Reference no: EM133898333 , Length: word count:1000
Cybersecurity Principles and Organisational Practice
Learning Outcome 1: Appraise cybersecurity standards and governance requirements to safeguard humans in organisations.
Learning Outcome 2: Investigate effective cybersecurity solutions that protect human and business assets with security assurance.
Assessment Task
Working in groups of three to four (3-4), you are required to write a 1,000-word (+/-10%) case report on human and cybersecurity principles that includes statistical diagrams, information on password policies, awareness campaigns and user training
Context
Cybersecurity experts agree that safeguarding human users is crucial in protecting a company's digital assets. It has been demonstrated that human users often pose the greatest cybersecurity risks to business entities (ThreatCop, 2022). To mitigate potential security breaches through unintentional or intentional user actions, it is essential to address the human factors in cybersecurity to provide preventative and proactive security assurances. Get Assignment Help from the Best tutors!
Assessment Scenario
For the purpose of this assessment, you and your group members will act as a cybersecurity team. Your team can select and handle one of the major cybersecurity case scenarios listed in Appendix 1. Alternatively, your team can elect to choose one of the latest cybersecurity case examples listed by the Australian Cyber Security Centre
In this assessment, you are to write a report addressed to the chief executive officer (CEO) of the relevant case example of your choice in which you set out your security recommendations. Your report should seek to ensure that the company will not be susceptible to the same cybersecurity threats in the future by providing proper enterprise-grade security governance, training and risk control.
Effective cybersecurity is often misunderstood and undervalued by most CEOs in the corporate world, who do not recognize its importance and may view it as having little or no business value. Knowing how to work in a team and develop written reports that can be understood by non-technical people and persuading them to make critical changes is an important skill to take into your future workplace.
Instructions
To complete this assessment, you must write a 1,000-word (+/-10%) case report that discusses human and cybersecurity principles. Your report should be addressed to the CEO of the organisation for which your team works. The objectives of the report are to ensure that your team receives the funding necessary to provide employees with adequate cybersecurity training and that the company invests in company-wide cybersecurity governance standards that also address the human factors in cybersecurity.
In completing this assessment, you should:
Review all the learning resources for Modules 4-7 before writing the report.
Ensure that your report contains information about the topics listed below and is aimed at people with limited technical knowledge.
Ensure that your report includes relevant diagrams that showcase statistics related to the increase in human exploitation attacks or any other suitable statistics. By using diagrams, the information presented in the report will be more accessible and visually appealing to readers, which will help them understand and retain the information more effectively.Your report must address:
The importance of consulting with users and conducting a business process impact evaluation before implementing cybersecurity methods. Examine at least five cybersecurity methods (technical, organisational or both) in presenting your argument.
Examine whether increasing password complexity would increase security. Justify your response in the report and discuss if and what type of awareness program and training for users is required to create secure but not too complex passwords.
Include selected topics in security solutions, including the separation of privileges, minimum security allowances, security group policing, biometrics, digital identity, artificial intelligence- driven security solutions and blockchain-driven security assurance.
Discuss how best the security policies should be communicated/trained and reinforced. Use appropriate statistics about attacks on users (e.g., phishing attacks and social engineering) to emphasise your arguments.
Detail at least three topics that will be covered in cybersecurity awareness training and recommend at least three subjects to feature in awareness campaigns.
Be written so that the CEO understands the necessity of the awareness training program and fundamental security governance solutions.
In addition to the recommended readings from Modules 4-7, you must support your report with further information obtained through at least five peer-reviewed articles and textbooks. In your search for these resources, you should specifically use the terms ‘cybersecurity governance' and ‘human factors in cybersecurity'.
Referencing
It is essential that you use current APA style to cite and reference the sources that you use.