Southern New Hampshire University IT 552 Case for Final Project
BACKGROUND:
You were just hired as the new chief informa on security o cer for Mul ple Unite Security Assurance (MUSA) Corpora on whose security posture is low. The rst thing your chief execu ve o cer tells you is that they have recently seen a presenta on by one of the informa on security team members emphasizing the importance of having a security awareness program. As a result, you have been asked to develop a security awareness program for MUSA Corpora on based on the following 10 security gaps:
1. No annual cyber security awareness training, which is causing high phishing and social engineering a acks 2. No con gura on change management policy (to reduce uninten onal threats) tt. No intrusion detec on/preven on system 4. Logs are not being collected or analyzed 5. No media access control policy 6. No encryp on or hashing to control data ow and unauthorized altera on of data 7. Vulnerability assessment is conducted every three years; unable to assess the security posture status
and work planning strategy)
9. High number of the reports and security incidents; possible unethical/disgruntled employees 10. No segrega on of du es or mandatory vaca on policies (to mi gate inten onal threats)
To that end, you will make recommenda ons for enhancing security policies, prac ces, and processes that are currently contribu ng to a dysfunc onal security culture. Your chief goal is to build a program that will foster a healthy security culture and ensure con nuous improvement. Your task is to develop a security awareness program that consists of four major components
1. Proposal Introduc on
11. Security Policies Development 12. Con nuous Monitoring Plan 1tt. Communica on Pl