Developing an Information Security Program for Denisovan Medical

Verified

Added on  2023/06/18

|5
|715
|454
Case Study
AI Summary
This case study solution addresses the security management and governance challenges faced by Denisovan Medical Supplies, a chemical product manufacturer for pharmacological medicines. It outlines the benefits and purpose of an information security program (ISP), detailing major elements such as prevention, detection, access management, privacy, risk assessment, audit, monitoring, and incident response. The solution suggests a hierarchical staffing structure with roles for risk management, data security, and compliance, emphasizing clear functions, tasks, and responsibilities. It highlights the importance of governance within the ISP, including strategic alignment, decision-making, and conformance to requirements, applicable across all staff levels. The suggested governance responsibilities include following strategic direction, achieving objectives, monitoring risk, taking strategic decisions, and ensuring compliance with internal and external requirements.
Document Page
SECURITY MANAGEMENT
AND GOVERNANCE
1
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
TABLE OF CONTENTS
MAIN BODY ..................................................................................................................................3
Describing benefit & purpose of having information security program .....................................3
Describing the major elements of Information Security Program (ISP)....................................3
Suggesting the Information Security staffing structure for the specified business .....................3
Justifying suggested structure.....................................................................................................4
Describing the suggested structure's functions, task and responsibility .....................................4
Discussing the importance of governance within information security program........................4
Suggesting the different governance responsibilities that need to be assigned in staffing
structure........................................................................................................................................4
REFERENCES................................................................................................................................5
2
Document Page
MAIN BODY
The security management & governance play important role in influencing success. The
current case study is based on Denisovan Medical Supplies which is related with identifying
scope, purpose and framework regarding staffing structure, etc.
Describing benefit & purpose of having information security program
It can help in preventing company from technology based risk, ineffective procedure and poorly
informed staff leading in appropriate production, administration, etc. It will allow improving
company culture, central framework, availability of resources, etc. The purpose behind
implementing the security based program is to prevent data, confidentiality and integration of
assets of company.
Describing the major elements of Information Security Program (ISP)
The major components comprise prevent & detection mechanism, access of management, access
management, privacy & compliance, risk , audit, monitoring, incident response , etc. these are
considered as crucial aspects of ISP that can benefit Denisovan Medical Supplies (AlGhamdi,
Win and Vlahu-Gjorgievska, 2020). It can be understood that it provides consideration on
confidentiality, pro-session, integration, availability and utility.
Suggesting the Information Security staffing structure for the specified business
The smooth functioning of organizational processes can be attained by developing appropriate
hierarchical functional structure. This will segregate the employees into level like top, medium
and lower level for understanding their roles & responsibilities effectively. It will involve
different manger for risk, securing data, compliance with government rule, etc.
3
Document Page
Justifying suggested structure
The mentioned hierarchical structure will help the Denisovan Medical Supplies to segregate the
responsibilities sin effectual manner to accomplish objectives. In addition to this, it will aid in
getting ability to decline prevailing threats and lacking areas of each function o that proper
coordination to get integrity in business practices via effectual information security system can
be derived.
Describing the suggested structure's functions, task and responsibility
The mentioned functional hierarchical structure shows the chain of command in which each
position will be responsible for specific task regarding information security to accomplish
determined objective. It will basically comprise security compliance, data prevention, risk
mitigation, etc. this will focus on having appropriate availability of information among
Denisovan Medical Supplies's department like administration, sales, production, etc. to get
proper coordination.
Discussing the importance of governance within information security program
There are various reasons for which the organization required to have governance within
information security programs (Henry, 2019). It includes making assurance that company has
correct informations structure, leadership , guidance, etc which are contributing in analysing,
monitoring and controlling risk. Proper coordination, strategic alignment with objectives,
decision formulation, etc. are exerted by having significant governance in ISP.
Suggesting the different governance responsibilities that need to be assigned in staffing structure
Governance is concerned with overall functioning of company which is implied on all the staff
of hierarchy. It will be applicable on all employees such as following strategic direction,
achieving objectives, monitoring risk, taking strategic decision, ensure conformance with
internal & external requirements, etc.
4
tabler-icon-diamond-filled.svg

Paraphrase This Document

Need a fresh take? Get an instant paraphrase of this document with our AI Paraphraser
Document Page
REFERENCES
Books and journals
AlGhamdi, S., Win, K.T. and Vlahu-Gjorgievska, E., 2020. Information security governance
challenges and critical success factors: Systematic review. Computers & Security. 99.
p.102030.
Henry, K., 2019. The human side of information security. In Information Security
Management (pp. 239-262). Auerbach Publications.
5
chevron_up_icon
1 out of 5
circle_padding
hide_on_mobile
zoom_out_icon
[object Object]