Lab 2 - IAP301
Lab 2 - IAP301
Upon completing this lab, students will be able to complete the following tasks:
● Identify human nature and behavior patterns of employee types in both hierarchical and
flat organizational structures
● Overcome user apathy with security awareness techniques in both hierarchical and flat
organizational structures
● Identify how security policies can help shape organizational behavior and culture in both
hierarchical and flat organizational structures
● Compare a hierarchical and flat organizational structure to equivalent IT security policy
framework structures
● Create an organizational policy implementation plan for the combined organization
1
Overview
In this lab, you are to create an organization-wide policy framework implementation plan for
two organizations that are merging. The parent organization is a medical clinic under HIPAA
compliance law. They recently acquired a remote medical clinic that provides a specialty
service. This clinic is organized in a flat structure, but the parent organization is organized in a
hierarchical structure with many departments and medical clinics.
Instructions
● Publish Your Policies for the Acquired Clinic – {Explain your strategy} ● Communicate
Your Policies to the Acquired Clinic Employees – {How are you going to do this?}
● Involve Human Resources & Executive Management - {How do you do this smoothly?}
● Incorporate Security Awareness and Training for the New Clinic – {How can you make
this fun and engaging?}
● Release a Monthly Organization-Wide Newsletter for All – {How can you make this short
and to the point?}
● Implement Security Reminders on System Login Screens for All – {For access to
sensitive systems only}
● Incorporate On-Going Security Policy Maintenance for All – {Review and obtain feedback
from employees and policy compliance monitoring}
● Obtain Employee Questions or Feedback for Policy Board – {Review and incorporate into
policy edits and changes as needed}
3
Strategy:
• Town Hall Meetings: Host live sessions to introduce essential policies and answer
questions.
• Welcome Packets: Include policy summaries and access information in onboarding
materials.
• Online Training Modules: Develop interactive modules explaining key policies, with
completion tracking.
• Designated Point of Contact: Establish a dedicated liaison for policy inquiries and
clarifications.
• Peer-to-Peer Support: Encourage experienced employees from the parent organization
to offer informal guidance.
• HR Integration: Involve HR from both clinics in reviewing and adapting policies to ensure
fairness and alignment.
• Executive Sponsorship: Secure commitment from executives in both organizations to
prioritize smooth policy integration.
• Joint Policy Review Committee: Establish a committee with representatives from both
clinics to assess and update policies collaboratively.
• Visual impact: Utilize engaging visuals and clear language to capture attention and
reinforce memory.
• Customization: Allow for occasional theme changes and updates to maintain
effectiveness.
• Regular Feedback Cycles: Conduct semi-annual reviews of policies with employee input.
• Anonymous Surveys: Use anonymous forms to encourage honest feedback on policy
effectiveness and clarity.
• Policy Monitoring Metrics: Track incidents, compliance rates, and feedback trends to
identify areas needing updates.
• Policy Champions: Appoint department-level champions to gather insights and act as
liaisons during reviews.
• Dedicated Feedback Portal: Create an online platform where employees can submit
questions or suggestions.
• Policy Board Meetings: Schedule regular meetings to review employee feedback and
prioritize changes.
• Transparent Updates: Publish a “What We Heard” section in the monthly newsletter to
show how feedback is being acted upon.
• Focus Groups: Organize small focus groups to discuss proposed changes and gather
additional insights.
Note: Your policy framework implementation plan should be no more than three pages long.
4