I have uploaded all the previous 7 labs. Due in 24 hoursSecurity Operations – Week #8 Final Project In this Project Final you are to update, refine and combine the past seven weeks of Labs to create t

Step 5: Develop the Violations of Policy section of your ISP

Lab 3 outlines the prohibited use section of the information security plan (ISP). It is in line with the diversification of in the global world with many users and providers in every aspect of life. Handling of data and information requires a standard of ethics and conduct code to ensure quality and reliability of the systems. The scope, policy and access policies in lab 2 act as a background to the development of the violations of policy of the developed ISP. The penalties for the violation of policies and instructions on how to report the policy violations are outlined as follows:

A description of penalties for violating policies

  1. A fine of not less than $150 shall be enforced for every violation and can be increased to a reasonable maximum given the nature of policy violation.

  2. Penalties shall involve the deduction on the reimbursements such as salaries and denial of certain benefits in payment of the violated policy. This affects the violation of low termed policies.

  3. All violations shall be categorized in terms of type and level of violation for easier follow up and enforcement of proposed or agreed upon forms of punishment.

  4. High level violations shall attract higher forms of punishment such as demotion, transfer or total dismissal from employment with the company.

  5. Verbal warnings shall be used for low level violations and action taken on a second violation of the same or another policy.

  6. Minimal policy violations shall attract a formal notification in writing on the type and level of policy violation for further action.

The process of reporting of policy violations

  1. Any form of violation shall be communicated earliest possible or within 24 hours of incidence to the higher-level management such as supervisors, and managers in the concerned departments or HR

  2. Reporting of any violation can be written, printed or verbal using the available modes of communication such as e-mails to the relevant authorities within the organization.

  3. The organization portal or website shall be open for any cases of violation for all employees and other stakeholders such as customers.