Security Standards and Procedures
This exercise is designed to have you write security standards and procedures. To accomplish this goal, you may build on available templates; but the exercise requires you to think for yourself because every enterprise is different and because security policies, standards and procedures must adapt over time to new threats.

Parts (i), (ii) and (iii)
Be sure to make sections as specific to BetterBankUSA as feasible.

Part (i): List what you consider to be the FIVE (5) most important security standards for BetterBankUSA and explain your reasoning. List your choices by priority, this should be at least 2 pages long.

Part (ii): List what you consider to be the FIVE (5) most important security procedures for BetterBankUSA and explain your reasoning. List your choices by priority, this should be at least 2 pages long.

Part (ii): Identify a regulation necessary to follow when working within financial markets. You may expand here on part three of assignment two and consider your selection within the context of allowing third party API access. Explain the security implications of this regulation and what BetterBankUSA would have to implement to ensure compliance. This should be 1 – 2 pages long. (If the regulation has several requirements, select ONE (1) requirement that has security implications.)

Solution PreviewSolution Preview

These solutions may offer step-by-step problem-solving explanations or good writing examples that include modern styles of formatting and construction of bibliographies out of text citations and references. Students may use these solutions for personal skill-building and practice. Unethical use is strictly forbidden.

Part (i)
Security standards
Standard one: Data Classification standard

Data classification standard applies to all electronic data collected, processed and stored within a service called "BankSmart."

The data can be classified in terms of its need for protection or its need for availability (1).

Classifying data according to protection needs:
1. Public data
2. Internal data
3. Sensitive data

Classifying data according to availability needs:
1. Supportive data
2. High priority data
3. Critical data (1).

The reason I have decided to put data classification standard at the top of my priority standards list is the fact that the data are the most valuable asset for BetterBankUSA Different types of data are collected, stored and processed within a service called “BankSmart” and those data needs to be classified in a proper manner in order to determine the need for protection of those data.

Given the fact that the first step in quality protection is effective classification, this standard must be on a top of the BetterBankUSA'a standards security list to effectively minimize reputation risk and associated types of risks.
Standard two: Two-factor authentication standard

The access to a restricted data within a BetterBankUSA system called "BankSmart" is protected by two-factor authentication.

Two-factor authentication is equally applied to both BetterBankUSA employees and end users.

The reason I find this standard important in terms of BetterBankUSA security is the fact that risks associated with poor authorization and authentication represent a serious security threat for bank's service called "BankSmart." The users accessing this service, both employees and...

