Skip to main content
Essay Undergraduate 2,092 words

IT Security Plan for a New Corporate Installation

~11 min read
Abstract

This paper presents a step-by-step IT security plan developed for ZXY Corporation's newly acquired building. The plan covers secure user access control, a password complexity policy, WPA2 and hard drive encryption, virtual private network (VPN) remote access, and malware and phishing defenses. It also addresses physical security, workstation lockout policies, file and folder access hierarchies, acceptable use monitoring, network cabling and wireless infrastructure upgrades, and document digitization. Together, these measures aim to protect the organization's data, limit liability, and establish a defensible security posture from the ground up.

Key Takeaways
  • Introduction and Background: Scenario context and current security gaps identified
  • Access Control and Password Policy: Network login requirements and password complexity rules
  • Encryption and Cryptography: WPA2 wireless and hard drive encryption methods
  • Remote Access via VPN: VPN setup for secure off-site network access
  • Malware Protection and User Awareness: Antivirus tools and phishing awareness training
  • Physical Security and Acceptable Use: Device security, monitoring, and acceptable use rules
  • Network Infrastructure and Document Management: Cabling upgrades, wireless standards, and digitization
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • The paper covers a wide range of security domains — logical, physical, and procedural — in a logical sequence, demonstrating breadth appropriate for a corporate IT security proposal.
  • It grounds recommendations in concrete examples (e.g., the TJX Wi-Fi breach, WEP versus WPA2) that justify policy choices rather than simply asserting them.
  • The acceptable use and legal liability sections show practical awareness of organizational risk beyond purely technical concerns, rounding out the plan's real-world applicability.

Key academic technique demonstrated

The paper uses a policy-proposal structure, organizing technical recommendations by functional category (encryption, access, remote access, etc.) and supporting each with brief rationale. This mirrors professional IT documentation practice and shows the student can translate academic security concepts into actionable organizational policy.

Structure breakdown

The paper opens with an introduction framing the hypothetical scenario, followed by a background section identifying gaps in the current setup. The bulk of the paper is a detailed plan section covering seven distinct security domains. A short conclusion synthesizes the importance of comprehensive security. The structure is practical and document-like rather than argument-driven, which suits the genre of an IT security proposal.

Introduction and Background

This report addresses a hypothetical situation at ZXY Corporation, where a new building has been procured to serve as the site for a new information technology (IT) infrastructure. The current setup is raw and unfinished, and that must change before operations begin. The facets of the IT security plan addressed in this report include: a plan to provide secure access for all users; a viable password policy covering complexity and related factors; a cryptographic method to ensure vital data is encrypted; a remote access plan to ensure that off-site connections are functional and secure; and a thorough plan to protect the network from malware and various types of malicious attacks such as phishing and social engineering. While the components of a sound IT security plan are straightforward to enumerate, implementing them well can present a real challenge.

Looking at the facts presented, a few questions and concerns immediately arise. A local area network (LAN) is present, but its capability and rating are not specified. Currently, everything is shared with everyone — that must change from the outset. Everything is essentially set to operating system defaults, which is clearly insufficient. This report presumes that Windows is the primary workstation environment. Given these parameters, the following sections offer a step-by-step plan that addresses both the explicitly stated requirements and the subtler best-practice considerations that any responsible IT security framework should include.

Access Control and Password Policy

For secure access control, all users of the new network will be required to use their Windows password to log into their workstations at the start of each day. This password will also serve as the network and intranet credential for the company. Absolutely no one will be permitted access to the secure LAN without entering this password.

The password policy of ZXY Corporation will be straightforward but firm. The minimum password length will be eight characters. Each password must contain an uppercase letter, a lowercase letter, a number, and a symbol. For example, Fishbowl22! would be acceptable, but omitting the capital letter, the numbers, or the exclamation point would not. Using any part of one's legal name will not be permitted, nor will reusing any previously used password. Passwords must be changed at least once every thirty days. If an employee loses or forgets their password, they must contact the IT department, which will have a specific recovery procedure in place.

Encryption and Cryptography

Encryption and cryptography will operate in two major forms: wireless encryption and hard drive-level encryption. For wireless traffic at the office, WPA2 encryption will be used. It is the current gold standard for wireless encryption and has not been compromised. By contrast, the obsolete WEP encryption will not be enabled or permitted on any workstations. As demonstrated by the TJX data breach — and the vulnerabilities known even before it — WEP has been thoroughly compromised (Ou, 2007). Unsecured wireless traffic will never be permitted unless the user is connected via the VPN. Even then, any responsible employee working from home should have a WPA or WPA2 router. Locations such as public Wi-Fi hotspots are generally unsecured, and use of such networks should be brief and exceptional.

The second component of the encryption strategy is hard drive-level encryption. While most important and vital data should not be stored on local hard drives, some data will inevitably reside there — for example, Microsoft Outlook PST files and similar minor exceptions. Regardless, the contents of every hard drive will be encrypted using a solution such as Sophos or a comparable product. This is essential in the event that a laptop is stolen. Encryption effectively limits a thief to reformatting and wiping the drive. Without a valid Windows password, the data on the drive will remain completely inaccessible.

4 locked sections · 1,030 words
Sign up to read the full analysis
Remote Access via VPN120 words
The secure access for the company's network will be facilitated through a virtual private network (VPN). Whether due to field work or working from home, a VPN…
Malware Protection and User Awareness210 words
Protecting the network from malware will involve several layers of defense. A well-established antivirus and malware detection solution — such as McAfee…
Physical Security and Acceptable Use420 words
Consistent with the importance of laptop security noted in the cryptography section, all employees will be clearly informed that leaving laptops or other company equipment in vehicles — especially in plain view — is absolutely forbidden. Each employee's laptop should remain on their person at all times,…
Network Infrastructure and Document Management280 words
The company should ensure it maximizes the LAN capabilities that exist. There needs to be a match between the capabilities of the…
Read the full paper →
Plus 130,000+ examples & all writing tools

Conclusion

The measures outlined above represent common-sense best practices that should be familiar to anyone mindful of computer security and the need to protect intellectual and private information. Failing to implement such a program — or failing to establish adequate physical and digital security — creates conditions under which information can be lost, stolen, or weaponized against the company or its individual employees. Beyond the operational risks, inadequate security can also create significant legal and financial liability. A well-designed, thoroughly implemented IT security plan is not optional; it is a fundamental requirement for responsible organizational operations.

References

Harrison, K. (2016). 5 steps to a (nearly) paperless office. Forbes.com. Retrieved 24 June 2016, from http://www.forbes.com/sites/kateharrison/2013/04/19/5-steps-to-a-nearly-paperless-office/#7e1a915b1cda

Nolo. (2016). Vicarious liability — Nolo's free dictionary of law terms and legal definitions. Nolo.com. Retrieved 24 June 2016, from

Ou, G. (2007). TJX's failure to secure Wi-Fi could cost $1B. ZDNet. Retrieved 24 June 2016, from http://www.zdnet.com/article/tjxs-failure-to-secure-wi-fi-could-cost-1b/

Rosoff, M. (2016). Netflix and YouTube are America's biggest bandwidth hogs. Business Insider. Retrieved 24 June 2016, from http://www.businessinsider.com/which-services-use-the-most-bandwidth-2015-12

Wood, L. (2016). 4 simple reasons why choosing CAT 7 cable really pays off. Loxone. Retrieved 24 June 2016, from http://www.loxone.com/blog/enuk/cat7-cable/

Key Concepts in This Paper
Access Control Password Policy WPA2 Encryption VPN Malware Defense Phishing Awareness Hard Drive Encryption Physical Security Acceptable Use Network Infrastructure
Cite This Paper
PaperDue. (2026). IT Security Plan for a New Corporate Installation. PaperDue. https://www.paperdue.com/study-guide/corporate-it-security-plan-installation-2158479

Always verify citation format against your institution’s current style guide requirements.