Construct web-based survey of all employees

Assignment Help Management Information Sys
Reference no: EM133786529

Assignment: IT Audit Policy & Plan- Cybersecurity Policy, Plans, and Programs

Company Background and Operating Environment

Red Clay Renovations is an internationally recognized, awarding winning firm that specializes in the renovation and rehabilitation of residential buildings and dwellings. The company specializes in updating homes using "smart home" and "Internet of Things" technologies while maintaining period correct architectural characteristics. Refer to the company profile (for additional background information and information about the company's operating environment.

Policy Issue and Plan of Action

The corporate board was recently briefed by the Chief Information Officer concerning the company's IT Security Program and how this program contributes to the company's risk management strategy. During the briefing, the CIO presented assessment reports and audit findings from IT security audits. These audits focused upon the technical infrastructure and the effectiveness and efficiency of the company's implementation of security controls. During the discussion period, members of the corporate board asked about audits of policy compliance and assessments as to the degree that employees were (i) aware of IT security policies and (ii) complying with these policies. The Chief Information Officer was tasked with providing the following items to the board before its next quarterly meeting:

I. Issue Specific Policy requiring an annual compliance audit for IT security policies as documented in the company's Policy System

II. Audit Plan for assessing employee awareness of and compliance with IT security policies

i. Are employees aware of the IT security policies in the Employee Handbook?
ii. Do employees know their responsibilities under those policies?

III. Audit Plan for assessing the IT security policy system

i. Do required policies exist?
ii. Have they been updated within the past year?
iii. Are the policies being reviewed and approved by the appropriate oversight authorities (managers, IT governance board, etc.)?

Task

As a staff member supporting the CISO, you have been asked to research this issue (auditing IT security policy compliance) and then prepare an "approval draft" for a compliance policy. You must also research and draft two separate audit plans (i) employee compliance and (ii) policy system audit. The audit policy should not exceed two typed pages in length so you will need to be concise in your writing and only include the most important elements for the policy. Make sure that you include a requirement for an assessment report to be provided to company management and the corporate board of directors.

I. For the employee compliance assessment, you must use an interview strategy which includes 10 or moremultiple choice questions that can be used to construct a web-based survey of all employees. The questions should be split between (i) awareness of key policies and (ii) awareness of personal responsibilities in regards to compliance.

II. For the policy system audit, you should use a documentation assessment strategy which reviews the contents of the individual policies to determine when the policy was last updated, who "owns" the policy, who reviewed the policy, and who approved the policy for implementation.

Research:

I. Review the table of contents and relevant chapters in the Certified Information Privacy Professional textbook to find information about legal and regulatory drivers.

II. Review the readings including the example audit assessment report.

III. Review work completed previously in this course which provides background about the IT Policy System and specific policies for the case study company.

IV. Find additional resources which discuss IT compliance audits and/or policy system audits.

Reference no: EM133786529

Questions Cloud

What population is being discussed : What population is being discussed? How all of the above mentioned are affected? Why do you think this article is interesting? Why did you choose this article?
Different health care services : Welcome to the Medical Record Department at Dunlap Medical Center. A number of medical records from different health care services
Identify appropriate laboratory : Identify appropriate laboratory, imaging, and other diagnostic/screening tools that apply to the disorder
Treatment for mental health therapy : Outline how you are currently taking care of your mental and physical health and your plan for upcoming/proposed treatment for mental health therapy,
Construct web-based survey of all employees : CSIA 413- You must use an interview strategy which includes 10 or moremultiple choice questions that can be used to construct web-based survey of all employees.
Significant challenges facing nurse leaders : What do you think are the most significant challenges facing nurse leaders today and explain you answer?
Address the social determinants of health when working : Address the social determinants of health when working with patients. Think about the ways in which this will positively impact your patients
Describes minority risk of child physical abuse : Which statement best describes minority risk of child physical abuse? Minorities are less at risk than Caucasian children.
History of hypertension : Mr. James Hobson is a 69-year-old male with a history of hypertension that is fairly well controlled on medication.

Reviews

Write a Review

Management Information Sys Questions & Answers

  Information technology and the changing fabric

Illustrations of concepts from organizational structure, organizational power and politics and organizational culture.

  Case study: software-as-a-service goes mainstream

Explain the questions based on case study. case study - salesforce.com: software-as-a-service goes mainstream

  Research proposal on cloud computing

The usage and influence of outsourcing and cloud computing on Management Information Systems is the proposed topic of the research project.

  Host an e-commerce site for a small start-up company

This paper will help develop internet skills in commercial services for hosting an e-commerce site for a small start-up company.

  How are internet technologies affecting the structure

How are Internet technologies affecting the structure and work roles of modern organizations?

  Segregation of duties in the personal computing environment

Why is inadequate segregation of duties a problem in the personal computing environment?

  Social media strategy implementation and evaluation

Social media strategy implementation and evaluation

  Problems in the personal computing environment

What is the basic purpose behind segregation of duties a problem in the personal computing environment?

  Role of it/is in an organisation

Prepare a presentation on Information Systems and Organizational changes

  Perky pies

Information systems to adequately manage supply both up and down stream.

  Mark the equilibrium price and quantity

The demand schedule for computer chips.

  Visit and analyze the company-specific web-site

Visit and analyze the Company-specific web-site with respect to E-Commerce issues

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd