Free Essay

Computer Science Xyz Company

In:

Submitted By ceeeeza123
Words 1011
Pages 5
About Organization:
ABC Inc. is a leading telecom provider with a customer base of over million of users. It provides all the telephone and internet services to its customers.

Management Controls

Risk Management
ABC Inc. is ready with the disaster recovery technique, so the risks can be handled in the organization with care and proper management; they are also maintaining a risk assessment report.
Review of Security Controls
They have documented the security plan for the organization and they keep on reviewing and improving the same.
Lifecycle
It deals with the configuration management system implemented in the company. On every Wednesday, the management plans a meeting for a change request. All the things regarding the change is discussed in the meeting, like why the change is required, what would be its benefits & is their any risk to execute them in the system, etc. The company has a separate development and pre-production environments set-up, so whenever any change is required in the system, the changes are done on Development environment, if it is successful, the same is replicated in pre-production environment. After the successful implementation in dev. and pre-prod environments the changes are done in the production system. But before implementing any changes in production environment, you need an approval from the same from the CMS Team, and this approval is taken in the change management meeting.
Certification and Accreditation
Company is following all the certification and accreditation and they have documented the same.
System Security Plan
ABC Inc. has deployed https protocol; they are following other security measures as well and have documented the same too.

Operational Controls

6. Personnel Security
The users are not trained on the security of the system; they have not taken any security awareness training. They have read the rules of behavior for the system but they are not following it practically. Users who have direct access to the system have not gone for any background investigations.There are no clearly defined duties between programmers and administrators.
7. Physical Security
The Physical security is being provided to the system by manpower and by using access restricted zones in the organization. The system is also prepared for any disaster recovery by using disaster recovery management.
8. Production, Input/Output Controls
The input for the production is the responsibility of only the authorized users. The data is sensitive and it can be retrieved after its disposal. The company has not as such implemented any controls for data disposal.
9. Contingency Planning
The company takes back-up after each month’s end.The system can be restored using OIM.Restoration of the system can take few minutes to an hour.Back-up procedures have been tested successfully.
10. HW/SW Maintenance
The HW/SW is maintained using oracle guidelines. All the required security patches have been implemented in the system.
11. Data Integrity
There are no measures to control the virus attack which may result into a lot of hazards.
12. Documentation
The company is following proper documentation. It has documented the security plan, risk evaluation & assessment report, etc.
13. Security Awareness and Training
The security awareness training has been provided only to limited number of employees, these employees are part of the upper-management. Rest of the employees does not know much about the security training.
14. Incident Response
If an incident occurs in the company, the reporter reports to the IT Helpdesk guys at the toll-free numbers and then they route the call to the concerned employee and then the action is taken. The logs are maintained for all this purpose.

Technical Controls
15. Identification and Authentication
ABC Inc. is following user and access management based on Oracle Identity Manager (OIM) and Oracle Access Manager (OAM). Every user is assigned with a unique user-id and password so that they can manage their unique identity in the organization so that the system can authenticate the valid user.
16. Logical Access Controls
Their access is defined on the role they have in the organization so they are following the logical access control by using the access policies created in the Oracle Access Manager. So a Manager is having different resource access as compared to his subordinates. Session Control: There is a time-line of 10 minutes for session expiration, it means if a user is inactive from past 10 minutes, his session will be expired. This policy has been implemented using OAM. A user can have various concurrent session logins from various machines which is a big flaw in the system which should be taken care by the organization.
17. Audit Trails
The Audit trails are done at the end of every quarter.

Analysis ABC Inc. is successfully following most of the management, operational and technical controls but it has to work on the loopholes analyzed in the system, because these loopholes can create hazards in the system. The company is following identity and access management platform supported by oracle identity and access manager. The user identities are also stored effectively in Active-Directory. It is good in managing the change configuration system for its up gradation. Various environments have been set for deploying and testing purpose. Audit trails are regularly followed. So, basically ABC Inc is doing well from the Technical controls view. There are some issues in Operational controls, like the employees are not very well aware regarding the security of the system. Proper training must be provided to the individual, this is necessary for the security of the system. There are no measures for virus protection which can create havoc in the system. But it is good in maintaining contingency planning and incident reporting. Company is following a proper lifecycle. There is a well-defined hierarchy to take the necessary approvals and all.

Action-Plan

• The first and the most important step is to implement measures to protect the system from virus attacks. • Provide security training for all the employees. • Implement some data disposal techniques in the system. • Maintain logs for all the major and minor transactions in the system.

Similar Documents

Premium Essay

Printer and Summer Spain

...Margaret L. Weaver | | |P.O. Box 0000 ( Sometown, 2000 ( (0400) 555-555 ( margaret@somedomain.com | | | E nterprising, hard-working and technically skilled accounts payable specialist known for accuracy, attention to detail and timeliness in managing disbursement functions for diverse-industry employers. A/P career spans 17 years of experience in manufacturing, retail, higher education and other industries and has included accountability for the processing of up to 20,000 invoices ($1M) per month. Backed by solid credentials (BS in accounting) and proficiencies in generally accepted accounting practices as well as MS Office Suite, Great Plains software, QuickBooks, ERP/EDI systems and SAP. See CareerOne’s advice articles, videos and resume building tool here | | |Key Skills | | ...

Words: 870 - Pages: 4

Premium Essay

Application of Management Science in Business

...Department of Management Information Systems Assignment on: Application of Management Science in Business [Type the document subtitle] Course Title: Management Science Course Code: EMIS 517 Submitted to: Professor Dr. Abdul Hannan Mia Honorable Course Teacher, Dept. of MIS Submitted by: Name | ID | Batch | Md. Al-Mamun Riyadh | 61427-20-079 | 20th | Abdullah-Al-Kashem | 61427-20-006 | 20th | Submission date: 31st August, 2014 Management Science Management Science is concerned with developing and applying models and concepts that help to clarify management issues and solve managerial problems. The models used can often be represented mathematically, but sometimes computer-based, visual or verbal representations are used. The range of problems and issues to which management science has contributed insights and solutions is vast. It includes scheduling airlines, both planes and crew, deciding the appropriate place to site new facilities such as a warehouse or factory, managing the flow of water from reservoirs, identifying possible future development paths for parts of the telecommunications industry, establishing the information needs and appropriate systems to supply them within the health service, and identifying and understanding the strategies adopted by companies for their information systems. Scientific Planning Successful management relies on careful coordination, often using scientific methods in project planning...

Words: 3150 - Pages: 13

Free Essay

Corporate Internal Communication

...Abstract 3 Company Background 3 Business Problems 3 High-Level Solution 4 Benefits of Solving the Problem 5 Approach 5 Technology Used to Augment the Solution 5 Conclusions and Overall Recommendations 7 High-level Implantation Plan 8 Summary of Project 8 References 10   Corporate Internal Communication for XYZ Company Abstract The business problem to be solved is how to improve business processes, employee engagement, business development, enabling global collaboration, enhancing project collaboration, and reduce IT costs for a greater opportunity and genuine, measurable success of the company. Company Background XYZ is a fully integrated engineering, architecture, construction, environmental and consulting firm with a multidisciplinary staff of more than 3,000 professionals worldwide. With annual revenues of $1.9 billion, XYZ is a network of highly skilled engineers. Founded in 1922, XYZ pitching their engineering solutions to municipalities across the country and putting to work its precise technical skills, their success continued for decades. The company needs to improve communications between corporate and employees at head office, its 55 regional office throughout the countries, and 3 branches outside the country. Business Problems XYZ needs access to timeous information to respond quickly to an uncertain business environment. The executives and managers are feeling overwhelmed by the huge amount of information generated by the company. In order...

