Chapter 14 Information Security
3. The importance of having vigilant IT professionals who are capable of detecting and
minimizing the damage from a security breach has become increasingly important. Is
this a type of job position that you would like to hold, and why or why not?
4. If you were offered the position of a CSO for a large organization, what reporting
relationship would you want? Under what circumstances do you think a reporting
relationship to the CIO is the best choice?
5. To achieve SOX compliance has required many organizations to significantly change
their business processes and invest in new software products. Use the Internet to
research some examples of these types of impacts that SOX has had on U.S.-based
companies in particular or J-SOX has had on Japanese companies?
6. HIPAA concerns will be growing over the next years as more physician practices in
the United States adopt electronic health records (to take advantage of a federal
government incentive plan under the HITECH Act). Find a recent article that discusses
concerns about the security of health information of patients.
7. Reflect on when you last received authority to have a computer account with an
organization (e.g., your university), and comment on your own experience when you
were asked to sign (or otherwise signify acceptance of) an organizational policy similar
to the acceptable use policy described in this chapter. Would you recommend any
changes to the organization for what to include in the policy and how to present this
policy to a new account holder?