Review NIST definition of an Issue Specific Policy

Assignment Help Computer Network Security
Reference no: EM131646855

Cybersecurity Policy, Plans, and Programs Project: Manager's Deskbook

Company Background & Operating Environment - Use the assigned case study for information about "the company."

Policy Issue & Plan of Action - The Manager's Deskbook contains issue specific policies and implementation procedures which are required to mitigate risks to the company and to otherwise ensure good governance of the company's operations. The Chief Information Security Officer (CISO) and key CISO staff members held a kick-off meeting last week to identify issue specific policies which should be added to the company's policy system in the IT Governance category. The policies will be disseminated throughout the company by incorporating them into the Manager's Deskbook. The required issue specific policies are:

1. Data Breach Response Policy

2. Preventing / Controlling Shadow IT Policy

3. Management and Use of Corporate Social Media Accounts Policy

For the purposes of this assignment, you will create a policy recommendations briefing package (containing an Executive Summary and draft policies) and submit that to your instructor for grading.

Your Task Assignment

As a staff member supporting the CISO, you have been asked to research and then draft an issue specific policy for each of the identified issues. These policies are to be written for MANAGERS and must identify the issue, explain what actions must be taken to address the issue (the company's "policy"), state the required actions to implement the policy, and name the responsible / coordinating parties (by level, e.g. department heads, or by title on the organization chart). After completing your research and reviewing sample policies from other organizations, you will then prepare an "approval draft" for each issue specific policy.

  • The purpose of each issue specific policy is to address a specific IT governance issue that requires cooperation and collaboration between multiple departments within an organization.
  • Each issue specific policy should be no more than two typed pages in length (single space paragraphs with a blank line between).
  • You will need to be concise in your writing and only include the most important elements for each policy.
  • You may refer to an associated "procedure" if necessary, e.g. a Procedure for Requesting Issuance of a Third Level Domain Name (under the company's Second Level Domain name) or a Procedure for Requesting Authorization to Establish a Social Media Account.

Your "approval drafts" will be combined with a one page Executive Summary (explaining why these issue specific policies are being brought before the IT Governance Board).

Research:

1. Review NIST's definition of an "Issue Specific Policy" and contents thereof (NIST SP 800-14 p. 14)

2. Review the weekly readings and resource documents posted in the classroom. Pay special attention to the resources which contain "issues" and "best practices" information for:

  • Data Breach Response
  • Preventing / Controlling Shadow IT
  • Social Media

3. Review NIST guidance for required / recommended security controls

  • NIST SP 800-53 Access Control (AC) control family (for Social Media policy)
  • NIST SP 800-53 Incident Response (IR) control family (for Data Breach policy)
  • NIST SP 800-53 System and Services Acquisition (SA) control family (Domain Name, Shadow IT, Website Governance)

4. If required, find additional sources which provide information about the IT security issues which require policy solutions.

Write:

1. Prepare briefing package with approval drafts of the two IT related policies for the Manager's Deskbook. Your briefing package must contain the following:

Executive Summary

"Approval Drafts" for

  • Data Breach Response Policy
  • Preventing / Controlling Shadow IT Policy
  • Management and Use of Corporate Social Media Accounts Policy

As you write your policies, make sure that you address IT and cyber security concepts using standard terminology.

2. Use a professional format for your policy documents and briefing package. Your policy documents should be consistently formatted and easy to read.

3. Common phrases do not require citations. If there is doubt as to whether or not information requires attribution, provide a footnote with publication information or use APA format citations and references.

4. You are expected to write grammatically correct English in every assignment that you submit for grading. Do not turn in any work without (a) using spell check, (b) using grammar check, (c) verifying that your punctuation is correct and (d) reviewing your work for correct word usage and correctly structured sentences and paragraphs.

