Saturday, August 17, 2019

In A long way gone by Ishmael Beah

In A long way gone, by Ishmael Beah the main character ishmael struggles to good in a society that demands evil. As ishamel feels he is doing good, the lines of good and evil become extreamly blured. During Ishmael first battle, he fought angirly to avenge the dead that the R. U. F killing mercelsey as it shows in text â€Å"Every time I stopped shooting to change magazines and saw my lifeless friend, I angirly pointed my gun into the swamp and killed more people†(119). Later in the text ishmael is no longer guided by revenge nor fairness. He starts to kill without any concious what so ever, as shown when ishmael Is not protected, and is willing to protect himself by standing up for his country and fighting for rights. â€Å" Killing those they had already severly wonded†(122). In this quote it shows how ishmael is doing extra work and taking his anger out on his enemies,that where doing harsh actions to ishmaels people. As ismael becomes a full cold blooded solider he seemingly forgets the reasons he fought for the R. U. F after U. N. I.  C. E. F takes ishmael and some of his comrades, they begin to hate the thing they fought for. In the text: â€Å"They have lost every that makes them human. They dont deserve to live, that is why we must kill every single on of them†(108). To anaylze this quote, ishmael points out that the rebels dont deserve to live due to what the rebels where doing to innocent people. According to ishmael he wants to kill all of them for all of the things they where doing to his people, and show them that he has power.

Child of Divorce Essay

Divorce is becoming a norm in the society nowadays. This refers to the complete termination of marriage between the couple who demands for it. Through the dissolution of the bonds of matrimony, both parties are allowed to marry again (Gallagher, 1996). However, opposing views are prevailing regarding divorce. For those who are in favor of it, divorce can be regarded as the only legitimate remedy when happiness and affection are no longer provided in the marriage (Scanzoni 1965). For those who are against it, divorce causes psychological problems and damage to social cohesion (Diefenbach, 2007). Divorce is not just the story of the couple parting ways but it is more of a story of the children who are products of a divorced marriage. â€Å"Human children need parents longer than any other species and are totally dependent on parents for food, shelter, and protection for the first several years of life. This dependency spawns a fear of abandonment. In divorce, one of the parents leaves. When one parent leaves, the children feel rejected. The loss children feel at divorce is similar to that experienced when a parent dies. Divorce might actually be harder on children because it lacks the concrete cause and finality of death (Bryner, 2001). † This causes most of the children of divorce to be more aggressive, impulsive and develop antisocial behavior compared to children from intact families (Hetherington, 1999). Others also exhibit lower academic performance (Kelly, 1998). However, some children manage to develop without these deleterious effects of divorce. As a matter of fact, these children are found to have less stereotyped sex behavior, greater maturity and greater independence (Emery, 1995). The developmental stage of the child when the divorce of his parents occurs is predictive of the child’s behavior and reaction towards the situation. An infant or a toddler will not react at all to his parents’ divorce because he can’t still comprehend the situation. However, a preschooler will tend to blame himself as the culprit of his parents’ divorce. Because he feels guilty and fears that the remaining parent may also leave him, he becomes more possessive of his parent (Roseby, 1998). For a young school-aged child, the divorce of his parents gives him a sense of responsibility. He feels that he should bring his parents together again and think of strategies that will make his parents interact in any way (Lansky, 1996). On the other hand, older school-aged children tend to blame one parent and take the side of the other parent. They become anxious and worrisome of the situation which makes them prone to illnesses such as headaches, sleeping disorders, chest pains, diabetes and asthma (Kimball, 1994). The reaction is more deleterious with adolescents who entirely mask their reactions. They switch to other outlets such as peers, sex, alcohol and drugs because they hate being bothered by their parents’ lives (Thompson, 1998). I have a friend named Diane. Fourteen years ago, her parents separated by divorce. Back then, she was only turning three and didn’t know anything about the chaotic situation between her parents. She was left to the custody of her mother while her father was just obliged by the court to provide some financial assistance. Everything went well with this arrangement until she entered primary school where she had greater monetary needs. Unfortunately, her father had another family and was compelled to reduce the money sent to her. This was the reason why her mother was obligated to work in order to support her. Because her mother became busy in her work, Diane was always left with her grandmother whenever she was off from school. It was only through her grandmother that everything regarding her family became clear. She hated the fact that her own mother concealed their broken family from her and would always say that her father is just working in a far away place. She realized that she will never have his father back and that her fantasies of having a complete family would never be real. That time, she began to skip classes in school and whenever she would attend a lecture, she never participates in the recitation. She also failed our exams. I was really worried about the big change in her behavior because she used to be the top student of our class. I just learned about her family problem when she never attended classes for a week and her mother came to our school looking for her. One of our classmates revealed that Diane eloped with her boyfriend. I can’t forget the face of Diane’s mother crying and blaming herself for what had happened to her daughter. After that, I never saw Diane again. The last news I heard about her was that she is living with her mother again. She broke up with her boyfriend but gave birth to a baby boy, who, like her, is a child of divorce. Diane’s story is just one of the millions of stories which we can get from the life of a child from a broken family. In her case, the effects of divorce were appalling because of the lack of effective communication. It would have been better if both her parents explained to her the situation and the reasons why they should have divorce. When Diane learned that her parents were already divorced, she was very frustrated because she fantasized of having a complete family when her father returns from work. She also felt betrayal because her mother never told her what’s real. These extreme negative emotions changed her attitude and made her rebel against the situation. Also, Diane’s mother was very preoccupied in her work that’s why she was not able to keep an eye on the performance of her daughter in school. If only she did, maybe she was able to help Diane solve her emotional problems at an early stage. After all, divorce can really cause a big scar but it doesn’t really have to. References: Bryner, C. L. (2001). Children of Divorce. Journal of the American Board of Family Medicine Practice;14:201–10. Diefenbach, H. and Opp, K. D. (2007). When and Why Do People Think There Should Be a Divorce? http://rss. sagepub. com/cgi/content/abstract/19/4/485. Emery, R. E. and Coiro, M. J. (1995). Divorce: consequences for children. Pediatric Review;16:306 –10. Gallagher, M. (1996). The Abolition of Marriage. Regnery Publishing. Hetherington, E. M. and Stanley-Hagan M. (1999). The adjustment of children with divorced parents: a risk andresiliency perspective. Journal of Child Psychology; 40:129–40. Kelly, J. B. (1998). Marital conflict, divorce, and children’s adjustment. Child Adolescent Psychiatry;7:259 –71. Kimball, G. (1994). How to survive your parents’ divorce: kids’ advice to kids. Chico, California: Equality Press. Lansky, V. (1996). Divorce book for parents helping your child cope with divorce and its aftermath. Minnetonka, MN: Book Peddlers. Roseby, V. and Johnston J. R. (1998). Common developmental threats in high-conflict divorcing families. Child Adolescent Psychiatry;7:295–309. Scanzoni, J. (1965). A Reinquiry into Marital Disorganization. Journal of Marriage and the Family 27: 483–91. Thompson, P. (1998). Adolescents from families of divorce: vulnerability to physiological and psychological disturbances. Journal of Psychosocial Nursing and Mental Health Service;36(3):34 –9.

Friday, August 16, 2019

An analysis of Information Security Governance in the Universities in Zimbabwe Essay

Abstract The complexity and criticality of information security and its governance demand that it be elevated to the highest organizational levels. Within a university setup, information assets include student and personnel records, health and financial information, research data, teaching and learning materials and all restricted and unrestricted electronic library materials. Security of these information assets is among the highest priorities in terms of risk and liabilities, business continuity, and protection of university reputations. As a critical resource, information must be treated like any other asset essential to the survival and success of the organization. In this paper the writer is going to discuss the need for implementing Information Security Governance within institutions of higher education. Further than that, a discussion on how to best practice Information Security governance within the universities in Zimbabwe followed by an assessment on how far the Zimbabwean universities have implemented Information Security Governance. A combination of questionnaires and interviews is going to be used as a tool to gather data and some recommendations are stated towards the end of the paper. Introduction Governance, as defined by the IT Governance Institute (2003), is the â€Å"set of responsibilities and practices exercised by the board and executive management with the goal of providing strategic direction, ensuring that objectives are achieved, ascertaining that risks are managed appropriately and verifying that the enterprise’s resources are used responsibly.† Information security governance is the system by which an organization directs and controls information security (adapted from ISO 38500). It specifies the accountability framework and provides oversight to ensure that risks are adequately mitigated as well as ensuring that security strategies are aligned with business and consistent with regulations. To exercise effective enterprise and information security governance, boards and senior executives must have a clear understanding of what to expect from their enterprise’s information security programme. They need to know how to direct  the implementation of an information security programme, how to evaluate their own status with regard to an existing security programme and how to decide the strategy and objectives of an effective security programme (IT Governance Institute, 2006). Stakeholders are becoming more and more concerned about the information security as news of hacking, data theft and other attacks happen more frequently than ever dreamt of. Executive management has been showered with the responsibility of ensuring an organization provides users with secure information systems environment. Information security is not only a technical issue, but a business and governance challenge that involves adequate risk management, reporting and accountability. Effective security requires the active involvement of executives to assess emerging threats and the organization’s response to them (Corporate Governance Task Force, 2004). Furthermore the organizations need to protect themselves against the risks inherent in the use of information systems while simultaneously recognizing the benefits that can accrue from having secure information systems. Peter Drucker (1993) stated: â€Å"The diffusion of technology and the commodification of information transforms the role of information into a resource equal in importance to the traditionally important resources of land, labor and capital.† Thus as dependence on information system increases, the criticality of information security brings with it the need for effective information security governance. Need for Information Security Governance within universities. A key goal of information security is to reduce adverse impacts on the organization to an acceptable level of risk. Information security protects information assets against the risk of loss, operational discontinuity, misuse, unauthorized disclosure, inaccessibility and damage. It also protects against the ever-increasing potential for civil or legal liability that organizations face as a result of information inaccuracy and loss, or the absence of due care in its protection. Information security covers all information processes, physical and electronic, regardless whether they involve people and technology or relationships with trading partners, customers and third parties. Information security addresses information protection, confidentiality, availability and integrity throughout the life cycle of the information and its use within the organization. John P. Pironti (2006) suggested that among many reasons for information security  governance, the most important one is the one concerned with the legal liability, protection of the organization’s reputation and regulatory compliance. With the university setup, all members of the university community are obligated to respect and, in many cases, to protect confidential data. Medical records, student records, certain employment-related records, library use records, attorney-client communications, and certain research and other intellectual property-related records are, subject to limited exceptions, confidential as a matter of law. Many other categories of records, including faculty and other personnel records, and records relating to the university’s business and finances are, as a matter of university policy, treated as confidential. Systems (hardware and software) designed primarily to store confidential records (such as the Financial Information System and Student Information System and all medical records systems) require enhanced security protections and are controlled (strategic) systems to which access is closely monitored. Networks provide connection to records, information, and other networks and also require security protections. The use of university information technology assets in other than a manner and for the purpose of which they were intended represents a misallocation of resources and, possibly, a violation of law. To achieve all this in today’s complex, interconnected world, information security must be addressed at the highest levels of the organization, not regarded as a technical specialty relegated to the IT department. Information security is a top-down process requiring a comprehensive security strategy that is explicitly linked to the organization’s business processes and strategy. Security must address entire organization’s processes, both physical and technical, from end to end. Hence, Information security governance requires senior management commitment, a security-aware culture, promotion of good security practices and compliance with policy. It is easier to buy a solution than to change a culture, but even the most secure system will not achieve a significant degree of security if used by ill-informed, untrained, careless or indifferent personnel (IT Governance Institute, 2006). In an interview the executive director and information security expert on IT Governance and cyber security with the IT Governance and Cyber Security Institute of sub-Saharan Africa, Dr Richard Gwashy Young has this to say â€Å"†¦remember in  Zimbabwe security is regarded as an expense not an investment† (Rutsito, 2012). Benefits of Information Security Governance Good information security governance generates significant benefits, including: The Board of directors taking full responsibility for Information security initiatives Increased predictability and reduced uncertainty of business operations by lowering information security-related risks to definable and acceptable levels Protection from the increasing potential for civil or legal liability as a result of information inaccuracy or the absence of due care. The structure and framework to optimize allocation of limited security resources Assurance of effective information security policy and policy compliance A firm foundation for efficient and effective risk management, process improvement, and rapid incident response related to securing information A level of assurance that critical decisions are not based on faulty information Accountability for safeguarding information during critical business activities. Compliances with local and international regulations will be easier Improved resource management, optimizing knowledge, information security and information technology infrastructure The benefits add significant value to the organization by: Improving trust in customer/client relationships Protecting the organization’s reputation Decreasing likelihood of violations of privacy Providing greater confidence when interacting with trading partners Enabling new and better ways to process electronic transactions like publishing results online and online registration. Reducing operational costs by providing predictable outcomes—mitigating risk factors that may interrupt the process The benefits of good information security are not just a reduction in risk or a reduction in the impact should something go wrong. Good security can improve reputation, confidence and trust from others with whom business is conducted, and can even improve efficiency by avoiding wasted time and effort recovering from a security incident (IT Governance Institute, 2004). Information Security Governance Outcomes Five basic outcomes can be expected to result from developing an effective governance approach to information security: Strategic alignment of information security with institutional objectives Reduction of risk and potential business impacts to an acceptable level Value delivery through the optimization of security investments with institutional objectives Efficient utilization of security investments supporting organization objectives Performance measurement and monitoring to ensure that objectives are met Best practices The National Association of Corporate Directors (2001), recognizes the importance of information security and recommends four essential practices for boards of directors. The four practices, which are based on the practicalities of how boards operate, are: Place information security on the board’s agenda. Identify information security leaders, hold them accountable and ensure support for them. Ensure the effectiveness of the corporation’s information security policy through review and approval. Assign information security to a key committee and ensure adequate support for that committee. It is critical that management ensure that adequate resources are allocated to support the overall enterprise information security strategy (IT Governance Institute, 2006). To achieve effective information security governance, management must establish and maintain a framework to guide the development and maintenance of a comprehensive information security programme. According to Horton, et al (2000), an information security governance framework generally consists of: An information security risk management methodology; A comprehensive security strategy explicitly linked with business and IT objectives; An effective security organizational structure; A security strategy that talks about the value of information both protected and delivered; Security policies that address each aspect of strategy, control and regulation; A complete set of security standards for each policy to ensure that procedures and guidelines comply with policy; Institutionalized monitoring processes to ensure compliance and provide feedback on effectiveness and mitigation of risk; A process to ensure  continued evaluation and update of security policies, standards, procedures and risks. This kind of framework, in turn, provides the basis for the development of a cost-effective information security program me that supports an organization’s goals and provides an acceptable level of predictability for operations by limiting the impacts of adverse events. In his article Kaitano (2010), pointed some characteristics of good corporate governance coupled with good security governance. These include and not limited to: Information security being treated as and organization wide issue and leaders are accountable. Leads to viable Governance, Risk and Compliance(GRC) Milestones It is risk-based and focuses on all aspects of security Proper frameworks and programs have been implemented It is not treated as a cost but a way of doing business Roles, responsibilities and segregation of duties are defined It is addressed and enforced by policy Adequate resources are committed and Staff are aware and trained It is planned, managed, measurable and measured It is reviewed and audited The overall objective of the programme is to provide assurance that information assets are protected in accordance with their value or the risk their compromise poses to an organization. The framework generates a set of activities that supports fulfillment of this objective. Principles for information security within the University In their article titled Information Security Policy: Best Practice Document, Hostland et al (2010) pointed out some guiding principles for information security within a university setup. The following are some of the principles they mentioned: 1. Risk assessment and management The university’s approach to security should be based on risk assessments and should be continuously done and the need for protective measures evaluated. Measures must be evaluated based on the university’s role as an establishment for education and research and with regards to efficiency, cost and practical feasibility. An overall risk assessment of the  information systems should be performed annually. Risk assessments must identify, quantify and prioritize the risks according to relevant criteria for acceptable risks. Risk assessments should be carried out when implementing changes impacting information security. Some recognized methods of assessing risks like ISO/IEC 27005 should be employed. Risk management is to be carried out according to criteria approved by the management at University. Risk assessments must be approved by the management and if a risk assessment reveals unacceptable risks, measures must be implemented to reduce the risk to an acceptable level. 2. Information security policy The Vice Chancellor should ensure that the information security policy, as well as guidelines and standards, are utilized and acted upon. He must also ensure the availability of sufficient training and information material for all users, in order to enable the users to protect the university’s data and information systems. The security policy should be reviewed and updated annually or when necessary, in accordance with principles described in ISO/IEC 27001. However, all important changes to university’s activities, and other external changes related to the threat level, should result in a revision of the policy and the guidelines relevant to the information security. 3. Security organization The Vice Chancellor is responsible for all government contact. The university should appoint CSO (Chief Security Officer). Each department and section should also be responsible for implementing the unit’s information security. The managers of each unit must appoint separate security administrators. The Registrar Academics has the primary responsibility for the information security in connection with the student registry and other student related information. The IT Director has executive responsibility for information security in connection with IT systems and infrastructure. The Operations manager has executive responsibility for information security in connection with structural infrastructure. He also has overall responsibility for quality work, while the operational responsibility is delegated according to the management structure. The Registrar Human Resources also has executive responsibility for information security according to the Personal Data Act and is the controller on a daily basis of the personal information of the  employees. The Registrar Academics and Research Administration have also executive responsibility for research related personal information. University’s information security should be revised on a regular basis, through internal control and at need, with assistance from an external IT auditor. 4. Information security in connection with users of University’s services Prior to employment security responsibility and roles for employees and contractors should be described. A background check is should also be carried out of all appointees to positions at the university according to relevant laws and regulations. A confidentiality agreement should be signed by employees, contractors or others who may gain access to sensitive and/or internal information. IT regulations should be accepted for all employment contracts and for system access for third parties. During employment, the IT regulations for the university’s information security requirements should be in place and the users’ responsibility for complying with these regulations is to be emphasized. The IT regulations should be reviewed regularly with all users and with all new hires. All employees and third party users should receive adequate training and updating regarding the Information security policy and procedures. Breaches of the Information security policy and accompanying guidelines will normally result in sanctions. University’s information, information systems and other assets should only be utilized for their intended purpose. Necessary private usage is permitted. Private IT equipment in the university’s infrastructure may only be connected where explicitly permitted. All other use must be approved in advance by the IT department. On termination or change of employment, the responsibility for termination or change of employment should be clearly defined in a separate routine with relevant circulation forms. The university’s assets should be handed in at the conclusion of the need for the use of these assets. University should change or terminate access rights at termination or change of employment. A routine should be present for handling alumni relationships. Notification on employment termination or change should be carried out through the procedures defined in the personnel system. 5. Information security regarding physical conditions IT equipment and information that require protection should be placed in secure physical areas. Secure areas should have suitable access control to  ensure that only authorized personnel have access. All of the University’s buildings should be secured according to their classification by using adequate security systems, including suitable tracking/logging. Security managers for the various areas of responsibility should ensure that work performed by third parties in secure zones is suitably monitored and documented. All external doors and windows must be closed and locked at the end of the work day. On securing equipment, IT equipment which is very essential for daily activities must be protected against environmental threats (fires, flooding, temperature variations). Information classified as â€Å"sensitive† must not be stored on portable computer equipment (e.g. laptops, cell phones, memory sticks). If it is necessary to store this information on portable equipment, the information must be password protected and encrypted in compliance with guidelines from the IT department. During travel, portable computer equipment should be treated as carry-on luggage. Fire drills should also be carried out on a regular basis. 6. IT communications and operations management Purchase and installation of IT equipment and software for IT equipment must be approved by the IT department. The IT department should ensure documentation of the IT systems according to university’s standards. Changes in IT systems should only be implemented if well-founded from a business and security standpoint. The IT department should have emergency procedures in order to minimize the effect of unsuccessful changes to the IT systems. Operational procedures should be documented and the documentation must be updated following all substantial changes. Before a new IT system is put in production, plans and risk assessments should be in place to avoid errors. Additionally, routines for monitoring and managing unforeseen problems should be in place. Duties and responsibilities should be separated in a manner reducing the possibility of unauthorized or unforeseen abuse of the university’s assets. Development, testing and maintenance should be separated from operations in order to reduce the risk of unauthorized access or changes, and in order to reduce the risk of error conditions. On system planning and acceptance, the requirements for information security must be taken into consideration when designing, testing, implementing and upgrading IT systems, as well as during system changes. Routines must be developed for  change management and system development/maintenance. IT systems must be dimensioned according to capacity requirements and the load should be monitored in order to apply upgrades and adjustments in a timely manner as it is especially important for business-critical systems. Written guidelines for access control and passwords based on business and security requirements should be in place. Guidelines should be re-evaluated on a regular basis and should contain password requirements (frequency of change, minimum length, character types which may/must be utilized) and regulate password storage. All users accessing systems must be authenticated according to guidelines and should have unique combinations of usernames and passwords. Users are responsible for any usage of their usernames and passwords. Data Gathering A structured questionnaire adapted and modified from previous questionnaires used by Corporate Governance Task Force, (2004) was used as the main instrument to gather data. Of the total 13 universities in Zimbabwe, 9 managed to participate in this research. The questionnaires were completed by the Executive Dean, IT Director, Operations Manager or Chairperson for the department. Section I: Organizational Reliance on IT The first section was designed to help in determining the institution’s reliance on information technology for business continuity. Table 1: Characteristics of Organization Questions Scores/Frequency 0 1 2 3 4 Dependence on information technology systems and the Internet to conduct academic, research, and outreach programs and offer support services 9 Value of organization’s intellectual property stored or transmitted in electronic form 2 7 The sensitivity of stakeholders (including but not limited to students, faculty, staff, alumni, governing boards, legislators, donors, and funding agencies) to privacy 2 3 4 Level of regulation regarding security (international, federal, state, or local regulations) 1 4 3 1 Does your organization have academic or research programs in a sensitive area that may make you a target of violent physical or cyber attack from any groups? 5 1 2 1 Total score 1 9 6 7 22 Scoring: Very Low = 0; Low = 1; Medium = 2; High = 3; Very High = 4 Section II: Risk Management: This section assesses the risk management process as it relates to creating an information security strategy and program. Table 2: Information Security Risk Assessment Questions Scores/Frequency 0 1 2 3 4 Does your organization have a documented information security program? 2 5 2 Has your organization conducted a risk assessment to identify the key objectives that need to be supported by your information security program? 2 4 3 Has your organization identified critical assets and the functions that rely on them? 2 2 5 Have the information security threats and vulnerabilities associated with each of the critical assets and functions been identified? 2 4 2 1 Has a cost been assigned to the loss of each critical asset or function? 1 3 3 2 Do you have a written information security strategy? 2 4 2 1 Does your written information security strategy include plans that seek to cost-effectively reduce the risks to an acceptable level, with minimal disruptions to operations? 4 2 2 1 Is the strategy reviewed and updated at least annually or more frequently when significant changes require it? 2 3 3 1 Do you have a process in place to monitor federal, state, or international legislation or regulations and determine their applicability to your organization? 