Reference no: EM132952353 , Length: word count:900 words
CIS 462 Security Strategy and Policy Assignment - IT Security Policy Framework, Strayer University, USA
The specific course learning outcome associated with this assignment is: Propose an IT security policy based on an industry-standard framework.
Instructions - Establishing an effective information technology security policy framework is critical in the development of a comprehensive security program. Additionally, there are many security frameworks that organizations commonly reference when developing their security programs. Review the security frameworks provided by NIST (SP 800-53), ISO/IEC 27000 series, and COBIT. Assume that you have been hired as a consultant by a medium-sized insurance organization and have been asked to draft an IT Security Policy Framework.
You may make all assumptions needed to complete this assignment.
Write a 3-5 page paper in which you:
1. Select a security framework, describe the framework selected, and design an IT security policy framework for the organization.
2. Describe the importance of and method of establishing compliance of IT security controls with U.S. laws and regulations, and how organizations can align their policies and controls with the applicable regulations.
3. Analyze the business challenges within each of the seven domains in developing an effective IT security policy framework.
4. Describe your IT security policy framework implementation issues and challenges and provide recommendations for overcoming these implementation issues and challenges.
5. Use three sources to support your writing. Choose sources that are credible, relevant, and appropriate. Cite each source listed on your source page at least one time within your assignment. For help with research, writing, and citation, access the library or review library guides.
Note - Need 900 words paper + title page + references with in-text citations.