Fill This Form To Receive Instant Help
Homework answers / question archive / Our class focuses on integrating many different aspects of cybersecurity, information security, and information assurance
Our class focuses on integrating many different aspects of cybersecurity, information security, and information assurance. Recent developments in the field of cybersecurity have resulted in a number of "maturity models" which can be used by external assessors to evaluate the maturity level of an organization's cybersecurity management program.
For this discussion paper, you will need to research the Department of Energy's Cybersecurity Maturity Model and then compare it to the NIST Cybersecurity Framework and other frameworks listed in the course readings. After you have done so, write a position paper in which you recommend a cybersecurity framework or maturity model as the basis for assessing the cybersecurity program for Padgett-Beale Financial Services. Assessments will be performed on an annual basis beginning one year after the company launches its new operations.
Your 5-7 paragraph position paper must answer the following questions (at a minimum). (You will need to write clearly and concisely to fit all required information into this restricted length.)
Recommended Approach
Upon purchasing financial services from Island Banking Services, the establishment of a cybersecurity management program for Padgett-Beale is inevitable. As informed by the National Institute of Standards and Technology (NIST), organizations in the modern world must balance the ever-changing cybersecurity threats against the necessity to accomplish business operations. With this in mind, I believe that the NIST Cybersecurity Framework is the ideal approach for Padgett-Beale Financial Services in developing its cybersecurity management program. The most notable reason for this standpoint revolves around the framework’s capability to establish a shared comprehension of cybersecurity risks. This implies that the aforementioned framework provides a shared language that permits all the staff “within an organization, including the stakeholders, to develop a shared understanding of their cybersecurity risks” (NIST, n.d., par.2).
Moreover, the NIST Cybersecurity Framework offers a broader range of other benefits, which will be significant for Padgett-Beale Financial Services. For instance, besides helping the organization to lessen cybersecurity threats with custom-built measures, the approach will further help Padgett-Beale Financial Services to respond as well as recover from cybersecurity incidents, notably by stimulating the analysis of the underlying causes and how to make enhancements. Generally speaking, the implementation of the NIST Cybersecurity Framework will be immensely valuable for the Padgett-Beale organization. To sum up, the framework is risk-based. This implies that upon its implementation, it will play a pivotal function in helping the determination of Padgett-Beale’s risky assets as well as devising ways to protect them (Scofield, 2016).
Laws and Regulations that Must Be Addressed
In the financial sector, there are multiple regulations that must be adhered to in order to conduct business. For this reason, when considering the implementation of a cybersecurity management program, it is vital for financial firms to comprehend how these regulatory standards impact the company’s daily operations. One of these regulations is the Payment Card Industry (PCI) Data Security Standards (DSS). Often referred to as PCI DSS, this regulation is an international set of standards governing how financial companies must handle credit card information. Further, the regulation requires financial service firms to sustain a secure data network as well as consistently monitor data across their network with the aim of preventing theft and destruction of credit card data. Thus, compliance with the PCI DSS mandates financial firms to devise programs that provide complex security solutions to safeguard crucial financial information.