2 2 3 2 1 Total 10 16 26 14 16 Scoring: Not Implemented = 0; Planning Stages = 1; Partially Implemented = 2; Close to Completion = 3; Fully Implemented = 4 Section III: People This section assesses the organizational aspects of the information security program. Table 3: Information Security Function/Organization Questions Scores/Frequency 0 1 2 3 4 Do you have a person that has information security as his primary duty, with responsibility for maintaining the security program and ensuring compliance? 4 3 1 1 Do the leaders and staff of your information security organization have the necessary experience and qualifications? 5 2 2 Is responsibility clearly assigned for all areas of the information security architecture, compliance, processes and audits? 3 4 1 1 Do you have an ongoing training program in place to build skills and competencies for information security for members of the information security function? 2 2 3 2 Does the information security function report regularly to institutional leaders and the governing board on the compliance of the institution to and the effectiveness of the information security program and policies? 2 3 3 1 Are the senior officers of the institution ultimately responsible and accountable for the information security program, including approval of information security policies? 3 4 2 Total 16 17 14 7 0 Scoring: Not Implemented = 0; Planning Stages = 1; Partially Implemented = 2; Close to Completion = 3; Fully Implemented = 4 Section IV: Processes This section assesses the processes that should be part of an information security program. Table IV: Security Technology Strategy Questions Scores/Frequency 0 1 2 3 4 Have you instituted processes and procedures for involving the security personnel in evaluating and addressing any security impacts before the purchase or introduction of new systems? 2 3 3 1 Do you have a process to appropriately evaluate and classify the information and information assets that support the operations and assets under your control, to indicate the appropriate levels of information security? 1 2 3 2 1 Are written information security policies consistent, easy to understand, and readily available to administrators, faculty, employees, students, contractors, and partners? 2 3 3 1 Are consequences for noncompliance with corporate policies clearly communicated and enforced? 1 3 2 3 1 Do your security policies effectively address the risks identified in your risk analysis/risk assessments? 2 3 4 Are information security issues considered in all important decisions within the organization? 3 2 3 1 Do you constantly monitor in real time your networks, systems and applications for unauthorized access and anomalous behavior such as viruses, malicious code insertion, or break-in attempts? 1 3 3 1 1 Is sensitive data encrypted and associated encryption keys properly protected? 2 3 2 1 1 Do you have an authorization system that enforces time limits and defaults to minimum privileges? 2 2 2 3 Do your systems and applications enforce session/user management practices including automatic timeouts, lock out on login failure, and revocation? 2 3 2 2 Based on your information security risk management strategy, do you have official written information security policies or procedures that address each of the following areas? Individual employee responsibilities for information security practices 4 3 1 1 Acceptable use of computers, e-mail, Internet, and intranet 2 3 2 2 Protection of organizational assets, including intellectual property 2 2 3 2 Access control, authentication, and authorization practices and requirements 1 2 3 1 2 Information sharing, including storing and transmitting institutional data on outside resources (ISPs, external networks, contractors’ systems) 2 1 3 2 1 Disaster recovery contingency planning (business continuity planning) 1 1 3 4 Change management processes 2 3 2 2 Physical security and personnel clearances or background checks 1 3 3 2 Data backups and secure off-site storage 1 1 3 4 Secure disposal of data, old media, or printed materials that contains sensitive information 2 3 4 For your critical data centers, programming rooms, network operations centers, and other sensitive facilities or locations: 2 3 4 Are multiple physical security measures in place to restrict forced or unauthorized entry? 1 2 3 3 Is there a process for issuing keys, codes, and/or cards that require proper authorization and background checks for access to these sensitive facilities? 2 1 3 3 Is your critical hardware and wiring protected from power loss, tampering, failure, and environmental threats? 1 4 4 Total 17 45 58 50 47 Scoring: Not Implemented = 0; Planning Stages = 1; Partially Implemented = 2; Close to Completion = 3; Fully Implemented = 4 Discussion As shown by the total scores on Table 1, a majority of the university has a very high reliance on the IT in their services. This is depicted by the structure and characteristics of the university. Information risk assessment and management leaves a lot to be desired by the universities. Most the universities have partially implemented such programs. A large number of employees in the IT departments of most universities do no have sufficient skills to implement good information security governance. Most universities lack the leaders who have the rightful know how on the subject. In addition  to that, there is no a representative in the council who will be an IT expert, hence most leaders lack interest and initiatives on information security. Due to lack of full responsibility of information security by the leaders, to implement processes for information security might also be a challenge especially to the IT department as normally is the department given the responsibility. Conclusion There is a need for institutions to start focusing on proper information security governance. For a start organization such as the Government, the Computer Society of Zimbabwe, Zim Law Society, POTRAZ, ICAZ, IIAZ, Zimbabwe Institute of Management and other industry governing bodies should put their heads together and define the appropriate legislations that mandates information security governance either by referring to existing international frameworks (PCI-DSS, SOX, COSO, ITIL, SABSA, Cobit FIPS, NIST, ISO 27002/5, CMM, ITG Governance Framework) or by consulting local information security and business professionals to come up with an information security governance framework. As the Zimbabwean economy is slowly sprouting, the art of information security governance in the universities should also take a leap. The adoption information security governance will ensure that security will become a part of any university and thus customers confidence will be boosted. References Drucker, P. ‘Management Challenges for the 21st Century’, Harpers Business , 1993. Corporate Governance Task Force, Information Security Governance: Call to Action, USA, 2004. IT Governance Institute, Board Briefing on IT Governance, 2nd Edition, USA, 2003, www.itgi.org. IT Governance Institute, Information Security Governance: Guidance for Boards of Directors and Executive Management, 2nd Edition, USA, 2006. ISO/IEC 38500: Corporate Governance of Information Technology, 2008. IT Governance Institute, COBIT 4.0, USA, 2005, www.itgi.org IT Governance Institute, COBIT ® Security Baseline, USA, 2004, www.itgi.org National Association of Corporate Directors, ‘Information Security Oversight: Essential Board Practices’, USA, 2001 John P. Pironti,  Ã¢â‚¬Å"Information Security Governance: Motivations, Benefits and Outcomes,† Information Systems Control Journal, vol. 4 (2006): 45–8. 21. Rutsito, T. (2005) ‘IT governance, security define new era’ The Herald, 07 November. Kaitano, F. (2010) ‘Information Security Governance: Missing Link In Corporate Governance’ TechZim. http://www.techzim.co.zw/2010/05/information-security-governance-missing-link-in-corporate-governance [accessed 02 May 2013]. Horton, T.R., Le Grand, C.H., Murray, W.H., Ozier, W.J. & Parker, D.B. (2000). Information Security Management and Assurance: A Call to Action for Corporate Governance. United States of America: The Institute of Internal Auditors. Hostland, K, Enstad, A. P, Eilertsen, O, Boe, G. (2010). Information Security Policy: Best Practice Document. Corporate Governance Task Force, (2004). Information Security Governance: Call to Action, USA

Thursday, August 15, 2019

Should Students Wear Uniforms

Are Uniforms A Good Way to Improve Students Discipline and Motivation? AED 200 Introduction Uniforms have been a big debate for years. Some educators and parents believe feel uniforms are a great addition to the school system while others feel it is not giving student’s freedom of speech by expressing themselves in what they wear. Should Students Wear Uniforms? Should students wear uniforms is the big debate across school districts across the united states today. According to Eduguide. rg, school uniforms are one step that may break the cycle of violence; truancy and disorder by helping young students understand what really counts. Some feel students benefit from uniforms because it boosts their self-esteem. Students also have feel like they are in a fashion show dressing in uniforms makes students realize what on the inside that counts. Uniforms decrease the influence of gangs and are known to make things difficult for weapons being brought in hidden inside of clothes. Unifor ms improve learning.Uniforms reduce distraction and shapes focus on school work and making the classroom a more serious environment. Uniforms improve behavior and increase school attendance. Uniforms save families time and money. Parents report uniforms are cheaper than buying designer clothes or keeping up with the latest trends. Uniforms helps the administrators quickly identify outsiders who could be a danger to the students. Some people believe uniforms shows neatness by requiring students to tuck in their shirts, wear belts and wear shoes similar in color.Students dressing the same decreases teasing about clothing and shoe appearance. Uniforms prepare children for following a dress code for the future when they reach adulthood and join the workforce. Some children form their own groups in school in which wearing a certain thing or color or style. Some children use fashion trends to differentiate the popular ones from the unpopular children according to what they wear. Uniforms make it less possible for kids to be judged based on clothing choices. Uniforms prevent the competition to have the most fashionable clothes.Competition in school causes students to lose focus on schoolwork instead of on who is wearing the latest fashion trends. Uniforms eliminate clothes competiveness. Another article from Proffessorshouse. com states that some people claim that requiring a uniform increase graduation rates and also has an impact on children’s educational experience. Students performed on the uniform debate claim that uniforms encourage discipline, helps prevent social groups from forming opinions based on fashion status, gets rid of economic barriers and makes easily to identify persons at the school who should not be there.The article also talks about how some form of dress codes enforced around 75% of all schools dress codes are in place to outlaws offensive clothing being worn to the school. After reviewing another article from Ezinearticles. com uniform s create a source of identity and provides a sense of belonging according to the article the article some children’s believe the school chosen for them is a sort of achievement and the school uniform is a mark of inclusion, something to brag about and they feel proud and empowered wearing it.It eliminates the child having to worry about what to wear each day. Uniforms also relieve the parent of having to spend money to helping the child to keep up with the latest trends every day. Uniforms allow a sense of unified purpose to develop particular rivalry with other establishments. Uniforms reinforce children’s since of belonging to reassuring communities. In a 1996 Long Beach, Calif. speech, former President Bill Clinton announced his support of that district's uniform initiative.It didn’t get far in the United States but it also helped start the debate. Uniforms also closes the debate on what children are allowed wear to school, then that makes mornings easier for parents and for children. Everyone knows exactly what the kids need to wear, their regulated school uniform. This leads to a decrease in morning arguments. Some experts believe that when the entire student body is dressed in uniforms, they develop a stronger team mentality. When they are all dressed alike, their all-for-one-and-one-for-all attitude is boosted.With parents saving by not having to buy day to day clothes, they can let their children buy a few nicer and more fashionable clothes for weekends and evenings. Wearing a uniform five days a week can make children appreciate their weekend fashions more. Why Students Should Not Wear Uniforms Parents on the opposing side feel uniforms violate the right to freedom of speech and expression; a uniform cost too much for families struggling financially, uniforms are a band aid on the problem of school violence and does not address the real issues behind it.Uniforms hide warning signs that point to problems that maybe going on with th e child. Some feel that uniforms have not been able to prove wither the decreased discipline or violence and uniforms fail to allow children the ability to learn and make good choices based on their own values. Most feel that uniform are not allowing children to be themselves. Some believe that children cannot be themselves clothes are an expression of who they are. Parents feel that uniforms can be more expensive than regular clothes.Some parents may feel they are a big waste of money wither the school paid for them or not. Some feel uniforms made children uncomfortable and made them focus on the uniform rather than focusing on school work. Also uniforms do not change a child’s behavior in school. Wearing uniforms stop children from getting in trouble and acting out in school. Self-expression is an important part of a child’s development and curbing it with uniforms can be determined to children. Some feel if students are not able to express themselves will in another way by excessive make-up or hairstyles or jewelry.Uniform wear delays transitions into adulthood. Some experts feel teenagers to wear uniforms limits their ability to express in their own way in which can delay their transition in adulthood. Studies show uniforms can be a difficult to enforce in public schools. Conclusion Uniforms have many pros and cons, most believe uniforms are a good option for kids while others feel they can compromise who kids are through expressing themselves through the clothes they wear uniforms cuts down on violence and is a solution to economic problems parents may be facing today.My own personal experience with uniforms causes me to look at uniforms in both sides of the issue. I feel uniforms should be forced in middle or high school but voluntary in elementary schools. I feel most kids in elementary school do not notice what each other wear. Middle and high school is the times where students notice what the other person is wearing or form groups based on who they think are popular or the other. Uniforms are a choice based on school officials and it is up to the child or school if uniforms work. References Website: EduGuide. com Website: Ezarticle. com Website: About. com

