Red Clay Renovations is an internationally recognized, awarding winning firm that specializes in the renovation and rehabilitation of residential buildings and dwellings. The company specializes in updating homes using “smart home” and “Internet of Things” technologies while maintaining period correct architectural characteristics. Please refer to the company profile (file posted in Week 1 > Content > CSIA 413 Red Clay Renovations Company Profile.docx) for additional background information and information about the company’s operating environment.
The Manager’s Deskbook contains issue specific policies and implementation procedures which are required to mitigate risks to the company and to otherwise ensure good governance of the company’s operations. The Chief Information Security Officer (CISO) and key CISO staff members held a kick-off meeting last week to identify issue specific policies which should be added to the company’s policy system in the IT Governance category. The policies will be disseminated throughout the company by incorporating them into the Manager’s Deskbook. The required issue specific policies are:
For the purposes of this assignment, you will create a policy recommendations briefing package (containing an Executive Summary and draft policies) and submit that to your instructor for grading.
Note: In a “real world” environment, the policy recommendations briefing package would be submitted to the IT Governance board for discussion and vetting. After revisions and voting, a package containing the accepted policies would be sent to all department heads and executives for comment and additional vetting. These comments would be combined and integrated into the policies and sent out for review again. It usually takes several rounds of review and comments before the policies can be sent to the Chief of Staff’s office for forwarding to the Corporate Governance Board. During the review & comments period, the policies will also be subjected to a thorough legal review by the company’s attorneys. Upon final approval by the Corporate Governance Board, the policies will be adopted and placed into the Manager’s Deskbook. This entire process can take 9 to 12 months, if not longer.
As a staff member supporting the CISO, you have been asked to research and then draft an issue specific policy for each of the identified issues (three separate policies). These policies are to be written for MANAGERS and must identify the issue, explain what actions must be taken to address the issue (the company’s “policy”), state the required actions to implement the policy, and name the responsible / coordinating parties (by level, e.g. department heads, or by title on the organization chart).
After completing your research and reviewing sample policies from other organizations, you will then prepare an “approval draft” for each issue specific policy.
The purpose of each issue specific policy is to address a specific IT governance issue that requires cooperation and collaboration between multiple departments within an organization.
Each issue specific policy should be no more than two typed pages in length (single space paragraphs with a blank line between).
You will need to be concise in your writing and only include the most important elements for each policy.
You may refer to an associated “procedure” if necessary, e.g. a Procedure for Requesting Issuance of a Third Level Domain Name (under the company’s Second Level Domain name) or a Procedure for Requesting Authorization to Establish a Social Media Account.
Your “approval drafts” will be combined with a one page Executive Summary (explaining why these issue specific policies are being brought before the IT Governance Board).
URLs for Recommended Resources
Title |
Type |
Link |
NIST SP 800-100 Information Security Handbook: A Guide for Managers |
|
|
NIST SP 800-12: An Introduction to Information Security |
|
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-12r1.pdf |
NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations |
|
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf |
As you write your policies, make sure that you address IT and cybersecurity concepts using standard terminology.
Submit your Manager’s Deskbook briefing package in MS Word format (.docx or .doc file) for grading using your assignment folder. (Attach the file.)
Hi there! Click one of our representatives below and we will get back to you as soon as possible.