Using the guidelines provided in this week’s chapter (and other resources as needed), create a step-by-step IT security policy for handling user accounts/rights for a student who is leaving prematurely (drops, is expelled, and so on).
You will need to consider specialized student scenarios, such as a student who works as an assistant to a faculty member or as a lab assistant in a computer lab and may have access to resources most students do not.
Write your answer using a WORD document. Do your own work. Submit here. Note your Safe Assign score. Score must be less than 25 for full credit.
Computer Security Fundamentals
by Chuck Easttom
Chapter 10 Security Policies
*
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Chapter 10 Objectives
Recognize the importance of security policies
Understand the various policies and the rationale for them
Know what elements go into good policies
Create policies for network administration
Evaluate and improve existing policies
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Explain what cyber terrorism is and how it has been used in some actual cases.
Understand the basics of information warfare.
Have a working knowledge of some plausible cyber terrorism scenarios.
Have an appreciation for the dangers posed by cyber terrorism.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Introduction
Technology by itself cannot solve all network security problems.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Cyber terrorism, according to the definition of the FBI:
Premeditated, politically motivated attack against information, computer systems, computer programs, and data that results in violence against noncombatant targets by subnational groups or clandestine agents.
Typically, loss of life in a cyber attack would be less than in a bombing attack.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Introduction (cont.)
Virus software won’t prevent a user from manually opening an attachment and releasing a virus.
A technologically secured network is still vulnerable if former employees (perhaps some unhappy with the company) still have working passwords. Or if passwords are simply put on Post-it notes on computer monitors.
A server is not secure if it is in a room that nearly everyone in the company has access to.
Your network is not secure if end users are vulnerable to social engineering.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
All these could lead to significant deaths: train wrecks, hospital deaths, loss of air traffic control resulting in plane crashes, and so forth.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
What Is a Policy?
A security policy is a document that defines how an organization deals with some aspect of security. There can be policies regarding end-user behavior, IT response to incidents, or policies for specific issues and incidents.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
All these could lead to significant deaths: train wrecks, hospital deaths, loss of air traffic control resulting in plane crashes, and so forth.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Defining User Policies
Passwords
Internet use
E-mail attachments
Installing/uninstalling software
Instant messaging
Desktop configuration
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
All these could lead to significant deaths: train wrecks, hospital deaths, loss of air traffic control resulting in plane crashes, and so forth.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
System Admin Policies
New Employees
Departing Employees
Change Control
Access Control
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
All these could lead to significant deaths: train wrecks, hospital deaths, loss of air traffic control resulting in plane crashes, and so forth.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Other Issues
Bring Your Own Device
A major concern in the modern network
New Employees
Departing Employees
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Bring your own device (BYOD) has become a significant issue for most organizations. Most, if not all, of your employees will have their own smart phones, tablets, smart watches, and Fitbits that they will carry with them into the workplace. When they connect to your wireless network, this introduces a host of new security concerns. You have no idea what networks that device previously connected to, what software was installed on them, or what data might be exfiltrated by these personal devices.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Change Management
RFC
CAB
Follow-up
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Software Development Policies
Security standards
Testing
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Incident Response Policies
Handling viruses
Dealing with breaches
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
All these could lead to significant deaths: train wrecks, hospital deaths, loss of air traffic control resulting in plane crashes, and so forth.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Data Classification
Public
Secure
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
BCP and DRP
DRP
BCP
BIA
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Fault Tolerance
Backups
Full: All changes
Differential: All changes since last full backup
Incremental: All changes since last backup of any type
RAID
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Relevant Laws & Regulations
HIPAA
Sarbanes-Oxley
PCI
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
Summary
In this chapter, you learned the technology is not enough to ensure a secure network. You must have clear and specific policies detailing procedures on your network. Those policies must cover employee computer resource use, new employees, outgoing employees, access rights, how to respond to an emergency, and even how secure code in applications and websites is.
User policies must cover all aspects of how the user is expected to use company technology. In some cases, such as instant messaging and web use, policies may be difficult to enforce, but that does not change that they must still be in place. If your user policies fail to cover a particular area of technology use, then you will have difficulty taking any action against any employee who performs that particular misuse.
© 2016 Pearson, Inc. Chapter 10 Computer Security Policies
*
We provide professional writing services to help you score straight A’s by submitting custom written assignments that mirror your guidelines.
Get result-oriented writing and never worry about grades anymore. We follow the highest quality standards to make sure that you get perfect assignments.
Our writers have experience in dealing with papers of every educational level. You can surely rely on the expertise of our qualified professionals.
Your deadline is our threshold for success and we take it very seriously. We make sure you receive your papers before your predefined time.
Someone from our customer support team is always here to respond to your questions. So, hit us up if you have got any ambiguity or concern.
Sit back and relax while we help you out with writing your papers. We have an ultimate policy for keeping your personal and order-related details a secret.
We assure you that your document will be thoroughly checked for plagiarism and grammatical errors as we use highly authentic and licit sources.
Still reluctant about placing an order? Our 100% Moneyback Guarantee backs you up on rare occasions where you aren’t satisfied with the writing.
You don’t have to wait for an update for hours; you can track the progress of your order any time you want. We share the status after each step.
Although you can leverage our expertise for any writing task, we have a knack for creating flawless papers for the following document types.
Although you can leverage our expertise for any writing task, we have a knack for creating flawless papers for the following document types.
From brainstorming your paper's outline to perfecting its grammar, we perform every step carefully to make your paper worthy of A grade.
Hire your preferred writer anytime. Simply specify if you want your preferred expert to write your paper and we’ll make that happen.
Get an elaborate and authentic grammar check report with your work to have the grammar goodness sealed in your document.
You can purchase this feature if you want our writers to sum up your paper in the form of a concise and well-articulated summary.
You don’t have to worry about plagiarism anymore. Get a plagiarism report to certify the uniqueness of your work.
Join us for the best experience while seeking writing assistance in your college life. A good grade is all you need to boost up your academic excellence and we are all about it.
We create perfect papers according to the guidelines.
We seamlessly edit out errors from your papers.
We thoroughly read your final draft to identify errors.
Work with ultimate peace of mind because we ensure that your academic work is our responsibility and your grades are a top concern for us!
Dedication. Quality. Commitment. Punctuality
Here is what we have achieved so far. These numbers are evidence that we go the extra mile to make your college journey successful.
We have the most intuitive and minimalistic process so that you can easily place an order. Just follow a few steps to unlock success.
We understand your guidelines first before delivering any writing service. You can discuss your writing needs and we will have them evaluated by our dedicated team.
We write your papers in a standardized way. We complete your work in such a way that it turns out to be a perfect description of your guidelines.
We promise you excellent grades and academic excellence that you always longed for. Our writers stay in touch with you via email.