Tuesday, August 6, 2019
Organizational Conflict Essay Example for Free
Organizational Conflict Essay Conflicts within an organization can be difficult on employees. Some conflicts may be petty and some could end up in violence. They are often started because of the difference of opinions between employees (Shetach, A., 2012). Regardless of the situation; employers cannot afford to have conflicts within their organization. The purpose of this paper is to analyze the reason for the conflict within this organization and to come up with ways to help solve the conflicts. Description of the Conflict The conflict at my place of employment is that there are never enough associates scheduled to perform the duties that are needed to be done. The ICS team is the main team that goes through the inventory in the back room on a daily basis. Their job is to bin every item that comes within this store with a labeling system. The problem that is being cause is that there are not enough associates able to keep up with binning the items after the ICS team finishes scanning and counting their freight. What conflict that has occurred from this is that the unloaders are coming in and they have to help them out. In return the un-loaders are falling behind in their work. When the morning shift associates comes in; mainly department managers they have to work out the items that the ICS team has scanned. When you look at the amount of freight that is needing to be work out, it could be from four to fifteen L-carts. L-carts are the large carts that are used to move large freight to the floor or to the customerââ¬â¢s car. Production was falling behind because there was not a good plan set into place on who, what, and how the receiving area of the store would be operated. There was lack of communication that was going on between upper management and lower management. It seemed as though the associates were the ones that were making the decisions instead of the managers. The ICS team and the un-loaders were constantly arguing with each other, claiming that the other one is not doing their job. The department managers were coming in to work stating that the overnight associates were not putting out freight. It looked as if the same freight was left from the day before was not being worked. Level of Conflict There are four levels of conflict within an organization (Baack, D., 2012). What is going on within this organization is called intragroup conflicts. Intragroup conflicts occur when incidents between members of a team do not have the same mind set concerning goals. They disagree with the way the operations are being handled and the leadership (Baack, D., 2012). If conflicts are left unattended within an organization it could affect the overall goal of the company. The teams may not do what they need to do and the decision that they make in doing their job may not be the right decision (Baack, D., 2012). Propose Steps to Resolve the Conflict There are five steps that must be followed in order to help resolve conflicts within this organization. The first thing is to identify the parties that are involved in the conflict. Determining if the entire team is involved or if there is an individual that is causing the conflict need to be investigated first (Baack, D., 2012). By doing this, it will allow for the managers to help determine what is need to be done in order to resolve the conflict. This conflict can be stopped with the proper communication between team members and management. But they need to have weekly meeting in order to go over their goals and their concerns (Shetach, A., 2012). Having meeting will allow the team members to voice their opinions if they feel they may not be doing ample amount of production that is needed in order to be productive. This can be analyzed by management as soon as it is brought up in the meeting. The management team needs to find out what the real issue is within the team and figure o ut how the problem started. While they are investigating this issue they need to also know what position that each team member have concerning this conflict (Baack, D., 2012). This can help management to understand where each team member stands on this conflict so it could help them come up with a better solution in order to stop the problem. Finding an area in which there can be bargaining is very important in resolving conflicts within an organization (Baack, D., 2012). Management need to stay neutral in making a decision regarding the conflict that is going on between the ICS team, the unloaders, and the department managers. There should be lines in which the managers need to be able to listen to all sides and not show favoritism. Finding the best solution for the organization in what is important. The policies need to be addressed at the time when bargaining process is going on (Montgomery, M., 1995). At the same time, the team members need to be able to work through their conflicts. There need to be a check list that needs to be done on a daily basis in order for each backroom associate to follow. If they are not able to do what they are assigned then they should be able to type in the reason why. For example, I was called to work in the garden center by Assistant Tony. It should have the time, and date on the log so that it can show the reason why a task was not completed. Management should not be able to call an ICS member out of their work area for more than 15 minutes a day. Considering they might be one of four that was assigned to scan in what is coming off of the trucks. Another step that could help resolve the conflict is to schedule people with the department managers that only have one associate. Some department managers do not have more than one associate within th eir area. A department manage usually have five hundred to five thousand prices changes to do on a daily basis. They have to work their bins; bins are the freight that they have to put out on the shelves. If more associates are schedule past 5 pm, it could help the organization to make a better profit; because the shelves will be filled. Not all conflict situations are the same. Some may be resolved if the people that are involved learn the effect that their opinion, attitudes, or behavior have on other team members (Montgomery, M., 1995). Some of the managers need to be more productive by helping the team members to see what they need to improve in or what they have to offer to make the team stronger. Outcomes to the Conflict Resolution By not doing anything and letting the teams argue about what each other are doing it will cause a lack of production within the team. It could affect the entire team as a whole. Agreement is very important in a conflict resolution (Baack, D., 2012). When all of the team members on the ICS, department managers, and the un-loaders believe that their opinions matters that is when agreement is reached. The managers have to let them all know that all of the concerns that were leading up to their conflicts have been met. Everyone will be held accountable for their own job expectation, and no one will be pulled out of their area for more than fifteen minutes a day. The night managers will make sure that they have associates working in areas that have the largest amount of freight in order to keep the department managers from being over whelmed. Stronger relationships may develop between the teams; however, some teams like to work without other teams being involved. Take the ICS team for example; they do not trust anyone to count what is coming in on the truck. If an upper member of management scans what comes in on the truck they do not have much of a choice. If a new employee is in training they have to gain trust within this group before they let them work by themselves. And finally organizational learning can take place among team members. The can learn how to work together by coming up with better ways to find solutions to the problems they may encounter within their team (Baack, D., 2012). They can learn how to deal with each other on a personal level because they may have learned what each team needs. If the meetings continue to be given between these three teams on a weekly basis, this will teach them. In conclusion, there conflicts can make it difficult for team to work together. This paper was to show ways that teams could resolve their conflicts in order to help their organization to run smoothly and put a handle on conflicts. References Baack, D. (2012). Organizational behavior. San Diego, CA: Bridgepoint Education, Inc Montgomery, M., (1995). Five steps to resolves conflicts. Supervisory Management, 40(10), 8 Shetach, A., (2012). Conflict Leadership. Navigating Toward Effective and Efficient Team Outcomes. Journal for Quality Participation, 35(2), 25-30
