Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

TO: YOU AS CISO FROM: Melanie Zeller, CFO SUBJECT: Employee Turnover I heard a r

ID: 3913763 • Letter: T

Question

TO: YOU AS CISO

FROM: Melanie Zeller, CFO

SUBJECT: Employee Turnover

I heard a rumor that a few top producers in our marketing and sales departments are thinking of leaving the company. I also overheard folks talking in the breakrooms that some of these people are using our resources to find a new job and print resumes. In fact, I found a resume on one of the high end color copiers we just purchased. I would really like to monitor these departments more closely, but I want all of the company to be aware of these issues. Can you put together a brief description of additional training you can provide in the security awareness program you are developing? Can you also discuss how we can get started on doing a better job at monitoring these people and protecting our intellectual property? We should keep this between us until we can get some solution in place.

Explanation / Answer

For the security awareness program we are planning to conduct one class every month which includes work related securty awareness and the physical security awareness. In this classes we mainly focus on the critical issues and how to handle and how to eradicate these going further. Also we train employees about how to be secure and what are the measures which we need to take when an unknown thing happened or in an unknown task assigned. Also we are planning to show some real time sitautions of security and will train how to identify breach and the consequences and the order to follow.

Regarding the company asset usage We will from now onwars ask the respective department to closly monitor the things happenning and the how the resources being used. We will setup one register at each asset and employees are requested to enter the reason for using that. I think by this the usage will ge restricted to the company use maximum. For ex If any employee wants to use printer then he must enter in the records that if it is his personal use or the company use and asked to enter the reason. If the employee crosses his monthly limit of personal use he will be charged accordingly. Because as an employee's they have some personal works which they can't left the work in between to do or there will be some urgency. So as a company we also have to give then some benifits so that they will do their work without any hurries.