Premium Essay

Riordan Enterprise Security Policies

In:

Submitted By timr30017
Words 1129
Pages 5
Riordan Enterprise Security Policies Tim L. Robinson CMGT/430 September 12th, 2011 Instructor: Dave Fedorchak

Riordan Enterprise Security Policies Because Riordan’s facilities include three locations in the United States and one in China Smith Systems Consulting views Riordan Manufacturing as an enterprise business. However, an unfortunate reality exists because Riordan’s existing security policies are either nonexistent or inadequate at best for an organization of this size. Consequently, Riordan should seriously consider implementing better security throughout the entire enterprise by defining and creating a Separation of Duties (SoD). In fact, many organizations including the Department of Defense use SoD to decrease security vulnerabilities and discourage collusion by employees for a number of reasons (Gligor, 1998). Therefore, Smith Systems Consulting provides the recommendations and reasoning herein to encourage Riordan to adopt the concepts of Role-Based Access Control (RBAC) to create a SoD throughout the enterprise to reduce risk exposure and enhance Riordan’s enterprise security. Role-Based Access Control Since 2010, research by the National Institute of Standards (NIST) provides indisputable evidence that RBAC has become an increasingly common choice of enterprises with 500 or more employees (National Institute of Standards and Technology, n.d.). As a result, even though Riordan’s users do not total 500 at this time, Smith Systems Consulting recognizes Riordan’s rapid growth justifies changes before attempts to establish adequate enterprise security becomes an overwhelming task. However, before initiating changes to enterprise security policies Riordan’s management and information technology (IT) staff

Similar Documents

Premium Essay

Security Policy

...Riordan Manufacturing Security Policy Smith Systems Consulting has been hired to evaluate and consult on the creation of a new information technology security policy to span the complete enterprise infrastructure. This document will serve as a recommendation for Riordan Manufacturing as it pertains to the enterprise wide information security strategy. Riordan Manufacturing currently has three locations within the United States and one location in Hangzhou, China. All of these locations have been evaluated and are considered part of the enterprise security policy. The review of the current information technology security policy was conducted based on the idea of improvement with respect to current technology trends and best practices. An evaluation of the enterprise infrastructure as a whole, as it pertains to information technology security, was also conducted. These evaluations were the starting point for Smith Systems Consulting to design a security strategy to best fit Riordan Manufacturing. The existing security policy consists of location-based data access to on-site servers and on-site access to Unix servers for ERP and MRP systems. Also, it was evident that there are a number of servers and data to be accessed from different operating systems that are deployed throughout the locations. The management of the existing security strategy is one that requires each individual to be assigned access permissions manually throughout their term of employment. This strategy is...

Words: 304 - Pages: 2

Premium Essay

Enterprise Security Plan Cmgt/430

...Enterprise Security Plan CMGT/430 Enterprise Security Plan This Enterprise Security Plan (ESP) for Riordan Manufacturing employees the levels of security required to protect the network and resources utilized to communicate. It is intended purpose is to formulate a means to counterattack against security risk from potential threat. The ESP servers as a way to identify risks and to ensure a contingency plan is in place to protect the availability, integrity, and confidentiality of the Riordan organization's information technology (IT) system. The ESP benefits all employees however it is most beneficial to information resource managers, computer security officials, and administrators as it is a good tool to use for establishing computer security policies. The ESP in its basic form is a systematic approach to addressing the company’s network, its capability, the threats it is susceptible to and a mitigation strategy that addresses those threats if and should they occur. In addition to addressing the threats the ESP will also make provisions for establishing contingency plans in case of a disaster. The information covered by this plan includes all information systems, IT resources, and networks throughout the Riordan global organization owned or operated by employees in the performance of their job duties, whether written, oral, or electronic. Further it establishes an effective set of security policies and controls required to identify and mitigate vulnerabilities that...

Words: 2085 - Pages: 9

Premium Essay

Riordan Manufacturing Human Resources Integration Project

...Riordan Manufacturing Human Resources Integration Project Brett Hall, Carl Rascoe, Juan (Danny) Castaneda, and Tina Schaffer CIS/207 November 6, 2012 Bill Fennell Riordan Manufacturing is a global plastics manufacturer that was founded by Dr. Riordan in 1991. Dr. Riordan obtained several patents that later turned into commercial applications that developed his company in to a Fortune 1000 enterprise, employing 550 people with projected earnings of $46 million dollars and over $1 billion in revenues. In 1993 the company expanded from high tensile strength plastics and fans into producing plastic beverage containers. The company’s latest expansion was in 2000 when it opened operations in China. Riordan Manufacturing is the industry leader in using polymer materials with future goals of achieving and maintaining reasonable profitability to ensure and sustain growth (Apollo, 2005). In response to Hugh McCauley’s, Riordan Manufacturing Chief Operations Officer‘s (COO) concern about the antiquated processes and his requirements the team analyzed the manual and redundant processes of the current Human Resources System Integration (HRIS). The team has determined with the use of state-of-the art information technology system the current manual intensive, multi-functional processes can be integrated into a single system. The team has kept in consideration that the integrated HRIS has to be accessible by all of Riordan’s plant locations. Based on the request...

Words: 3533 - Pages: 15

Free Essay

Autism

...To: Riordan Executive Officers and Directors Date: Monday, February 14, 2011 Subject: Corporate Compliance Plan for Riordan Manufacturing Inc. Overview of Riordan Manufacturing Riordan Manufacturing is a global plastics manufacturer employing 550 people with projected annual earnings of $46 million. The company is wholly owned by Riordan Industries, a Fortune 1000 enterprise with revenues in excess of $1 billion. Its product include plastic beverage containers produced at its plant in Albany, Georgia, custom plastic parts produced at its plant in Pontiac, Michigan, and plastic fan parts produced at its facilities in Hangzhou, China. The company’s research and development is done at the corporate headquarters in San Jose. Riordan’s major customers are automotive parts manufactures, aircraft manufacturers, the Department of Defense, beverage makers and bottlers, and appliance manufactures. (University of Phoenix 2011) Corporate Compliance Overview Riordan Manufacturing has created a Corporate Compliance Plan customized to the organization’s specialized field of plastic designs.   Riordan is committed to managing and operating the organization programs with the utmost degree of business, ethical and moral principals.   Employee expectations are maintain an innovative and team oriented working environment by assuring that the employees are well informed and properly supported, the company will provide a climate focused on the long-term viability of the...

Words: 1898 - Pages: 8

Premium Essay

Riordan Sr-Rm-006

...Riordan SR-rm-006 University of Phoenix Windows Server Networking POS.421 Riordan SR-rm-006 Riordan Manufacturing is a “leader in the field of injection plastic molding with state of the art manufacturing capabilities” ("Sales Plan - Riordan Manufacturing," 2006), and they desire to remain a leader in this competative market. To help them stay on top of the market they have requested a comprehensive review of their business systems servers and operating systems. This review will benefit their managing of their information technology data resources. The primary systems this overview concentrates on are Windows Vista, Windows XP Professional, Windows Server 2003, and Windows Server 2008. Within each of these systems are sub-systems that will be addressed as needed. Features and Benefits of Windows XP Professional Windows XP Professional includes Active Directory integration along with the Microsoft Management Console (MMC) that is a server and domain management tools. “You manage Windows 2000 and Windows 2003 domains using tools loaded into a Microsoft Management Console (MMC) window. You can access these tools over the network directly or over the Internet via Internet Information Server.” ("Windows XP and desktop management," 2011).  Windows XP Professional is an excellent choice to serve as a client-based network administration workstation. Windows XP Professional contains two remote connectivity tools. First XP Professional contains the Remote Assistant and...

