Preview

Security Policy: Development and Implementation

Powerful Essays
Open Document
Open Document
2113 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Security Policy: Development and Implementation
Security Policy: Documentation and Implementation

Most babies cry when they receive their first set of vaccines. Mothers know that they must go through this to ensure a healthy future. Like a vaccine the development and execution of a good security policy will help prevent danger and intrusion later. Being one step ahead of the virus is half the battle; it’s the development and implementation that will essentially win the war.

The average American is surrounded by security policies in just about every aspect of their lives, but never takes the time to acknowledge that fact. Your bank probably has fraud protection for you, the same as when you travel you must go through an entity of a security policy (e.g. metal detectors, baggage scans etc). Prime example of when a security policy must change because of its inefficiency was 9/11. Until that day most airlines had policies that kept passengers safe on their flight, policies to ensure or secure your luggage arrival and policies with procedures to follow if ever in an emergency situation. On 9/11 it was made clear that airline security policies were outdated and we as Americans were left vulnerable to a deadly “virus” that up until that day we had neither vaccine nor quick cure. This unfortunate example is exactly why the vitality of a security policy must stay one step ahead so that America may have a safe and healthy future. And like a vaccine a good security policy should prevent future attacks and infections of the virus that is in this example terror.

“By definition, security policy refers to clear, comprehensive, and well defines plans, rules and practices that regulate access to an organizations system and the information included in it. Good policy protects not only information and systems, but also individual employees and the organization as a whole. It also serves as a prominent statement to the outside world about the organizations commitment to security.” When developing a



References: System Sciences, 2007. HICSS 2007. 40th Annual Hawaii International Conference on Jan • *Siponen, M.T, “Analysis of modern IS security development approaches: towards the next generation of social and adaptable ISS methods”, Information and organization, 15, 4, 2005, 339-375. • *Villarroel, R, Fernandez-Medina, E. and Piattini, M., “Secure information systems development ' ' a survey and comparison”, Computers and Security, 24, 4, 2005, 308-321. • *Stanton, J. M., Stam, K. R., Mastrangelo, P. and Jolton, J., “An analysis of end user security behaviors”, Computers & Security, 24, 2005, 124-133. • *Fishbein, M. and Ajzen, I., Belief, Attitude, Intention and Behavior: An Introduction to Theory and Research. MA, Addison-Wesley. 1975. • *Aydin, C. E. and Rice, R. E., “Social worlds, individual differences, and implementation. Predicting attitudes toward a medical information system”, Information & Management 20, 1991, 119-136.

You May Also Find These Documents Helpful

  • Better Essays

    Whitman, M., & Mattord, H. (2004). Information Security Policy. In Management of information security(Fourth ed., p. 154). Boston, Mass.: Thomson Course…

    • 2101 Words
    • 8 Pages
    Better Essays
  • Powerful Essays

    INF 325 Week 1: A Case Study

    • 2472 Words
    • 10 Pages

    Olzak, T. & Bunter, B. (2010, May 07). Security basics - components of security policies. Bright…

    • 2472 Words
    • 10 Pages
    Powerful Essays
  • Good Essays

    Often Information Technology Directors overlook that information security is more of a people issue rather than a technology issue. We rely heavily on people’s awareness, ethics and behavior, and an understanding of what they want to achieve is essential to accomplish the goals of business. This includes the employees that deliver services and the customers that take advantage of them, as well as the senior executives that outline the budgets.…

    • 801 Words
    • 4 Pages
    Good Essays
  • Powerful Essays

    D 'Arcy, J., Hovav, A., & Galletta, D. (2009). User awareness of security countermeasures and its impact on information systems misuse: a deterrence approach. Information Systems Research, 20(1), 79-98…

    • 1478 Words
    • 5 Pages
    Powerful Essays
  • Good Essays

    Maintaining and implementing of the security policies is one way that this can be accomplished, it is important the everyone knows their role in overall information security within the company.…

    • 717 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    NT2580

    • 1232 Words
    • 14 Pages

    Introduction to Information Security © ITT Educational Services, Inc. All rights reserved. Page 4 Introducing ISS…

    • 1232 Words
    • 14 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Class I worked with a community college network a few years ago and it was almost fun to watch. No matter how much bandwidth they purchased, the students would use it all. They could not get educational traffic to work because there was too much competition from students gaming and streaming audio and video. Ultimately they purchased some expensive bandwidth management equipment to give priority to certain traffic. The problem was not really security, but rather, controlling usage.…

    • 1177 Words
    • 5 Pages
    Satisfactory Essays
  • Good Essays

    LESMA204

    • 2205 Words
    • 7 Pages

    References: The Open University of Hong Kong. LESM A204 Security Practices and Management (Unit2). Hong Kong: OUHK…

    • 2205 Words
    • 7 Pages
    Good Essays
  • Satisfactory Essays

    Week 4 Assignment 3

    • 316 Words
    • 2 Pages

    Cited: (2012). Request for Proposals for Information Security Assessment Services (isas). Sudburry, MA: Jones & Bartlett Learning.…

    • 316 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Discussion 1

    • 396 Words
    • 2 Pages

    A security policy defines limitations on individual behavior or system performance and details activities that are permitted, controlled or prohibited within the company. In order for policies to be effectual, senior management must endorse them, they must be communicated to all employees, undergo recurring reviews, and be assessed for usefulness. A security program encompasses all of the required pieces necessary to successfully protect a business. It should include policies, requirements, standards and procedures. Security plans should be operative at all levels of a corporation to be effective. Management should communicate a formal explanation of what is acceptable by all employees. Management should also clearly dictate what the consequences of noncompliance are. Organizations can use the ISO-27002:2005 as an outline to create a security policy.…

    • 396 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    My doctoral study topic focuses on internet security for businesses. Internet security is a broad topic that involves a multitude of theories, beliefs, recommendations, and guidelines. My article selections detailed a synopsis of the government’s responsibility and the end users obligation to internet security. In addition, the annotated bibliographies give the reader a summarization of the article through it 's main focal points. The two articles below are for my doctoral study.…

    • 380 Words
    • 2 Pages
    Good Essays
  • Powerful Essays

    Parker, Donn B. “Our Excessively Simplistic Information Security Model andHow to Fix it,” ISSA Journal, July 2010: 12-21, http://www.issa. org/ images/upload/files/ParkerSimplistic%20Information%20…

    • 1056 Words
    • 5 Pages
    Powerful Essays
  • Satisfactory Essays

    Defining policies for every domain of an IT infrastructure breaks down in depth how each entity should be properly used. The policies should also identify the key players that will play a key role in ensuring optimum use of all devices, as well as establishing and maintaining security throughout the process of information traveling through the Infrastructure. Here are some best practices to keep in mind when defining policies for a few of the domains within the infrastructure:…

    • 545 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    Why do we need a Security Policy? This is without a doubt the first measure that must be taken to reduce the risk of the unacceptable use of any of our information resources. A security policy is the first step towards enhancing our security. We need security so that we can inform staff on the various aspects of their responsibilities, inform staff on the general use of company resources, explain to staff how sensitive information and large quantities of money should be handled, and inform staff of the meaning of acceptable use. The development of the security policy is highly beneficial to us as it will turn all staff members into participants in the…

    • 676 Words
    • 2 Pages
    Good Essays
  • Good Essays

    References: Johnson, Rob. with Merkow, Mike. Security Policies and Implementation Issues. First Edition. Copyright © 2011by Jones & Bartlett Learning, LLC, an Ascend Learning company…

    • 577 Words
    • 2 Pages
    Good Essays