Premium Essay

Security Awareness

In:

Submitted By katdylan
Words 2691
Pages 11
Information Security - Security Awareness

Abstract: 3
Security Awareness 4 Regulatory Requirements for Awareness and Training 7
References 13

Abstract:

Information security means protecting information and information systems (IS) from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction. A policy can be described as a set of principles intended to manage actions. An Information Security Policy (ISP) is a defined set of principles intended to protect information and information systems by controlling the actions allowed within an organization.

There is not a single off the shelf approach to implement an ISP. The ISP is tailored to the specific organization and defined by the environment of the IS, the classification of the information, governance and compliance laws, and the levels of acceptable risk to the organization.

An IPS has many areas to cover but the most prominent subject matter is risk management. Risk management addresses an organization's assets exposure to environmental risks. Since risk management is continuous and must be reevaluated whenever changes are introduced into the environment or when a breach of the policy has occurred so should the ISP.

Policies must be useable, workable and realistic. In order to truly measure the effectiveness of an ISP measurements or metrics must be defined in order to grade or rate the effectives. ISPs that are not applicable, reviewed or updated can end up simply as “shelfware”. This means that they are designed, printed and stored on a bookshelf. An ISP that is not continually reviewed, measured and maintained is not effective in today’s fast paced and competitive computer age.

Security Awareness

Information is the lifeblood of an organization, and represents a fundamental business asset in today’s

Similar Documents

Premium Essay

Security Awareness Training

...Security Awareness Training Security Awareness Training Paper Patton-Fuller Community Hospital (PFCH) maintains strict confidentiality of their information via four different information systems. Accurate, reliable, and prompt information must be provided to those that need to make decisions based on several predetermine conditions. In a hospital environment, like PFCH, information is predominantly passed via computer systems. Management cannot have the luxury of minimizing the importance of systems security at all levels of their staff. The writer intends to provide a security awareness training plan for PFCH in the following paragraphs (Apollo Group Inc., 2013). Which employees should be trained, why, how, and when? All employees must be trained to protect the confidential information kept in the hospital. That means senior management, employees (regular or temporary), contractors, doctors, nurses, and anyone that has or could gain access to confidential information like partners and volunteers. Information like Personal Identifiable Information (PII), patient records, hospital financial information, staff payroll and personal records, to mention a few, must be protected against physical or electronic attacks. Making all personnel aware of potential threats, vulnerabilities, reporting security breaches and the PFCH security policies deters or makes it difficult for possible data hackers to acquire hospital confidential information (Gregory, 2010). The best ways...

Words: 607 - Pages: 3

Premium Essay

Security Awareness Training

...Security Awareness Training Jay Phillips GMGT/431 September 14, 2015 Shivie Bhagan Security Awareness Training With the ever increasing use of technology to be more productive and save on materials costs, more and more companies are converting their data electronically. Some data contains customer’s information while other data may contain confidential information about a company and how it operates. Just because data is sitting on a server somewhere in a locked data center or perhaps a company stores all their data in the cloud, it doesn’t necessarily mean that it is safe where it is at. This is why there is a demand for Security Awareness Training. According to Rouse (n.d.), security awareness training is a formal process for educating employees about computer security. Why would educating employees about computer security be so important? There are many different levels of end users and most do not know the first thing about protecting valuable data. Patton Fuller Hospital is an ideal candidate to implement security training with its employees. PFH has multiple sites, including Doctors who connect from home to review patient data. What kind of training should be implemented? General security training should cover topics such as the company’s policies and procedures, who to contact if an employee believes they have identified a security risk or threat, and rules for how to handle confidential information. General security training also has the potential of combining...

Words: 527 - Pages: 3

Premium Essay

Security Awareness Proposal

...to for effective communications, and increase security awareness in the organization. Please be sure to create this portion of the final proposal with all elements in mind as you prepare this portion. Final Course Project Proposal (22%) You have been hired as the new protection officer for ESL Inc. ESL Inc. has a large facility over 900 employees can be in at any given time. The organization has core hours from 8 AM to 6 PM but workers arrive at the organization as early as 6 AM and leave as late as 9 PM. The organization has 3 guards that work core hours only, posted at the front entrance to the building. Employees have badges that have their picture and key cards that let them in the building. The security guards open the door and check badges in the event a key card does not work. There is no security to prevent users from getting on the grounds, the front of the organization is off a major highway, and the back of the plant is backs up to acres of undeveloped woods. ESL Inc was just awarded a federal contract and after the site visit they were told they would lose the lucrative contract if they did not make their organization secure. As the new protection officer, you are to create a comprehensive proposal to make the facility secure which includes the following elements: * New adequate security staffing levels and shifts * Effective plan to increase communications * Plan to raise security awareness in the organization * Automation operations...

