Question: UCS422- CYBERSECURITY FOR NON-COMPUTING SCIENCES The DigiTech Sdn Bhd company has been operated for the last 10 years and has more than 500 customers and
UCS422- CYBERSECURITY FOR NON-COMPUTING SCIENCES
The DigiTech Sdn Bhd company has been operated for the last 10 years and has more than 500 customers and more than 50 suppliers/vendors for various services. The administration office is located at a 3 stories shop lots with 50 personnel and a warehouse located 1 kilometer away with 10 personnel taking care of the warehouse activities. The administration offices are using combination of computer automated information systems that can only be accessed within the companys network and manual systems for daily business activities and the data center is also located on the administration building handled by IT personnel. The company also uses email for communication and normal telephone systems. The company is using a websites as a method to put its present to public and recently also join the wagon using social media. The company have been experiencing some theft and misplaced things here and there in administration office as well at the warehouse. Some classified information reaches the receptionist and have been topic of discussion among all employees freely, even the vendors are talking about it. Some data been edited without consent. Although all of these has not affect the business yet but its make the top management worry. The IT personnel is also complaining that server is experiencing some slowdown in processing requests. With the current scenario, the CEO wants to harden the security of the company with some budget constraint. The current security the company have are: Lock at the entrance door, Password to the information systems that are shared within the department, Fire extinguishers, fire alarm and smoke detector. The warehouse is fenced with locked gate during off business hour.
Based on the above information, you is responsible to propose how to harden the company security.
Your discussion should cover the following 1- Roles & Responsibility 2- Data Protection 3- Security awareness, training, and education 4. High-level plan for achieving information security goals and objectives (short & mid-term objective)
(Note: Answer should be in 2000 words in typed with APA referencing)
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