Words: 2013 - Pages: 9

Premium Essay

Go Green with Cloud Computing-Benefits to Hr

...` Title: Go-Green with Cloud Computing: Benefits to HR Name: Mala Srinivas & Animesh Giri (Assistant Professor, Dept of Information Science technology, PEs Institute of Technology-BSc) Affiliation: III Semester, MBA – HR, PES Institute of Technology – BSc Email: Mala.s44@gmail.com animeshgiri@pes.edu Title: Go-Green with Cloud Computing: Benefits to HR Name: Mala Srinivas Affiliation: III Semester, MBA – HR, PES Institute of Technology – South Campus, Bangalore Email: Mala.s44@gmail.com ABSTRACT Cloud Computing is the hot topic in today’s World. Cloud computing comes with the great advantage of providing higher energy savings, a fact which translates into being environmentally friendly. In the last few years, technology has improved immensely, taking the environment into account and providing a solution for those worrying about carbon footprints and the impact of technology into the environment. In the last couple of decades, HR has re-invented itself from the mundane activities like Industrial Relations, labour etc. to the front of a Company’s Business radar on par with Marketing, Finance, Administration and other departments. HR managers today use hundreds of strategic and collaborative technology tools to keep up the HR function fast moving. But lot of these technology tools is not implemented in a large number of Small & Medium Enterprises (SME) who forms 75% of our country’s market. Why? Because many of the SME’s are of...

Words: 2648 - Pages: 11

Premium Essay

Brazil Market R

...eserach Market Research: Research Methodology Introduction XYZ Inc wants to launch its top-selling product in the Brazilian market and the company needs to conduct a research before entering into the market. Brazil is a South American Country and is the fifth largest country in the world in terms of the geographical area. Among the most populous countries in the world, Brazil acquires fifth position and it is fourth among the most populous democracy in the world. Brazil has a diversified middle-income economy and it is one of the ten largest economies in the world. Its economy has wide variations in the manufacturing, agricultural and mining sectors and in the levels of development. Technology and service sectors also play a significant role in its economy and are growing rapidly (Infoplease, 2005). Objective The objective of the research is to design the research methodology to sell the top-selling product of the XYZ Inc. in Brazil. The different objectives, which the company wants to achieve with the help of the research, are various in numbers. Some of them are: • The company wants to study the market size, market potential and market growth. • The study of market profile and market characteristics is also one of the objectives of the research. • The analysis of market share and market segment. • The measurement and forecasting of the sale for the short run and long run. • The identification of complete business...

Words: 1178 - Pages: 5

Premium Essay

Student

...INFORMATION SECURITY SPECIALIST Multicertified Expert in Enterprise Security Strategies Infosec specialist whose qualifications include a degree in computer science; CISSP, MCSE and Security+ designations; and detailed knowledge of security tools, technologies and best practices. Nine years of experience in the creation and deployment of solutions protecting networks, systems and information assets for diverse companies and organizations.  TECHNOLOGY SUMMARY * Security Technologies: Retina Network Security Scanner; SSH; SSL; Digital Certificates; Anti-Virus Tools (Norton, Symantec, Ghost, etc.) * Systems: Unix-Based Systems (Solaris, Linux, BSD); Windows (all) * Networking: LANs, WANs, VPNs, Routers, Firewalls, TCP/IP * Software: MS Office (Word, Excel, Outlook, Access, PowerPoint) KEY SKILLS * Network & System Security * Risk Management * Vulnerability Assessments * Authentication & Access Control | * System Monitoring * Regulatory Compliance * System Integration Planning * Multitier Network Architectures | IT EXPERIENCE * XYZ Co., Sometown, FL, Information Security Consultant, 2009-Present * ABC Co., Sometown, TN, Senior Information Security Specialist, 2004-2008 * 123 Co., Sometown, FL, Information Security Specialist, 2002-2004 * R&R Ltd., Sometown, FL, Network Administrator, 2000-2002 Became an expert in information systems security for multiple clients and employers.  Recent Project...

Words: 368 - Pages: 2

Premium Essay

Intership

...Cover Letters and other career correspondence Your letter is your introduction —it continues or starts a conversation about work or education Just as you start a conversation by introducing yourself, a résumé should always be sent with an accompanying letter. Picture yourself sitting face-to-face with a person doing work that is interesting. What would you say? What do you want to ensure they know about you before you leave the room? Your letter is a chance to make a great first impression or continue a conversation that has already been started. Your letter is something employers expect —it shows your professionalism and helps them get to know you Every time you submit a résumé, you should attach an accompanying letter. Even if they don’t specifically request it, employers expect documentation from you that shows your professionalism and potential contributions. What better way to start than by using a cover letter? Your letter should clearly show the match —it illustrates the connections between you and the work Some employers scan your résumé first, while others start with the cover letter. To increase your chances of being invited to an interview, ensure that both documents clearly show the match between what the employer needs and what you can contribute. Once you have made the match, remember that the letter is your chance to stand out as an individual from the many other qualified applicants. Include information that supports and points to your résumé, without...

Words: 1716 - Pages: 7

Free Essay

Student

...Tianyi “Cindy” Wang 1717 Broadway Street, Apt. #C New Orleans, LA 70118 (504)344-0647 twang6@tulane.edu EDUCATION Tulane University, A.B. Freemen School of Business New Orleans, LA Master of Accounting May 2016 Upon graduation, I will have met the educational requirements to sit for the CPA exam and become licensed in the state of NY, CA, TX, and MA. Tulane University, A.B. Freemen School of Business New Orleans, LA Bachelor of Science in Management May 2016 Major: Finance Overall GPA: 3.79 Finance Major GPA: 3.88 (13 courses) Accounting Major GPA: 4.0 (4 courses) Honors: Dean’s List (3 semesters) Burkenroad Reports, Research Equity Analyst (Currently Enrolled) • Interviewed management, conducted industry and business analyses, and produced cash flow and earning models as member of four-student team in nationally recognized securities research program • Published an investment research report on Company XYZ (Stock Index / Market-Nasdaq, NYSE, AMEX), based on our findings, which will be presented at the annual conference in April EXPERIENCE ALPHA LAMBDA DELTA, Women’s honor society New Orleans, LA President May 2014- Present • Elected by fellow students to provide leadership to the entire society • Coordinated with other executive members to disseminate information on proposal • Developed legacy plan to encourage new students to join the committee KPMG Shanghai...

Words: 294 - Pages: 2

Premium Essay

A Carbon Footprint Based Reverse Logistics Network Design Model

...Resources, Conservation and Recycling 67 (2012) 75–79 Contents lists available at SciVerse ScienceDirect Resources, Conservation and Recycling journal homepage: www.elsevier.com/locate/resconrec Full length article A carbon footprint based reverse logistics network design model Devika Kannan a,∗ , Ali Diabat b , Mahmoud Alrefaei c , Kannan Govindan d , Geng Yong e,∗ a Indian Institute of Industrial Engineering, Navi Mumbai, India Engineering Systems and Management, Masdar Institute of Science and Technology, Abu Dhabi, United Arab Emirates c Department of Mathematics and Statistics, Jordan University of Science and technology, Irbid 22110, Jordan d Department of Business and Economics, University of Southern Denmark, Odense, Denmark e Institute of Applied Ecology, Chinese Academy of Science, Shenyang, Liaoning Province 110016, PR China b a r t i c l e i n f o Article history: Received 2 March 2011 Received in revised form 12 March 2012 Accepted 12 March 2012 Keywords: Carbon footprint Reverse logistics Greenhouse emissions Case study a b s t r a c t Due to the environmental legislation and regulations, manufacturing firms have realized the importance of adopting environmental friendly supply chain management (SCM) practices. In this paper, a mixed integer linear model is developed for a carbon footprint based reverse logistics network design. The proposed model aims at minimizing climate change (specifically, the CO2 footprint),...

