Reference no: EM132475651
Assignment Part 1 - The CISO blog
Assume you are a newly employed chief information security officer (CISO) for the University of Innovation. You decide to write a short blog article that will be published on the University's intranet.
Your article will introduce your role, responsibilities and duties as CISO as well as the cyber security group structure. It will then outline the importance of cyber security for the University with a special focus on the General Data Protection Regulation (GDPR) for Higher Education Institutions. You decide to expand further on how the GDPR impacts your role as well as the security operations for Higher Education Institutions.
Your blog article should not exceed 500 words and follow an appropriate blog formatting style.
You are expected to use appropriate peer reviewed sources for developing your arguments and the Harvard referencing style as per the University regulations.
Generic formative feedback on your work will be provided during the lecture the week commencing 17.02.2020 giving you the opportunity to reflect on your activities and improve your work where necessary. You are strongly advised to have worked on a complete draft by then.
Assignment Part 2 - Information Security Policy
After the completion of Task 1 you decided your second task as a CISO is to draft an Acceptable Use Policy (AUP) for the University of Innovation along the lines of ISO27000 family. You should consider the ‘Bring Your Own Device' (BYOD) usage as part of your AUP as well.
You should take into consideration any confidentiality, integrity, and availability (CIA) issues of the information assets at the University and assess all relevant risks. Any work as part of your research on security policies for higher education institutions, consideration of issues and risk assessment MUST be provided as an appendix.
Please note that you will NOT be producing an academic report, but an Information Security Policy (ISP) document. You should use an appropriate ISP template of your choice for your work.
As a general guideline your policy should not be more than three (3) pages long and approximately 1500 words. You need to be concise and precise.
Generic formative feedback on your work will be provided during the lecture the week commencing 09.03.2020 giving you the opportunity to reflect on your activities and improve your work where necessary. You are strongly advised to have worked on a complete draft by then.
Assignment Part 3 - Incident Response
Because of your role as the CISO at the University of Innovation you have been contacted by the National Crime Agency to inform you they have strong indications a data breach that involves critical data has occurred. They provide you with specific details about the incident and you decide to initialise incident response and investigation procedures, only to realise your team is not well prepared. You know this will cause delays in the process and important information might get lost in the meantime. It is vitally important that this matter be kept confidential at this stage.
You decide to prepare an infographic that you will distribute to your team as a matter of urgency. The infographic should address the following items:
a. The severity level of a data breach for the University.
b. The groups that are involved in incident response.
c. A plan for disaster recovery and business continuity.
d. Measures to contain, recover and prevent similar incidents from occurring in the future.
Your infographic needs to be professional, brief and informative. A recommended tool to create your infographic is PowerPoint, but you may also use any other tool of your choice. You may also select any template of your choice, but you should leave some space at the bottom of your infographic for citations and author credits.
You are expected to use appropriate peer reviewed sources and the Harvard referencing style as per the University regulations.
Attachment:- Assignment task ISM.rar