Monday, August 5, 2019
Models of Change Tasks at Tata Motors
Models of Change Tasks at Tata Motors Tata Motors Limited is Indias largest automobile company, with consolidated revenues of US$20.5 billion in 2009-10. It is the leader in commercial vehicles in each segment, and among the top three in passenger vehicles with winning products in the compact, midsize car and utility vehicle segments. The company is the worlds fourth largest truck manufacturer, and the worlds second largest bus manufacturer. The companys 25,000 employees are guided by the vision to be Best in the manner in which we operate, best in the products we deliver, and best in our value system and ethics. Established in 1945, Tata Motors presence indeed cuts across the length and breadth of India. Over 5.9 million Tata vehicles ply on Indian roads, since the first rolled out in 1954. Following a strategic alliance with Fiat in 2005, it has set up an industrial joint venture with Fiat Group Automobiles to produce both Fiat and Tata cars and Fiat powertrains. The companys dealership, sales, services and spare parts network comprises over 3500 touch points; Tata Motors also distributes and markets Fiat branded cars in India. Tata Motors, the first company from Indias engineering sector to be listed in the NewYork Stock Exchange (September 2004), has also emerged as an international automobile company. Through subsidiaries and associate companies, Tata Motors has operations in the UK, South Korea, Thailand and Spain. Among them is Jaguar Land Rover, a business comprising the two iconic British brands that was acquired in 2008. In 2004, it acquired the Daewoo Commercial Vehicles Company, South Koreas second largest truck maker. Task 1: a) Kurt Lewins change management model The concept of change management is a familiar one in most businesses today. But, how businesses manage change (and how successful they are at it) varies enormously depending on the nature of the business, the change and the people involved. And a key part of this depends on how far people within it understand the change process. One of the cornerstone models for understanding organizational change was developed by Kurt Lewin, a physicist as well as social scientist, Back in the 1950s, and still holds true today. His model is known as Unfreeze Change Refreeze, refers to the three-stage process of change he describes. Unfreeze This first stage of change involves preparing the organization to accept that change is necessary, which involves break down the existing status quo before you can build up new way of operating. To prepare the organization successfully, you need to start at its core you need to challenge the beliefs, values, attitudes, and behaviours that currently define it. Using the analogy of a building, you must examine and be prepared to change the existing foundations as they might not support add-on storeys; unless this is done, the whole building may risk collapse. This first part of the change process is usually the most difficult and stressful. When you start cutting down the way things are done, you put everyone and everything off balance. You may evoke strong reactions in people, and thats exactly what needs to done. By forcing the organization to re-examine its core, you effectively create a (controlled) crisis, which in turn can build a strong motivation to seek out a new equilibrium. Without this motivation, you wont get the buy-in and participation necessary to effect any meaningful change. Change After the uncertainty created in the unfreeze stage, the change stage is where people begin to resolve their uncertainty and look for new ways to do things. People start to believe and act in ways that support the new direction. The transition from unfreeze to change does not happen overnight: People take time to embrace the new direction and participate proactively in the change. A related change model, the Change Curve, focuses on the specific issue of personal transitions in a changing environment and is useful for understanding this specific aspect in more detail. In order to accept the change and contribute to making the change successful, people need to understand how the changes will benefit them. Not everyone will fall in line just because the change is necessary and will benefit the company. This is a common assumption and pitfall that should be avoided. Time and communication are the two keys to success for the changes to occur. People need time to understand the changes and they also need to feel highly connected to the organization throughout the transition period. When you are managing change, this can require a great deal of time and effort and hands-on management is usually the best approach. Unfortunately, some people will genuinely be harmed by change, particularly those who benefit strongly from the status quo. Others may take a long time to recognize the benefits that change brings. You need to foresee and manage these situations. Refreeze When the changes are taking shape and people have embraced the new ways of working, the organization is ready to refreeze. The outward signs of the refreeze are a stable organization chart, consistent job descriptions, and so on. The refreeze stage also needs to help people and the organization internalize or institutionalize the changes. This means making sure that the changes are used all the time; and that they are incorporated into everyday business. With a new sense of stability, employees feel confident and comfortable with the new ways of working. The rationale for creating a new sense of stability in our every changing world is often questioned. Even though change is a constant in many organizations, this refreezing stage is still important. Without it, employees get caught in a transition trap where they arent sure how things should be done, so nothing ever gets done to full capacity. In the absence of a new frozen state, it is very difficult to tackle the next change initiative effectively. How do you go about convincing people that something needs changing if you havent allowed the most recent changes to sink in? Change will be perceived as change for changes sake, and the motivation required to implement new changes simply wont be there. As part of the Refreezing process, make sure that you celebrate the success of the change this helps people to find closure, thanks them for enduring a painful time, and helps them believe that future change will be successful. McKinsey 7S framework The McKinsey 7S model involves seven interdependent factors which are categorized as either hard or soft elements: Hard Elements Soft Elements Strategy Structure Systems Shared Values Skills Style Staff Hard elements are easier to define or identify and management can directly influence them: These are strategy statements; organization charts and reporting lines; and formal processes and IT systems. Soft elements, on the other hand, can be more difficult to describe, and are less tangible and more influenced by culture. However, these soft elements are as important as the hard elements if the organization is going to be successful. The way the model is presented in Figure 1 below depicts the interdependency of the elements and indicates how a change in one affects all the others. http://www.mindtools.com/media/Diagrams/mckinsey.jpg Lets look at each of the elements specifically: Strategy: the plan devised to maintain and build competitive advantage over the competition. Structure: the way the organization is structured and who reports to whom. Systems: the daily activities and procedures that staff members engage in to get the job done. Shared Values: called superordinate goals when the model was first developed, these are the core values of the company that are evidenced in the corporate culture and the general work ethic. Style: the style of leadership adopted. Staff: the employees and their general capabilities. Skills: the actual skills and competencies of the employees working for the company. Placing Shared Values in the middle of the model emphasizes that these values are central to the development of all the other critical elements. The companys structure, strategy, systems, style, staff and skills all stem from why the organization was originally created, and what it stands for. The original vision of the company was formed from the values of the creators. As the values change, so do all the other elements. The model is based on the theory that, for an organization to perform well, these seven elements need to be aligned and mutually reinforcing. So, the model can be used to help identify what needs to be realigned to improve performance, or to maintain alignment (and performance) during other types of change. Whatever the type of change restructuring, new processes, organizational merger, new systems, change of leadership, and so on the model can be used to understand how the organizational elements are interrelated, and so ensure that the wider impact of changes made in one area is taken into consideration. You can use the 7S model to help analyze the current situation (Point A), a proposed future situation (Point B) and to identify gaps and inconsistencies between them. Its then a question of adjusting and tuning the elements of the 7S model to ensure that your organization works effectively and well once you reach the desired endpoint. John P Kotters eight steps to successful change American John P Kotter (b 1947) is a Harvard Business School professor and leading thinker and author on organizational change management. Kotters highly regarded books Leading Change (1995) and the follow-up The Heart Of Change (2002) describe a helpful model for understanding and managing change. Each stage acknowledges a key principle identified by Kotter relating to peoples response and approach to change, in which people see, feel and then change. Kotters eight step change model can be summarised as: Increase urgency inspire people to move, make objectives real and relevant. Build the guiding team get the right people in place with the right emotional commitment, and the right mix of skills and levels. Get the vision right get the team to establish a simple vision and strategy, focus on emotional and creative aspects necessary to drive service and efficiency. Communicate for buy-in Involve as many people as possible, communicate the essentials, simply, and to appeal and respond to peoples needs. De-clutter communications make technology work for you rather than against. Empower action Remove obstacles, enable constructive feedback and lots of support from leaders reward and recognise progress and achievements. Create short-term wins Set aims that are easy to achieve in bite-size chunks. Manageable numbers of initiatives. Finish current stages before starting new ones. Dont let up Foster and encourage determination and persistence ongoing change encourage ongoing progress reporting highlight achieved and future milestones. Make change stick Reinforce the value of successful change via recruitment, promotion, new change leaders. Weave change into culture. Task 1: b) Change should not be done for the sake of change its a strategy to accomplish someoverall goal. Usually organizational change is provoked by some major outside driving force, e.g., substantial cuts in funding, address major new markets/clients, need for dramatic increases in productivity/services, etc. Typically, organizations must undertake organization-wide change to evolve to a different level in their life cycle, e.g., going from a highly reactive, entrepreneurial organization to more stable and planned development. Transition to a new chief executive can provoke organization-wide change when his or her new and unique personality pervades the entire organization. Tata Motors was predominantly a manufacturer of commercial vehicles, and that is a very cyclical business. The commercial-vehicle market in India shrank by more than 40 percent, with massive consequences for both the top and, more particularly, the bottom lines of the company. The 110 million US$ loss was the first time something on this scale had happened in the companys history, and it really shook everybody within the organization. They tried to understand what had gone wrong and wanted to create a path for the future to ensure that they never got into such a situation again. So they decided on a recovery strategy that had three distinct phases, each of which was intended to last for around one and half years and 5 years in all. Phase one was intended to stem the bleeding. Costs had to be reduced in a big way, and that was going to be a huge challenge for a company that was not only the market leader but had been used to operating in a sellers market and employing a cost-plus approach to pricing. Phase two was to be about consolidating their position in India, and phase three was to involve going outside India and expanding operations internationally. Task 1: c) To be an effective leader of an organization requires you to do five things: Understand and interpret the environment in which he operate Develop winning strategies Execute them brilliantly; Measure the impact of your strategies followers. If you get results, people will support you, systematically, adjusting strategies as often without caring too much about how you got indicated. Develop organizational, departmental; the world wont retain the support of your followers team and personal capabilities. Team building is an application of various techniques of Sensitivity training to the actual work groups in various departments. These work groups consist of peers and a supervisor. Task 2: a) In recent times Tata Motors have faced a lot of challenge especially from the growing competition and globalization. To fight back these external evils, Tata Motors came out with plans of expansion to fight back competition via mergers and acquisitions and to fight back globalization it decided to cut costs and thereby introduced the worlds cheapest car. But all these activities had severe implications on its internal organizational change. Change was seen both on the management and at the employee level. At the management level change was seen for cutting costs and providing the cheapest car to the world market and at the employee level change was seen because of the much needed Tata Motors to merge with Daewoo, which caused a lot of change in its employees. Task 2: b) Enterprise-wide change is undertaken as a matter of survival. It is not an option and it is not a whim. Change carries high costs in terms of human and physical resources, share prices, stakeholder insecurity, customer dissatisfaction, receivables and cash flow. The reality is often a painful period of change, during which resistance is high, morale is low, productivity is falling, and confusion is rampant. (Calvello Seamon, 1995) No organization undertakes this lightly. So, the question is, if the cause is just, the need is clear, the alternatives evaluated, and the path to success communicated so that anyone in the organization can see that the change is not optional but essential, why does the change fail? The answer, Just being right isnt enough: you have to win the hearts and minds of the people who will make the change happen. (Marsh, 2001) There is no disembodied organization that can be changed. Only the people within an organization can make planned change a reality by changing their behaviours and the ways they relate to one another. Implementing change in an organization forces people to alter how they relate to one another. Not only do their goals, processes, equipment, and reality change but the very way they deal with others in the organization changes. This causes anxiety and anxiety causes resistance. only people who instigate change enjoy it; other have to suffer it. (Marsh, 2001) Faced with forced change many employees feel threatened believing that they will lose power, prestige, competence, and security. They feel that what is happening is beyond their control, outside their sphere of influence, and they fear it. Depending on how the particular organization has managed past change, the fears may be well grounded in experience. Task 3: a) The changes that have happen within organizations around the world over the last five years, have revolutionized how organizations will continue to operate for the next five years. Ãâà Businesses have realized that people are more important, whether that be the customer or the employees. Ãâà Employees must be happy, self assured, educated, trained, motivated, and leaders in order to be able to create the type of business that produces quality product. Ãâà The customer must be happy, and if the employees are not happy, they have a hard time making the customers happy. Ãâà Task 3: b) Stakeholder Analysis is the process that: Is intended for group stakeholders and Understands what stakeholders expect from the project and what they need in relation to potential risks Identifies actions to minimize project risks and maximize benefits by working with the stakeholders. This covers organisational stakeholder analysis but you might ask What do I do about directly involving people? There are two basic approaches to this which can be summed up as Representation v Delegation. Both have advantages and drawbacks. Representation: Attempts to take in the full range of views, interest groups and organisational units as part of the full decision making process. Characterised by democratic, committee-type decision-making. Advantages Disadvantages Covers full range of views An obvious route to gain widespread acceptance of decisions Involves people who may have limited knowledge of the subject area Slows decision-making Can result in compromises which dont really represent best fit in any particular area Delegation: Delegates responsibility to those identified as being best suited to the job. Advantages Disadvantages Work carried out by those with appropriate skills and knowledge Permits project to move forward more rapidly Acceptance relies on trust in those delegated may be an alien approach in the education culture Needs care to ensure that all relevant issues are properly understood and covered Task 3: c) A change management strategy identify, prioritise, engage and assess stakeholders. Explicit areas of spotlight include: Ensure that all key stakeholders have an adequate understanding of the objectives, timeline and process. Ensure that stakeholders who will be significantly impacted by the initiative or the change resulting from it have a clear understanding of how and when they will be affected. Influence stakeholder attitudes to become more positive (or at least less negative) towards the initiative and/or the change that it will bring about. Establish an effective feedback loop between the stakeholder group and the project team. Task 3: d) The three greatest barriers to organizational change are most often the following. Inadequate Culture-shift Planning. Most companies are good at planning changes in reporting structure, work area placement, job responsibilities, and administrative structure. Organizational charts are commonly revised again and again. Timelines are established, benchmarks are set, transition teams are appointed, etc. Failure to foresee and plan for resultant cultural change, however, is also common. When the planning team is too narrowly defined or too focused on objective analysis and critical thinking, it becomes too easy to lose sight of the fact that the planned change will affect people. Even at work, people make many decisions on the basis of feelings and intuition. When the feelings of employees are overlooked, the result is often deep resentment because some unrecognized taboo or tradition has not been duly respected. Lack of Employee Involvement. People have an inherent fear of change. In most strategic organizational change, at least some employees will be asked to assume different responsibilities or focus on different aspects of their knowledge or skill. The greater the change a person is asked to make, the more pervasive that persons fear will be. There will be fear of change. More important, however, there will be fear of failure in the new role. Involving employees as soon as possible in the change effort, letting them create as much of the change as is possible and practical is key to a successful change effort. As employees understand the reasons for the change and have an opportunity to try the change on for size they more readily accept and support the change. Flawed Communication Strategies. Ideal communication strategies in situations of significant organizational change must attend to the message, the method of delivery, the timing, and the importance of information shared with various parts of the organization. Many leaders believe that if they tell people what they (the leaders) feel they need to know about the change, then everyone will be on board and ready to move forward. In reality, people need to understand why the change is being made, but more importantly, how the change is likely to affect them. A big picture announcement from the CEO does little to help people understand and accept change. People want to hear about change from their direct supervisor. A strategy of engaging direct supervision and allowing them to manage the communication process is the key to a successful change communication plan. Task 4: a) RELEVANCE OF THE MODELS OF CHANGE Kurt Lewin theorized that there are three stages to change: Unfreezing: Old ideals and processes must be tossed aside so that new ones may be learned. often, getting rid of the old processes is just as difficult as learning new ones due to the power of habits. Just as a teacher erases the old lessons off the chalkboard before beginning a new lesson, so must a leader help to clear out the old practices before beginning the new. During this part of the process you need to provide just a little bit of coaching as they are unlearning not learning and a lot of cheerleading (emotional support) to break the old habits. Changing: The steps to the new ideals are learned by practicing: W h a t I h e a r , I f o r g e t . W h a t I s e e , I r e m e m b e r . W h a t I d o , I u n d e r s t a n d . Although there will be confusion, overload and despair, there will also be hope, discovery, and excitement. This period requires a lot of coaching as they are learning and just a little bit of cheerleading due to the affect of Arousal Overloading. Refreezing: The new processes are now intellectually and emotionally accepted. What has been learned is now actually being practiced on the job. Just a little bit of coaching is required and a lot of cheerleading is used to set up the next change process. . . remember it is c o n t i n u o u s process improvement! Task 4: b) 1. Formulation of a clear strategic vision: In order to make a cultural change effective a clear vision of the firms new strategy, shared values and behaviours is needed. This vision provides the intention and direction for the culture change. 2. Display Top-management commitment: It is very important to keep in mind that culture change must be managed from the top of the organization, as willingness to change of the senior management is an important indicator (Cummings Worley, 2005, page 490). The top of the organization should be very much in favour of the change in order to actually implement the change in the rest of the organization. De Caluwà © Vermaak (2004, p 9) provide a framework with five different ways of thinking about change. 3. Model culture change at the highest level: In order to show that the management team is in favour of the change, the change has to be notable at first at this level. The behaviour of the management needs to symbolize the kinds of values and behaviours that should be realized in the rest of the company. It is important that the management shows the strengths of the current culture as well, it must be made clear that the current organizational does not need radical changes, but just a few adjustments. 4. Modify the organization to support organizational change: The fourth step is to modify the organization to support organizational change. 5. Select and socialize newcomers and terminate deviants: A way to implement a culture is to connect it to organizational membership, people can be selected and terminate in terms of their fit with the new culture. 6. Develop ethical and legal sensitivity: Changes in culture can lead to tensions between organizational and individual interests, which can result in ethical and legal problems for practitioners. This is particularly relevant for changes in employee integrity, control, equitable treatment and job security. Change of culture in the organizations is very important and inevitable. Culture innovations is bound to be because it entails introducing something new and substantially different from what prevails in existing cultures. Cultural innovation is bound to be more difficult than cultural maintenance. People often resist changes hence it is the duty of the management to convince people that likely gain will outweigh the losses. Besides institutionalization, deification is another process that tends to occur in strongly developed organizational cultures. The organization itself may come to be regarded as precious in itself, as a source of pride, and in some sense unique. Organizational members begin to feel a strong bond with it that transcends material returns given by the organization, and they begin to identify with in. The organization turns into a sort of clan. Marsh, Christine. (2001, March). Degrees of Change Resistance or Resilience. Performance Improvement, v40 n3 pp 29-33.
Principles Of Information Security And Governance Information Technology Essay
Principles Of Information Security And Governance Information Technology Essay The progress and expansion of the field of information technology and worldwide network has given birth to the issues like, violation of information security, hacking and virus attacks. Information security governance play vital role in providing regular protection of information from a wide range of threats to ensure business continuity. It helps minimize risk factors, maximize profits, investment returns, and boost the reputation. Virus attacks, hacking and information theft are some of the basic dangers faced by many organizations, and the solution lies not only in the hands of technology but management as well. Information security failure or poor management lead to business and financial loss and reputation damage. I will be shedding light upon the principles, risk factors, privacy threats and then the required strategies, policies and procedures for administration and management of an information security and governance program in my organization. Information Security Governance A structured framework of policies, procedures and authority of handling, sharing and recording information securely and confidentially is termed as information security governance (NHS, 2005). A successful information security governance in an organization ensures the confidentiality, integrity, availability, authentication and identification, authorization, accountability and privacy (Whitman and Mattord, 2009, p. xvii) of information and data related to security and reputation of an organization. Information governance in an organization requires teamwork, where all the staff members are aware of the importance of the confidentiality of information. This framework makes sure that the information and data is secure with accuracy and also that the information are shared and recorded in compliance with all the legal and lawful procedures and proper set of rules and guidelines (Simmons, Scott, et al., 2006). Information security governance compliments the Information technology and corporate governance and is an important segment of both. Most of the companies in order to provide a contemporary environment to the information system of governance are using internationally recognised frameworks like; COBIT and ISO 17799. The Control Objectives for Information and related Technology (COBIT) is a framework designed in 1992, by the IT Governance Institute (ITGI) and the Information Systems Audit and Control Association (ISACA). This framework works for the IT management in implementing and developing the Information security governance on a wider platform. It includes the threat analysis, risk assessment, cost estimation as well as countermeasures and future (Solms, 2005). Figure 1 : Proposed Integrated IT Governance Framework (Dahlberg and Kivijà ¤rvi, 2006). Figure 1 shows a proposed integrated IT governance framework. A successful information governance structure builds on the integration between the structural and processes perspectives of IT governance, business-IT alignment, and senior executives needs (Dahlberg and Kivijà ¤rvi, 2006, p. 1). The framework requires the involvement of the management board, executive and subject steering committees, service delivery teams and all the staff members related to the networking, systems, applications, desktops and cross functional works (Richardson, 2010, Q 3). Implementation and administration of IT security are carried out by the Information security management of the organisation which help identify the levels of requirements. Information security management follows a methodology or framework which include top management commitment and information security policies (Ghonaimy, El-Hadidi, et al., 2002). Information security governance ensures that the information security management establish, implement, monitor, and review these procedures and policies in order to meet the business objectives of the organization (Pironti, 2008). The Information security team is responsible for handling security issues regarding the safety and confidentiality of companys information and data protection. It also helps maintain the integrity and availability of information. Information security management deals with the security team, organisational culture, change management, assessment risk factors, people and risk behaviour. It is responsible for the deve lopment of strategies, policies and procedures to reduce threats, risks and attacks. The Security team presents to the management team the security analysis, reviews and implementation plans (Parker, 1981). Information Security issues and risk factors A hack, a virus or a denial-of-service attack may have the effect of halting business operations (Ross, 2008, p 1). The main dangers faced by many organizations include, identity theft, leakage of personal information, data manipulation and modification and improper access to security passwords and secure areas. Widespread IT security risks include; malware, hacking the system, terrorism, extortion, people and non compliance behaviour of the staff and mangers. These dangers can affect the overall reputation of the company and stakeholders become concerned. Main losses and threats include; loss of Confidentiality, integrity, availability, authenticity and reliability of information, which require protection (Stoneburner, Goguen, et al., 2002). Confidentiality threat means the unauthorised access to secure information. The breach of confidentiality can occur in number of ways, like the absence of the screen savers on the personal computers and laptops would invite dangers like leakage of data information as staff members or any external visitor with bad intentions can easily access them. Similarly, the post-it notes with id and passwords reminders would pose the same violence of confidentiality. Secondly, the direct access to the server room key would be like inviting security theft and accessibility of the unauthorised person (Stoneburner, Goguen, et al., 2002). Integrity implies unauthorised modification and manipulation of data. Unauthorised access implies leakage of important information which could mean that anyone can steal or misuse the confidential information of the company and this could lead to the distribution; alteration and stealing of personal data and identities of key personnel and hacking and virus attacks on the organization secure system. An employee can misuse the data information by changing the main figures, mistyping or deleting important information by accident or on purpose. When members of staff take the official laptops home with unencrypted personal information, this could mean the leakage and distribution of confidential data going in the wrong hands (Stoneburner, Goguen, et al., 2002). Availability means providing accessibility only to the authorised users. Loss of availability of data could be caused by attacks like hacking, virus or hardware failure. Unavailability of system to the end-users could mean for example affecting the productivity time and hence affecting the organisational goals of the company (Stoneburner, Goguen, et al., 2002). There are number of other issues and risk factors regarding information security that can threaten the Information security governance. Lack of professionalism of the employees can generate many high risk issues, for example, sending unofficial emails within the organization indicate improper use of internet, which is wrong and unethical. Plus if someone is incharge of companys high risk or sensitive data information then internet browsing or emailing can easily invite virus attacks or hacking. Information Security Strategies, Policies and Procedures These risk factors and security issues require proper security policies and advanced framework. Although the HR department already possess a set of security policies and procedures but they are seldom implemented. The information security governance program works with the risk management program with strategies, security policies and procedures to work effectively in providing a completely secure environment. Information governance ensures application of all the security policies (Nagarajan, 2006). Risk analysis is very important before implementing