Attachment:- Assignment File.rar

Reference no: EM131646855

Questions Cloud

Define dosage of drugs safer for children from infancy : describe strategies to make the off-label use and dosage of drugs safer for children from infancy to adolescence
Identify the population of interest : Gallup. At its Web site (www.gallup.com) the Gallup Poll publishes results of a new survey each day. Scroll down to the end, and you'll find a statement.
Determine for a list of characters : Write algorithm to determine for a list of characters whether or not it forms a palindrome (spelled the same either forward or backward).
Create a project plan with the given components : Create a project plan with the following components. Upload on MS Word document as the project plan. Title page and abstract/executive summary.
Review NIST definition of an Issue Specific Policy : CSIA 413: Cybersecurity Policy, Plans, and Programs Project: Manager's Deskbook. Review NIST's definition of an "Issue Specific Policy" and contents thereof
Assess proficiency in using historical documents : Assess the ability of students to think and reason, to organize and to communicate their ideas effectively and in their own words.
Review problem related to the gallup world : Gallup World. At its Web site (www.gallupworldpoll .com) the Gallup World Poll describes their methods.
Find the population parameter of interest : What did they do? For the following reports about statistical studies, identify the following items (if possible).
Worst case propagateion delay : What is the minimum number of gates required to construct a 5x32 decoder? What is the worst case propagateion delay for the decoder in units of gate delays?

Reviews

len1646855

9/18/2017 3:32:13 AM

“Approval Drafts” for - Data Breach Response Policy, Preventing / Controlling Shadow IT Policy and Management and Use of Corporate Social Media Accounts Policy. Use a professional format for your policy documents and briefing package. Your policy documents should be consistently formatted and easy to read. Common phrases do not require citations. If there is doubt as to whether or not information requires attribution, provide a footnote with publication information or use APA format citations and references. You are expected to write grammatically correct English in every assignment that you submit for grading. Do not turn in any work without (a) using spell check, (b) using grammar check, (c) verifying that your punctuation is correct and (d) reviewing your work for correct word usage and correctly structured sentences and paragraphs.

len1646855

9/18/2017 3:32:05 AM

Note: In a “real world” environment, the policy recommendations briefing package would be submitted to the IT Governance board for discussion and vetting. After revisions and voting, a package containing the accepted policies would be sent to all department heads and executives for comment and additional vetting. These comments would be combined and integrated into the policies and sent out for review again. It usually takes several rounds of review and comments before the policies can be sent to the Chief of Staff’s office for forwarding to the Corporate Governance Board. During the review & comments period, the policies will also be subjected to a thorough legal review by the company’s attorneys. Upon final approval by the Corporate Governance Board, the policies will be adopted and placed into the Manager’s Deskbook. This entire process can take 9 to 12 months, if not longer.

Write a Review

Computer Network Security Questions & Answers

  An overview of wireless lan security - term paper

Computer Science or Information Technology deals with Wireless LAN Security. Wireless LAN Security is gaining importance in the recent times. This report talks about how vulnerable are wireless LAN networks without any security measures and also talk..

  Computer networks and security against hackers

This case study about a company named Magna International, a Canada based global supplier of automotive components, modules and systems. Along with the company analysis have been made in this assignment.

  New attack models

The Internet evolution is and is very fast and the Internet exposes the connected computers to attacks and the subsequent losses are in rise.

  Islamic Calligraphy

Islamic calligraphy or Arabic calligraphy is a primary form of art for Islamic visual expression and creativity.

  A comprehensive study about web-based email implementation

Conduct a comprehensive study about web-based email implementation in gmail. Optionally, you may use sniffer like wireshark or your choice to analyze the communication traffic.

  Retention policy and litigation hold notices

The purpose of this project is to provide you with an opportunity to create a document retention policy. You will also learn how to serve a litigation hold notice for an educational institute.

  Tools to enhance password protection

A report on Tools to enhance Password Protection.

  Analyse security procedures

Analyse security procedures

  Write a report on denial of service

Write a report on DENIAL OF SERVICE (DoS).

  Phising email

Phising email It is multipart, what are the two parts? The HTML part, is it inviting the recepient to click somewhere? What is the email proporting to do when the link is clicked?

  Express the shannon-hartley capacity theorem

Express the Shannon-Hartley capacity theorem in terms of where is the Energy/bit and is the psd of white noise.

  Modern symmetric encryption schemes

Pseudo-random generators, pseudo-random functions and pseudo-random permutations

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd