Question: Task 1: Transcon SETA Matrix Transcon have defined the following policy statement for managing instances of social engineering, particularly relating to various types of phishing

Task 1: Transcon SETA Matrix Transcon have defined the following policy statement for managing instances of social engineering, particularly relating to various types of phishing attacks. Policy Statement: Social Engineering Transcon will provide the necessary SETA program to maintain the protection of the NOMS IT infrastructure, services and data from all types of social engineering attacks. An organizational SETA program consists of three elements: security education, security training, and security awareness. You have been hired by Transcon to provide a SETA program for the NOMS system. This will be based on developing a strategy for the following 3 roles: 1. CIO; 2. Senior ICT Security Specialist; and 3. Administrative staff. You are required to develop one strategy for each role. You MUST choose which SETA element is best suited for each role based on your knowledge and research. You may choose more than one element for a particular role e.g. both awareness and training for administration staff. It is most important that your choice is appropriately justified. Use the criteria below to complete 'Table 1 Transcon SETA Matrix' that will result in providing the SETA program for Transcon. Element - State and justify the SETA element i.e. education, training, awareness; for each role. Risk - Describe an example of how a social engineering spear-phishing attack could be used to target each role. When writing your example, consider the background and skill level of the users in each role to ensure they understand its meaning. Method - Identify a suitable method to implement the SETA element. Explain why the method will be effective for each role and use a reference to support your answer. Learning - Identify a suitable activity the user in each role will complete to measure their learning. Explain why you have chosen this particular activity and use a reference to support your answer. ROI (Return on Investment) - Describe a favourable outcome of the SETA element that will demonstrate to Transcon management that it has been successful in terms of protecting users from spear-phishing attacks
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
