Making and Enforcing 1
Running Head: Making and Enforcing Security Legislations and Standards in a College: A
Political Challenge.
Module 3 – Session Long Project
Course #: ITM517
Information Security Overview for Managers and Policy Makers
Making and Enforcing 2
Introduction
Making and enforcing information security legislations and standards are generally
challenging whether it is for private or for government purposes. These processes get even more
complex when politics is added to the matrix. One may possess the proper credentials to make
the best security rules and regulations that are ideal to glean the best information security,
however, passing such laws and enforcing them is a totally different arena. Politics therefore,
cannot be ignored when making and enforcing legislations. This paper begins with an overview
of an information security issue that exists at a community college, followed by a discussion on
the difficulty in enforcing legislations and concludes with a discussion on the role politics plays in
making and enforcing Legislations and Standards.
An Overview of the Information Security Issue: Success Training College is a small
community college located in the Bahamas. The college has three different campuses located on
separate islands in the country. The college has approximately 1000 students. In terms of
information technology the institution has two computer labs, one is used as a classroom for the
computer courses and the other lab is made available to the students during the days. There is
also a wireless internet service made available to the students and faculties which can be
accessed while on campus. The main software that is used by the institution is Campus
Anywhere. Campus Anywhere is a software that allows campus PCs and applications to be
securely available to students, staff, and faculty from ‘anywhere’, at anytime. Campus Anywhere
provides 24/7 computer lab access to students from anywhere; it allows faculty and staff to
access it on their own desktop PCs from anywhere. As it relates to technical staffing, the
institution does not have a structured IT department of such. The main IT person is the
Making and Enforcing 3
institution’s systems administrator who ensures the smooth running of the network and oversees
other systems tasks such as information security. There is also one lab technician who monitors
the activities in the computer labs. All other IT duties are carried out by outsiders.
As with most organizations STC finds it difficult to implement its security laws and
standards. There are many in the institution who believe that the institution’s information
security is a technical task, therefore certain rules and regulations should not be necessary for the
average system users. Information security is not solely a technical problem and when its system
users disregard certain rules and regulations they are putting the institution at risk.
The Difficulty in enforcing legislation: In December 2003, U.S. President George W.
Bush signed into law the Controlling the Assault of Non-Solicited Pornography and Marketing Act
of 2003 (S.877), more commonly referred to as the CAN-SPAM Act of 2003 (Griam, 2003). The
intent of this Act is to set specifications for how email advertisers can legally distribute unsolicited
commercial email (UCE) messages and specifically commercial email messages containing
pornographic text and images (Griam, 2003). Two years after the enactment of CAN-SPAM the
overall compliance rate was to only 5.7%. Armed with CAN-SPAM, U.S. authorities have taken
action against violators and since January 2004 more than 50 federal arrests have been made against
alleged violators of CAN-SPAM (Griam, 2003). However, the threat of federal prosecution has not
been a very strong deterrent because the amount of spam has continued to increase since the
enactment of CAN-SPAM. If this is such a challenging task for the Federal government, just imagine
a small technical team at a community college. Enforcing legislations is not easy; not because a law
exist that say doing something is illegal means that people will avoid doing it. Having a corporate
security policy that is not monitored or enforced is tantamount to having laws but no police
(West, 2008). If the security systems have good auditing capabilities and are watched by event
Making and Enforcing 4
monitoring systems, users at STC who make poor security decisions could be caught and
reprimanded.
Like automated systems at traffic lights that snap pictures and issue violations
to drivers that run red lights, users who make poor security decisions could
receive automated email notifications of their actions and the corporate policy
or safe computing practice (West, 2008).
The role of Politics in making and enforcing Legislations and Standards: Enforcing
legislations signed into law by the Federal government is a tedious task but what about organizational
legislations that are put in place by an organization. These legislations and standards are normally
designed to optimize an organization’s information security; however, just like the Federal ones, they
are often disregarded. Security legislation is political. A list of undocumented security procedures
made by STC technical department will not have the same impact as a detailed document clearly
outlining information security rules and regulations established by the governing body of the
institution. In establishing information security legislation for the institution, all top managers
especially the ones with the clout should be involved in the making of the legislations. When the tech
team involves all top management in the making of the security laws, it is playing positive politics
since the makers of the law will also use their powers to ensure that they are enforced.
The BS ISO/IEC17799: 2000 suggests that employees should follow security producers
correctly, and the standard implies that producing an introduction to information security awareness
programs (education and training activities) is the way to ensure this (Siponen, 2006). Only through
top management involvement can the implementation of such standards be successful. When the
college president has to fund the awareness programs she will be more involved in what is taking
place since the institution’s budget in now involved.
Conclusion
Making and Enforcing 5
It is clear the developing and enforcing information security legislation is a very
challenging task for the Federal government. Such a challenge is equally difficult for private
organizations and institutions. Politics however, plays a very important role in developing and
establishing security legislations and standards. Therefore, if STC law makers are to be
successful in establishing and implementing such rules and regulations they must involve
positive organizational politics.
Making and Enforcing 6
References
Grimes, G. (2007) Compliance with the CAN-SPAM Act of 2003. Communications of the
ACM, Vol. 50 Issue 2, p56-62. Retrieved February 16, 2010 from TUI library.
Siponen, M. (2006). Information security standards focus on the existence of process, not its
content. Communications of the ACM, Vol. 49 Issue 8, pp. 97-100. Retrieved February
West, (2008).