Top risks are Users and social engineering
2. Why do organizations have acceptance and policies? (AUPS)
In order to protect the company and for a legal action to take If there is a violation.
3. Can internet use and email use policies be covered in an Acceptable Use Policy?
Yes anything done on work time and on work devices will be covered in an AUP
4. Do compliance laws such as HIPPA or GLBA play a role in AUP definition?
Absolutely, this should be used as a template for the AUP.
5. Why is an acceptable use policy not a failsafe means of mitigating risks and threats within the User Domain?
Because you cannot control humans
6. Will the AUP apply to all levels of the organization, why or why not?
Yes this will apply to all levels from the lower level to the executive level. The AUP protects all employees.
7. When should this policy be implemented and how?
This policy should be in effect from day 1 of operation and periodically needs to be audited for weaknesses and vulnerabilities.
8. Why does an organization want to align its policies with existing compliance requirements?
This way they do not have to do double work with keeping up with two policies and the organization will need to be compliant regardless so this makes sense to have the same policies.
9. Why is it important to flag any existing standards (hardware, software, configuration, etc.) from an AUP?
This way there are no hidden surprises for anyone and everyone will be on the same page when it comes to policies and procedures
10. Where in the policy definition do you define how to implement this policy within you organization?
In the middle of the AUP this way you can know the expectations before the implementations.
11. Why must an organization have an Acceptable Use Policy (AUP) even for non-employees such as contractors, consultants, and other third parties?
Because it makes everyone responsible that works regardless of what type of worker they are.
12. What security controls can be deployed to monitor ad mitigate users form accessing external websites that are potentially in violation of an AUP?
You can use services like Websense to block specific sites and specific key words.
13. What security controls can be deployed to monitor and mitigate users form accessing external webmail systems and services (i.e., Hotmail, Gmail, Yahoo, etc.)?
Depending on the organization there should only be work emails allowed.
14. What security controls can be deployed to monitor and mitigate users from imbedding privacy data in email messages and/or attaching documents that may contain privacy data?
You could have any email that goes to a personal email address and non-authorized web based email blocked all together.
15. Should an organization terminate the employment of an employee if he/she violates AUP?
Yes, chances are if someone is violating the AUP then they know they are and should be terminated.
You May Also Find These Documents Helpful
-
- Ensure compliance requirements of this policy concerning data at rest and role-holders access to managed networks, systems and servers…
- 582 Words
- 2 Pages
Good Essays -
Olzak, T. & Bunter, B. (2010, May 07). Security basics - components of security policies. Bright…
- 2472 Words
- 10 Pages
Powerful Essays -
This policy is made so people in charge of student and finical data know what to do.…
- 1146 Words
- 5 Pages
Better Essays -
5. - Give five examples of areas that should be covered in a policy/procedure manual.…
- 5586 Words
- 19 Pages
Good Essays -
“Examples of the internal structure may be employee/labor relations, compensation/performance management, training and development, recruiting benefits, health and safety, payroll/HRIS, time and staffing records, etc.” (HR Organizational Structure (September 2010) Toolbox.com). The revised Human Resources Organizational Structure will allow for the separation of duties to be distributed among the two (2) new Human Resource Generalist positions, thereby allowing each generalist to provide specialized focus on their responsibilities. At the conclusion of the 12 month project, all HR Generalist will be responsible for Workforce Planning since the planning affects all processes in this functional area. By working together as a Team, each Generalist will be able to communicate how changes in the workforce will affect their workload, including current…
- 6981 Words
- 28 Pages
Powerful Essays -
entire exercise before you begin. Take time to organize the materials you will need and set…
- 2921 Words
- 18 Pages
Good Essays -
Describe the HIPPA security requirement that could have prevented each security issue identified if it had been…
- 1284 Words
- 6 Pages
Better Essays -
1.2 + 1.3: We have regulations and guidelines with policies and procedures to follow to protect the client for example hear are just a view ways in which we must do this:…
- 1183 Words
- 4 Pages
Satisfactory Essays -
Having a clear and well thought out user policy will keep the work environment and ultimately…
- 338 Words
- 2 Pages
Satisfactory Essays -
1. Identify one organisational policy that is relevant to the work of a team (10 marks)…
- 972 Words
- 4 Pages
Powerful Essays -
The limitations that are put on these policies are not good and there should be some kind of compromise involved; like…
- 1861 Words
- 8 Pages
Good Essays -
Providing information is the key to preparing employees for the change, which in return will help prevent people from completely resisting the new plan put in place. Not all…
- 1182 Words
- 5 Pages
Good Essays -
therefore making it difficult for employees to find any loopholes in the system therefore escaping the…
- 1714 Words
- 7 Pages
Powerful Essays -
There may also be a requirement for certain employees where they would have to submit to the…
- 1877 Words
- 8 Pages
Good Essays -
For example, the company can give a guideline to employee or set up a code of practice.…
- 535 Words
- 3 Pages
Good Essays