information security rules, strategies, policies and controls. Risk analysis forms the basis of risk management system. Implementations of information security in an organization comprise six major activities: Policy development, understanding roles responsibilities, suitable information security design, regular monitoring, security awareness, training and education. Now in order to achieve reliable information security essential elements of control within the organization is required. Security controls include technical and non-technical controls. Technical Control Technical control provides logical protection by implementing protective software into the system. This includes; access control mechanisms, identification and authentication mechanisms, data encryption, access control list and intrusion detection system, plus other software and hardware controls. Computer security can be achieved by creating strong passwords, updated anti-viruses anti-malwares, firewalls, screen savers, proper encryption and creating backup files (Stoneburner, Goguen, et al., 2002). Keeping in minds that the passwords should be strong and well protected and employees must not share them with anyone and these passwords should be changed periodically. Organisations must have incident response procedures which include the backup generators for electric failure and off-location data centres in case of natural disasters or accidents. Non-technical Controls Management control include management and administration of security policies, operational measures, risk assessments and training and education. Management control is responsible for educating staff members to guide them in handling the case sensitive data and information through a suitable security awareness program. HR team should conduct a proper background check on the employees and especially on the ones who are incharge of handling confidential information in addition to providing proper training to the staff members. The administrative control should also inform employees the UK legislation and laws of data protection that are in place. Internet threats can be handled by educating staff member and creating an awareness of confidentiality, prohibiting web browsing, chatting and useless emailing within the computers containing confidential information and downloading software from unknown or unprotected sources. Moreover, their level of computer literacy must be analysed in or der to identify their capabilities in handling information. It must also administer the authorization and re-authorization of the system (Stoneburner, Goguen, et al., 2002). Security awareness program should provide security training and must also analyse the level of computer literacy in each employee. Information security officer must administer and implement information security awareness program, which should include providing training and awareness to the senior management, staff and employees involved in handling data information as well as educating the end-users or the clients. Involvement of all the users within the organisation is essential (Ghonaimy, El-Hadidi, et al., 2002). Operational control include physical control and environmental security. It plays a vital role in implementing administrative and technical controls. Operational security ensures the quality of electric supply, humidity, temperature controls and physical facility protection system. Some examples include; backup generator, physical intrusion detection systems like alarms and motion detectors. This system also monitors and controls physical accesses to the secured areas, some examples include; locks, doors, cameras, security guards and fencing (Stoneburner, Goguen, et al., 2002). The HR department should provide security awareness training to the staff members and must make sure that when appointing a new employee, the contract of employment must include the security policies and procedures. These security controls should be revised and renewed annually in order to achieve successful information security. All these essential controls and security awareness program must be implemented by the Human Resource department. Information security culture Peoples behaviour and attitude towards their working atmosphere forms the organisational culture of the organisation. Information security culture evolves from the behaviour and attitudes of the people towards confidentiality, integrity and availability of the organisational information and knowledge. It includes people, training, processes and communication because the inside behaviour poses a more serious threat to the security of information than outside behaviour (Ghonaimy, El-Hadidi, et al., 2002, p. 204). It is therefore essential to understand and analyse the organisational and corporate culture of the organisation as well as the need to change the security culture within the organisation. Threat analysis would indicate how much the organisational culture contributes towards the violation of security and it should be changed accordingly by educating staff members (Ghonaimy, El-Hadidi, et al., 2002). Figure 2 describes a proposed information security culture in an organisation. Figure 2 : A proposed information security culture (Ghonaimy, El-Hadidi, et al., 2002). A healthy security culture is achieved when people in the environment are trained to handle the clients confidential information securely and are completely aware of the threats and dangers around them regarding information theft; hacking and virus/malware attacks and they should be trained to handle these situations with confidence and responsibilities (Richardson, 2010, p. 3). Information security culture can change the organisational culture in a positive way. For example, the staff must understand that if servicing or repairing is required than this should only be handled by an authorized person. Security culture depends upon the managerial attitude, including the top management, security awareness and training and awarding of security conform behaviour (Ghonaimy, El-Hadidi, et al., 2002). Risk Management System However, the information security policy alone cannot be counted upon to effectively eliminate these threats because it narrowly focuses on the use of technology to mitigate threats as the nature of threats and attacks have changed to become highly targeted, highly effective and nonadvertised (Pironti, 2008, p. 1). Therefore a proper risk management model is compulsory. The ever changing faces of attacks and dangers on the information security require proper risk management system which must be understood and supported by the senior management and business leaders of the organization, to identify and finalize investment levels utilizing proper information protection and risk management capabilities. Moreover, regular reporting is essential to demonstrate the effectiveness of the Information Risk management practices. This model will definitely improve the efficiency of the information security team in following the Risk management teams decisions, which is made by the higher officials, who can have the valuable approach towards information infrastructure and can make these decisions effectively. The corrective approach of a successful risk management program depends upon the presence of a single team leader (Pironti, 2008). Information risk management program helps in characterizing and analyzing whole system of companys information highlighting risk factors and information infrastructure. It combines individual functional capabilities into one single well managed and well oriented organization enhancing business strategies. It increases the efficiency of security teams. It produces a bridge of confidence and communication between the team and the leaders. This program provide protection against wide range of threats in terms of security theft not by limiting access but by evaluating appropriateness and requirement of extent of that access, which in turn does not stop an organization to achieve their targets (Pironti, 2008). Conclusion In order to achieve a level of satisfaction in terms of confidentiality, integrity and availability of companys case sensitive information and data protection, reliable information security governance is required. This framework must include the implementations, renewal and revision of the strategies and policies within the organisation, understanding the need to change the organisational security culture and monitoring and management of the information security team with the supervision of the top management. However with the expansion of global network day by day, there are major risk factors of viruses and malware which require a risk management system as well. These policies, strategies and procedures must be implemented through the HR department including hiring and training of security officers and staff members with the approval of the top management. Appendix A: Summary of the paper presentation Key Elements of an Information Risk Management Program As part of our MSc assessment we were asked to take part in a paper presentation on the key elements of an Information Risk Management system based on a paper written by John Pironti, which was published in 2008 in the Information Systems Control Journal, Volume 2. Information security has become more challenging with the ever-changing and evolving faces of threats in the information processing. The adversary creates a new threats as soon as the defender develops and implements the defensive controls. The defenders get affected by the ethics, rules, knowledge, time, and lack of investment and resources. The adversaries can only be defeated by a suitable Risk management approach by using available assets, resources and potential. Policies, procedures and processes complemented by technology prove far more effective in mitigating security threats than the technology alone. Information security only relies upon the technology to create defences against threats that can easily be downloaded or purchased. The reason is that these components require proper implementation and operation. The organizations Information Risk Management approach identifies which information to protect and the level of protection required to align with organizational goals. It must be understood and supported by the senior management and business leaders of the organization, to identify and finalize investment levels utilizing proper information protection and risk management capabilities. Team Structures in most of the companies today have segregated leaders with the title chief, which is of no significance as the main chief has limited access to the senior positions and business strategies. In order to meet current challenges, all these independent capabilities must be united on a single platform as Information Risk Management program. Information Risk Management Program helps in characterizing and analyzing the whole system of companys information highlighting risk factors and information infrastructure. It combines individual functional capabilities into one single well managed and well oriented organization enhancing business strategies lead by the Chief Risk Officer. The leader becomes the focal point to produces a bridge of confidence and communication between team and leaders regarding all communications about risk identification, mitigation and management. This program provide protection against wide range of threats not by limiting access but by evaluating appropriateness and requirement of extent of that access, which does not stop an organization to achieve their targets. This team leader has regular access to higher officials to provide them correct and update information regarding risk factors and business strategies. Key performance indicators are essential measurement tools for the performance of a business function, process or capability. These indicators need to be assigned thresholds to ensure that they are working within normal limits. The key elements of risk management program include; presence of a Chief Information Risk Officer, Information security, Physical security, compliance, privacy, financial risk, market strategy risk, business operations risks, risk methods, practices, key performance analysis effectiveness, cultural awareness, training, communications, strategy governance and risk oversight board and committee. Information Risk Management serves as a mature progression of information security. The Risk management program structures the Risk management, utilizing existing capabilities and provides a 360 degree holistic view of security risks within the organization. Appendix B: Discussion generated from the paper presentation Q. What do you mean by the holistic view of risks that affect productivity and success? A. A holistic view implies focusing from a high perspective and ensuring that all the organisational requirements are met with relevant policies, processes and procedures complimented by technology rather than certain technical area on which the information security team focuses on. Q. How would you convince the businesses that such a wide model of Risk management program can get implemented with the requirement of so many resources? A. This program probably applies mostly to the larger organisations with more number of people involving different levels so that they are able to map on this new mature model, explaining the benefits and understanding why change the structure of the information governance. Another key element to highlight would be that this model re-uses the existing resources within the organisation. Q. Who decide the key performance indicators in the policy and standards maintained by the Risk Management program? A. Normally it would be something which is discussed by all the actual relevant departments rather than the IT department telling you what your KPI should be. It will be coming from a higher level and senior management. Appendix C: References
Sunday, August 4, 2019
Touch: The Foundation of Infant Growth and Bonding Essay examples -- P
Touch: The Foundation of Infant Growth and Bonding A premature infant is defined by Whaley & Wongââ¬â¢s Nursing Care of Infants and Children as "any infant born before completion of 37 weeks of gestation, regardless of birth weight." (Wong, p. 1999, p.392) Many premature infants are also considered high risk neonates because the major activities of life, including thermoregulation, respiration and digestion, cannot fully function at their time of birth. This poses a problem for both the health professionals and the parents of the infant. The health professionals must closely monitor this vulnerable infant and, in most situations, assist the infant in thermoregulation, respiration, and feeding while the cautious, nervous parents look on, concerned about their childââ¬â¢s progress. The parent or parents often feel removed from their childââ¬â¢s care as another adult cares for their childââ¬â¢s every need. Infant stimulation can be as subtle and slight as touch of the infantââ¬â¢s arm or as much as skin to skin contact th rough holding. Touch actively involves the parents in the their childââ¬â¢s care and has proven to be beneficial for improving the vulnerable, tiny infantââ¬â¢s condition. Parents, as well as medical professionals, should be encouraged to touch these vulnerable tiny infants as much as, if not more than, they would touch a full term infant. Despite their low birth weight, tiny size and vulnerable condition, these infants should be held, caressed and cuddled with as often as possible. The experience of birth for a mother of a premature infant varies drastically from the birth of a normal full term infant because of the lack of infant stimulation or even sight of her newly born child. Peggy, a mother of newly born premature infant states "... ...tion and interaction, medical professionals need to calm the parents and encourage interaction with their child. What better way is there for interaction than touch? References Manginello M.D., Frank P., & Foy DiGeronimo M.D., Theresa. (1991). Your Premature Baby New York: John Wiley & Sons, Inc. Gorski M.D., Peter, & Huntington Ph.D., Lee & Lewkowicz Ph.D., David J. (1987). Handling Preterm Infants in Hospitals: Stimulating Controversy about Timing Stimulation. In Infant Stimulation For Whom, What Kind, When and How Much? (pp. 43-51) (no place of publication): Johnson & Johnson Baby Products. Co. Wong, Donna L. (1999). Whaley and Wongââ¬â¢s Nursing Care of Infants and Children. St. Louis: Mosby, Inc. Ludington-Hoe Ph.D., Susan M., & Golant, Susan K. (1993). Kangaroo Care: The Best You Can Do to Help Your Preterm Infant. New York: Bantam Books, Inc.
