Skip to main content

Information System (IS) Risk Management - Post 5

Karabati application is an online marketplace for the construction industry where users (people that need a task completed) post it online for tradespeople and suppliers (of related material) to bid. All three parties interact and complete payment transactions on the platform. The current risk is in payments since users can bypass the system and make payments offline which compromises the business case. This department has significant problems and vulnerability for potential system failure.  Some data is transmitted using data files.  Some is transmitted via hard copy and must be reentered.  The current situation is that tradespeople and suppliers also use their own systems, so integration and settlement is an issue. This calls for manual re-inputting of the information.  The accidental entry of incorrect data is one of the identified causes of IT system failure (Alexander et al., 2013).   To remedy this vulnerability the company must purchase an accounting software system that it can deploy to handle all the Finance and Accounting Departments work and allow each facilities system to interface with the others.  However, this increases the potential risk associated with the transmission of this information and opening the system to further intrusion.  For this reason, the company must institute security policies and procedures to protect such intrusion from taking place. 
The first ingredient is support from management.  Without support and firm commitment from the management of the company the security policy will be a meaningless document that will become shelfware as the system is compromised and company information is attacked, and systems are rendered useless (Broad, 2013).   Ongoing training must also be a part of the company culture to avoid unintentional compromise from within the company through errors or oversight in security measures.  Employees must be trained in standard operating procedure relating to the use of the company’s systems with regard to password maintenance and structure, use of outside systems such as the World Wide Web, and proper uses of email. 
There are two essential aspects of network security, one being behavioral.  This refers to the habits and behaviors of the individuals within the organization.  The other is the physical and system measures that will prevent an attack from the outside.  The physical security controls access to the mechanics of the system.  The behavioral controls start with the selection of personnel not only on their qualifications to perform the specific job they are chosen for but their backgrounds as law-abiding and moral beings who would do anything to protect the company they have chosen as the providers of their livelihood. 
The human factor should start in the selection of the people chosen to serve the company.  Through checks on their qualifications, references, and financial and criminal backgrounds need to be performed.  These are items that are easily overlooked in the pursuit of individuals who seem to be desirable to fill positions.  In haste, many companies fail to do full checks on these items.  However, these checks are an essential part of network security to avoid problems from within.  These checks are just the first part.  The company must commit to constantly train its people on security measures that they can employ to ensure safe operation of the system.

Physical security is of utmost importance.  Access control needs to be maintained to all areas that contain components of the system that may be compromised.  Monitoring of all the company’s laptops must be a regular practice.  These are deployed for use by personnel who use them for remote work whether it is from home or while traveling.  They must always be accounted for and regularly scanned to ensure that they are not infected by any malware.  Continuous training in the use of the VPN’s and encryption to be used need to be done.
Management commitment, proper selection of employees and proper ongoing training are essential for the protection of internal threats.  A risk assessment and well-planned security policy is the beginning of the protective measures against threats from the outside.  Constant monitoring of both the behavioral aspects of the company’s personnel and a constant and vigilant watch on the system and traffic that it handles are two of the important factors in IS security.

References

Alexander, D., Finch, A., Sutton, D. and Taylor, A. (2013). Information security management principles. Swindon, U.K.: BCS Learning & Development Ltd.
Broad, J. (2013). Risk management framework. Waltham, MA: Syngress.




DECLARATION OF ORIGINALITY

I affirm that the attached work is entirely my own, except where the words or ideas of other writers are specifically acknowledged according to accepted citation conventions. This assignment has not been submitted for any other course at Robert Kennedy College or any other institution. I have revised, edited and proofread this paper. I certify that I am the author of this paper and that any assistance I received in its preparation is fully acknowledged and fully disclosed in this paper (examination). I have also cited any sources from which I used data, ideas, theories, or words, whether quoted directly or paraphrased. I further acknowledge that this paper has been prepared by myself specifically for this course.


Comments