Question Description
Oneof the responsibilities of a Security Administrator is to create anddocument policies that protect the organization and guide users tomaking smart decisions. In this assignment you will build a handbookthat can be used for such a purpose. The NIST’s Special PublicationsWebsite, a government operated Website, provides several documents foryou to review in order to see examples that may be helpful to start thisassignment (http://csrc.nist.gov/publications/PubsSPs.html).
Other helpful Websites for this assignment include:
- DISA.mil (http://iase.disa.mil/)
- TechRepublic (http://www.techrepublic.com/search?q=Security+Administrator+handbook&e=1)
- ACM (http://www.acm.org/search?SearchableText=security+administration)
Additional resources should be used when necessary. Write a thirteen to twenty (13-20) page Security Administrator’s handbook includingpolicies tailored to your work environment or for a business environmentwith which you are familiar. You may select a fictitious name for yourorganization for the purpose of this paper. Do not duplicate yourcompany’s existing handbook. Create your own unique work based on whatyou have learned in this course. There will be two (2) major sections ofthe handbook: Main Body and Policies.
Section 1: Main Body
In five to seven (5-7) pages total, develop the basic procedures and
guidelines that the organization must address to properly secure its
corporate network and information assets in the followings seven (7)
items:
- Network Architecture and Security Considerations
- Wireless Security
- Remote Access Security
- Laptop and Removable Media Security
- Vulnerability and Penetration Testing
- Physical Security
- Guidelines for Reviewing and Changing Policies
Section 2: Policies
Develop the policies section of the handbook and include three to four(3-4) pages for each policy in which you define the policies used by theorganization identifying the unique requirements of your industry. Itmust include, at a minimum, the following four (4) security policies:
- Acceptable Use Policy
- Password Policy
- Incident Response Policy
- User Awareness and Training Policy
To organize your policies and to give your policies structure, follow this sequential format:
- Policy Statement
- Purpose
- Objectives
- Standards
- Procedures and Guidelines
- Responsibilities
- Review and Change Management
- Useat least five (5) quality resources in this assignment. Note: Wikipediaand similar Websites do not qualify as quality resources.