Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

1- There are two approaches to information security policies: the parallel appro

ID: 3802459 • Letter: 1

Question

1- There are two approaches to information security policies: the parallel approach and the integrated approach.

a- Explain each of them.

b- Which one is more efficient? Explain your response.

2- Describe each of the six stages of the employee life cycle using your own words ?

Define and provide examples for the following :

a- Information assets

b- Information system

4:-

a- Based on what the Federal Information Processing Standard 199 (FIPS-199) requires information owners to classify information and information systems? Provide a detailed answer.

b- Are there any differences between classifying governmental information and commercial information? And are there any common levels of classification have been used to classify governmental information and commercial information? Explain your answers and supported them with examples (NOT from the book or slides).

c- Can a company make a change on classified information? Assuming now a company feels that such information need higher protection or the company decide to make some information that was classified as secret to be accessed by public. Here, is there any mechanism or process that allows a change in classified information. Explain your answers and supported them with examples (NOT from the book or slides).

Explanation / Answer

1.

a- Information Security: Information security is used to avoid the misuse, loss and modification of important information because there will be a large amount of valuable data which must be secured. The information security policies are the rules directing the usage of certain standards .By using some authorized approaches the information security policy is responsible for protecting information system of an organization.

The two approaches to information security policies are:

b- Integrated approach to information security policy is better than parallel one because all the policies of an organization are pre-planned keeping information security in mind. In parallel approach it is difficult to change the predefined patterns when security issues are detected. So the integrated approach is better and saves time and energy.