{"id":433726,"date":"2018-06-21T10:30:54","date_gmt":"2018-06-21T10:30:54","guid":{"rendered":"https:\/\/essaypaper.org\/?p=27581"},"modified":"2018-10-24T09:01:16","modified_gmt":"2018-10-24T09:01:16","slug":"issue-specific-policy-assignment-paper","status":"publish","type":"post","link":"https:\/\/www.benedictsol.com\/blogs\/issue-specific-policy-assignment-paper\/","title":{"rendered":"Issue Specific Policy Assignment Paper"},"content":{"rendered":"<h2>Issue Specific Policy<\/h2>\n<div class=\"question-body\">\n<div>\n<h3>Your Task Assignment<\/h3>\n<p>As a staff member supporting the CISO, you have been asked to research and then draft an <em>issue specific policy <\/em>for each of the identified issues (three separate policies). These policies are to be written for MANAGERS and must identify the issue, explain what actions must be taken to address the issue (the company\u2019s \u201cpolicy\u201d), state the required actions to implement the policy, and name the responsible \/ coordinating parties (by level, e.g. department heads, or by title on the organization chart).<\/p>\n<p>After completing your research and reviewing sample policies from other organizations, you will then prepare an \u201capproval draft\u201d for each issue specific policy.<\/p>\n<p>\u00b7 The purpose of each <em>issue specific policy<\/em> is to address a specific IT governance issue that requires cooperation and collaboration between multiple departments within an organization.<\/p>\n<p>\u00b7 Each <em>issue specific policy<\/em> should be no more than two typed pages in length (single space paragraphs with a blank line between).<\/p>\n<p>\u00b7 You will need to be concise in your writing and only include the most important elements for each policy.<\/p>\n<p>\u00b7 You may refer to an associated \u201cprocedure\u201d if necessary, e.g. a <em>Procedure for Requesting Issuance of a Third Level Domain Name <\/em>(under the company\u2019s Second Level Domain name) or a <em>Procedure for Requesting Authorization to Establish a Social Media Account<\/em>.<\/p>\n<p>Your \u201capproval drafts\u201d will be combined with a one page Executive Summary (explaining why these <em>issue specific policies<\/em> are being brought before the IT Governance Board).<\/p>\n<h3>Research:<\/h3>\n<p>1. Review NIST\u2019s definition of an \u201cIssue Specific Policy\u201d and contents thereof in NIST SP 800-12 Section 5.3. This document provides information about the content of an issue specific policy (as compared to comprehensive system and enterprise security policies).<\/p>\n<p>2. Review the weekly readings and resource documents posted in the classroom. Pay special attention to the resources which contain \u201cissues\u201d and \u201cbest practices\u201d information for:<\/p>\n<p>\u00b7 Data Breach Response<\/p>\n<p>\u00b7 Preventing \/ Controlling Shadow IT<\/p>\n<p>\u00b7 Social Media<\/p>\n<p>3. Review NIST guidance for required \/ recommended security controls (see NIST SP 800-12, NIST SP 800-53, and NIST SP 800-100). Some suggested control families are:<\/p>\n<p>\u00b7 Access Control (AC) control family (for Social Media policy)<\/p>\n<p>\u00b7 Incident Response (IR) control family (for Data Breach policy)<\/p>\n<p>\u00b7 System and Services Acquisition (SA) control family (Domain Name, Shadow IT, Website Governance)<\/p>\n<p>4. Find and review additional authoritative \/ credible sources on your own which provide information about IT security issues (related to data breaches \/ responses, shadow IT, and\/or social media use) which require policy solutions.<\/p>\n<p><strong>URLs for Recommended Resources<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Title<\/strong><\/p>\n<p><strong>Type<\/strong><\/p>\n<p><strong>Link<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>NIST SP 800-100 <em>Information \u00a0\u00a0Security Handbook: A Guide for Managers<\/em><\/p>\n<p>PDF<\/p>\n<p>https:\/\/doi.org\/10.6028\/NIST.SP.800-100<\/p>\n<p>&nbsp;<\/p>\n<p>NIST SP 800-12: An Introduction to Information Security<\/p>\n<p>PDF<\/p>\n<p>https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-12r1.pdf<\/p>\n<p>&nbsp;<\/p>\n<p>NIST SP 800-53 Security and Privacy Controls for Federal Information \u00a0\u00a0Systems and Organizations<\/p>\n<p>PDF<\/p>\n<p>http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-53r4.pdf<\/p>\n<h3>Write:<\/h3>\n<p>1. Prepare briefing package with approval drafts of the three IT related policies for the Manager\u2019s Deskbook. Your briefing package must contain the following:<\/p>\n<p>\u00b7 Executive Summary<\/p>\n<p>\u00b7 \u201cApproval Drafts\u201d for<\/p>\n<p>o Data Breach Response Policy<\/p>\n<p>o Preventing \/ Controlling Shadow IT Policy<\/p>\n<p>o Management and Use of Corporate Social Media Accounts Policy<\/p>\n<p>As you write your policies, make sure that you address IT and cybersecurity concepts using standard terminology.<\/p>\n<p>2. Use a professional format for your policy documents and briefing package. \u00a0Your policy documents should be consistently formatted and easy to read.<\/p>\n<p>3. Common phrases do not require citations. If there is doubt as to whether or not information requires attribution, provide a footnote with publication information or use APA format citations and references.<\/p>\n<p>4. You are expected to write grammatically correct English in every assignment that you submit for grading. Do not turn in any work without (a) using spell check, (b) using grammar check, (c) verifying that your punctuation is correct and (d) reviewing your work for correct word usage and correctly structured sentences and paragraphs.<\/p>\n<h3>Submit For Grading<\/h3>\n<p>Submit your Manager\u2019s Deskbook briefing package in MS Word format (.docx or .doc file) for grading using your assignment folder. (Attach the file.)<\/p>\n<\/div>\n<h6 class=\"text-info\"><\/h6>\n<\/div>\n<div class=\"clear\"><\/div>\n<div class=\"clearfix\">\n<div class=\"question-attachments\">\n<ul class=\"attachment-list\">\n<li class=\"attachment-wrap\"><\/li>\n<\/ul>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Issue Specific Policy Your Task Assignment As a staff member supporting the CISO, you have been asked to research and then draft an issue specific policy for each of the identified issues (three separate policies). These policies are to be <a href=\"https:\/\/www.benedictsol.com\/blogs\/issue-specific-policy-assignment-paper\/\" class=\"read-more\">Read More &#8230;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"class_list":["post-433726","post","type-post","status-publish","format-standard","hentry","category-essay-paper-writing"],"_links":{"self":[{"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/posts\/433726","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/comments?post=433726"}],"version-history":[{"count":0,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/posts\/433726\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/media?parent=433726"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/categories?post=433726"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/tags?post=433726"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}