Most loyal employees want to comply with the security policies their organizatio
ID: 3818371 • Letter: M
Question
Most loyal employees want to comply with the security policies their organizations define, yet they may feel forced to violate those policies to satisfy their work requirements. Describe a scenario where an employee might compromise a security policy in order to perform a particular job function. Examples of common security policies that may not always be possible to comply with include sharing passwords with coworkers, leaving a computer logged in while the employee is away from the desk, connecting computers to the company network without the latest antivirus software, and providing system access information over the phone or through email without proof of identity by the requester.
Explanation / Answer
One of the biggest scenario where an employee might compromise a security policy in order to perform a particular job function is to use storage devices which are not secured.
There comes a need for a software developer to install some particular software into his laptop. The reason behind the need of the software installation could be either of installing a new software for new task or crashing of the existing software.
Sometimes, in the pressure of completing the task given to him, he consider copying the software from his colleague's laptop rather than downloading it from the internet(which might take more time).
In order to copy data from other laptop to his own laptop, he might go with his personel storage device. This device first connects with the first person and then his own. Since, the storage device is not fully secured(since its personel), there might be a case when the virus present in the device enters into the user's laptop. And since, both the employees are connected to the office network, the virus can spread into the whole network and infect all the systems in the network.
Thus, the security of the whole network is compromised.
NOTE: this is a real life incident in a software company.
============================================================
feel free to ask if you have any doubt :)
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.