0% found this document useful (0 votes)
5 views6 pages

Enforcing Security Legislation at STC

Uploaded by

floydmullings
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views6 pages

Enforcing Security Legislation at STC

Uploaded by

floydmullings
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Making and Enforcing 1

Running Head: Making and Enforcing Security Legislations and Standards in a College: A

Political Challenge.

Module 3 – Session Long Project

Course #: ITM517

Information Security Overview for Managers and Policy Makers


Making and Enforcing 2

Introduction

Making and enforcing information security legislations and standards are generally

challenging whether it is for private or for government purposes. These processes get even more

complex when politics is added to the matrix. One may possess the proper credentials to make

the best security rules and regulations that are ideal to glean the best information security,

however, passing such laws and enforcing them is a totally different arena. Politics therefore,

cannot be ignored when making and enforcing legislations. This paper begins with an overview

of an information security issue that exists at a community college, followed by a discussion on

the difficulty in enforcing legislations and concludes with a discussion on the role politics plays in

making and enforcing Legislations and Standards.

An Overview of the Information Security Issue: Success Training College is a small

community college located in the Bahamas. The college has three different campuses located on

separate islands in the country. The college has approximately 1000 students. In terms of

information technology the institution has two computer labs, one is used as a classroom for the

computer courses and the other lab is made available to the students during the days. There is

also a wireless internet service made available to the students and faculties which can be

accessed while on campus. The main software that is used by the institution is Campus

Anywhere. Campus Anywhere is a software that allows campus PCs and applications to be

securely available to students, staff, and faculty from ‘anywhere’, at anytime. Campus Anywhere

provides 24/7 computer lab access to students from anywhere; it allows faculty and staff to

access it on their own desktop PCs from anywhere. As it relates to technical staffing, the

institution does not have a structured IT department of such. The main IT person is the
Making and Enforcing 3

institution’s systems administrator who ensures the smooth running of the network and oversees

other systems tasks such as information security. There is also one lab technician who monitors

the activities in the computer labs. All other IT duties are carried out by outsiders.

As with most organizations STC finds it difficult to implement its security laws and

standards. There are many in the institution who believe that the institution’s information

security is a technical task, therefore certain rules and regulations should not be necessary for the

average system users. Information security is not solely a technical problem and when its system

users disregard certain rules and regulations they are putting the institution at risk.

The Difficulty in enforcing legislation: In December 2003, U.S. President George W.

Bush signed into law the Controlling the Assault of Non-Solicited Pornography and Marketing Act

of 2003 (S.877), more commonly referred to as the CAN-SPAM Act of 2003 (Griam, 2003). The

intent of this Act is to set specifications for how email advertisers can legally distribute unsolicited

commercial email (UCE) messages and specifically commercial email messages containing

pornographic text and images (Griam, 2003). Two years after the enactment of CAN-SPAM the

overall compliance rate was to only 5.7%. Armed with CAN-SPAM, U.S. authorities have taken

action against violators and since January 2004 more than 50 federal arrests have been made against

alleged violators of CAN-SPAM (Griam, 2003). However, the threat of federal prosecution has not

been a very strong deterrent because the amount of spam has continued to increase since the

enactment of CAN-SPAM. If this is such a challenging task for the Federal government, just imagine

a small technical team at a community college. Enforcing legislations is not easy; not because a law

exist that say doing something is illegal means that people will avoid doing it. Having a corporate

security policy that is not monitored or enforced is tantamount to having laws but no police

(West, 2008). If the security systems have good auditing capabilities and are watched by event
Making and Enforcing 4

monitoring systems, users at STC who make poor security decisions could be caught and

reprimanded.

Like automated systems at traffic lights that snap pictures and issue violations

to drivers that run red lights, users who make poor security decisions could

receive automated email notifications of their actions and the corporate policy

or safe computing practice (West, 2008).

The role of Politics in making and enforcing Legislations and Standards: Enforcing

legislations signed into law by the Federal government is a tedious task but what about organizational

legislations that are put in place by an organization. These legislations and standards are normally

designed to optimize an organization’s information security; however, just like the Federal ones, they

are often disregarded. Security legislation is political. A list of undocumented security procedures

made by STC technical department will not have the same impact as a detailed document clearly

outlining information security rules and regulations established by the governing body of the

institution. In establishing information security legislation for the institution, all top managers

especially the ones with the clout should be involved in the making of the legislations. When the tech

team involves all top management in the making of the security laws, it is playing positive politics

since the makers of the law will also use their powers to ensure that they are enforced.

The BS ISO/IEC17799: 2000 suggests that employees should follow security producers

correctly, and the standard implies that producing an introduction to information security awareness

programs (education and training activities) is the way to ensure this (Siponen, 2006). Only through

top management involvement can the implementation of such standards be successful. When the

college president has to fund the awareness programs she will be more involved in what is taking

place since the institution’s budget in now involved.

Conclusion
Making and Enforcing 5

It is clear the developing and enforcing information security legislation is a very

challenging task for the Federal government. Such a challenge is equally difficult for private

organizations and institutions. Politics however, plays a very important role in developing and

establishing security legislations and standards. Therefore, if STC law makers are to be

successful in establishing and implementing such rules and regulations they must involve

positive organizational politics.


Making and Enforcing 6

References

Grimes, G. (2007) Compliance with the CAN-SPAM Act of 2003. Communications of the

ACM, Vol. 50 Issue 2, p56-62. Retrieved February 16, 2010 from TUI library.

Siponen, M. (2006). Information security standards focus on the existence of process, not its

content. Communications of the ACM, Vol. 49 Issue 8, pp. 97-100. Retrieved February

West, (2008).

You might also like