What is the purpose of your proposal

Assignment Help Computer Network Security
Reference no: EM131650666

Assignment: Milestone One Guidelines

The final project for this course is the creation of a security awareness program proposal. In Module Two, you will take the first step in completing this project by creating the introduction section of your proposal. Begin by reviewing the Case Document, which will provide you with information about the organization for which you are creating the security awareness program proposal. Then, based on the scenario provided in the Case Document, write an introduction to your proposal that addresses the concerns of the chief executive officer and explains why the security awareness proposal will be vital to the organization. Specifically, the following critical elements must be addressed:

• What is the purpose of your proposal? Why is the new security awareness program vital for the organization? Use specific examples to illustrate your claims.

• Overall, how would you characterize the security posture of the organization? What were the major findings in your risk assessment of the organization's current security awareness policies, practices, and processes?

• Specifically, are there human factors that adversely affect the security climate within the organization? If so, how? Be sure to consider unintentional and intentional threats to a healthy security culture.

• Specifically, are there organizational factors that contribute to an unhealthy security culture in the organization? If so, how? Be sure to consider organizational data flow, work setting, work planning and control, and employee readiness.

Case for Project

BACKGROUND:

You were just hired as the new chief information security officer for Multiple Unite Security Assurance (MUSA) Corporation whose security posture is low. The first thing your chief executive officer tells you is that they have recently seen a presentation by one of the information security team members emphasizing the importance of having a security awareness program. As a result, you have been asked to develop a security awareness program for MUSA Corporation based on the following 10 security gaps:

1. No annual cyber security awareness training, which is causing high phishing and social engineering attacks
2. No configuration change management policy (to reduce unintentional threats)
3. No intrusion detection/prevention system
4. Logs are not being collected or analyzed
5. No media access control policy
6. No encryption or hashing to control data flow and unauthorized alteration of data
7. Vulnerability assessment is conducted every three years; unable to assess the security posture status
8. High turnover and low morale among the employees (due to lack of employee readiness programs and work planning strategy)
9. High number of theft reports and security incidents; possible unethical/disgruntled employees
10. No segregation of duties or mandatory vacation policies (to mitigate intentional threats)

To that end, you will make recommendations for enhancing security policies, practices, and processes that are currently contributing to a dysfunctional security culture. Your chief goal is to build a program that will foster a healthy security culture and ensure continuous improvement.Your task is to develop a security awareness program that consists of four major components:

1. Statement of work that includes objectives, goals, business requirements, technical requirements
2. Security policies and procedures to address the company's 10 security gaps
3. Continuous monitoring plan
4. Communication plan.

Reference no: EM131650666

Questions Cloud

Discuss case of the security enhanced linux : Security Enhanced Linux (SELinux) was designed and developed by a team from the U.S. National Security Agency and private industry.
What is the present value : If my discount rate is 12%, what is the present value, and should I go forward with the project?
Find the contribution margin per haircut : Find the contribution margin per haircut. Assume that the barbers' compensation is a fixed cost. Show calculations to support your answer.
Compose a business letter to an external customer : Compose a business letter to an external customer. Assume that there are no enclosures; and since you are the typist,
What is the purpose of your proposal : What is the purpose of your proposal? Why is the new security awareness program vital for the organization? Use specific examples to illustrate your claims.
Which type of resources would the firm require : How does GE's framework give it the opportunity to be at the forefront of the markets in which it participates?
Find the prefered bundle : For each utility function find the prefered bundle between X=(4 cloth,3pen) and Y=(5 cloth,10pen). Whether X is preferred to Y or Y is preffered.
Your own business and had problem with employee theft : If you owned your own business and had a problem with employee theft, would you use an integrity test? Why or why not?
Examination of a program''s overall effectiveness : All public agencies receive a program evaluation, which is an external examination of a program's overall effectiveness.

Reviews

Write a Review

Computer Network Security Questions & Answers

  An overview of wireless lan security - term paper

Computer Science or Information Technology deals with Wireless LAN Security. Wireless LAN Security is gaining importance in the recent times. This report talks about how vulnerable are wireless LAN networks without any security measures and also talk..

  Computer networks and security against hackers

This case study about a company named Magna International, a Canada based global supplier of automotive components, modules and systems. Along with the company analysis have been made in this assignment.

  New attack models

The Internet evolution is and is very fast and the Internet exposes the connected computers to attacks and the subsequent losses are in rise.

  Islamic Calligraphy

Islamic calligraphy or Arabic calligraphy is a primary form of art for Islamic visual expression and creativity.

  A comprehensive study about web-based email implementation

Conduct a comprehensive study about web-based email implementation in gmail. Optionally, you may use sniffer like wireshark or your choice to analyze the communication traffic.

  Retention policy and litigation hold notices

The purpose of this project is to provide you with an opportunity to create a document retention policy. You will also learn how to serve a litigation hold notice for an educational institute.

  Tools to enhance password protection

A report on Tools to enhance Password Protection.

  Analyse security procedures

Analyse security procedures

  Write a report on denial of service

Write a report on DENIAL OF SERVICE (DoS).

  Phising email

Phising email It is multipart, what are the two parts? The HTML part, is it inviting the recepient to click somewhere? What is the email proporting to do when the link is clicked?

  Express the shannon-hartley capacity theorem

Express the Shannon-Hartley capacity theorem in terms of where is the Energy/bit and is the psd of white noise.

  Modern symmetric encryption schemes

Pseudo-random generators, pseudo-random functions and pseudo-random permutations

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd