Business needs-information security, Computer Network Security

Assignment Help:

BUSINESS NEEDS

Information security performs four main functions for an organization.

1. Protects the ability of organization to function.
2. Enables safe operation of applications implemented on organization’s its IT systems.
3. Protects data which the organization collects and uses.
4. Safeguards technology assets in use at the organization

Both general management and IT management responsible for implementing information security which protects the organization’s ability to function. Information security is management issue and people issue both as they perceive it to be a technically complex task; actually implementing information security has much to do with management than with technology.

Each and every organization should address information security in the terms of business impact and cost instead of focusing on security as a technical problem.

Enabling the Safe Operation of Applications

Modern organization is required s to create an environment which safeguard applications by using the organization’s IT systems. Like operating system (Windows/Unix/Linux etc.,), electronic mail, and instant messaging (IM) applications. Management should continue to oversee infrastructure once in place—not defer to IT department.

Protecting Data that Organizations Collect and Use

Without data, an organization loses the record of transactions and ability to deliver value to customers. Both protecting data in motion and data at rest are significant aspects of information security.

 Safeguarding Technology Assets in Organizations

To perform effectively, organizations should posses secure infrastructure services based on size and scope of enterprise. For example, a small business can get by using an e- mail service provided by an ISP and augmented with the personal encryption tool. Additional security services may be required as organization expands. For instance, organizational growth could lead to the requirement of public key infrastructure (PKI), an integrated system of software, legal agreements and encryption methodologies which can be used to support entire information infrastructure of an organization. More robust solutions may be required to replace security programs the organization has outgrown.


Related Discussions:- Business needs-information security

What is an autonomous system, QUESTION 1: a) Differentiate between a r...

QUESTION 1: a) Differentiate between a routing protocol and a routed protocol. b) Describe any three design goals of Routing protocols. c) Lists some of the features shared

Distinguish between passive and active attacks, Problem (a) Distinguis...

Problem (a) Distinguish between passive and active attacks. (b) Give two reasons why it is important to organise security awareness programs for users. (c) Describe how

Short term scheduler, Short term Scheduler function , also shown as a disp...

Short term Scheduler function , also shown as a dispatcher runs most frequently, and creates the finest-grained decision of which program could run next. This scheduler is called

Explain the basic network topologies, Question: (i) ‘Implementation' is...

Question: (i) ‘Implementation' is a critical stage of the Systems Development Life Cycle. Show the four approaches which are commonly used to implement information systems in

TCP/ ip, Q1 (15 marks, 5 marks each part): This question has three parts: ...

Q1 (15 marks, 5 marks each part): This question has three parts: In a short paragraph (200-300 words) explain the fundamentals of Packet Switching and how it works. In a short pa

Packet filtering firewall-stateless packet filtering, Stateless Packet Filt...

Stateless Packet Filtering Stateless or static packet filtering is the most straightforward kind of packet filtering that allows or disallows data transfer based on the addres

Mention most relevant clause of iso 27001:2005, QUESTION (In this ques...

QUESTION (In this question, you will need to use the ISO 27001:2005 and ISO 27002:2005 standards) For each of the situations below, comment on the following: 1. Mention

Enterprise information security policy (eisp), Enterprise Information Secur...

Enterprise Information Security Policy (EISP) EISP also known as security policy directly supports the mission of the organization and sets the strategic direction, scope, and t

Udp- datagram transport service, UDP- DATAGRAM TRANSPORT SERVICE INT...

UDP- DATAGRAM TRANSPORT SERVICE INTRODUCTION:  UDP is the one of the transport protocols in TCP/IP protocol suite. UDP protocol accepts applications on the computers to

Asset identification and valuation-information security, ASSET IDENTIFICATI...

ASSET IDENTIFICATION AND VALUATION This process begins with identification of assets that includes all elements of an organization’s system (people, procedures, data and informa

Write Your Message!

Captcha
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd