Explain the policies and guidelines for managing organisational IT security
issues (P4)
Disaster recovery policies
It’s a prearrangement that organised, when a problem occurs in a business, example a fire
and it damaged the whole business, it will need a backup prearrangement, to make
everything back to the way it was. If they didn’t plan this, then the business has to go out of
business or start again, they will lose a fair amount of money and additionally have an awful
reputation through the consumers, because the businesses data was corrupted and
permanently erased through the fire.
Updating security procedures
Imperative that the business utilise the security procedure, because changes in IT come fast.
Hence a business has to be ready for quick changes, so they may put in new security for the
business, example if there were a different security strategy like thumb scanning. The
business has to update the safety procedures to achieve the newer security, that is thumb
scanning. For this to happen the business have to have specific guidelines which workers will
do like updated research in security procedures.
Scheduling of security audits
It’s about security monitoring which has to be done on things, PC hardware, physical
protection and software’s, one example a business has to make sure their hardware is
secured through servers. Their software’s need to be tested, so it becomes virus free. The
monitoring has to be frequently scheduled through the business, hence if viruses are trying
to get in or have already gotten in. It will be handled quickly before it impacts the business
or turns into a bigger problem.
Codes of conduct
It’s vital and goes for workers who are working within a business because if workers do not
follow the rules given through the business then the security set in place will restrict the
employer from utilising certain features through the business. Code of conduct include the
following:
Utilisation of e-mail: Workers won’t be permitted to type up specific words and will not be
allowed to send an e-mail to someone who’s not a from their business.
Internet usage policy: The business will not be allowed to view certain sites because of the
policy put in place, for example the websites may be social networking sites or adult sites.
Software acquisition: The worker is only allowed to utilise certain software. Because of legal
reasons or the software can be unsafe to utilise.