¶ … Security Management
During the span of one's college career, a select number of courses become something more than a simple requirement to be satisfied to assure graduation; these are moments in a student's educational process which make the most lasting impacts. In my personal case, the lessons I have learned as part of my studies in ISSC680 will likely be remembered in those terms, as my eventual career will find me utilizing much of the foundational knowledge I gained in this course on a daily basis. As an aspiring information security officer, who hopes to apply the skills imparted throughout my time in ISSC680 during my professional career, I am sure that when I reflect on my college experience this class will stand out above the rest in terms of significance. The two textbooks which have provided detailed instruction on the field of information security, Information Security Fundamentals and Information Security: Design, Implementation, Measurement, and Compliance, have become essential resources both in and out of the classroom setting, as the wealth of experiential data contained within has enabled me to comprehend both the requirements of my future career, and the great responsibility my duties as an information security officer will entail. From the theoretical underpinnings of data protection and access control methods, to the moral and ethical ramifications of protecting a firm's invaluable data by any means necessary, the course material I have been exposed to during my time in ISSC680 ranks among the most influential of my college career. Through a thorough review of the course itself, including the crucial concepts that form the foundation of an information security officer's daily duties, I hope to examine the multitude of ways that this course has improved my base of knowledge, expanded my skill set, and enhanced my capabilities as a defender of digital data.
Throughout the entire course I have been continually exposed to new sources of knowledge regarding the field I aspire to work within, from the textbook material, instructors, and even fellow students. The process of reading individual chapters from the textbooks, which covered such diverse topics as risk assessment models, risk analysis and management, and access control methods, and writing detailed essays on the relevant material proved to be a highly informative process. By approaching the various methodologies and procedures used by information security analysts in the field, and contemplating how I may apply them within my own career, I found my confidence increasing as my base of knowledge continued to expand. As the authors of Information Security Fundamentals state in the introduction to their expansive volume, the book "was designed to give the information security professional a solid understanding of the fundamentals of security and the entire range of issues the practitioner must address" (Peltier, Peltier & Blackley, 2005). It was through this course that I was first exposed to the network of organizations working to serve information security professionals, including the Computer Security Institute (CSI), "the original and leading educational membership organization for information security professionals" whose mission is "to provide high quality products that focus on practical, cost-effective strategies, solutions and methodologies that will help you to protect your organization's greatest asset: Information" (Computer Security Institute, 2012). Having come to the conclusion of my experience in the ISSC680 course, I firmly believe that I am more fully prepared to accomplish my duties as a professional information security analyst, because today I am equipped with both the theoretical foundations of the industry's fundamental tenets, and the ability to discern when, where and how to most properly deploy those skills.
One of the core concepts within the field of information security and data protection is that of risk assessment, and considering Timothy P. Layton states in the preface to Information Security: Design, Implementation, Measurement, and Compliance that "the heart of every information security program is always risk assessment" (2007), it is useful to begin any discussion of ISSC680 with this critical component. While the idea of assessing the litany of risk factors, both from external threats and internal misconduct, may appear to an obvious step in securing an organization's data delivery networks, I soon discovered through our readings and lectures that a true information security professional must be capable of seeing beneath the proverbial surface of every security issue they confront. After becoming familiarized with the Information Security Risk Assessment Model (ISRAM), as well as other assessment types such as the Global Information Security Assessment Methodology (GISAM), I now feel extremely prepared to assist the organization that hires me by identifying threats through anticipatory...
Security Information security is a primary concern for consumers and businesses. In "IT security fails to keep pace with the rise of cloud computing," the author claims that in spite of the advancements in cloud technology, information security has not kept pace. This assessment is rooted firmly in fact and best practices in the information security industry. Although their analysis is thorough, the authors would do well to point out the
Security Management Information Security Management Managing the information security at a major university is never an easy task, and especially with a team of only ten the complexities and the resource demands can sometimes make the situation seem all but impossible even on the best of days. When the former head of information security management suddenly departs as the result of an FBI arrest -- and when that arrest stems from the
SECURITY Information Security and Risk Management in IT This essay is designed to present and discuss both an assessment of information security and risk management in IT systems and a comparative discussion of important academic theories related to security and risk. In the first section, An assessment, a conceptual framework will emerge including reference to important terminology and concepts as well as an outline of legislation and authorized usage examples. In the
Security at Work Information Security within the nursing fraternity With the advent of consolidated information storage within the nursing fraternity, there has grown the need to have better security and controlled access to such information that may be considered confidential and for the use by the nurse and the patient alone. When anyone wants therefore to have access to the documents I will always need to verify several details just to be
Information Security The discussion below provides answers to questions raised with regard to a case at Greenwood Company A forensic plan of readiness comes with several advantages. If there arises a situation that forces a company to be engaged in litigation, and there is need for digital evidence, e-discovery is of central importance. The laws and rules that govern the e-discovery, such as the Federal Rules of Civil Procedure or the Practice
Security A broad definition of information security is given in ISO/IEC 17799 (2000) standard as: "The preservation of confidentiality (ensuring that information is accessible only to those authorized to have access), integrity (safeguarding the accuracy and completeness of information and processing methods), and availability (ensuring that authorized users have access to information and associated assets when required" (ISO/IEC 17799, 2000, p. viii). Prior to the computer and internet security emerged as we
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now