Karabati application is an online marketplace for the construction
industry where users (people that need a task completed) post it online for
tradespeople and suppliers (of related material) to bid. All three parties
interact and complete payment transactions on the platform. The current risk is
in payments since users can bypass the system and make payments offline which
compromises the business case. This department has significant problems and
vulnerability for potential system failure. Some data is transmitted
using data files. Some is transmitted via hard copy and must be
reentered. The current situation is that tradespeople and suppliers also
use their own systems, so integration and settlement is an issue. This calls
for manual re-inputting of the information. The accidental entry of
incorrect data is one of the identified causes of IT system failure (Alexander
et al., 2013). To remedy this vulnerability the company must
purchase an accounting software system that it can deploy to handle all the
Finance and Accounting Departments work and allow each facilities system to
interface with the others. However, this increases the potential risk
associated with the transmission of this information and opening the system to
further intrusion. For this reason, the company must institute security
policies and procedures to protect such intrusion from taking place.
The first ingredient is support from
management. Without support and firm commitment from the management of
the company the security policy will be a meaningless document that will become
shelfware as the system is compromised and company information is attacked, and
systems are rendered useless (Broad, 2013). Ongoing training must
also be a part of the company culture to avoid unintentional compromise from
within the company through errors or oversight in security measures.
Employees must be trained in standard operating procedure relating to the use
of the company’s systems with regard to password maintenance and structure, use
of outside systems such as the World Wide Web, and proper uses of email.
There are two essential aspects of network
security, one being behavioral. This refers to the habits and behaviors
of the individuals within the organization. The other is the physical and
system measures that will prevent an attack from the outside. The
physical security controls access to the mechanics of the system. The
behavioral controls start with the selection of personnel not only on their
qualifications to perform the specific job they are chosen for but their
backgrounds as law-abiding and moral beings who would do anything to protect
the company they have chosen as the providers of their livelihood.
The human factor should start in the selection of the people
chosen to serve the company. Through checks on their qualifications,
references, and financial and criminal backgrounds need to be performed.
These are items that are easily overlooked in the pursuit of individuals who
seem to be desirable to fill positions. In haste, many companies fail to
do full checks on these items. However, these checks are an essential
part of network security to avoid problems from within. These checks are
just the first part. The company must commit to constantly train its
people on security measures that they can employ to ensure safe operation of
the system.
Physical security is of utmost importance. Access control
needs to be maintained to all areas that contain components of the system that
may be compromised. Monitoring of all the company’s laptops must be a
regular practice. These are deployed for use by personnel who use them
for remote work whether it is from home or while traveling. They must
always be accounted for and regularly scanned to ensure that they are not
infected by any malware. Continuous training in the use of the VPN’s and
encryption to be used need to be done.
Management
commitment, proper selection of employees and proper ongoing training are
essential for the protection of internal threats. A risk assessment and
well-planned security policy is the beginning of the protective measures
against threats from the outside. Constant monitoring of both the
behavioral aspects of the company’s personnel and a constant and vigilant watch
on the system and traffic that it handles are two of the important factors in
IS security.
References
Broad, J. (2013). Risk management framework. Waltham, MA: Syngress.
DECLARATION OF ORIGINALITY
I affirm that the attached work is entirely my own, except where the words or ideas of other writers are specifically acknowledged according to accepted citation conventions. This assignment has not been submitted for any other course at Robert Kennedy College or any other institution. I have revised, edited and proofread this paper. I certify that I am the author of this paper and that any assistance I received in its preparation is fully acknowledged and fully disclosed in this paper (examination). I have also cited any sources from which I used data, ideas, theories, or words, whether quoted directly or paraphrased. I further acknowledge that this paper has been prepared by myself specifically for this course.
Comments
Post a Comment