Our Services

Get 15% Discount on your First Order

[rank_math_breadcrumb]

Discussion and Replies

Please see attachment for instructions

 

 
Discussion

 

In 250 words total, answer the questions below with 4 evidence base scholarly articles. APA format.

1. Discuss some of the common issues with implementation of security policy.

2. What are some possible mitigations to ensure policy can be enforced.

Replies

In 400 words total, replying to the two posts below. Each reply must be 200 words for post 1 and post 2. 


E.A POST 1

Hello class, hope we all had a great weekend? Below is my initial submission.

The implementation of information security policies is hampered considerably by an employee’s lack of understanding or interest. Most of them do not read the policies, or they do read them, but fail to comprehend how these policies relate to their daily activities. (Peltier, 2013) argues that the effectiveness of a policy is directly influenced by how well it is disseminated and sustained through training. Even the most well-crafted policies start failing without user awareness.

The other challenge involves policies that are overly verbose or contain complicated language. Policies that are too complicated to read are unlikely to be followed. (Peltier, 2013) emphasizes tailoring content for various groups, like staff, managers, and IT to improve understanding and compliance. Making policies easier to understand improves the likelihood of adoption compliance.

Policy enforcement is also a weak point. Policies often lack apparent enforcement mechanisms such as audits, and no one is verifying compliance. (Peltier, 2013) advocates for the incorporation of technical policy enforcement mechanisms, as well as audit logs, monitoring tools, and policy accountability controls. Policies also need support from organization leadership for legitimacy.

Lastly, many organizations do not routinely review and revise their policies. Policies need to be reviewed and updated at appropriate intervals because both threats and technology evolve over time. An organized review process, especially following audits or if an incident were to occur, will help to keep security practices current (Peltier, 2013). Therefore, policies that are easy to understand, enforceable, and updated regularly can contribute to compliance and reduce risk.

Reference

Peltier, T. R. (2013). Information security fundamentals (2nd ed.). Auerbach Publications.


A.M POST 2

Putting security policies into action is crucial for keeping an organization’s data and systems safe, but it’s not always smooth sailing. A big problem is that employees often don’t follow rules, either because they don’t get why they matter or find them a hassle—like using weak passwords or sharing sensitive info. Regular training and explaining why these policies are important can help build a security-focused mindset. Another issue is spotty enforcement, often because no one’s clear on who’s responsible or there aren’t enough tools to track compliance. Setting clear roles and using automated monitoring can fix this. Smaller organizations especially struggle with limited budgets or know-how. They can lean on affordable cloud security tools or hire outside experts to bridge the gap. Overly complicated policies also cause trouble, confusing everyone and leading to mistakes. Keeping policies simple yet strong, maybe by following standards like NIST, can make things clearer. People often push back against new rules, too. Getting everyone on board early and showing how these changes lower risks can smooth things over. Lastly, policies need to keep up with new threats, so they should be reviewed and updated regularly using the latest threat info. By tackling these challenges with practical solutions, organizations can make sure their security policies actually work without being a burden.

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

Blockchain app programming

i have the template provided and you will have to use the term project presentation to complete it.  Secure-Trade CIS-5730 – Blockchain Applications TERM PROJECT PRESENTATION The money is stored in a digital wallet in the blockchain until two parties pass release or refund (Safe, 2026). The same agreement promotes

HIMS 655 ASS8

Watch the YouTube Video MEDICAL CODING ICD-10-CM GUIDELINES LESSON – 1.B – Coder explanation and examples for 2021 Review the ICD-10-CM Official Guidelines for Coding and Reporting at   and in your assignment respond to the following questions: Who is responsible for framing these Guidelines? Why are these guidelines necessary for

HIMS 645 ASS8

Using Internet resources, search  three national and three international healthcare organizations that maintain databases and use the information based on the processed data from these databases in their decision-making process. Briefly describe the organizations and types of data contained in their databases (make sure to remember quality of data points and

W8: Topic 1 – Course Wrap-Up

 Pick one topic from this class that most interested you. State the topic and your reasons for the choice. ii. You need to respond to at least 2 students.  This is part of your grade to be active in the threads and responding to students.   NB: THIS IS THE TOPIC

Big Data Tools and Emerging Technologies

please see attachment  4 [ Note: To complete this template, replace the bracketed text with your own content. Remove this note before you submit your project.] Big Data Tools and Emerging Technologies Paper [Your Name] DAT 260: Emerging Technologies and Big Data [Your Instructor’s Name] [Date—for example, May 1, 2021]

HIMS 655 ASS7

Mapping between SNOMED-CT and ICD-10-CM Note: For completing this assignment, use of the I-MAGIC tool (Interactive Map-Assisted Generation of ICD Codes) is required. To access the I-MAGIC tool, click on the following  ) Problems and diagnoses can be recorded in SNOMED CT in the EHR, while the cross-mappings to ICD-10-CM can

HIMS 645 ASS7

Four types of databases are Relational, Network, Hierarchical, and Object-Oriented. What are their salient features (a table format is acceptable)? Assess their usability for healthcare facilities that generated numerical, text, and images data citing reasons for your choice.  Two most commonly used databases in healthcare organizations are Relational and Object-Oriented (O-O). Both employ respective

MS ACCESS

Need to do a Microsoft Access document for my work.  2 Consideration of MS Access Database Development on Healthcare. Name Instructor School Date Consideration of MS Access Database Development on Healthcare. Introduction The task entailed developing a Microsoft access database of a small healthcare facility, which has just abandoned the

Effective security programs

Organizational policies define the direction for an organization and contribute to its overall security culture by setting the tone on what is and is not acceptable. 

The Equifax Data Breach

Briefly explain what the Equifax data breach was, why it happened, and why it was important. You should mention that Equifax failed to protect personal data, discuss the ethical and security issues involved, and explain what companies can learn from the incident. Please see attached documents. 

Reflection on Big Data and AI

please see attached DAT 260 Module Five Journal Guidelines and Rubric Overview In this journal assignment, you will reflect on key concepts covered in this module. This assignment directly supports your work in Project Two, which is due in Module Seven. Directions In a well-crafted journal entry, address the following: