The rookie chief information security officer

Assignment Help Basic Computer Science
Reference no: EM133158610

Assignment - The Rookie Chief Information Security Officer

Overview

Imagine that you have been recently promoted to serve as Chief Information Security Officer (CISO) for a Fortune 500 organization. This organization has known brand products across the world and expects top-secret methods for safeguarding proprietary information on its recipes and product lines.The Board of Directors requests that their information security strategy be upgraded to allow greater opportunities for secure cloud collaboration between suppliers and resellers of their products. Another concern they have is the recent number of hacktivist attacks that have caused the network to fail across the enterprise. Their concern extends to making sure that they have controlled methods for accessing secured physical areas within their various regional facilities.For your new position, you will be responsible for developing standards, methods, roles, and recommendations that will set the new IT security path for the organization. The existing organization has limited experience in supporting an enhanced level of IT security; therefore, you may need to outsource certain security services.

Part 1: Organization Chart

Create an organization chart (use Visio or Dia) which illustrates the roles that will be required to ensure the design, evaluation, implementation, and management of security programs for the organization.

Within your organizational chart, clearly identify the reporting structure for roles such as IT Security Compliance Officer, Security Manager, CIO, CISO, IT Security Engineer, Privacy Security Professional, and IT Procurement Specialist.

List the types of resources required to fulfill each forensic duty of the organization below each of the roles you identified.

Align your organization chart to reflect the Department of Homeland Security (DHS) Essential Body of Knowledge's three areas of information security: physical security professional, privacy professional, and procurement professional.

Provide comments and comparisons on how your organizational chart fosters these three values.

Part 2: Request for Proposal (RFP) Plan

Develop a Request for Proposal (RFP) plan to solicit qualified vendors that could partner with your internal team to deliver optimum IT service delivery.

The RFP Plan should contain qualifying criteria of potential vendors and the responsibilities of the vendor once the contract is awarded.

As part of the plan, you must:

Describe at least two perspectives that need to be closely monitored within the contract.

Give your perspective on at least two methods that could be used to evaluate and develop a qualified trusted supplier list.

Part 3: Physical Security Plan

Recommend a physical security plan that could be used to protect sensitive areas such as telecom rooms, employee-only areas, and manufacturing facilities in which you include at least three specific methods.

Part 4: Enterprise Information Security Compliance Program

Establish an enterprise information security compliance program that addresses the concerns of the board of directors of the organization in which you describe specific plans and control objectives that could be adopted to address the known issues.

Suggest at least three information security policies that could be developed and practiced within the organization for data security assurance.

Outline the steps you would take to define the security needs of the organization in terms of duties, staffing, training, and processes.

Part 5: Risk Management Plan

Develop a risk management plan in which you describe at least three possible risk management efforts that could be used to assess threats and unknown issues.

Determine why defining priorities is an important part of the process when enumerating and having efficient risk control measures.

Suggest specific technical and management controls that could be enacted in order to monitor risks accurately.an organization's security plan, including an organization chart, a request for a proposal plan, a physical security plan, an enterprise information security compliance program, and a risk management plan.

Reference no: EM133158610

Questions Cloud

Definition for protocol in general : What is your definition for protocol in general? What are the most commonly used IoT protocol for short distance communication?
Overview of data mining : "Overview of Data Mining", The author provides five key takeaways. Examine one key takeaway and expand on the information provided.
Project management plan : You are to finalize the overall project management plan (PMP) and to integrate all previously submitted components incorporated with instructor (project sponsor
Facial recognition software raise : What risks, if any, does facial recognition software raise? How much information about you can be found on-line with a simple google search?
The rookie chief information security officer : Develop a Request for Proposal (RFP) plan to solicit qualified vendors that could partner with your internal team to deliver optimum IT service delivery.
Computer virtualization-storage and cloud-based : Compare the architectures of virtual machine-based and container-based virtualization.
Thinking about password attacks : Thinking about password attacks, identify two that you believe are the most dangerous. Why do you believe these two are the most dangerous?
Web application security review : During a web application security review, Alice discovered that one of her organization's applications is vulnerable to SQL injection attacks.
Network without requiring human interact : The Internet of Things is system of connected computing devices and objects using unique identifiers, sending data over network without requiring human interact

Reviews

Write a Review

Basic Computer Science Questions & Answers

  Identifies the cost of computer

identifies the cost of computer components to configure a computer system (including all peripheral devices where needed) for use in one of the following four situations:

  Input devices

Compare how the gestures data is generated and represented for interpretation in each of the following input devices. In your comparison, consider the data formats (radio waves, electrical signal, sound, etc.), device drivers, operating systems suppo..

  Cores on computer systems

Assignment : Cores on Computer Systems:  Differentiate between multiprocessor systems and many-core systems in terms of power efficiency, cost benefit analysis, instructions processing efficiency, and packaging form factors.

  Prepare an annual budget in an excel spreadsheet

Prepare working solutions in Excel that will manage the annual budget

  Write a research paper in relation to a software design

Research paper in relation to a Software Design related topic

  Describe the forest, domain, ou, and trust configuration

Describe the forest, domain, OU, and trust configuration for Bluesky. Include a chart or diagram of the current configuration. Currently Bluesky has a single domain and default OU structure.

  Construct a truth table for the boolean expression

Construct a truth table for the Boolean expressions ABC + A'B'C' ABC + AB'C' + A'B'C' A(BC' + B'C)

  Evaluate the cost of materials

Evaluate the cost of materials

  The marie simulator

Depending on how comfortable you are with using the MARIE simulator after reading

  What is the main advantage of using master pages

What is the main advantage of using master pages. Explain the purpose and advantage of using styles.

  Describe the three fundamental models of distributed systems

Explain the two approaches to packet delivery by the network layer in Distributed Systems. Describe the three fundamental models of Distributed Systems

  Distinguish between caching and buffering

Distinguish between caching and buffering The failure model defines the ways in which failure may occur in order to provide an understanding of the effects of failure. Give one type of failure with a brief description of the failure

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd