question archive Only needs to Answer underlined questions below
Subject:Computer SciencePrice: Bought3
Only needs to Answer underlined questions below.
Note: To highlight something briefly mentioned in the article from the previous part, a prominent difference between companies with hierarchical and flat structures is size. A company’s size can affect employee behavior as much as the structure or other factors can, especially an employee’s sense of job security, purpose, and potential to contribute to the company’s overall success. These factors can make an employee feel dissatisfied or even apathetic.In this part of the lab, you will apply what you learned in Part 1 to design an organization-wide policy framework implementation plan.
Review the following scenario for the fictional Specialty Medical Clinic:
The Specialty Medical Clinic is a fictional medical clinic that is currently being acquired by a larger organization, United Medical Services. United Medical Services follows a hierarchical structure with multiple departments and clinics. The Specialty Medical Clinic is a flat organization. You are a policy analyst working for United Medical Services and have been tasked with extending the parent organization's security policy framework to the newly acquired clinic.
United Medical Services Acquires Speciality Medical Clinic
Publish Your Policies for the New Clinic : Explain your strategy
Communicate Your Policies to the New Clinic EmployeesHow are you going communicate policies to employees?
Note: Special all-hands meetings, called “town hall meetings,” can be held between team or departmental leads. Team leaders might then share the information they’ve gained from town hall meetings with employees.
Involve Human Resources and Executive ManagementHow would you smoothly involve HR and executive management?
Incorporate Security Awareness and Training for the New ClinicHow do you make the training fun and engaging?
Note: Like any mandatory training, employees often dread mandatory security awareness training. It can be dry, not relevant to their positions, and a distraction from what they’re paid to do. But it doesn’t have to be that way. As with any training, security awareness training can become more effective by employing unconventional or interactive delivery mechanisms. For example, rather than requiring employees to read a policy and take an assessment quiz, the employees could participate in a role-playing exercise with teams of “good guys” and “bad guys.” This type of training takes considerably more planning, but, once it’s designed for a small group, the exercise is easily repeatable. The training will likely be talked about and remembered for much longer.
User behavior will also more likely be changed if the training is tailored to the employees and their specific department. An employee in shipping may be more receptive if security topics are presented in the context of freight docks rather than a cubicle setting. Relevance goes a long way toward fostering real learning.
Finally, the rationale behind the security training must be explained. Without presenting the why, or the consequences, the employees have little reason to internalize the valuable training.
Release a Monthly Organization-Wide NewsletterHow can you make this newsletter succinct and informative?
Implement Security Reminders on System Log-in ScreensWhich critical systems would you deploy these to?
Incorporate Ongoing Security Policy Maintenance for AllHow will you review and obtain feedback from employees and policy-compliance monitoring?
Note: Be mindful that a new policy or procedure doesn’t negatively impact a business process or create unintended challenges in a particular department. When users find that a policy is going to make their jobs harder, they’re much more likely to try to circumvent that policy.
Employee feedback may be the only method for revealing how a policy might impose unintended challenges on an employee. Be certain to clearly communicate, to leaders and employees alike, that feedback must be open and honest and may be given without fear of adverse repercussions.
Obtain Employee Questions or Feedback for Policy BoardHow will you review and incorporate employee questions and feedback into policy edits and changes as needed?