Wednesday, August 14, 2019

Porters Force Analysis On Leisure Cruise Industry

The universe economic system has been engulfed by strong international competition. Porter has argued that scheme equates how any steadfast competes against others in its concern. He argued that scheme is non merely a series of theoretical accounts at the corporate degree of scheme. The scheme includes analysing possible entrants, providers, purchasers, replacements and rivals. He describes the competitory forces determining an industry in his six forces theoretical account of industrial competition. By analysing the forces, one assesses the forces driving competition in an industry and evaluates the odds of a house successfully come ining and viing in an industry. The forces are includes: possible entrants with their menace of entry, providers with their bargaining power, purchasers with their bargaining power, industry rivals with their competition among existing houses, and replacements with their menace of utility service or merchandise and. Government engagement is another force that affects any industry[ I ]. The full leisure industry is composed of bomber industries including gambling, sail, lodging, athleticss installations, travel and touristry and vocational ownership. Cruise is one of the fastest turning sectors in the leisure industry which ensures that people basking their holidaies get conveyance installations. Under this sector, the companies which largely operate are transporting companies which transport people in leisure from one topographic point to another. The companies include AIDA Cruises, Celebrity Cruise, Cunard line, Disney Cruise Line, Holland American Line, Ocean Village, Princes Cruises, Royal Caribbea International and Seabourn Curise Line. All these named operate in Florida under the umbrella organic structure Florida-Carebbean Cruise Association ( Maya, 2010 )[ two ]. This is an industry of merriment characterized monolithic investings. Taking Ocean Village as an illustration of companies stand foring the full industry, this research paper will analyse the six po rter forces that affect the industry[ three ]. Buyers and dickering power In the industry, purchasers are traveler traveling for vocational Tourss, leisure activities and all that pertains to fun. Buyer power is the capableness of purchasers, their agents, and clients of the industry to act upon the monetary value charged and footings of purchase. If purchasers ‘ power is high, so the net income borders of the houses runing in the industry tends to be low. If the purchasers are organized and are few, so their power is high. The industry whose purchaser power is high tends to be unattractive to new investors since the realized net incomes are usually low ( Peng, 2009, p. 42 ) . In this sail sector of the leisure industry, purchasers are few and be given to be organized. Therefore, Ocean Village Company feels the force per unit area of good organized purchasers who have high-bargaining powers. The industry represents purchasers from higher economic and societal category who can form and inquire for their rights in the industry. They are willing to pass their money for leisure services therefore do non see much impact on pricing every bit long as they get choice services. Ocean Village Company has tried to include some other services to do any ocean trip successful and pull more clients. These include the wellness installations provided within the company and adjustment characteristics offered to travellers. Potential entrants and entry barriers When a company and industry in general, is doing net incomes, other investors think of embarking into that industry so that they enjoy the net incomes realized. This creates a inquiry of how the incumbent houses within the industry attempt to make barriers for new entrants. The executives of the industry attempt to make barriers even if it means passing some money on the same undertaking[ four ]. If the current houses in the industry can maintain possible entrants at bay, the full topic of competition and its impacts on the incumbent houses ‘ net incomes become moot. The menace of new houses to come in an industry is low if the incumbent houses have high powers to act upon monetary values, control resources and determine the nature of competition within the industry. In Florida, the industry has organized its houses and formed an association to cover with such affairs. The association, Florida-Caribbean Cruise Association, protect the houses from any external entrants every bit much as possible. It has partnered with the authorities to put high criterions for any house that wish to come in into the industry. This makes possible investors be scared off from come ining such a market hence the industry can be classified as basking the powers to protect its current signifiers from the possible entrants. Suppliers and their bargaining power Supplier power is the capableness of sellers to make up one's mind the monetary values and footings of supply. Suppliers include sellers of labour, natural stuffs, and capital goods. If their power is high, so the net income borders of the incumbent houses tend to be low. Such low net income borders make an industry unattractive to possible entrants. The being of many providers indicates low provider power, and frailty versa. Firms in the industry rely on many supplier classs to carry through its services. The major providers of the industry are those that supply fuel to houses in the industry. Shell Company[ V ]is the chief provider of fuel in the industry but there are other possible companies which can provide. Ocean Village Company has entered into understanding its providers on footings of sale which are non altered till the understanding period expires. Substitute merchandises and services The handiness of replacements for an industry ‘s merchandises and services alters the power of the incumbent houses. As the handiness of replacement merchandises and services rises and the easy of replacement additions, the power of incumbent houses to command monetary values and footings of concern diminutions. In the instance of this industry, the replacement might be air hose conveyance, rail and route. However, they do non supply the intended services the purchaser wants when taking. Cruise industry provides diversion installations, good environment in H2O and others that a individual on leisure activities needs. This makes the industry enjoy limited replacement merchandises and services. The power of the houses runing in the industry is hence high. Rivals and competition Competitive competition is the extent to which houses respond to competitory moves of other houses in the same industry. In some industries like sail industry, â€Å" gentleman ‘s understanding † exists whereby houses respect one another ‘s market niches and follow a â€Å" unrecorded and allow unrecorded † scheme ( Ireland et al, 2008, p. 82 ) . The industry has formed an association which deals with such issues as competition and unwanted behaviours within the industry. This reduces competition and competition within the industry doing the companies operated in a friendly mode. They are associated to supply better and quality clients to leisure clients and there is no demand to vie in the disbursal of the industry and consumers. In other sectors within the larger leisure industry, a â€Å" dog eat Canis familiaris †[ six ]thought prevails, cutthroat competition is the regulation and competitory moves are smartly encountered. This happens in hotel bo mber industry since many houses exist here. Government engagement This is another force, although non normally talked as, which influences any industry. It is a demand for the houses in any industry to follow with all authorities ordinances including enrollment, paying revenue enhancements and be responsible to the environment. Government engagement determines the profitableness of an industry. Sometimes, the authorities comes in to protect its consumers from development by houses in any industry[ seven ]. They can make up one's mind to command monetary values and quality of services offered. The sum of revenue enhancement charged besides reduces the company operating in that industry ‘s net incomes. It can be realized that in Florida, the authorities ensures that the safety of crewmans is maximal and the quality of services offered is optimum. Since the house operates in H2O, it is supposed to keep high criterions to protect the environment, H2O in this instance. Harmonizing to Kassing ( 2006 )[ eight ], Government provides substructure for all commercial diversion and touristry endeavors. However, the authorities engagement in this industry is minimum. This is because the industry does non offer basic trade goods which would do the authorities intervene to command monetary values. The company enjoys authorities protection from sea challengers. The demands the authorities has put in footings of new entrants are excessively affecting doing the industry one of those that are difficult to come in into by new companies. Decision The forces determine profitableness of any industry as they influence the costs, monetary values, and needed investing of houses in that peculiar industry. Buyers power influence the monetary values Ocean Village Company and any other company can bear down. It besides has an influence on investing cost since sceptered purchasers asks for expensive services. Supplier ‘s bargaining powers influences input costs like fuel. The competition influences monetary values and viing costs. On the other manus, entry menace bounds monetary value charged and makes incumbent houses invest to avoid it ( porter, 1985, p. 7 ) . The Florida based companies runing in the sail industry formed an association, Florida-Caribbean Cruise Association, which has changed the industry construction. They agree on how to carry on concerns, how to make entry barriers and common characteristics to follow so as to fulfill their clients in Leisure-Cruise industry. It is a strong association of houses that have ma de the industry one of the popular in Florida and profitable.

