Developa 6- to 7-page manual using theSecurity Standards, Policies, and Procedures Templatewith recommendations to management of security standards, polices, and procedures which should be implemented

Cyber Security Engineers are responsible for safeguarding computer networks and systems in an organization in order to protect the sensitive data they store.


Take on the role of Cyber Security Engineer for Capital One Bank the organization you chose in Week 1.


Develop a 6- to 7-page manual using the Security Standards, Policies, and Procedures Template with recommendations to management of security standards, polices, and procedures which should be implemented in your chosen organization.


Research and include the following:

  • REFER TO ADDITIONAL RESOURCES BELOW and the grading rubric.

  • Explain the importance to your organization of implementing security policies, plans, and procedures. Discuss how security policies, plans, and procedures will improve the overall security of the organization. 

  • Recommend appropriate policies and procedures for: 

    • Data classification policies and procedures (data isolation)

    • Non-disclosure Agreement policies and procedures

    • Strong authentication (password policies and procedures... and multi factor authentication)

    • Acceptable use of organizational assets and data 

    • Employee policies (separation of duties/training) 

    • Risk Management 

      • Avoidance 

      • Transference 

      • Mitigation 

      • Acceptance 

  • Compliance examples that might affect your organization or others [Regulatory, Advisory, Informative]

    • HIPAA 

    • NIST Cybersecurity Framework

    • Sarbanes/Oxley 

    • GLBA

    • PCI DSS

  • Incident response (How should we prepare, and what should happen in each phase)

    • Preparation 

    • Identification 

    • Containment 

    • Eradication 

    • Recovery 

    • Lessons learned (root cause analysis and action plan)

  • Auditing 

  • Environmental/Physical 

  • Administrative

    • From the text:

      • "Controls are implemented as administrative, logical, and physical. Administrative controls are also known as management controls and include policies and procedures. Logical controls are also known as technical controls and are implemented through technology. Physical controls use physical means to protect objects."

  • Configuration (change management and system hardening)