Information Security Policy
Write a three (4) page paper in which you:
- Develop an IT security policy statement for your organization that addresses the following:
- social engineering
- malware
- the use of external storage devices on organizational equipment
- the education and training of users
- Explain and defend your proposed security policy statement.
- Suggest three (3) automated and / or physical controls to be incorporated into the IT infrastructure that support your proposed security policy statement.
- Analyze how the implemented controls would be monitored and evaluated for the purpose of effectiveness.
next section needs to be one page
- Define social engineering, malware, and removable storage devices.
- Identify the potential risks of social engineering, malware, and removable storage devices.
- Describe how the organization intends to combat the potential risks of social engineering, malware, and removable storage devices.
the work needs 4 references in apa
Information Security Policy
Information security policy refers to a set of policies that an organization uses to ensure that the users of information technology operate within the defined organization domain and at the same time ensure that organizational networks comply with guidelines and rules that govern the security of stored data (Skoudis & Zeltser, 2004). This analysis discusses an IT security policy for an organization focusing on major areas such as social engineering, external storage devices, and user training and education. The analysis includes arguments…………………