Saturday, August 3, 2019
Dr. Charles Richard Drew Essay -- Doctors Medical Health Biography Ess
Dr. Charles Richard Drew Charles Richard Drew was born on June 3, 1904 in Washington, D.C. He was very athletic as a child. Charles attended Dunbar High School where he won letters in track, baseball, basketball and football. He won the James E. Walker Memorial Medal as outstanding all-around athlete. Charles attended Amherst College in Massaschusetts on a scholarship. He was named an all-American halfback and won the Thomas W. Ashley Memorial Trophy as the Most Valuable Player on Amherst's football team. He graduated in 1926 and received the Howard Hill Mossman trophy for his outstanding contributions to Amherst sports. Drew was always interested in science and wanted to pursue a medical career. He attended medical school at McGill University in Montreal, Canada. He participated in sports while in medical school and won many championships. He was captain of the track team and won the all-time top score at McGill in intercollegiate track competition. Drew graduated from McGill in 1933. That year he won the annual prize in neuroanatomy, the study of the structure of the nervous system, and the Williams Prize, passing an examination and scoring in the top five in his class. He interned at the Royal Victoria and Montreal General Hospitals. In 1935, he became an instructor in pathology at Howard University Medical School in Washington, DC. In addition to teaching, he was assistant surgeon at Freedmen's Hospital. In 1938, he was awarded a Rockefeller fellowship to...
Friday, August 2, 2019
Organizational Plans Essay
Many organizations design and implement plans that are put into action to ensure that each department of a company is running as efficiently and as effectively as possible. There are three main plans that organizations use to assist managers with the tasks of achieving their goals; strategic planning, tactical planning, and operational planning. Strategic planning is the broad overview of goals and strategies made by top-level management, which are set for the long-term future. Tactical planning is taking these long-term goals and breaking them down into more specific and direct objectives. ââ¬Å"Operational planning identifies the specific procedures and processes required at lower levels of the organization.â⬠(Bateman & Snell, 2011). All three of these planning procedures are crucial in the success of an organized and successful company. In addition, a business might want to set up a contingency plan. A contingency plan will come into action if any of the prior plans should fail. If we take a look at Subaru of America, we can see that their structure depends on these three organizational plans. This vast of an organization needs as much planning as possible because there is such a variety of departments and management alike, there need to be plans set in place so that the company can operate as one complete unit. Using the strategic plan, Subaru of America is able to let its top-level managers make decisions for future business. Using the tactical plan, the strategic plan is broke down between departments and has specific goals and deadlines. These goals are then passed onto floor managers who in turn put the goals and strategies into action. These goals can either be ââ¬Å"single-use,â⬠or on going day-to-day tasks. References Bateman, T. S., & Snell, S. A. (2011). Management: Leading & collaborating in a competitive world (9th ed.). New York, NY: McGraw-Hill Irwin
Thursday, August 1, 2019
Jungle Rot
Tropical ulcers (also commonly known as Jungle Rot) are necrotic painful lesions that are a result from a mixed bacterial infection. These ulcers are common in hot humid tropical or subtropical areas. They are usually found on the lower legs or feet of children and young adults. Typically, the ulcers have a raised border, and a yellowish necrotic base. The ulcers may heal spontaneously, but in many instances extension may occur which results in deep lesions that can penetrate into muscles, tendons and bone.If the so called Jungle Rot goes untreated it can result in much scar tissue and disability. A person can contract this disease or disorder in the skin from having preexisting abrasions or sores that sometimes begin from a mere scratch. The majority of tropical ulcers will occur below the knee of the patient, usually around the ankle. These lesions can sometimes also occur on the arms, but it is more likely to occur on the lower parts of the body. Most of the people who get this ul cer are subjects with poor nutrition which puts them at a higher risk, or people who do not wear socks or proper footwear and clothing.Jungle rot has been described as a disease of the ââ¬Å"poor and hungry'. Urbanization of populations could be a factor in the disorder seeing as tropical ulcers are usually a rural problem. Sometimes outbreaks can occur; one was recorded in Tanzania in sugarcane workers cutting the crops while barefoot. Another piece of information on these ulcers is that males are more commonly infected than females. There are not really any symptoms from having a tropical ulcer. You are simply Just infected in some way and the ulcer appears. It is initially circular, superficial, very painful, and has purple edges.It will enlarge rapidly across the skin and down into deeper tissues such as the muscle or even the periosteum, which is the fibrous membrane covering the surface of bones. Tropical ulcers (or Jungle Rot) are known to reach several centimeters in diamet er after a couple of weeks. The edges will become thickened and raised at this stage of the ulcers growth. The central crater may also become necrotic, or blackened due to the death of tissue. Sometimes, the ulcer becomes foul smelling and quite simply, very nasty looking or else disgusting.Luckily, there are some known treatments for hese ulcers, although not all of the ulcers are treatable. In the early stages of the ulcers growth antibiotics such as penicillin or metronidazole can be used in combination with a topical antiseptic to reduce the size of the ulcer and ultimately clear the ulcer up altogether. For other subjects, if you simply improve nutrition and vitamins into their diet the ulcer can be healed. Sometimes if you Just keep the infected area clan or elevated the area becomes well. In extreme cases, amputation is necessary, but most of the time the Tropical ulcer can be treated with success.The reatments are usually quite affordable, it all Just depends on the person b eing treated and the amount ot money they nave . This disorder is also curable. The ulcers are known to go away in time as little as a week after being treated. Once a person has been ridded of the ulcer life can go on as normal if the treatment was successful. Sometimes there are complications with the skin pigmentation of the patient after treatment. Victims have been known to have different colors such as bright red, blue, and green around and on the infected area. It is even rare for there to be a color hange from regular pigmentation to orange.Although life goes on normally for some, for others it is different. If a patient's ulcer grew deep into large muscles or a bone, they can be left walking with a limp or other things such as not being able to use their arm or fingers in such ways like lifting things that they used to be able to. There are also more serious cases involving amputation that can put a person in a handicapped position such as having to use crutches to help wal k or only having one arm which limits very many things. There are known to be outbreaks of tropical ulcers, but nothing is said on a person preading the infection to another person physically.
Subscribe to:
Posts (Atom)