Words: 4160 - Pages: 17

Premium Essay

Cover Letter

...COVER LETTER SAMPLES Your Name Your Street Address City, State, Zip Date Employer’s Name Title Company Street Address City, State, Zip Dear Mr. or Ms. Last Name: Your opening paragraph should briefly introduce you and your interest in the company. If you are aware of a specific position or opening, refer to it now. This paragraph should also be used to mention the names of individuals you have met from the company (e.g., at the EIS, company event or other networking event), or the individual who directed you to this person. Cite other research that prompted you to write, such as a recent article on the company or a positive networking interaction. The last line in this paragraph should give a summary statement of who you are and why you are a strong fit for the position. Your middle paragraph (or two) should consist of specific examples from your background that would be of greatest interest to the company and consequently create the “notion of fit.” Do not just make broad generalizations about your skill set – any assertions about your skills have to be backed up with specific examples of how/why you have developed those skills. Focus on your skills and accomplishments and how they could contribute to the company, but do not simply restate what is on your resume. Demonstrate that you know about the organization and the industry. If you are a career changer, it is essential to clearly state your transferable skills from previous experience that directly...

Words: 4257 - Pages: 18

Free Essay

Career

...RESUMES WHAT IS A RESUME? A resume is a custom designed, written summary of your background. It provides a thumbnail sketch of your education, experience, and qualifications to a prospective employer. An effective resume targets a specific type of position and relates your skills and experience to that position. WHO WRITES A RESUME? A resume is written by anyone seeking employment, both part-time and full-time. Although there are companies that provide resume-writing services, the most effective resumes are written by the job seeker--after all, who else knows you, your qualifications, and your experiences better--someone you just met, or you? WHAT IS THE PURPOSE OF A RESUME? A good resume (in combination with a cover letter) will provide you with an interview. The employer will select applicants on the basis of how well their skills match up with the job requirements. Sometimes, the difference between getting an interview and being placed in the “no” pile is a well put-together resume. GENERAL RESUME GUIDELINES: Length: • A one-page resume works for the recent graduate. If you have extensive work history, two pages are reasonable. Remember to limit pertinent to what is important to the current job objective. Appearance: • Developing a well organized, readable layout determines if it gets read! Direct the reader’s eyes to the format. • Avoid dense text appearance, which is difficult to read. • Use high-quality white or off-white paper--stay conservative...

Words: 3001 - Pages: 13

Premium Essay

Student

...BDS 4614, Management Decision Science Trimester 2, 2013/2014 Due date: 10/01/2014 (Week 12) before 12pm General information: Organisation | Individual | Assessment | This assignment contributes to 15% to the total coursework marks. | Student Learning Time | This assignment shall take 6 hours to complete. | Submission requirements | Submission to | Mr.Oh | | Cover page | Please use the attached cover page | | Typeface/Font | Times new Roman | | Font size | 12 | | Line spacing | 1.5 | | Margins | Top: 2.54 cm; Bottom: 2.54cm; Left: 2.54cm; Right: 2.54cm | | Reference format | APA Style | | Binding | Stapled/Comb binding | Mapping of assignment learning outcomes to subject learning outcomes: Assignment’s Learning OutcomesUpon completion of this assignment, students should be able to: | Subject Learning OutcomesUpon completion of this subject, students should be able to: | 1 | Structure LP problems using the transportation model | LO2 | Diagnose the business decision making problems and formulate as a mathematical problems | 2. | Use Excel Spread sheets to solve Linear Programming Problem | LO3 | Apply appropriate tools for problem solving | 3. | Perform Monte Carlo Simulation Using QM for Window software or Excel Spread Sheets. | | | Assessment rubrics Score | Description | 80% - 100% | * Demonstrate complete understanding of the problem * Original contribution * All requirements are included. * Report is well organised...

