Preview

Unit 5 Assignment 5

Satisfactory Essays
Open Document
Open Document
514 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Unit 5 Assignment 5
Unit 5 Assignment 5.3

Implementing Comprehensive Human Resources Risk Management Plan
Human resources policies and practices should reduce the human risk factors in information technology IT security and information access controls. Decrease the risk of theft, fraud or misuse of information facilities by employees, contractors and third-party users.
The organization’s human resources policies taken as a whole, should extend to all the persons within and external to the organization that do or may use information or information processing facilities. This could include: tailoring requirements to be suitable for particular roles within the organization for which persons are considered; ensuring that persons fully understand the security responsibilities and liabilities of their role(s); ensuring awareness of information security threats and concerns, and the necessary steps to mitigate those threats; and
Providing all persons to support organizational privacy and security policies in the course of their normal work, through appropriate training and awareness programs that reduce human error; and ensuring that persons exit the organization, or change employment responsibilities within the organization, in an orderly manner.
Roles and responsibilities • Security roles and responsibilities of employees, contractors and third-party users should be defined and documented in accordance with the organization's information privacy and security policies. This could include:
To act in accordance with the organization's policies, including execution of all processes or activities particular to the individual's role(s);
To protect all information assets from unauthorized access, use, modification, disclosure, destruction or interference;
To report security events, potential events, or other risks to the organization and its assets
Assignment of responsibility to individuals for actions taken or, where appropriate, responsibility for actions not taken, along with appropriate

You May Also Find These Documents Helpful

  • Good Essays

    It244 R Appendix E

    • 650 Words
    • 3 Pages

    Describe the policies for securing the facilities and the policies of securing the information systems. Outline the controls needed for each category as relates to your selected scenario.…

    • 650 Words
    • 3 Pages
    Good Essays
  • Good Essays

    This report gives a brief description the general security solutions planned for the safety of data and information that belongs to the organization. The outline will provide elements of a multi-layered security plan, and will indicate a general security solution for each of the seven domains of a typical IT infrastructure. Also I will describe a layer of security for each of the seven domains.…

    • 801 Words
    • 4 Pages
    Good Essays
  • Better Essays

    1.3 - Explain the purpose of legal and organizational requirements for the security and confidentiality of information…

    • 1681 Words
    • 7 Pages
    Better Essays
  • Better Essays

    LIT1 Task 2

    • 1171 Words
    • 4 Pages

    Human resource departments are responsible for effectively, legally, fairly, and consistently attempting to maximize an organization’s return on its human capital investment while minimizing financial risk. This is why labor laws and Civil Acts are placed in the work place and other felicities to insure the well fare of others are without risk and effective(WGU).…

    • 1171 Words
    • 4 Pages
    Better Essays
  • Better Essays

    In an organization of any size or complexity, employees ' responsibilities typically are defined by what they do, who they report to, and for managers, who…

    • 1089 Words
    • 5 Pages
    Better Essays
  • Good Essays

    Organisations have a duty to ensure the security and confidentiality of information under their control. Most organisations have policies on information security and confidentiality which go beyond the requirements of the Data Protection Act. They also have quality control procedures which staff must follow in order to keep information systems secure, accurate and updated.…

    • 501 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    Is 411 Study Guide

    • 305 Words
    • 2 Pages

    Privileged Access Agreement (PAA) - Page 220 – Contractors and temporary workers sign this type of document.…

    • 305 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    Est1 Task 1

    • 623 Words
    • 3 Pages

    The security rule has meaningful standards that are grouped into five categories; administrative safeguard, physical safeguard, technical standards, organizational standards, and policies, procedures, and documentation requirements. Administrative safeguards have several standards that help implement the security rule. The security operation purpose require organizations to evaluate their risks to security and implement policies and procedures that prohibit, detect, and acceptable security violations and to define appropriate approval for security violations. Another, workforce security has three implementation qualifications that are mandatory by the organizations. The organization has to contain policies and procedures to ensure that each members of the particular…

    • 623 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    Discussion 1

    • 396 Words
    • 2 Pages

    A security policy defines limitations on individual behavior or system performance and details activities that are permitted, controlled or prohibited within the company. In order for policies to be effectual, senior management must endorse them, they must be communicated to all employees, undergo recurring reviews, and be assessed for usefulness. A security program encompasses all of the required pieces necessary to successfully protect a business. It should include policies, requirements, standards and procedures. Security plans should be operative at all levels of a corporation to be effective. Management should communicate a formal explanation of what is acceptable by all employees. Management should also clearly dictate what the consequences of noncompliance are. Organizations can use the ISO-27002:2005 as an outline to create a security policy.…

    • 396 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    nvq unit 2

    • 1616 Words
    • 5 Pages

    1) know the statutory responsibilities and rights of employees and employers within own area of work…

    • 1616 Words
    • 5 Pages
    Good Essays
  • Better Essays

    not disclosed without consent, preventing accidental disclosure of information, practicing strict security measures, like shredding paperbased information, logging out of electronic data systems and operating effective incident reporting processes; ensure the security of access to records and reports according to legal and organizational procedures, ethical codes or professional standards; the importance of keeping legible, accurate, complete and up-to-date records eg signed and dated,…

    • 1407 Words
    • 6 Pages
    Better Essays
  • Powerful Essays

    Unit 201

    • 1645 Words
    • 7 Pages

    To protect the rights of employers and employees by providing rules and regulations that must be followed.…

    • 1645 Words
    • 7 Pages
    Powerful Essays
  • Good Essays

    Myles Munroe believes that, “The value of life is not in its duration, but in its donation. You are not important because of how long you live, you are important because of how effective you live.” People in the world have their own view on life, but as Munroe states, it’s not about how long a person lives but the effectiveness of what they have done with their life because it affects how the future generations will turn out. Throughout time and space, people have debated about what the purpose of life is and why do people have the opportunity to experience it. People like William Shakespeare, Robert Ebert, and Amanda Ripley all have their own appointing views on life but they all relate to each other in many different ways.…

    • 802 Words
    • 4 Pages
    Good Essays
  • Powerful Essays

    Human resource policies are the formal rules and guidelines that businesses put in place to hire, train, assess, and reward the members of their workforce. These policies, when organized and disseminated in an easily used form, can serve to preempt many misunderstandings between employees and employers about their rights and obligations in the business place.…

    • 2117 Words
    • 7 Pages
    Powerful Essays
  • Good Essays

    Human resource policies are the formal rules and guidelines that businesses put in place to hire, train, assess, and reward the members of their workforce. These policies, when organized and…

    • 1035 Words
    • 4 Pages
    Good Essays