Third Level Domain Name (under the company's Second Level Domain name) or a Procedure for Requesting Authorization to Establish a Social Media Account.
Your "approval drafts" will be combined with a one page Executive Summary (explaining why these issue specific policies are being brought before the IT Governance Board).

Research:

1. Review NIST's definition of an "Issue Specific Policy" and contents thereof (NIST SP 800-14 p. 14)

2. Review the weekly readings and resource documents posted in the classroom. Pay special attention to the resources which contain "issues" and "best practices" information for:

• Data Breach Response

• Preventing / Controlling Shadow IT

• Social Media

3. Review NIST guidance for required / recommended security controls

• NIST SP 800-53 Access Control (AC) control family (for Social Media policy)

• NIST SP 800-53 Incident Response (IR) control family (for Data Breach policy)

• NIST SP 800-53 System and Services Acquisition (SA) control family (Domain Name, Shadow IT, Website Governance)

4. If required, find additional sources which provide information about the IT security issues which require policy solutions.
Write:

1. Prepare briefing package with approval drafts of the two IT related policies for the Manager's Deskbook. Your briefing package must contain the following:

• Executive Summary

• "Approval Drafts" for

o Data Breach Response Policy

o Preventing / Controlling Shadow IT Policy

o Management and Use of Corporate Social Media Accounts Policy

Reference no: EM131389521

Questions Cloud

What is the ethical status of a campaign contribution : What is the ethical status of a campaign contribution given to a politician to secure future business? Is this a bribe? Is it the same as a kickback? Perhaps line drawing would help answer this question.
Describe brand primary channel of distribution : Describe your brand's primary channel of distribution. Is your organization a producer, merchant wholesaler, retailer, agent, or broker?  Why does this type of channel work for this organization? What do you think are the most important factors th..
Explain whether black will succeed in its attempt : Black, Inc., a minority shareholder in Zenith Steel Company, brings an appropriate action to enjoin the payment by the company of the $1 million bonus. Explain whether Black will succeed in its attempt.
Is raphael correct in given contention and why : Raphael, a minority shareholder of the Sample Corporation, claims that these sales are void and should be annulled. Is he correct? Why?
Review nists definition of an issue specific policy : The Manager's Deskbook contains issue specific policies and implementation procedures which are required to mitigate risks to the company and to otherwise ensure good governance of the company's operations. The Chief Information Security Officer (..
Will gore be able to obtain a copy of shareholders list : Further, he did not offer to transmit Gore's offer to the shareholders of record. Gore then brought an action to compel the corporation to make the shareholders' list available to her. Will Gore be able to obtain a copy of the shareholders' list? ..
Construction equipment company with responsibilities : Mike O'Brien is a new regional sales manager for a U.S.-based construction equipment company with responsibilities for the Asian and Eastern European markets. Thanks to a multimillion-dollar loan from the World Bank, one of the less-developed nati..
Should all problems be overcome with more engineering : Should new methods have been employed to solve the fissured rock problem, rather than relying on technology (the grout curtains) that the bureau had experience with at other less fissured sites?
Provide decisions as to each action : X Corporation now brings actions to rescind its contract with D Company and to compel Green to assign to X Corporation his contract for the purchase of Q Corporation. Decisions as to each action?

Reviews

Write a Review

HR Management Questions & Answers

  Alternative funding brainstorm ideas for alternative

alternative funding brainstorm ideas for alternative funding for the program you selected from appendix b. search the

  Description of major equal employment opportunity laws

Explain What are the five major federal Equal Employment Opportunity or Affirmative Action laws and How do these laws govern the employment relationship

  Please assist in a five slide power point presentation with

please assist in a five slide power point presentation with documentation for each slide with a recommendation for

  Develop a strategic hrm analysis

Develop a strategic HRM analysis and roadmap for the organization you selected in Module One. Combine your previous papers for this project and synthesize the information, analysis, and programs you have collected, conducted, and developed to prod..

  Later adulthood scenarios

The aging process affects us all. Sooner or later, we will be faced with challenges unique to later life. As medical technology pushes the outer boundaries of longevity, we will be confronted with more and more issues related to aging in later lif..

  How would you define sexual harassment

How would you define sexual harassment? What is the legal definition?Does the complaint in the scenario fall under the definition of sexual harassment? Why or why not?What would be the implications of this complaint, if it is found true, for the seni..

  Characteristics of individual effective leader

Discuss 3 factors or characteristics that you think makes this individual (CEO) an effective leader.

  Provide an example of change in attitude because of

1 give an example of change in attitude because of effective marketing communication?2. what are the different roles

  Article about an organization or a product or a service

Find (online) a news article about an organization or a product or a service that discusses amarketing issue. The date of the online news article must be from within the last 3 months.

  State how you could apply this aspect at your current

Watch the video titled "Scripps," located in Week 5 of your Blackboard course. From the video, isolate one (1) of the many aspects of the Scripps recruitment and interview process that could be most attributable to Scripps' ample supply of registe..

  Evaluating the recruiting function how would you evaluate

ltbrgt ltbrgt ltbrgthow would you evaluate the nurse recruitment strategy currently being used by the hospital? is the

  Examine two reasons why employees join labor unions

Examine two (2) legal responsibilities that employers have when dealing with labor unions. Suggest two (2) ways in which management and unions might work together to craft mutually beneficial contracts. Provide a rationale for your response.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd