Part1, ISSC481:
When rolling out information security policiescommunications should be a priority. Looking at page 119 in the textbook,please explain the importance of this statement. (Write a 1 page paper discussing your answer). page 119 is attached as a screen shot.
Part 2, ISSC431:
The assignment must be a minimum of one (1) full page in length with a minimum of two (2) outside sources. Please be sure
to follow APA guidelines for citing and referencing source:
Assignment: Using the Internet as a resource, develop a security checklist for an SQL Server.
Firefox
File
Tools
Window
Help
25% (4)
Sun 11:32 AM
Q
E
Edit View History Bookmarks
VitalSource Bookshelf: Security X +
0
A https://online.vitalsource.com/#/books/9781284070637/cfi/139!/4/4@0.00:0.00
I 0
O
=
CHAPTER 5
Information Security Policy Implementation Issues
119
Robert
FYI
? HELP
When rolling out information security policies, make communications a priority. Be sure your
approach includes these points:
1. Be clear-avoid technical jargon when possible.
2. Set the tone at the top-ask your leaders to help deliver the message
3. Use many channels-reinforce the message as many times as possible.
4. Be forthcoming-be honest and candid about any impact the policy will have
5. Say “thank you acknowledge the efforts both to create and to implement
the security policies
This list is not exhaustive, but it highlights key points.
lex of pages
O O O O jij
To be successful in implementing security policies in a large organization, you must
continually sell the message at each layer. You must build support at the top, middle,
and bottom ranks. You must choreograph the review, approval and release process
so you continue to be part of the messaging. Rememberthe message can change as
it moves through the layers of the organization. For example, when dealing with senior
leaders, a core part of the message could be cost avoidance and reduction in operating
risks. Messages to other layers might have greater emphasis on regulatory compliance
or meeting customer expectations of privacy. It’s important to tailor the benefit message
to resonate with the audience. If workers can connect with the importance and priority
they are more likely to follow the policy.
Advantages of a Hierarchical Model
There are some distinct advantages to a hierarchical model. The importance of
specialization has been discussed. In a hierarchical model. communication lines are
more clearly defined. When you encounter a problem, there is most likely a group
that specializes in that area that can help solve it. The depth of knowledge in a subject
area tends to be greater. This allows managers to predict and avoid problems before
they occur.
Managers can also create “centers of excellence.” These are small, specialized teams
that focus on specific problems within an organization to help provide high-quality
products and services. Large organizations often have teams dedicated to identifying the
next big threat. These teams examine industry breaches and analyze if the company
would be vulnerable to those types of attacks. In a small flat organization, these
specialties and skills may not be available.
5
》
o
119
0
Aal
A
23 (3
MAY
24
W
N
tv
WIE