10. Why must an organization have an acceptable use policy (AUP)
even for nonemployees, such as contractors, consultants, and other
third parties?
11. What security controls can be deployed to monitor and mitigate
users from accessing external Web sites that are potentially in
violation of an AUP?
12. What security controls can be deployed to monitor and mitigate
users from accessing external webmail systems and services (for
example, g m a i l etc.)?
13. Should an organization terminate the employment of an employee
if he/she violates an AUP?
10)
Answer:
The acceptable use policy is needed for non-employees such as contractors, consultants, and other third parties to let them know of them know the rules regarding access to the systems.
This helps prevent third parties from abusing corporate systems and holding all users of the systems to the same standards. This is needed to ensure that the organizations policies are followed.
11)
Answer:
The security controls that can be deployed to monitor and mitigate users from access external websites that violate an AUP would be a proxy server or firewalls. A proxy server can be configured to allow or deny traffic to websites that hold certain content.
A company could specify that gaming, porn, or social sites are banned. These meta-tags can be placed into a proxy server to block websites of these types from being accessed on a corporate network.
The use of a proxy server is one of the most effective methods
of limiting traffic on the company’s network from accessing sites
that are banned or disallowed by the companies AUP.
12)
Answer:
The security controls that can be deployed to monitor and mitigate would be through the use of firewalls that can block those sites or through the use of proxy servers that can be used to block sites that are webmail related.
This way a company can lock down access to sites like G mail, Hot mail, Yahoo, and other similar sites.
13)
Answer:
An organization should terminate employees who violate the AUP multiple times. There should be a formal process to how an employee is terminated.
In many instances employees violate the AUP on a daily basis, so if the company were to fire any employee who violated the AUP then they would lose a large amount of staffing.
The use of training should be done in conjunction with write-ups and other disciplinary actions. In some instances terminating and employee would be justified, but it would depend upon the offense.
If you have any doubts, leave a comment below and I'll help you out
Can you PLEASE UPVOTE. Thank you so much
Get Answers For Free
Most questions answered within 1 hours.