{"id":34579,"date":"2023-09-26T04:16:01","date_gmt":"2023-09-26T04:16:01","guid":{"rendered":"https:\/\/www.goodacademic.com\/blog\/questions\/multiple-unite-security-assurance-corporation-milestone-one-proposal-introduction\/"},"modified":"2023-09-26T04:16:01","modified_gmt":"2023-09-26T04:16:01","slug":"multiple-unite-security-assurance-corporation-milestone-one-proposal-introduction","status":"publish","type":"questions","link":"https:\/\/www.goodacademic.com\/blog\/questions\/multiple-unite-security-assurance-corporation-milestone-one-proposal-introduction\/","title":{"rendered":"Multiple Unite Security Assurance Corporation &#8211; Milestone One: Proposal Introduction"},"content":{"rendered":"<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">The CISO of the organization reaches out to you, the senior information security officer, and tasks you with creating an agency-wide security awareness program. He states that he will give you all of his support to complete this project (remember, this is the first component of security awareness program). He hands you a security gap analysis (the second component of a security awareness program) that was conducted, which shows 10 major security findings. These 10 deficiencies will serve as the foundation for developing the agency&#8217;s security awareness program&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">Based on the scenario provided in the Case Document, develop the Introduction to your Proposal. In your introduction, be sure to include the purpose of the proposal, address the security concerns of the chief executive officer (CEO), explain why the security awareness proposal will be vital to the organization, describe how the security posture will be addressed, clarify how human factors will be assessed, and list any organizational factors that will contribute to the status of the security posture.<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\"><\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">10 security gaps:<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">1.\tNo annual cyber security awareness training, which is causing high phishing and social engineering attacks&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">2.\tNo configuration change management policy (to reduce unintentional threats)&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">3.\tNo intrusion detection\/prevention system&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">4.\tLogs are not being collected or analyzed&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">5.\tNo media access control policy&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">6.\tNo encryption or hashing to control data flow and unauthorized alteration of data&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">7.\tVulnerability assessment is conducted every three years; unable to assess the security posture status&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">8.\tHigh turnover and low morale among the employees (due to lack of employee readiness programs and work planning strategy)&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">9.\tHigh number of theft reports and security incidents; possible unethical\/disgruntled employees&nbsp;<\/p>\n<p style=\"margin: 0.5em 0px 1em; font-size: 19px; cursor: auto; color: inherit;\">10.\tNo segregation of duties or mandatory vacation policies (to mitigate intentional threats)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The CISO of the organization reaches out to you, the senior information security officer, and tasks you with creating an agency-wide security awareness program. He states that he will give you all of his support to complete this project (remember, this is the first component of security awareness program). He hands you a security gap [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":[],"disciplines":[1161],"paper_types":[],"tagged":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/questions\/34579"}],"collection":[{"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/questions"}],"about":[{"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/types\/questions"}],"author":[{"embeddable":true,"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/comments?post=34579"}],"version-history":[{"count":0,"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/questions\/34579\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/media?parent=34579"}],"wp:term":[{"taxonomy":"disciplines","embeddable":true,"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/disciplines?post=34579"},{"taxonomy":"paper_types","embeddable":true,"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/paper_types?post=34579"},{"taxonomy":"tagged","embeddable":true,"href":"https:\/\/www.goodacademic.com\/blog\/wp-json\/wp\/v2\/tagged?post=34579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}