Cumberlands Nist IT Security Policy Frameworks Paper

Cumberlands Nist IT Security Policy Frameworks Paper

IT Security Policy Frameworks

COSO

COBIT

ISO

ITIL

NIST

PCI DSS

HIPAA

Sarbanes Oxley

BS 7799

AS/NZS 4444

Assignment

As a group, please select a IT Security Policy framework from above and write a 10 -15-page paper that must include the following:

  • Discuss the framework chosen and how it works.
  • Discuss the strengths and weakness of the framework.
  • Discuss why is it important for businesses to understand their business objectives when selecting an IT security policy framework.
  • Provide three real-world examples of business organizations that use your chosen framework and discuss how the framework fits their business objectives. Your examples should be complete.
  • For each example, discuss what can happen if the framework you chose does not fit its business objectives.
  • For each example, describe the roles and responsibilities of people needed to support your security policy framework. Discuss why is it important to have the different roles defined and have people assigned to those roles. Discuss what can happen when you don’t.
  • For each example, discuss the legal and ethical aspects that pertain to each business using your chosen IT security policy framework.
  • Discuss what you have learned from this assignment and how you will apply it moving forward.
  • Your paper should be Times New Roman Font, 12-point, double spaced.
  • Please cite your references in APA format. Your reference page does not count toward your 10-15-page paper requirement.