Words: 674 - Pages: 3

Premium Essay

It Report Guidelines

...Page 1 of 26 Shaheed Udham Singh College of Engg. &Technology,Tangori(Mohali) Department of computer Science & engineering TABLE OF CONTENTS 1) Format for synopsis. 2) Format & Guidelines for Midterm Report. 3) Guidelines for preparing six-months industrial training report 3.1) Standards for Project Report 3.2) Format of Title Page 3.3) Declaration 3.4) Acknowledgement 3.5) Certificate 3.6) Abstract 3.7) Table of contents for the final report. 3.8) List of figures 3.9) Format of final report. 4) Annexure I 5) Annexure II 6) Annexure III 7) Annexure IV 8) Annexure V 9) Annexure VI Page 2 of 26 Guidelines for Preparing Six Months Industrial Training Report Department of Computer science & Engineering Shaheed Udham Singh College of Engineering and Technology,Tangori(Mohali) (www.suscet.ac.in) SHAHEED UDHAM SINGH COLLEGE OF ENGG. & TECHNOLOGY Page 3 of 26 (NAME OF THE DEPARTMENT) Format for Synopsis Title page: 1. Name of Student and PTU registration No cum Roll No 2. Present official Address with E-mail, telephone No 3. Branch 4. Session 5. Name of Company 6. Proposed Project Topic: 7. Name of Department/College Introduction to Company(may not exceed 3 pages including Figs.) Brief Introduction to Project (may not exceed 3 pages) Design of solution (may not exceed 3 pages) Methodology/ Planning of work (may not exceed 4 pages) Facilities provided for the proposed work. Page 4 of 26 SHAHEED UDHAM SINGH COLLEGE OF ENGG. & TECHNOLOGY (NAME OF THE...

Words: 1815 - Pages: 8

Free Essay

Sdg Dg

...Notes AP Notes Citation Generator More Case Analysis Of Ann Taylor Survival In Specialty Retail Essays and Term Papers Search Advanced Search Documents 1 - 20 of 1000 Book Review of Business Policy and Strategy: an Action Guide Book Review of Business Policy and Strategy: An Action Guide Submitted in partial fulfillment of B.S. in Business Administration Century University, New Mexico Grade = 95% {A} Business Policy and Strategy: An Action Guide, by Robert Murdick, R. Carl Moor and Richar Premium 4514 Words 19 Pages Burger King and Its Advertising Campaigns Burger King and Its Advertising Campaigns Burger King is a reliable burger company which has had its ups and downs. In 1974, it came out with a slogan of "Have it your way" and at this time it also had a 4 % market share. Burger King's idea was to have the customer have their burger done their w Premium 1694 Words 7 Pages Foreign Aid Foreign Aid There are two words that many politicians like to shy away , and those two words are, "foreign aid." Taking a firm stand on either side of this topic is usually side stepped by decision makers. Their opinions are usually based on a case by case analysis. This extremely controv Premium 1773 Words 8 Pages Rainforest Cafe, Inc: Outline to Rainforest Cafe Research Report Rainforest Cafe, Inc: Outline to Rainforest Cafe Research Report CORPORATE BACKGROUND History Formation Rainforest...

Words: 1227 - Pages: 5

Premium Essay

Project Management

...of broader social, economic and political trends. Mental health as a general public concern – and its role in the workplace – has garnered increasing attention over the past several years. One in five Canadians will experience a mental disorder in their lifetime. Whatever the reason for this new awareness, mental illness and poor mental health is now being recognized as a major business concern. 3 In order for workplace health promotion to be adopted, it must make a difference to the financial bottom line and be presented as a strategic priority to organizations. Taking a proactive approach to protecting employees’ mental health is the right move for organizations looking to keep a healthy staff team and a healthy budget. There this company, XYZ want to help improve the mental health of employees as it is beneficial in helping both the individual and the whole organization to achieve long-term excellence. As a result, a detailed project plan is described in the report that tells how the overall project will be carried out. 3 1 The Definition of Project 3 1.1 Project Objectives: 4 2. Business Projects: 4 Key Personnel Involved is: 5 2.1Assessment of costs relating to stress and psychosocial risks 5 2.2 Methodology for Carrying out the Project: 6 Creating a Healthy Workplace Committee 6 2.3 Conducting a Situational Assessment – Getting to the Root of the Problem 7 2.4 Developing a Healthy Workplace Plan 8 2.4.1 Types of planning 8 2.5 Role and responsibilities...

Words: 4745 - Pages: 19