ABC Technologies - Coursework Case Study
ABC Technologies - Coursework Case Study
ABC Technologies - Coursework Case Study
ISMS
COS7030-B
ABC Technologies is the new name of ABC Printing. Paul Evans (President) and
Sally McCarty (Executive Vice-President) created ABC Printing in 2011 at the end
of their university studies. The Yorkshire company saw rapid expansion. It had 253
employees in 2016 when Paul and Sally decided to diversify their activities by
venturing out into 3D graphics printing. This activity, then emerging with the
development of information technologies, was supported by both senior executives
who saw in it the means to strike a balance between their traditional activities and
what they considered the future of the printing industry.
These longtime friends are enthusiasts of new technologies. They have always
known that the information technology sector had a great growth potential.
Conscious of the importance of information and technologies, Paul and Sally
seized an opportunity offered them in 2016: A&B Technologies, a company that
developed and commercialised Customer Relationship Management (CRM)
software, and that was located about a hundred meters from their premises, went
bankrupt. Since their printing and computer graphics activities generated cash
surpluses, they decided to buy out A&B Technologies. ABC Printing was then
renamed to ABC Technologies to display an image more in line with its new field
of activity. The merging of ABC Printing and A&B Technologies produced a
company with 567 employees distributed as follows: 556 employees in the printing
and 3D graphics divisions, and 11 employees in the CRM division.
COMPANY HISTORY
The software developed by A&B Technologies facilitates the acquisition of
information, including customer data entry (name, contact information, availability,
recreation). It allows a company to store, control and modify information, plan
tasks, annotate notifications as well as several other functions. Three products are
distributed: ABC Supreme (£3,995), ABC Pro (£495) and ABC (£295).
ABC Technologies’ head office is located in Bradford. This location combines the
printing, 3D graphics printing and software development activities.
Following the growth of the company, another office was opened in Leeds in 2012.
1
Paul Evans decided to take charge of the Leeds office, where sales and services
are managed. Since these involve a strong need for managing customer relations,
he was the best candidate for the job thanks to his communication and negotiation
skills. Administration team was also located in Leeds.
COMPANY HISTORY
started to slow the growth of the company’s software activity.
2
ABC Technologies Facilities
All the employees have desktop computers connected through a network and
operating with Windows 10 operating system. The network is connected to a
central file server. This server is used to store all relevant information, such as
orders sent by email in PDF format from the Leeds office, production records,
personnel data, and the information on the design of products.
The Leeds office has the same configuration as the head office. The personnel
use desktop computers that operate with Windows 10. The network is also
connected to a central server, which is used to store customer data, customer
orders, financial and accounting records, and contracts of partnerships. The sales
team is concentrated in this sales office under the supervision of Owen Roger.
And, all orders are transferred by email to Paul Evans who is in contact with Sally
McCarty for deliveries.
IT Network
3
Recent Facts and Events
After the arrival of the new CEO, Mrs. Senat, the following employees were fired:
• The Bradford office alarm system does not work and the company that
installed it went bankrupt two months ago
• Julia Robinson, the website designer, was sick for one month
• Eric Lewis was informed by a customer that Steven Baker and Ian Kovalev
were hired by their competitor, BearClan
• Personal information on customers is kept in a database with no security
measures in place to protect it
• Although a formal description of the employees’ roles and responsibilities
exists but, several employees perform additional tasks and do not adhere
to the document
• ABC Technologies has bought a list of 500,000 emails of potential
customers from a company located in the Bahamas to launch an Internet
advertising campaign
• A corporate website of ABC Technologies was built by a website
development company that also took responsibilities of relevant updates.
4
Organization Chart
CEO
Sabina Senat
The information assets considered to be the most important are the product
source code, and the company financial and accounting data.
You must take into account that each employee can connect to the network from
anywhere, through an Internet connection, using their own login and password
thanks to a VPN.
6
Following the clarification of the ISMS scope, you should create:
The key to this assessment is the reflective narrative related to academic literature
around the development of your ISMS. You can structure this such that you reflect
on each stage or that you have a reflective piece that encompasses all you have
developed.
You must make assumptions about some components of the ISMS if this
information is not available in the case study, but you need it for the effective
implementation of the ISMS.
7
ISMS Policy
Statement
- The object of this policy is to define the policy of the Information Security
Management System for ABC Technologies.
Definitions
- The current policy applies to all Users. The use of Information Assets by a User
constitutes in itself an implied acceptance of the policy.
- It is up to the Support Department Manager, in cooperation with ABC
Technologies Management, to ensure the respect of this policy and to take the
necessary measures to apply it.
ISMS POLICY
8
Objectives
Policy
ISMS POLICY
where they need them with the lowest level of interruption possible.
- Information integrity must be maintained, and its exactness and completeness
must be ensured to protect it against changes and unauthorized accesses.
- Information confidentiality must be ensured. The date of human or electronic
communications must be protected to ensure that valuable or sensitive
information is protected against unauthorized disclosures or inevitable
interruptions. The organization must conform to all the IT sector regulatory and
9
legal specifications to avoid any fines or financial costs caused by
nonconformity to the law.
- A management framework of business continuity must be provided using a
business continuity plan to counter business activity interruptions and to protect
the critical business processes in case of disaster. The business continuity plan
must be maintained, tested and reviewed to be efficient in case of an event that
can cause damages to ABC Technologies.
- ABC Technologies must train its employees on information security by putting
in place a continuous awareness program on the importance of information
security and the participation to the necessary trainings.
- Real or suspected security breaches must be evaluated and reported to the
competent authorities.
- Adequate access control must be put in place and the information must be
protected against unauthorized accesses.
- To support the ISMS, all policies, procedures and guidelines must be available
in print or electronic version to all authorized persons by means of an internal
network system (intranet).
- All supervisors are responsible for implementing the ISMS in their Department.
- All personnel have the responsibility to adhere to the ISMS policy.
- In case of an information security problem, the situation must be handled using
ABC’s risk management framework.
10
Additional Notes
11
13. It isn’t clear if backups have ever been tested
14. The company has efficient and effective logging and monitoring activities. All
are kept up to date, reviewed appropriately and stored securely
15. Installation of software and the integrity of operational systems are
maintained effectively
16. Network segregation needs clarification
17. The company needs to spend some time developing useful transfer policies
and procedures. Staff don’t know what it is acceptable and what is not
18. As the company wants to focus on software development, the company
needs to ensure that information security is applied to the complete
development lifecycle. This needs to be embedded in all aspects (from initial
planning to testing)
19. Supplier relationships and contracts are key; clarification with suppliers and
their part in ensuring security of information is essential. Contracts are in
place, but these don’t include all the necessary activities. In particular service
delivery needs to become better controlled
20. Only the important incidents related to the network are documented and
discussed during the IT team’s weekly meeting
21. The last review of security controls took place 18 months ago
22. The organization assumes it complies with all legislation, but there isn’t a
definitive list of applicable legislation
23. The review of compliance with policy, standards and procedures is overdue.
12