Words: 368 - Pages: 2

Free Essay

Journal

...Journal 01 Week: Two Date:18/08/2010 Words: 532 Task/Incident: Introducing and Socializing Selecting & Describing With the fear of not knowing anyone I entered in the first class of the Leadership and Organisation Dynamics. As not being a native English speaker I was worried that either the members of the groups will take me into their groups. As the class began my tutor John asked us to write our names in a tag and wear it, we were also required to sit in away so that we are facing each other in the class. John then asked to start the first activity which was to introduce the member sitting in front of each of the students. My mate sitting in front of me was Liam and he is working in hospital as a part time employee. On the other hand Abdul sitting next to me is doing HR as major. I felt that by undertaking this activity john was trying to develop our team or classmates and build strong relationship within our group. The activity enabled students get to know each other and It was about to think which group or people I would join for the group task. Finally at the end of the class john formed us in a small group and also helped us to understand the unit outline. Reflecting & Inferring By being a part of the introductory class I realised that we were all in the same track and therefore we needed to introduce ourselves so that we can all reach our task. The first task was to form PLG(Peer Learning Group) which did require us to know each other so that we are...

Words: 3199 - Pages: 13

Free Essay

Human Trafficking

...Human Trafficking SLK 320 Group Assignment T a bl e of c o nt e n t s 1. 2. 3. Understanding of trafficking in persons ............................ 1 Understanding of why it occurs ....................................... 2 Qualitative research to determine the impact of human trafficking .................................................................... 4 4. Holistic understanding of the impact of human trafficking on multiple levels .............................................................. 5 5.Community psychologist intervention .................................. 12 5.1. Implementation of programmes to assist with the effects of human trafficking ............................................. 12 5.2. Addressing communities concerns with regards to human trafficking .......................................................... 13 5.3. Plausible solutions to prevent this event from happening in the community ................................................. 13 7. Bibliography .................................................................. 16 1 . U n d e r s t a ndi n g of t r a f f i c k i ng i n p e r s o ns Human trafficking is a serious crime and a violation of human rights. It occurs in women, children and men. People are trafficked all over the world and are moved in and out of countries for various reasons (UNDOC, 2014). 1 Roxanne Zanato 12096441 Monique Scheepers 12070425 Sean Dickson 10686232 Ryan Cartwright 11001969 Human trafficking has...

Words: 4823 - Pages: 20

Premium Essay

Black Lives Matter Persuasive Speech

...motivated to create this memorial after seeing hurt, injustice, and pain that she felt needed to be remedied. Their goal behind this memorial was to raise awareness as well as help both students and staff see past any political ideology and understand people have lost their lives. Another goal was to raise awareness and understanding that Black Lives Matter isn’t about black superiority, but about the fact that people are dying. Gabbie and Katie’s goal seems to have been actualized. Multiple students and faculty have stopped by the plaza to write scripture, kind words, and inspirational song lyrics in chalk on the ground. Photos of several black Americans who have lost their lives were put on display and surrounded by flowers, stuffed animals, and pinwheels. Prayer vigils have also taken place, further uniting students. While there has been a positive reaction to the memorial, several volunteers have felt the need to watch over the space. Hill’s expressed fear that the memorial would be taken down were actualized sometime between February 15 and February 16. Hill woke up and visited the memorial only to find several photos and candles taken. Eventually it was discovered that Campus Safety took parts of the memorial down, leaving only the stones that held down posters. Michael Lennix, the Director of Campus Safety and Security, expressed regret over the situation. “It was a miscommunication. The message [about the memorial] wasn’t relayed to the midnight officer. It [also] wasn’t...

Words: 785 - Pages: 4

Free Essay

Protecting What's Important

...often the individuals the system was designed to protect creating a serious gap in implementing the HSE-MS. Some 4 years ago the former Shell Deepwater Services (SDS) was facing the roll out of their HSE-MS and the question was asked by the Management Team how do we get our personnel to explicitly understand our HSE-MS so that we can get maximum benefit from it? The result of asking this question has been the development and introduction of a series of critically acclaimed workshops aimed at demonstrating an HSE-MS as simply as possible. “Protecting What’s Important 1” and “Protecting What’s Important 2” workshops have received considerable approval from participants for the manner in which the information is presented and for the awareness the courses bring. Description of Workshops Protecting What’s Important 1 In 2000 a team of SDS employees were organized with the goal of bridging the gap between SDS personnel and the HSE-MS. A series of development meetings and pilot programs resulted in the unveiling of Protecting What’s Important (PWI) in 2001. The team that designed the workshop set forth clear objectives for the workshop, with the aim of having participants: • Receive an introduction to the HSE-MS • Get comfortable with the terminology of the HSE-MS • Understand the basic structure of the HSE-MS • Understand what impact an...

Words: 1506 - Pages: 7

Premium Essay

Health Promotion Program Plan

...trends show that they have a harder time of losing the weight. The CDC reports that for Tennessee specifically adults ages 18 and over, 67% of our population is obese (CDC.gov, 2012). What are the ramifications of this? Women in the southern states are more prone to being obese and carrying it into their later years than most other American woman. Obesity can be a stepping stone to severe health problems later on in life. Issues such as HTN, cardiac problems, diabetes, orthopedic problems, the list goes on and on. Obesity is something that can be changed first; by creating awareness of the existing problem, second; by identifying what needs to be changed, third; creating the opportunity for change and following thru with the plan for change; and finally creating a lifestyle change that will last a lifetime. Program Plan: O'Donnell Program This paper will discuss a program plan to raise awareness of the problem that Tennessee women are facing with Obesity. Providing the opportunity for educational programs for obesity...

Words: 1938 - Pages: 8

Premium Essay

Asean

...ASEAN is a region of immense and colourful cultural diversity, one that shares common historical threads.  ASEAN Member States promote cooperation in culture to help build an ASEAN identity. They seek to promote ASEAN awareness and a sense of community, preserve and promote ASEAN cultural heritage, promote cultural creativity and industry, and engage with the community.  ASEAN Leaders envision ASEAN as a community of caring societies, conscious of its ties of history, aware of its cultural heritage and bound by a common regional identity.  One of the main bodies in ASEAN cooperation in culture is the ASEAN Committee on Culture and Information (COCI). Established in 1978, its mission is to promote effective cooperation in the fields of culture through its various projects and activities. The COCI comprises representatives from national institutions like the Ministry of Foreign Affairs, Ministries of Culture and Information, national radio and television networks, museums, archives and libraries, among others. Together, they meet once a year to formulate and agree on projects to fulfil their mission. Activities in the area of culture include the conservation and preservation of cultural heritage, promotion and cooperation on cultural industry and the production of cultural showcases. To cite some examples, 2009 saw the production of the coffee table book “Water: A Unifying Force in ASEAN”, a workshop that gathered experts from the region to discuss the prevention of illicit transfer...

Words: 271 - Pages: 2

Premium Essay

Personal Responsibility

...Awareness of Individual Responsibility Each individual has an obligation to attempt to perform as an ideal and well-intentioned citizen. In order to achieve this goal, it is imperative to be aware of the significance of such an expression as personal responsibility. Personal responsibility refers to an ability to care for actions, feelings, emotions, good habits, and their consequences. In addition to that, responsibility covers all in regards to the understanding of the effects from making certain choices in life, accountability for obligations, difficulties, as well as the lack of responsibility in some people. The comprehension of all these definitions can interfere and be applied to success in college. The capacity to pay attention to actions and consequences is an ability, which not everyone can embrace. Basically, it is something that typically has to be learned during the early years and should be applied to the rest of the life. For instance, little children understand that by crying, is a way to get a bottle of milk, or someone will change the wet diaper. A child is supposed to understand that if the schoolwork is not finished, there will not be time for recess and so on. Although later in life, depending on people’s backgrounds, costumes, and experiences, the individual begins to form a personality. Unfortunately, not always a fully-grown person ends up having this ability. Robert Peter gives us a simple definition of Personal Responsibility in his article Personal...

Words: 472 - Pages: 2

Premium Essay

Consumer Awareness

...consumer awareness BY: REETANSHU SINGHAL Objective :1.To find out consumer awareness among households in Rajpur Road, Civil Lines Note: You are requested to please give a little time to fill this questionnaire . This data would only be used in an academic project . NAME: ______________________ AGE: ______ OCCUPATION: __________________ Q1. Do you take the bill/cash memo of your purchase at a store ? ___ ALWAYS ___ SOMETIMES ___NEVER BOTHERED Q2. Do you check the expiry date of items like medicines, food, etc. _ ___ALWAYS ___SOMETIMES ___NEVER BOTHERED Q3.Do you check the MRP(Maximum Retail Price) of product before buying it ? ___ALWAYS ___SOMETIMES ___NEVER BOTHERED Q4. Do you check the weight of items like fruits , vegetables , grains ,etc. before buying ? ___ALWAYS ___SOMETIMES ___NEVER BOTHERED Q5.Do you check the certified markings like (agmark, CE, ISI) of items before buying ? ___ALWAYS ___SOMETIMES ___NEVER BOTHERED Q6.When buying something , what is the 1st thing you look for in a store/shop ? | Most important | Slightly important | Not important | POPULARITY | | | | PRICES GIVEN | | | | SPECIAL OFFER | | | | QUALITY | | | | Q7.Have you fallen prey to acts like adulteration , false claims , very high prices and other malpractices when shopping ? ____YES ____NO Q8.If answer...

Words: 271 - Pages: 2

Free Essay

A Study on Brand Preference of Wallcare Putty

...A STUDY ON BRAND PREFERENCE OF WALLCARE PUTTY IN THE AREA OF PARAMAKUDI QUESTIONNAIRE 1. Name : 2. Address of the firm : (With seal) 3. Status of the firm : Individual firm [ ] Partnership firm [ ] 4. Sex : Male [ ] Female [ ] 5. How you’re doing the business? 6. Total year of experience? 7. How did you know about the product? a) Promotional activities [ ] b) Friends & Relatives [ ] c) Distributors [ ] d) Company official [ ] 8. State your awareness regarding BIRLA WALLCARE PUTTY a) Fully aware [ ] b) Partly aware [ ] c) Just awareness [ ] 9. Which type of product does you familiar with the BIRLA WHITE? a) Birla white cements [ ] b) Birla wall care putty [ ] c) Birla white texture [ ] d) other`s name:______________ 10. How long you are using Birla white Products? a) Below 1 year [ ] b) 1-2 years [ ] c) 3-5 years [ ] d) above 5 years [ ] 11. Mentions the company that you have dealerships? a) Birla wall care putty [ ] b) J.K. wall care putty [ ] c ) ASIAN [ ] d) Berger [ ] e) Nrolee [ ] f ) Nippon [ ] g) Other’s name:______________ 12. Please ranking the following brands customer will prepare to...

Words: 480 - Pages: 2

Premium Essay

Acct573 Week 5

...happen in you department then you are more likely able to prepare you and your organization from fraud. The major challenge that the text finds is to cultivate one with the reality rather then rhetoric. If you do keep thinking that this could only happen to another company and not yours, then you are letting your guard down and more likely to have someone to commit these crimes in your organization. Generally the government wants action and laws and regulations put into place to prevent these types of crimes from happening. The text says this could be better served as a middle ground. Just because we have the laws or regulations does not mean the crime is going to be deterred or stopped. We need to come up with the correct training and awareness as well. The main strategy option could be a preventive strategy. You need to have the correct policies in place so you can encourage people not to do these crimes. If you make your staff aware and of teach them what could happen and how to safe guard their information. Give them proper training they maybe able to prevent these crimes or at least lessen the chances of them happening. Source:  Friedrichs, David O. Trusted Criminals: White Collar Crime In Contemporary Society, 4th...

Words: 316 - Pages: 2

Free Essay

Poverty

...1) Reducing world poverty is a topic that has been around for quite some time. To reduce world poverty, the author states we must raise awareness by ensuring that our students are adequately informed about world poverty, its consequences, and ways it can be reduced. My impression from this is that the author is going to try and persuade me that poverty can be treated by showing me the advantages of awareness to poverty from students. This is a value based statement because it’s the authors inferred opinion that world poverty can end if we raise awareness. 2) Better health care, agricultural techniques and techniques generating electricity are all advancements made in technology that will aid in the fight of poverty. (Singer, 2009) With the technology we have today, the author states that poverty is more presently linked between the rich and the poor. This gives you the impression that because poverty is more mainstreamed into your home and school that it will make you more aware to the poverty problem. Does seeing it on television make you feel worse than seeing it in person? Once again this is a value based statement. Just because technology is better today does not mean that people will magically grow a heart and become compassionate. I believe we must first deal with the lack of empathy there is in the world today. 3) 1.4 billion people are living on 1.25 a day. Due to this many children our going malnourished and dying because the food that they are eating lacks vital...

Words: 733 - Pages: 3

Free Essay

Psychology

...is to help professional socialization by instilling an understanding of the relevant ethical principles and standards to be a significant component in providing therapeutic rapports. The primary reasons for clinical supervisions are to ensure quality care and provide professional development in a systematic and planned manner. In todays’ society, clinical supervisions require a foundation in the understanding of the ethical and legal aspects of the supervisory relationship. There are many ethical and legal issues that can affect the supervisory relationship. All supervisors consistently approach all aspects of clinical supervision from an ethical and legal viewpoint. With more time and attention devoted to these important topics, awareness of the ethical and legal aspects can be demonstrated as they are put into practice. The role of a supervisor is to prevent harm from occurring to clients. Supervisors are in charged of reviewing and monitoring the quality of services and the key focus should be to insure that clients’ needs are being met. A primary focus of supervision is to be vigilant and aware of issues that could result in clients receiving inadequate service or being harmed by the therapeutic process. A supervisor must do everything within their power to insure that issues or behaviors of other counselors are not harming clients. New professionals need to develop an understanding of what it meant to be a professional, and this is accomplished by pairing them with...

Words: 426 - Pages: 2