Words: 3579 - Pages: 15

Premium Essay

Riordan

...business will fail. Business Overview Riordan Manufacturing is a global plastics manufacturer employing 550 people with projected annual earnings of $46 million. The company is wholly owned by Riordan Industries, a Fortune 1000 enterprise with revenues in excess of $1 billion. Its products include plastic beverage containers produced at its plant in Albany, Georgia, custom plastic parts produced at its plant in Pontiac, Michigan, and plastic fan parts produced at its facilities in Hangzhou, China. The company's research and development is done at the corporate headquarters in San Jose. Riordan's major customers are automotive parts manufacturers, aircraft manufacturers, the Department of Defense, beverage makers and bottlers, and appliance manufacturers. Legal Liability of Administration Riordan Manufacturing’s Corporate Compliance plan is for all employees. Compliance with the program starts with the officers and directors of Riordan. All employees of Riordan are expected to follow the set standards. The administration of Riordan is no exception to the set standards. The Corporate Compliance Plan will focus on the liability of the officers and directors of Riordan Manufacturing. Legal Options When legal problems arise for Riordan Manufacturing, the easiest and cost effective method will be used. When applicable, Alternative Dispute Resolutions (ADR) will be used in place of traditional forms of litigation to save Riordan time, money and possible public scrutiny...

Words: 1391 - Pages: 6

Premium Essay

Bsa375

...Riordan Manufacturing is an international manufacturer of plastics and is currently make its mark on the industry as an industry leader. Currently Riordan Manufacturing has four locations that all serve different purposes in the company. Riordan Manufacturing has locations in Albany, Georgia, Pontiac, Michigan, Hangzhou, China and the corporate headquarters in San Jose, California. Riordan Manufacturing uses a Wide Area Network (WAN) that allow the three locations to be connected to the corporate headquarters in San Jose, California. Along with the Wide Area Network to connect the locations to the Corporate Headquarters of Riordan Manufacturing, each location has its own Local Area Network (LAN). Network Architecture. The topology of the networks varies from site to site. The network of the Corporate Headquarters and the location in China both use a bus topology in both networks there is a single 100BaseT line that is either connected to a server or an interface device. The other two site Albany, Georgia and Pontiac, Michigan both use what seems to be a partial mesh topology or a hybrid topology. The servers on these networks are all connected together , the interface devices are connected to the server, and the clients and printers are then connected to only the interface devices. All of the locations have their own local area network which is connected to the Corporate Headquarter though a point to point connection which is a star topology. The China location has a point...

Words: 2198 - Pages: 9

Premium Essay

Corporate Erm

...I have prepared the following Enterprise Risk Management (ERM) plan for your review. This plan was developed for use in Riordan Industries, Inc., Riordan Manufacturing, and all other Riordan ventures, subsidiaries, and partnerships. Unless otherwise noted, the term “Riordan” will refer to any or all of these entities. I have used the Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework as a guide for recommendations regarding internal controls and corporate governance. The goal of this document is to provide a broad enterprise level framework that unifies the various parts of Riordan, to create an integrated whole. In doing so, the ERM mitigates the legal liability of the officers and directors of Riordan. Alternative Dispute Resolution It is reasonable to assume that in the course of business, Riordan will encounter conflict with a customer, a vendor, an employee, or some other person or organization. Riordan Manufacturing currently retains an independent law firm to handle all legal matters. Aside from the practice of keeping an attorney on retainer, Riordan appears to have no particular dispute resolution process in place. If a conflict escalates to the point that legal action is taken, it is most likely in Riordan’s best interests to settle disputes through the process of mediation. Mediation is preferable to other methods of dispute resolution for several reasons: Riordan avoids the risk of a potentially hostile venue or jury...

Words: 2026 - Pages: 9

Premium Essay

Bsa 310 Team Paper

...Riordan Manufacturing Service Request Team B BSA/310 Steve Johnson February 21, 2012 Riordan Manufacturing Service Request Introduction The Riordan Manufacturing Company is an industry leader in plastics manufacturing and has earned international acclaim for its state-of-the-art plastic designs since 1991. Riordan Manufacturing is a company owned by Riordan Industries. “Riordan Manufacturing currently employs 550 people, and has manufacturing plants in Albany, Georgia, Pontiac, Michigan, and Hangzhou, China, and Corporate Headquarters in San Jose, California” (Apollo Group, Inc., 2006). They have taken the lead for the past 20 years in their design of products such as plastic bottles, fans, heart valves, and medical stents. As the company has expanded over the past few years, their business systems have expanded as well. This review analysis will identify existing system and subsystems for Riordan Manufacturing, Inc., and provide recommended system solution software, hardware and applications to improve current business processes and standards. Home Page Optimization In view of Riordin’s electronic information presence, the Web site Home page displays a meaningless banner that lends the company to twentieth-century technology. It provides no Web market presence. Optimization of the Riordin Web site Home page needs to be the focal point of their business system and sub-system upgrade. Now, companies have realized that database...

Words: 3654 - Pages: 15

Free Essay

Bsa-310 Riordan Business Systems

...Riordan Business Systems Christina Cruel, Steven Keller, Mick Robey, James Simkins BSA/310 November 4, 2013 Paula Billups Table of Contents Abstract……………………………………………………………………………………………3 Company Background…………………………………………………………………………….4 Business Systems Overview...…………………………………………………………………….4 Riordan Business Systems……………………………………..………………………………….5 Accounting and Finance……………………………………………………………….….5 Sales and Marketing…………………………………………………………….…………8 HR……..………………………………………………………………………….……….9 Legal……………………………………………………………………………………..11 Operations………………………………………………………………………………..12 IT Security……………………………………………………………………………………….13 Conclusion……………………………………………………………………………………….14 References………………………………………………………………………………………..15 Appendices: Service Requests…………………………………………………………………...16 Appendix A: Accounting and Finance...…………………………………………………16 Appendix B: Sales and Marketing……………………………………………………….17 Appendix C: Human Resources - HRIS…………………………………………………18 Appendix D: Human Resources – CM...……………………………………...…………19 Appendix E: Operations – CAD...……………………………………………………….20 Appendix F: Operation – ERP…..……………………………………………………….21 Appendix G: Operations - Legal…...…………………………………………………….22 Appendix H: IT Security…………...…………………………………………………….23 Abstract This is a formal response to Service Request, SR-rm-012 Business Systems, which requests analysis and recommendation of Riordan Manufacturing’s current business systems. This paper evaluates the electronic...

Words: 3750 - Pages: 15

Premium Essay

Riordran Test Case

...Riordan Information System Business Requirements Over the last decade Riordan has expanded from a single hospital and pair of clinics to a health network that includes more than a dozen hospitals, as many small clinics and four pharmacies. Riordan’s impressive growth has resulted from a combination of new expansion, partnerships and buyouts and driven the company to become the dominant health care provider in the region. Unfortunately, this rapid growth has led to a situation in which different network facilities have different SOPs governing patient care, record keeping, billing and human resources and has begun to affect the bottom line of the company as it attempts to consolidate the disparate practices into a cohesive whole. With the advent of the Affordable Care Act, Riordan found it needed ensure that all of its facilities were operating under a common set of policies and guidelines in order to help ease the regulatory requirements the ACA brought with it. Under the current system, each hospital or clinic operates effectively as a discrete business unit. Tracking a given patient’s treatments, insurance benefits, medications and more is expensive and open to mistakes that could leave the company vulnerable to legal actions either by the patient or the government. In addition, trying to analyze potential problem areas with such a diverse set of data silos spread across so many different facilities was proving to be impossible. With different reporting standards in use...

Words: 3003 - Pages: 13

Free Essay

Law531

...Riordan Corporate Compliance Plan LAW531 Professor John Huschen May 23, 2011 Riordan Corporate Compliance Plan Riordan Manufacturing is part of Riordan Industries; the company currently has around 550 employees and is worth $46 billion. “The company was founded by Dr. Riordan, a professor of chemistry, who obtained several patents relative to the processing polymers into high tensile strength plastic substrates” (Apollo Group, 2006). Dr. Riordan’s desire to become a successful business, reached new regions: Michigan, Georgia, and China. Alternative Dispute Resolution Alternative dispute resolution is part of Riordan Manufacturing’s new compliance plan and will be the primary method of resolving disputes versus litigation. In the event of problems, conflicts, or unfavorable action that may occur will evoke the need for alternative dispute resolution (ADR) measures. ADR should not be used to resolve personal issues in the workplace, only those that are work related or affect the production of work. In addition, ADR is a last resort measure and problems should be addressed by the immediate supervisor and employees are given avenues to report the dispute, which is by email and the company’s toll-free help line. The primary forms of ADR that Riordan Manufacturing will use are mediation and arbitration. “Mediation is a form of negotiation in which a neutral third .party assists the disputing parties in reaching a settlement of their dispute” (Cheeseman...

Words: 1307 - Pages: 6

Premium Essay

Riordan Corporate Compliance Plan

...Phoenix LAW/531: Business Law Group: DB12MBA01 Joseph Balistocky, JD, MFCC April 17, 2012 Workshop 6 Riordan Corporate Compliance Plan Riordan Manufacturing is a $1 billion Fortune 100 organization with approximately 550 employees specializing in plastic patient design with operations in the United States and China that realized $46 million in revenue last year. Due to concerns originating out of the company’s expansion into e-Commerce and increasing international sales, the company has decided to implement a enterprise risk management (ERM) program based on internationally recognized Committee of Sponsoring Organization of the Treadway Commission (COSO) Guidelines. The COSO design was chosen for its emphasis on defining processes that enhance an organization’s management responsibilities, legal risks and rights of employees in relation by advocating a dispute management process (University of Phoenix, 2012). Management Responsibilities At Riordan Corporation, the executive level officers also act in a fiduciary capacity with responsibility for acting in the best interest of the organization while upholding a high standard of corporate behavior. The executive level senior management of the organization along with the internal auditor level officers of the company are included in the Riordan organizational chart with clear duty responsibilities outlined in detail with corporate SEC filings. Additionally, due to government...

Words: 2360 - Pages: 10

Free Essay

Ntc 362 Week 2

...Riordan Network Design Project NTC/362 November, 2013 Riordan Network Design Project Riordan Manufacturing is a plastics manufacturing company that produces products such as beverage containers, custom plastic parts and plastic fans. Riordan was created in 1991 and was founded by Dr. Riordan. Riordan currently has a location in Hangzhou China and is moving that location to Shanghai China. This document will outline the network design, Project timeline, design approach, detailed design, current network topology, new network topology, security and plans for starting up new location and decommissioning the old location. Network Design Project Timeline Assignment | Timeline | Design Approach | Phase 1-Four Weeks | Detailed Design | Phase 1-Four Weeks | Current Network and Establishing New Network | Phase 2 6 weeks | Security Considerations | Phase 2 6 weeks | Decommissioning Old Facility | Phase 3 4 weeks | Old Equipment | Phase 3 4 weeks | Old and New Employees | Phase 3 4 weeks | Design Approach and Rationale Riordan Manufacturing is currently seeking to move the current location from Hangzhou China to Shanghai China. In order to successfully move the entire location to its new location we will setup the new location and get it up and running before we shut down the current location. In doing so we will need to purchase new hardware and software for the new location and also setup a new firewall...

Words: 1997 - Pages: 8

Premium Essay

Service Request Sr-Rm-022, Part 2

...analyze are the best ways to improve the project and how the department communicate, promoting better communication and save time and money for Riordan. Security Controls One of the most important points in a system design and security for this reason that the whole system needs to have security controls in this way it is possible to install and operate controls as recovery, firewall, backup and other, all this are operations group tasks , developers also are responsible, especially with regard to information systems. Keep all data from Riordan safe and confidential mainly are two crucial points. Data such as information from employees, company policy and procedures will be the responsibility of Riordan, passwords, along with data encryption will be used, thus bringing more security to the company. Processes Use a third-party software can bring benefits to the company, will be an advantage for Riordan as the third-party seller will have the security guaranteed by them. The Riordan Manufacturing can save time by using COST, just use the training and services that are included in the programs that are already developed, this process can delay but had saved money if the case is necessary to use an additional program, this will be included in an in-house development. Interfaces Systems interfaces requires a high level of security because the exchange of valuable information. This environment can be included the use of passwords to unlock confidential documents, such...

Words: 495 - Pages: 2