Information Security Plan for a Small Media Business
This paper presents a comprehensive information security plan for Pixel Inc., a 100-person media production company specializing in short animations for advertising clients. The plan begins with a preliminary assessment of the company's hardware infrastructure — including desktops, servers, and network equipment — and identifies its key digital and physical assets. It then categorizes security risks by priority, addressing external network intrusions, industrial espionage, internal social threats, and accidental data loss. The document outlines specific countermeasures across four domains: network fortification, employee education, internal access controls, and disaster recovery. A 30-day implementation timeline, assigned responsibilities, and a projected budget round out the plan.
- Company Overview and Plan Scope: Introduces Pixel Inc. and plan applicability
- Preliminary Infrastructure Assessment: Inventory of desktops, servers, network, and assets
- Risk Identification and Priorities: Four threats ranked by risk level and priority
- Security Measures and Controls: Network, education, internal, and disaster controls
- Implementation Timeline and Responsibilities: 30-day phased rollout with assigned tasks
- Resources and Budget: Software, hardware, and offsite backup costs
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The plan follows a logical progression from asset inventory to risk assessment to specific countermeasures, giving it a professional, actionable structure typical of real-world security documentation.
- Risks are clearly ranked by both likelihood and priority, helping the reader understand why certain controls are addressed before others.
- The inclusion of a concrete 30-day timeline and budget section moves the document beyond abstract policy into practical planning territory.
Key academic technique demonstrated
The paper demonstrates applied risk-tiering: each identified threat is assigned a risk level (High/Low) and a priority level (High/Medium), and the security controls are then sequenced to address the highest-priority items first. This structured alignment between risk analysis and remediation planning is a foundational technique in information security management frameworks such as NIST and ISO 27001.
Structure breakdown
The document opens with a scope statement, then moves through six numbered sections: infrastructure inventory, risk and priority analysis, the four-part security plan (network, education, internal controls, disaster recovery), a phased implementation timeline, and a resource/budget overview. Each section builds directly on the previous one, creating a clear cause-and-effect chain from vulnerability identification to remediation action.
Company Overview and Plan Scope
Pixel Inc. is a 100-person business dedicated to the production of media — most specifically short animations — for advertising clients worldwide. Personnel include marketing specialists, visual designers, video editors, and other creative staff.
This security plan encompasses both the general and practical characteristics of the security risks expected for the business, and the specific actions that aim, first and foremost, to minimize such risks. Where full prevention is not possible, the plan also addresses how to mitigate damage should a security breach occur.
The measures and assigned responsibilities stated in this document apply to all departments within the company. Exemptions may be granted, but only under the prerogative of the CEO in consultation with the Chief Security Officer, who will be formally assigned after the finalization of this document. Otherwise, no exceptions to the security measures stated here will be permitted.
Preliminary Infrastructure Assessment
Each individual in the company is assigned a desktop computer, with operating system and software specifications dependent on the nature of the employee's work. Creative staff use Apple G5 desktops running OS X, while general staff are assigned Windows XP workstations. All desktop computers have email, web, database access, and office productivity software installed.
Servers are utilized specifically for Internet connectivity, file and print sharing, email, database management, and 3D rendering. Twenty dual-core Xeon servers running Red Hat Linux 9.0 are employed for rendering high-resolution video animations. The database and email servers run Windows Server 2003 with Microsoft Exchange. Internet and resource-sharing servers (i.e., file and print sharing) also run on Red Hat Linux 9.0.
A 10 Mbps connection on a SOHO firewall — which also doubles as a DHCP server — provides the company's primary web access. The firewall secures the network from outside intrusions while allowing access via email, web, and secure FTP through the servers. The network is TCP/IP-based and utilizes Cisco routers and switches. Guests using laptop computers can obtain an IP address from the DHCP server when needed.
Both Cisco and Hewlett-Packard Ethernet hardware are used in the setup. Server equipment is stored in a dedicated server room. Printers are installed at strategic locations throughout the office area.
Beyond physical property and tangible products, the company's main assets are:
Access to assets is determined on a need-to-know basis, with master access granted only to the CEO and COO. Departmental access is provided for data or materials directly relevant to each department's responsibilities.
Risk Identification and Priorities
1. Direct Outside Intrusion (High Risk, High Priority)
Hacking, malware intrusion (e.g., viruses, worms, Trojan horses), and other malicious actions are high-risk possibilities given the company's dependence on its Internet connection. This is an expected threat given the nature of the World Wide Web and the software infrastructure used by the business. Examples include viruses, social engineering, and Trojan horses delivered via email.
2. Espionage and Industrial Sabotage (High Risk, High Priority)
Given the nature of the company's primary products, there is a possibility of intellectual property theft — physical or virtual — through either network-based attacks or physical means. Sabotage is also a possibility given the competitive nature of the field. An example would be a disgruntled employee obtaining confidential information for a rival company.
3. Social and Internal Threats (Low Risk, Medium Priority)
The widespread use of online social networks makes it necessary to monitor employee behavior for circumstances that increase the risk of disclosing confidential data. Employees may also inadvertently expose confidential information through physical means. Examples include leaving documents unattended or posting status updates that reveal confidential company information.
4. Accidents and Disasters (High Risk, Medium Priority)
There will always be a risk of accidents and natural disasters that could undermine the company's capacity to complete its projects. Examples include network crashes, flooding, and accidental project deletion.
1. Network intrusion fortification: This includes strengthening the network against malware attacks and hacker-directed intrusions targeting company servers.
2. Employee education: All employees must be trained to understand general security precautions relevant to the company's situation and to know the non-specific roles they could take should a breach occur. An important example of this is the use of strong passwords and related precautions when downloading files from the Internet.
3. Internal security: Preventing theft of all company assets is a high-priority objective, since the company's primary products depend on these materials — virtual or otherwise. This includes precautions against employees knowingly or unknowingly disclosing or misappropriating those materials.
4. Safeguards against disasters and accidents: While natural disasters are difficult to prevent given the company's resources, accidents can be guarded against and measures can be taken to minimize damage. For example, critical documents and files should be backed up frequently to an offsite location.
Always verify citation format against your institution’s current style guide requirements.