Tuesday, August 13, 2019

Homicide criminal law Essay Example | Topics and Well Written Essays - 2000 words

Homicide criminal law - Essay Example e criminally liable if his conduct was the factual cause of Tom’s death and the consequence of death would not have happened â€Å"but for† Sanjay’s conduct. If we apply the â€Å"but for† test to the current situation, arguably Tom would not have been in hospital with severe internal injuries if had not been for Sanjay’s actions, therefore under the â€Å"but for test†, it is more than likely that Sanjay’s conduct will have satisfied the requirement of factual cause of death. However, it is also evident from the facts that Tom subsequently died of a blood transfusion at the hospital as a result of receiving the wrong blood type, which the doctors failed to notice. As a result, Tom died and this begs the question as to whether Sanjay was in fact the legal cause of death or whether the failure to give Tom the correct blood type in the transfusion was in fact the cause of death. Under the legal causation test, it is not necessary for Sanjay’s conduct to be the sole cause of death however it must be the substantial cause and have made a significant contribution to Tom’s death3. Ultimately, this is determined according to the facts of each case, however case law has established that the original wound must still be operating and a substantial cause at the time of death4. With regard to the current scenario, the doctors failed to administer the correct blood type in the transfusion and therefore one could argue that it was their failure was the substantial cause of Tom’s death. However, UK courts have been reluctant to break the chain of causation in cases where medical negligence is involved. A prime example is the case of Smith,5 where the victim was stabbed by Smith but died due to medical negligence. Despite there being a 75% chance of recovery but for these events occurring, the courts still held that the chain of causation was not broken. Although a different approach was used in the case of Jordan6 where negligent medical treatment was

Monday, August 12, 2019

Finance Assignment Example | Topics and Well Written Essays - 2250 words

Finance - Assignment Example A firm with more contractual obligations i.e debt but insufficient cash or marketable securities to repay the debt definitely faces liquidity problems. The circumstances turn grimmer with more and more liquidity crisis in the organization when the firm becomes completely unable to repay its obligations, thus the firm in such situations become insolvent or faces solvency problems. Thus with more amount of liquidity crisis with not much fresh cash or marketable securities in the system, the firm tends to borrow more from the banks and financial institutions thereby increasing its obligations of repayment more. But with high debt to equity ratio sometimes it becomes difficult for organizations to obtain debt from the financial institutions. This definitely hampers the operational activities of the organization. In such a situation with deep crisis of liquid cash to carry out business and with difficulty in getting loans from the banks, the sustainability of the firm in the long run gets hampered. In certain cases the firm becomes insolvent and may go out of business. (Burnside, 2005, pp.87-90; Course material, pp.112-118) Different approaches to Financial Asset Valuation: One of the major approaches designed in the financial valuation process includes valuation of Equity. The major forms of equity valuation include- 1) Dividend discount modeling- Under this method of valuation, the valuation of the firm is determined by the dividends paid out by the firm. Using the  projected growth rate in dividends in the next 5 years with an estimated growth rate and then using a constant growth rate for the rest of the years, discounted by the required rate of return by the shareholders’  the valuation of the firm is determined. 2) 2) The free cash flow modeling approach- The valuation method is performed using the free cash flow. The free cash flow is the cash flow available to the firm after meeting the necessary capital expenditures and necessary short-term worki ng capital requirements. In this method also, the valuation is performed using the projected free cash flow in the next 5 years using a projected growth rate and then a constant rate for the rest of years after the 5-year period, discounted by the required return for the shareholders. 3) 3) Price earning model- This equity valuation method is a market based method which calls for the market price an investor wants to pay for 1 rupee earning by the company. Higher Price-Earnings ratio designates that the company is overvalued in terms of its market compared to its earnings. Besides equity valuation, we have valuation for fixed income securities like bonds. Bonds, which have fixed coupon rate attached to them, pay fixed interest every year. The fair value of the bond is calculated by the annuity approach which is calculated by the summation of the net present value of the fixed coupon interest over the maturity of the bond with a discount rate as required by the bond holders. (Pinto, Henry, Robinson & Stowe, 2010, p.1) 1B)   On the Capital and Liability side of the Balance sheet of different organizations, the different types of capital and liabilities have different features. These are categorized under the major head ‘Financial capital’. The different classifications include the following: 1) Senior debt, 2) Mezzanine debt, 3) Subordinate debt, 4) Preferred Stock and 5) Common Stock. In case a company goes bankrupt, the company has to first pay back its obligations to the debt holders and finally to