Highlights
Task:
Question 1
The following scenario relates to Question 1 (a), (b) and (c) below.
A large organisation, similar to the University of Canberra, is in the process of implementing a new human resource management (HRM)* system that includes aspects of workflow. An example of the workflow includes facilitating the on-line submission of leave forms and the subsequent approval (or not) the leave applications by supervisors. It will also allow staff to have on-line access to relevant personnel and payroll records where appropriate (for example, checking payslips and leave balances, submitting performance assessment reports,etc.). The system would facilitate activity normally undertaken by senior managers. * for those unfamiliar with HR/HRM systems, these are the systems that organisations use to manage their staffing. This may include: payroll (making sure staff are paid the right amount at the right time); the recording of leave and leave balances (holidays, sick leave, and long service leave etc.); and a repository for performance management data. They are frequently connected with finance systems and sometimes include other details, but the list mentioned here is sufficient for this exercise.
Part (a)
As part of the implementation of this system, relevant security policies need to be reviewed, redeveloped, replaced or modified. Assume that the organisation already has a general information security policy in place along with a range of issue specific security policies, but no current system specific security policy for a HRM system.
Outline the major issues you would expect to see covered in a system specific security policy for the HRM system. Discuss this in broad terms, mostly using the headings and brief statements covering the issues that you would expect to find in the system specific policy (you are not expected to provide the detailed clauses of the policy). Do NOT include things that you would normally find in the general University information security policy or issue specific policies.
Part (b)
A system-specific information security policy for the HRM system may include access control lists, or ACLs. This question will require you to create some of the details you might find in the ACLs for the HRM system. For the purposes of this question, the ACLs will be kept relatively simple.
The general classes of users that should be used for this question are: 1 – staff (these are all staff not included in one of the other categories, but staff in the other categories would have this staff level access in addition to that proposed for their specific category); 2 – supervisors; 3 – HR department admin staff; 4 – IT systems administration staff; 5 – senior management.
The IT data resources should include: 1 – staff personal details; 2 – payslip records; 3 – leave balances; 4 – leave applications.
Note that the system is likely to use more specific user groups (particularly for admin and IT roles), and it is likely to include other data, but these dimensions have been kept simple for this exercise.
Draw up an access control matrix (in the form of a table) for this situation. The table should have the various classes of users in the rows, and the IT resources of the system in the columns.
The cells within the matrix should note the appropriate level of access for the relevant user to the data resource. The access permissions can include: read; update; delete; or other particular privileges or restrictions.
For the purposes of this exercise you should assume that someone with limited knowledge of HR systems will then implement this system and associated access security using the data provided in your table. As such, avoid omitting data because you think it might seem obvious.
Part (c) (10 marks)
In your answer to part (b), you should have described the access privileges for all of the classes of users. Provide a rationale that justifies the level of access that you have given to the following two classes of users of the HRM system:
Question 2 [20 marks]
Part (a) (10 marks)
One of the challenges with ICT security is ‘selling’ the notion of investing in ICT security. One approach is to use a traditional return on investment approach with an emphasis on information security issues. This is referred to as a Return on Security Investment (ROSI) and ROSI calculations can be presented to management to justify security investments.
The ROSI elements discussed during the semester included the following formula components: Single Loss Expectancy (SLE); Annual Rate of Occurrence (ARO); Annual Loss Expectancy (ALE) which is calculated: ALE = ARO * SLE; Modified Annual Loss Expectancy (MALE) (the ALE after the implementation of the proposed security controls). The ROSI takes account of the ALE, the MALE and the cost of the proposed controls.
Considering the following scenario involving the help desk staff responsible for providing support to the HRM system from question 1:
On average the help desk staff reset 10 passwords annually without verifying the staff member’s identity correctly. The damages in reputational and privacy breaches is estimated to cost $5,000 per incident. By implementing a verification software package with a licence cost of $5,000 per annum, the loss expectancy would be reduced by 50%.
Calculate the ROSI for this scenario.
Part (b) (10 marks)
Given the scenario from part (a), discuss the limitations with using a ROSI calculation in this manner. You should provide 5 issues that highlight limitations with the application of a ROSI used in this manner.
Question 3 [20 marks]
Part (a) (5 marks)
Information security should be balanced against the business goals of the organisation. What symptoms might be exhibited by an organisation in which information security considerations have been overdone?
Part (b) (5 marks)
What role should the top level management of an organisation (usually the CEO and associated executive level management committee) play in relation to the security of the organisation’s information assets?
Part (c) (10 marks)
During the semester, we discussed the concept of ‘normalisation’ of information security.
Provide two examples to illustrate how this could work in a practical context.
Question 4 [20 marks]
Insider threats describe threats to an organisation coming from people working inside the organisation. As the CISO (Chief Information Security Officer) of an organisation, you are aware that insider threats are an increasing exposure for all organisations.
For each of these insider threats listed below:
a) identify ways in which you could reduce the risk the threat occurring (prevention);
b) identify controls that would assist with the detection of these threats, should they occur.
The solutions can use some technology, but the human factor is the key to addressing these issues. The solutions shouldn’t prevent the normal work of the organisation from occurring. Answer by listing the number of the threat (1a,1b, 2a 2b) and your answer. You shouldbriefly describe two controls for each of the parts. Insider Threats
1. An IT systems administrator uses their privileged access to insert some additional (ghost) staff members on the payroll system and then collects their pay;
2. A member of a University student administration area with access privileges to update grades in the student records system has been taking bribes from students to modify their grades for important units.
This IT Assignment has been solved by our IT experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.
Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.